This page defines how controls from the Control Library are linked to audits within AuditFlow OS.

Control-to-audit mapping shows which controls were selected for review, which domains were in scope, what evidence was expected, and how findings and actions relate back to the control baseline.

The purpose is to make audit scope traceable, repeatable, and based on defined controls rather than broad themes alone.


Purpose

The purpose of Control-to-Audit Mapping is to:

This mapping helps users show why specific controls were included in an audit.


What Control-to-Audit Mapping Is

Control-to-Audit Mapping is the method used to associate specific controls, or control areas, with an audit.

It shows: