Skip to main content

How to: Set up Policies as Available Evidence

Learn how to set up your policies to be picked up as "Available Evidence" in an Audit.

Written by Suzette Richards

Thoropass is designed to automatically detect if a Policy was created using a Thoropass template. If a Thoropass template is used, it will be displayed as "Available Evidence" in the corresponding Evidence Requests (ER).

Policies that were not created using a Thoropass template, a.k.a Custom policies, are not automatically detected. To include custom policies in "Available Evidence", please add a Policy Type and Related Framework as follows:

  • Log into Thoropass.

  • In the left navigation bar Select Audit Lifecycle , Policies.

  • Select the desired policy.

  • In the right side panel, click the Edit button under Ownership and Details.

  • Complete the Policy Type and Related Framework fields.

    • i.e.: For a SOC 2 ER requesting your Risk management policy, add the Related Framework: SOC 2 and Policy Type: Risk Assessment Policy.

  • Click Update.

If the Policy Types and Related Frameworks match with an Evidence Request, the policy will be picked up and displayed as Available Evidence.

Note: For combined audits, the Related Framework selected must match at least one of the Evidence Request’s Frameworks.

Did this answer your question?