The auditor login
Auditors do not share a member account and do not get a static password. An admin invites them by name and email and picks how long the access lasts: from 1 to 60 days, 30 by default.
- Two factors by design: the invitation email contains a personal link, and opening it is not enough. The auditor requests a 6-digit code that is sent to the invited address, and only that code opens a signed auditor session.
- Abuse limits: at most 5 code requests an hour, 5 attempts per code and 10 failed attempts an hour.
- Time-limited: access ends on the chosen date. A session never outlives the access period.
- Revocable: revoke an auditor and their session stops working on the next request. Regenerating a link invalidates the old one and keeps the same end date.
- Stored as hashes: invitation links are shown once and kept only as a hash.
- Logged: invitations, verifications, revocations and regenerated links appear in the activity log as
auditor.invited,auditor.verified,auditor.revokedandauditor.link-regenerated. - The admin overview lists every auditor with name, email, who invited them, end date and whether the access is active, expired or revoked.
What auditors see
The auditor portal at compliance.dazr.eu/auditor opens on a framework overview with completion per framework, followed by these tabs:
| Tab | Contents |
|---|---|
| Controls | Every control with description, recommendation, evidence (notes, links and files), comments and the full history; filter by framework and status |
| Risks | The risk register with inherent and residual scores, treatment and acceptance |
| Incidents | The incident register with timeline, notification fields and clocks |
| Sub-processors | The vendor register |
| Policies | Policies and their versions |
| Processing | GDPR records of processing and DPIAs, with RoPA and DPIA PDF downloads |
| Statement of Applicability | Applicability and justification per control, with PDF download |
| Documents | The documents linked in the compliance profile |
| Activity | The activity log since the auditor's access began, without free-text details |
Evidence files download through an authenticated proxy, never through a raw storage link. Everything is read-only: any attempt to change data is refused.
Comments, notes and follow-up
- Auditor comments on any control, labelled as auditor comments in the control's thread, next to comments from your own team.
- Auditor notes on incidents, added to the incident timeline as their own entry type.
- Follow-up runs on tasks: turn each observation into a custom task with an owner and due date (from Basic). The due-soon and overdue reminders then chase it like any control, and ISO 22301 and ISO 27001 include their own nonconformity and corrective-action controls.
- Corrective actions from incidents: an incident can link the corrective-action task it produced, so the lesson learned closes in a tracked task.
Dazr does not have a separate findings register with its own workflow; findings live as comments and tasks.
Prepare for Audit and the readiness score
Prepare for Audit runs the questions an auditor asks in the first days of an engagement against your live workspace. Each check is pass, warn, fail or not applicable, with the detail behind it and a link or an inline field to fix it.
| Section | Checks | Examples |
|---|---|---|
| Workspace identity | 6 | Organisation name, country, address, VAT number, security lead, DPO contact |
| Core policy library | 11 | Information security, acceptable use, access control, cryptography, incident runbook, BC/DR plan, asset inventory, supplier register, network diagram |
| Operating evidence | 17 | Control owners, nothing overdue more than 90 days, risk register populated, critical risks mitigated, management review, internal audit, awareness training, phishing test, BC/DR test, backup-restore test, pen test, vulnerability scan, access review |
| Per framework | 2 + specific | All controls owned, controls reviewed in the last 12 months, plus framework checks such as the ISO 22301 BIA and exercise programme |
The score is (passed + 0.5 × warned) / applicable checks, shown as a dashboard card and recorded in the trend. Prepare for Audit is included in Enterprise; on other plans a preview shows how many gaps there are, with the first two in full.
The PDF audit trail and other hand-over files
- PDF audit trail: cover, summary with total, completed, open and overdue controls, completion per framework, outstanding items, a section per framework grouped by theme, the completion log and a sign-off page. Dazr-branded on Basic, with your company name on Pro, fully white-label on Enterprise: your logo, subtitle, footer text and signing officer.
- Statement of Applicability as PDF or XLSX, including approved versions.
- GDPR: Art. 30 records of processing and DPIA reports as PDF.
- Excel and CSV of vendors, assets, incidents, risks, processing activities, DPIAs, controls, members, the activity log, policies, trust-page answers and the SoA (from Basic).
Evidence integrity and the activity log
- Once a control is completed, its evidence note and link are locked. Only the validity date can still change.
- Every state-changing action lands in the activity log with who and when, including actions taken by Dazr support. Search, filter by type and date, and export it.
- The log keeps the most recent 2,000 events on Free, 5,000 on Basic, 25,000 on Pro and 50,000 on Enterprise.