ISOwl’s audit workflow follows ISO 19011 — Guidelines for auditing management systems.
Finding types
Every audit finding is classified into one of four types defined by ISO 19011:NC Mayor
Non-Conformity Major — A significant failure to meet a requirement that puts the management system or its objectives at risk.
NC Menor
Non-Conformity Minor — A limited or isolated failure to meet a requirement that does not undermine the system as a whole.
Observación
Observation — A situation that, while not yet non-conforming, could deteriorate and become a non-conformity if left unaddressed.
OFI
Opportunity for Improvement — A positive suggestion to enhance effectiveness, even though no requirement is violated.
Logging a new finding
Open the Audit module
Navigate to Audit in the left sidebar. The two-column layout loads with the entry form on the left.
Fill in the finding details
Complete the form fields:
| Field | Description |
|---|---|
| ID | Auto-generated identifier (e.g., NC001) |
| Type | Select NC Mayor, NC Menor, Observación, or OFI |
| Date | Date the finding was identified (YYYY-MM-DD) |
| Additional fields | Description, auditor name, clause reference, and any other contextual information |
Findings tracker table
The tracker on the right side of the screen displays all logged findings with the following columns:- ID — Unique finding reference
- Type — NC Mayor, NC Menor, Observación, or OFI
- Date — Date identified
- Status — Current state of the finding (
Abierto)
Audit finding lifecycle
Relationship with other modules
Corrective Action Plan
Promote audit findings into the PAC tracker to assign owners, set due dates, and monitor remediation progress.
Security Metrics
Audit findings feed into the KPIs for closure rate and overdue findings on the Security Metrics dashboard.
Frequently asked questions
Can I edit a finding after submitting it?
Can I edit a finding after submitting it?
Audit findings logged here are immutable records. To update the remediation status or assign corrective actions, use the Findings & Corrective Actions module.
What is the difference between the Audit module and the Findings module?
What is the difference between the Audit module and the Findings module?
The Audit module is a log for findings identified during formal internal audits. The Findings module (PAC) is the corrective action tracking system where you assign owners, due dates, and progress to each finding that requires remediation.
How are finding IDs assigned?
How are finding IDs assigned?
IDs are auto-generated sequentially (e.g.,
NC001, NC002) when a finding is submitted. They cannot be changed after creation.