Audits with explicit scope
Audits now begin with an applicability statement that separates relevant controls from exclusions. Each exclusion keeps its rationale and remains available in results and exports.
Risks teams can treat and approve
Gaps can become risks with probability, impact and exposure. Teams can document mitigation, acceptance or transfer, assign owners, set target dates and review residual risk.
- Suggested scoring that can be reviewed before confirmation
- Internal signatures for accepted or transferred risks
- A consolidated dossier for management review and approval
Policies and evidence with traceability
Policies and evidence can include an owner, reviewer and review date. An approved policy can become evidence from its current version while preserving control and origin links.
Controlled integrations
The new integrations space connects Audexa with NinjaOne, SentinelOne, Jira Cloud and Microsoft Entra. Availability depends on the plan, active modules and organization configuration.
Human review stays central
Automated assessments, mappings and suggestions help teams prioritize, but they do not replace the responsible owner or auditor review.