Skip to main content

Section 5: Drata for Auditors

What Drata Is

Drata is a trust management and continuous compliance automation platform used by your client to manage security, risk, and compliance programs (for example, SOC 2, ISO 27001, and other frameworks). It connects to the client’s technology stack (cloud providers, identity providers, ticketing systems, etc.) to:

  • Continuously monitor and test controls

  • Automatically collect and centralize evidence

  • Maintain an organized control/evidence library for audit readiness

Your client is using Drata so that you and they are working from the same, consistent set of controls and evidence during the audit.


The Drata Audit Portal (Auditor View)

Your access to the client’s environment is through the Drata Audit Portal, a secure, read‑focused workspace that mirrors what the client sees, but scoped for external auditors. From the portal you can:

  • View the audit overview (framework, period, status, assigned auditors)

  • Review requests, related controls, and mapped evidence

  • Download pre‑audit packages and control evidence packages, generated from the same data source as the client’s view

  • Set or adjust audit samples and, where enabled, create/manage requests and mark them Completed

Your client controls your permissions (for example, read‑only, ability to download packages, and which specific audits you can see). All actions are logged for transparency.


What You Can Expect to See

Within the Audit Portal, you will typically have access to:

  • Audit list & details – active and historical audits, including name, period, and status

  • Requests – each mapped to relevant controls and evidence, with status such as New, Prepared, Completed, or Deleted

  • Control Evidence package – ZIP file snapshot of mapped evidence for the defined sample period, identical for both client and auditor

  • Pre‑audit package – exports of policies, control mappings, and other artifacts, again generated from the same underlying data the client sees

  • Messages – secure, audit‑specific messaging between you and the client within Drata (for clarifications or follow‑up requests)

This structure is designed to reduce out‑of‑band evidence transfer (email, shared drives) and keep the audit trail centralized.


Key Resources for Auditors

  1. Auditor Webinar Series (Live & On‑Demand)
    Periodic webinars hosted by Drata’s team that dive deeper into:

    • How auditors work in the Drata Audit Portal

    • Best practices for sample selection, evidence review, and request workflows

    • Common implementation and scoping patterns across frameworks
      Registration (with access to upcoming/live sessions and, where available, recordings): Registration Link

  2. Help Center: Auditor Experience
    Written guide describing the auditor view in Drata, including how it compares to the customer view and how evidence packages behave.


How This Supports the Audit

By using Drata, your client is aiming to:

  • Provide consistent, tamper‑evident evidence directly from connected systems

  • Reduce manual evidence collection and file handling

  • Give auditors a single, structured environment to review controls, evidence, and requests

  • Maintain a clear, exportable audit trail for future periods and follow‑up work

If you have questions about portal access, permissions, or specific reports, your primary contact remains your client; they can adjust access or introduce you to Drata Support or their Drata team as needed.


Did this answer your question?