Skip to content

Products

Compliance Officer Service Expert-led compliance, end to end Compliance Portal Share security documents securely Open-source platform Deploy Probo on your own infrastructure

Resources

Probo stories How teams get compliant with Probo Blog Ideas and guidance from the Probo team Guides & tools Practical compliance guides and free tools Love from Customers What customers say about working with Probo Changelog Latest product updates Download Get the Probo Agent

Company

About The people and vision powering Probo Careers Join the team building Probo Brand assets Official logos and visual resources Security Review our security and compliance posture
Overview Understand Probo and its core concepts Product Explore Probo's GRC capabilities Developers Explore GraphQL, CLI, MCP, n8n, and webhooks Deployment Probo Cloud, self-hosting, and configuration

Explore

GitHub Explore our open-source compliance tools

Audits and findings

Scope audits, connect controls, record findings, and preserve review history

View as Markdown

An audit in Probo represents a defined review of an organization’s compliance program. It provides a place to scope the review, connect relevant controls, and collect the findings produced by that work.

Define the audit independently from a framework. An audit may review all or part of a framework and can connect to controls and supporting program records. This keeps the review boundary explicit even when the organization operates several frameworks.

Findings describe issues or observations identified during an audit or another review. Supported kinds include major nonconformity, minor nonconformity, observation, and exception. A finding can be linked to more than one audit when the same underlying issue affects multiple reviews.

Use a finding for the reviewed issue and tasks or measures for remediation work. This preserves the original conclusion while allowing owners, due dates, and implementation evidence to change as work progresses.

Audit reports are generated from current audit records. Before sharing a report, verify the scope, linked controls, finding classification, and supporting evidence. Document publication and electronic signatures provide separate approval records when a report or policy requires formal sign-off.