Feature sheet

OneAudit

The auditor's own workspace: one engagement, one place to request, review and record a decision.

DesignAuditMVP target Q4 2026
The auditor
Serves
EvidenceEdge
Pairs with
Released material only
Sees
Recorded as made
Decision
Walk the simulation →Request access, at launch← Back to the productPrint or save as PDF for a procurement pack.

What it is

OneAudit is the auditor's side of the engagement, as its own application. Where the evidence workspace serves the organisation being audited, OneAudit serves the firm doing the auditing: one engagement, one place to request, review and record a decision.

It exists because the auditor is the one participant who is usually given a shared folder and a spreadsheet. An audit conducted that way is reconstructed afterwards rather than recorded as it happens.

Who it is for

Certification bodies and audit firms

One engagement in one place: scope, requests, responses and decisions, recorded as the audit happens rather than assembled afterwards.

Internal audit functions

The same discipline applied to internal reviews, with the decision and its reasoning captured at the point it is made.

Auditors currently working from shared folders

The folder and the spreadsheet are how findings lose their context. Here a request stays attached to the control it concerns.

And who it is not for

Capabilities

01
Request in context

A request is raised against the control it concerns, so the answer arrives attached to the question rather than in a mail thread.

02
Only what was released

The auditor sees what the organisation has deliberately released, and internal working state stays internal.

03
A decision is a record

A pass, a finding or a request for change is written as it is made, with its reasoning, and it cannot be quietly amended afterwards.

04
The engagement is the unit

Scope, period and framework are set once, and everything in the engagement inherits them.

How it works

  1. 1
    Open the engagement

    Scope, period and framework are set once. Everything raised inside the engagement inherits them, so nothing has to be restated on each request.

  2. 2
    Raise requests against controls

    A question is attached to the control it concerns, so the answer arrives with its context instead of in a thread.

  3. 3
    Review what has been released

    The organisation decides what to release. You see that, and you can tell what you have not been given, which is often the more useful signal.

  4. 4
    Record the decision as you make it

    A pass, a finding or a request for change is written with its reasoning at the time, and cannot be quietly amended later.

What it does not do

Stated deliberately. A product that only lists what it can do leaves the reader to discover the boundary themselves, usually at the worst moment.

It does not form an opinion for you

The judgement is the auditor's. The application makes it recordable, traceable and hard to lose.

It does not give you access the client has not granted

You see released material. Internal working state stays with the organisation, which is what makes them willing to work in the open.

It does not issue certificates

The certificate remains the certification body's instrument, issued through its own process.

It does not let a decision be rewritten quietly

A decision and its reasoning are recorded as made. Changing a position leaves a trail, because an audit record that can be edited silently is evidence of nothing.

Engagements it supports

ISO 27001SOC 2Certification bodiesInternal audit

How it fits the family

EvidenceEdge

The paired product. What an organisation releases there is what appears here, which is why requests and answers stay attached to their control.

ControlRegistry

Both sides read the same control set, so a request means the same thing to the auditor and to the organisation.

CertEdge

Certification preparation on the client side lines up with the engagement structure here.

Release plan

FeatureMilestoneScope
Engagement with scope, period and frameworkv1.0In MVP v1.0
Requests raised against a controlv1.0In MVP v1.0
Governed view of released evidencev1.0In MVP v1.0
Findings with corrective action trackingv1.1Planned
Decision record and report assemblyv1.2Planned

Milestones are roadmap targets rather than shipped dates. Target for MVP v1.0: Q4 2026. Provisioning is white-glove, never self-serve.

What these products establish, and what they do not

Every SecureEdge Advisory product prepares you for a certification, an audit or an assessment. None of them awards one. A certificate is issued by an accredited certification body, an attestation opinion by an independent auditor, and a regulatory finding by a regulator. We prepare the position and facilitate the process; the affirmation is made by someone else, and we do not blur that line.

Everything a product reports is derived from information supplied by your organisation, or by the person representing it. Ratings, maturity levels, readiness figures, mappings between frameworks and any monetary exposure are calculated from those inputs. Where an input is incomplete, out of date or optimistic, the output carries that forward faithfully. A result is therefore a structured statement of the position you have described, not an independent verification that the position is true.

An assessment is a documented position at a point in time. It is useful precisely because it is explicit about what it rests on, and it should be read that way rather than as a proof. Nothing here is a substitute for an audit, and no output should be presented to a regulator, a customer or a board as one.

SecureEdge Advisory
OneAudit

Part of a family of ten products sharing one governed control library. Provisioning is white-glove and scope follows a due diligence review.

secureedgeadvisory.com
cio@secureedgeadvisory.com
Dubai, United Arab Emirates

Before it can be provisioned