Skip to main content

Create and add auditors to an audit (New experience)

Use this article to create an audit, add auditors, and resolve common reasons an auditor may not have access in Drata.

Updated this week

💡 Still using the classic Drata experience? Refer to Create and add Auditors to your audit for the original UI.

An audit in Drata is how you share your compliance data, evidence, and controls with an auditor in a structured, time-bound way.

Creating an audit defines:

  • What is being audited (framework and audit type)

  • When it’s being reviewed (audit period)

  • Who can access it (assigned auditors)

If these are set up incorrectly, auditors may not see the expected evidence or requests, or may be unable to work in the audit as intended.

Prerequisites

  • The auditor must use a work email address

  • The auditor must exist on the Auditor list

  • The audit period must be set to a valid date range


Create an audit

  1. Go to Compliance > Audits.

  2. Select Create Audit.

  3. Choose how you want to conduct the audit.

  4. Enter the audit details, including:

    • Framework

    • Audit period

      • Auditors can access an audit only when the audit period has started.

  5. Add auditors by:

    • Selecting existing auditors from the dropdown, or

    • Adding new auditors

  6. Save the audit.

ℹ️ What the audit period means

The audit period defines which evidence is included and which dates auditors can sample, and it affects which request‑level downloads are available during that window. It does not control whether an auditor can sign in or open the audit at all.

When creating an audit:

  • Set the start date to a past date or today

  • Set the end date based on the audit scope and timeline

If you’re unsure what dates to use, confirm them with your auditor before creating the audit.

Recap:

  1. The audit period defines which evidence is in scope for this audit and which dates auditors can sample from.

  2. Evidence that falls outside this range is not available to the auditor until you extend the period and they re‑sample.

  3. If the entire audit period is in the future, auditors can open the audit but won’t see any in‑scope evidence yet, and request‑level downloads may not return data until dates fall within the period.


Add or update auditors on an existing audit

You can add or update auditors at any time while the audit is active.

  1. Go to Compliance > Audits.

  2. Open the audit.

  3. In Assigned auditors, select the edit icon.

  4. Add or remove auditors as needed.

  5. Confirm your changes.

Result:
Assigned auditors receive an email invitation to access the audit.


Verify auditor access

If an auditor still can’t access the audit, confirm the following:

  • The auditor is assigned to the audit

  • The audit period is currently active

  • The auditor appears on the active auditor list

  • The auditor accepted the email invitation

Always verify audit cycle dates and auditor assignment before troubleshooting further.

Did this answer your question?