AuditBoard is a cloud-based audit management software solution from the company of the same name in Cerritos.
N/A
Secureframe
Score 9.0 out of 10
N/A
Secureframe, headquartered in San Francisco, helps companies get enterprise ready by streamlining SOC 2, ISO 27001, and HIPAA compliance. Secureframe aims to enable companies to get compliant within weeks, rather than months and monitors 40+ services, including AWS, GCP, and Azur.
Auditboard is especially useful for SOX control testing. It is very convenient having all our information on a single platform. It is easy to communicate PBC requests to clients, store control testing working papers for review, communicate deficiencies and build dashboards to provide visual statistics. Situations where it might not be useful are for organizations that are smaller in size where the templates don't fit well with their internal audit/controls program. There is a significant amount of testing required before using the platform, and adapting working papers to fit in well with AuditBoard
Secureframe is well suited for repeatable compliance tasks like sharing SOC 2 documents through the Trust Center, managing vendor reviews, tracking employee training, and collecting audit evidence. It is less suited for situations that need business judgment or context outside the tool, such as deciding whether a requester is a legitimate customer, answering complex security questionnaires, or helping non-security owners interpret vendor risk questions.
We used to perform our Risk Control Analysis (RCA) for each audit's planning in an Excel spreadsheet. Once we purchased the Risk Oversight module, AuditBoard helped us convert the RCA to a system function rather than a spreadsheet. At first, we lost some of the functionality the spreadsheet provided, but AuditBoard did continue to help us build and work towards a solution more similar to what we previously had. Though happy with it, it's still not perfect. As one example, I'd like to be able to link actual Ops Audit work steps that cover the risk and controls being outlined in the RCA, rather than just adding a comment to state which steps cover them. More of a preference, I suppose.
I also had demoed their beta Resources and Scheduling module, but it didn't have enough functionality at the time to work for how we put the quarterly Internal Audit schedule together (using Excel). One thing I recall was that you couldn't pull in SOX controls or non-chargeable work (such as education or administration) to auditor's schedules; it was meant to schedule the Ops Audits only. It is possible they have already fixed or improved this; I just haven't seen the updated version.
The Questionnaires feature (which assists in RFP's, security questionnaires, etc) could be designed a lot better. I see what they were going for, and based on their track record for improving features I'm sure it will get a refresh, but in it's current state it is the only features that I do not use.
I remember there were a lot of sync issues when I used the internally developed software, but that's probably because a few people were working on the same project at the same time. I have not come across this issue in AuditBoard
From purely comparing marketing sites (unable to trial others), Secureframe had better first time SOC 2 audit documentation and explanations for free to ease you into understanding the processes.
Hard to quantify. It was cheaper than the tool we had and we were able to get rid of standalone tool for surveys. overall, just better user experience for all.