Skip to main content

How to: Set up Policies as Available Evidence

Learn how to set up your policies to be picked up as "Available Evidence" in an Audit.

I
Written by Ian Hamilton
Updated over a week ago

Thoropass is designed to automatically detect if a Policy was created using a Thoropass template. If a Thoropass template is used, it will be displayed as "Available Evidence" in the corresponding Evidence Requests (ER).

Policies that were not created using a Thoropass template, a.k.a Custom policies, are not automatically detected. To include custom policies in "Available Evidence", please add a Policy Type and Related Framework as follows:

  • Log into Thoropass.

  • In the left navigation bar Select Audit Lifecycle > Policies.

  • Select the desired policy.

  • In the right side panel, click the Edit button under Ownership and Details.

  • Complete the Policy Type and Related Framework fields.

    • i.e.: For a SOC 2 ER requesting your Risk management policy, add the Related Framework: SOC 2 and Policy Type: Risk Assessment Policy.

  • Click Update.

If the Policy Types and Related Frameworks match with an Evidence Request, the policy will be picked up and displayed as Available Evidence.

Note: For combined audits, the Related Framework selected must match at least one of the Evidence Request’s Frameworks..

Did this answer your question?