# Create an Audit (Plans 1 and 2)

### Prerequisites

Before you begin:

* You must have the **Admin** role in Sprinto.
* Your compliance framework should be connected if you're creating an integrated audit.
* Relevant zones and integrations should already be configured.

***

### Create an Audit

&#x20;These audits are pre-configured audits tied to a compliance framework (e.g. SOC 2, ISO 27001). These audits automatically map framework requirements to Sprinto’s control set.

#### Steps:

1. **Navigate to** **Audits** from the left navigation menu.
2. **Click** **Plan new audit.**
3. **Fill in audit details** in the "Plan an audit" screen:
   * **Zone**: Select the operational zone the audit applies to (e.g. Pacific).
   * **Audit Type**: Choose **External** or **Internal**, depending on whether it’s conducted by an external auditor.
   * **Framework**: Select the applicable compliance framework (e.g. SOC 2).
   * **Standards for the framework**: Choose one or more control categories (e.g. Security, Confidentiality).

{% hint style="info" %}
Once the audit is created, the framework cannot be changed.
{% endhint %}

<figure><img src="https://3220032727-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FEsyn5VMU6e0OyGjRtKgx%2Fuploads%2FyNsBuzFTCbKQKPoKTc0V%2FL1.jpg?alt=media&#x26;token=f08c5963-f59f-48b8-8565-044acb3c1782" alt="" width="246"><figcaption></figcaption></figure>

4. **Set the evidence collection period**:
   * Select an **evidence collection start date** using the calendar picker.
   * Choose the **duration** (12, 6, or 3 months), or select **Custom** to define your own period.
   * The **end date** will automatically adjust based on your selection, and can be modified if needed.

<figure><img src="https://3220032727-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FEsyn5VMU6e0OyGjRtKgx%2Fuploads%2FNtxGF55lyvivBoXxbjcF%2FProperty%201%3DVariant2.jpg?alt=media&#x26;token=bfc285e9-6187-41eb-a58b-5a64428c1b36" alt="" width="350"><figcaption></figcaption></figure>

5. **Click “Start Audit”** to generate the audit and proceed to the requirement mapping stage.

<figure><img src="https://3220032727-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FEsyn5VMU6e0OyGjRtKgx%2Fuploads%2FWNF6Vr216zqL5ypgjMKM%2FL2%20-%20Custom.jpg?alt=media&#x26;token=fca92fd2-9a8b-4504-b926-15509cc3728c" alt="Custom Audit Drawer" width="246"><figcaption></figcaption></figure>

***

### Add Your Audit Requirements

After you create your audit, you’ll land on the **Summary** page. At this stage, no requirements are linked to your audit.

To begin defining the scope of what the audit will cover, you must add audit requirements.

#### To Add Audit Requirements

1. On the **Summary** page, locate the **Requirements** panel.
2. Select **Add**.

<figure><img src="https://3220032727-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FEsyn5VMU6e0OyGjRtKgx%2Fuploads%2FQgQIWE5EQC2nCtvfriKM%2FAdd%20requirement.png?alt=media&#x26;token=e5fb708d-6d5f-4871-8b1f-66374fc5fa44" alt="" width="246"><figcaption></figcaption></figure>

3. In the side drawer, choose one of the following methods:

#### Upload Your Requirements

Use this method to upload your own list of audit requirements using a CSV file.

**To Upload a CSV File**

1. In the drawer, select **Upload your requirements**.
2. Click Download CSV template to download the template.
3. Fill in the required details and upload the file into the uploader.

<figure><img src="https://3220032727-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FEsyn5VMU6e0OyGjRtKgx%2Fuploads%2FWkWpNBtojmnxlky9TFxk%2FL2%20-%20Upload.jpg?alt=media&#x26;token=567a8b1e-233d-47ba-9d36-1a4198a13ab7" alt="" width="563"><figcaption></figcaption></figure>

3. Review the uploaded requirements.
   * Sprinto displays a preview of the parsed file.
   * Any issues, such as missing fields or formatting errors, are shown with inline guidance.

<figure><img src="https://3220032727-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FEsyn5VMU6e0OyGjRtKgx%2Fuploads%2F4mXQSEFMBEF7ZztIFdFK%2FL2.jpg?alt=media&#x26;token=a3b97898-4954-4781-bffa-67f202f54621" alt="" width="563"><figcaption></figcaption></figure>

4. Make necessary corrections if validation errors appear.
5. Select **Save** to confirm and import your requirements.

{% hint style="info" %}
You can upload additional files later or delete and re-upload files as needed.
{% endhint %}

<figure><img src="https://3220032727-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FEsyn5VMU6e0OyGjRtKgx%2Fuploads%2Fby759RX3q8HUkTjQIE4Y%2FAdd%20requirement.jpg?alt=media&#x26;token=5011549c-9049-4f2b-a721-18a57b297a82" alt="" width="368"><figcaption></figcaption></figure>

***

#### Add Requirements by Framework Criteria

Use this method to select specific requirements from a compliance framework (for example, SOC 2 or ISO 27001).

**To Add Framework-Based Requirements**

1. In the drawer, select **By framework criteria**.
2. Choose a framework and the applicable standards (such as Security or Confidentiality).

<figure><img src="https://3220032727-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FEsyn5VMU6e0OyGjRtKgx%2Fuploads%2FoOV31UzknVfswypktpat%2FL2%20-%20Criteria.jpg?alt=media&#x26;token=e7ed655d-0bde-4bf3-8d1a-3267823b4ded" alt="" width="563"><figcaption></figcaption></figure>

3. Use the search or scroll to locate the relevant criteria.
4. Select the checkboxes next to the requirements you want to include.
5. Select **Save** to confirm.

{% hint style="info" %}
Sprinto auto-populates framework-based requirements with instructions and metadata, where available.
{% endhint %}

<figure><img src="https://3220032727-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FEsyn5VMU6e0OyGjRtKgx%2Fuploads%2FZe6tcMuOekghWdP8WriT%2FL2%20(1).jpg?alt=media&#x26;token=533bdcbf-8670-40a5-92a8-d39e767bb6d4" alt="" width="563"><figcaption></figcaption></figure>

***

#### Add Requirements by Controls

Use this method to convert existing controls into audit requirements.

**To Use Existing Controls**

1. In the drawer, select **By controls**.
2. Choose a framework to filter available controls.

<figure><img src="https://3220032727-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FEsyn5VMU6e0OyGjRtKgx%2Fuploads%2FKTvOwCAplY94yfikXDtL%2FL2%20-%20Controls.jpg?alt=media&#x26;token=a57410d4-6d99-47d1-a665-54f0709dedf9" alt="" width="563"><figcaption></figcaption></figure>

3. Tick the checkboxes next to the controls you want to convert.
4. Select **Add** to confirm.
5. Your selected controls are added as audit requirements with mapped descriptions.

{% hint style="info" %}
This method works best if your controls are already configured in Sprinto.
{% endhint %}

<figure><img src="https://3220032727-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FEsyn5VMU6e0OyGjRtKgx%2Fuploads%2FzHxy2jIUUw3xGJaGqonp%2FL2%20(2).jpg?alt=media&#x26;token=a2f04edc-f206-4fa7-9765-f319606bfaa1" alt="" width="563"><figcaption></figcaption></figure>

### What’s Next?

After creating the audit:

* Monitor completion status via the Audit Dashboard.
* Share access securely with auditors when you're ready.
