Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Create an auditable unit and scope entities at risk

Create auditable units to identify business entities that can possibly be at risk and scope them into audits.

Before you begin

Role required: sn_audit.manager, sn_audit_ws.supervisor, sn_audit.user, sn_audit_ws.auditor

About this task

Auditable units are a combination of different entities such as business units, products or services, legal entities, regulatory required audits, processes, programs, systems, policies, regulation, financial statements, and others.

After you determine the nature and scope of the auditable units, your goal is to perform risk assessments, and scope auditable units and entities based on the risk rating.

See also Perform advanced risk assessment in the Risk workspace.

Procedure

  1. Navigate to All > Audit > Audit Workspace.

  2. Click Create and select Auditable unit from the Home page.

    You can also create an auditable unit by navigating to the Audit workspace List page.

    1. Click the lists icon (
Image omitted: ListsIcon.jpg
List icon.\).
2.  Click **All auditable units** or **My auditable units** in the Scoping list.
3.  Click **New**.
  1. On the form, fill in the fields.
FieldDescription
NumberUnique number of the auditable unit.
NameName of the auditable unit. For example, Accounts Payable – Finance.
StateState of auditable unit. The default state is Draft.
PriorityPriority of the auditable unit.
DescriptionBrief description of the auditable unit.
Assignment
Owning groupGroup that owns the auditable unit.
OwnerOwner of the auditable unit.
Risk assessment
MethodType of risk assessment to obtain the risk rating of the auditable unit. The choices are:- Basic Risk Assessment: Allows you to manually enter a value for the risk rating. - Detailed Risk Assessment: Appears when the Advanced Audit plugin is activated. When you select this option, the Risk Assessments related list appears.
Risk ratingRisk rating of the auditable unit obtained from a basic risk assessment.
Inherent risk ratingInherent risk score. The value in this field is derived from advanced risk assessment. This field appears if the risk assessment method is Detailed Risk Assessment.
Control effectivenessControl effectiveness score. The value in this field is derived from advanced risk assessment. This field appears if the Method field has Detailed Risk Assessment.
Residual risk ratingResidual risk score. The value in this field is derived from advanced risk assessment. This field appears if the Method field has Detailed Risk Assessment.
  1. Click Save.

  2. To add entities such as business units, department, vendors, products, business processes, and others to the auditable unit, click the respective related list in the Details page.

  3. Select the records from the respective pop-up.

  4. Click Add.

  5. Click Activate.

    The state of the auditable unit becomes Active.

  6. To retire the auditable unit, click the Retire button in the more actions icon (

Image omitted: MoreActionsIcon.jpg
More actions icon.\)
  1. If you have GRC: Advanced Risk application installed and if you have selected Risk Assessment Method as Detailed Risk Assessment, then you can assess risk by clicking the Assess risk button.

    For more information, see risk assessment method in Create an auditable unit.