Audit evidence, assessed against the criteria it is meant to satisfy.
Auditwyse reads your policy and evidence documents, maps the obligations in them onto NIST 800-53 and ISO 27001 criteria, and produces a control assessment in which every statement cites the passage it came from. Where the evidence does not settle a criterion, the assessment says so, and states what would resolve it.
- NIST SP 800-53
- ISO/IEC 27001
- CIS BENCHMARKS
- AWS SECURITY HUB
- GUARDDUTY
Beyond checklists. Built for the audit file.
Five stages. Each one writes into a shared knowledge graph that the next stage reads, and every conclusion keeps the citation it was built from.
Compliance knowledge
Obligations and controls are extracted from your policy documents and mapped onto framework criteria. A mapping is accepted only when two independent model families agree on it. Disagreements are left out rather than averaged.
- ✔Obligation 14 → AC-2 Account management
- ✔Obligation 14 → A.9.2.1 User registration
- –Obligation 19 → AC-6(1) not accepted: one family disagreed
- Obligation 20: comparing model families
Access rights are reviewed by the asset owner at least quarterly.
Evidence intelligence
Each uploaded document is parsed, classified, checked for currency, and tested against the criteria it is offered as evidence for. Superseded versions stay on record, because what replaced what is part of the audit trail.
- ✔Classified: access review record
- ✔Dated within period, supersedes Q1 record
- ✔Offered for AC-2(3), A.9.2.5
- Testing against criterion text
quarterly-access-review-Q1.pdf
Narrative assessment
Coverage and a confidence signal are computed for each control, with the reasoning written out and the open questions listed for a human reviewer. Nothing is published to an audit file without that review.
- ✔AC-2 a covered · 2 citations
- ✔AC-2 b covered · 1 citation
- –AC-2 h could not judge · no evidence for account removal timing
- Writing reviewer questions
Infrastructure findings
Security findings your cloud provider has already generated are collected read only and recorded against the same control model, so configuration evidence and document evidence sit in one place.
- ✔Finding read: S3 bucket without default encryption
- ✔Recorded against SC-28, A.10.1.1
- ✔IAM Access Analyzer: 3 findings recorded
- Linking to document evidence for the same control
Audit work papers
The reviewed assessment is frozen into a work paper for the audit file, with the citations it was built from attached.
- ✔Reviewer decision recorded, attributed by name
- ✔4 citations attached as document spans
- ✔Assessment version pinned; later edits create a new paper
- Exporting to the audit file
From documents to a defensible assessment
Four steps, and a person signs off on the last one.
-
Ingest
Policies and evidence are parsed, classified and dated.
-
Map
Obligations are linked to framework criteria, only where two models agree.
-
Assess
Each control gets a coverage count, reasoning, and citations.
-
Review
A named reviewer decides, and the work paper is frozen.
A tool that always answers is easy to build and impossible to defend.
These are product decisions, not gaps waiting to be closed.
What the easy version does
- Issues an opinion. Output shaped like a verdict, with no qualified person behind it.
- Guesses when evidence is missing. A gap becomes a fail, or worse, a pass.
- Reports a compliance percentage. One number that reads as precision the evidence does not support.
- Asks for write access. Broad cloud permissions to read a handful of findings.
What Auditwyse does instead
- Does not issue an audit opinion. It prepares and evidences assessments. The opinion stays with a qualified auditor.
- Does not guess. An unsettled criterion is recorded as could not judge, shown as a neutral state, with what would resolve it.
- Does not report a percentage. Coverage is counts against a stated denominator.
- Does not modify your infrastructure. Read only permissions, with the write side of every service explicitly denied in policy.
Data handling
Documents you provide are processed to extract obligations and to assess control evidence. Assessment output is derived from those documents and stored with references back to the specific passages it was built from, so any conclusion can be traced to its source and checked.
Hosting region, subprocessors, and retention periods are set out in the privacy policy.
Contact
Auditwyse is in active development and is not generally available.
If you are evaluating it for an audit programme, or you are an audit firm assessing it on a client's behalf, get in touch and we will walk you through the current state directly rather than through a demo environment.
Email: consulting@optywise.com