Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Create an issue for an engagement

Create an issue to document policy, risk, or audit observations, or to accept any GRC problems. You can also identify the source of the issue to help analyze and classify the issues.

Before you begin

Role required: sn_audit.manager, sn_audit_ws.supervisor

Procedure

  1. Navigate to All > Audit > Audit Workspace.

  2. Click the lists icon (

Image omitted: ListsIcon.jpg
List icon.\).
  1. Click All engagements or My engagements in the Execution list.

  2. Click the link to the engagement record in the Name column.

    The engagement record details open in the Overview tab.

  3. Click the Other issues related list.

  4. Click New.

  5. On the form, fill in the fields.

FieldDescription
NumberUnique identification number.
NameName of the issue.
Issue sourceSource from where the issue was created. This field is auto-populated with one of the following options based on how the issue is created:- Indicator Failure: Issue is created by a failure of the indicator. - Risk Assessment: Issue is created in a risk. - Risk Event: Issue is created in a risk event. - Control Attestation Failure: Issue is created due to a non-compliant control. - Control Test Failure: Issue is created when a control is ineffective and the control test is marked as closed and complete. - Ad-hoc: Issue is manually created.
Issue typeType of issue.
ClassificationClassification of the issue as a risk, compliance, or audit, based on the issue type.
State- New - Analyze - Respond - Review - Closed Complete - Closed Incomplete
SubstateSubstate and applicable details for the substate.
PrioritySequence in which an issue needs to be resolved, based on its impact and urgency:- 1 — Critical - 2 — High - 3 — Moderate - 4 — Low - 5 — Planning
Issue ratingIssue manager can assign a issue rating to the issue. Based on the issue rating, the Due date in the Dates tab is calculated as follows and displayed:- Very high (2 days) - High (4 days) - Moderate (8 days) - Low (10 days) - Very Low (15 days) You can manually override the Due date.
DescriptionComprehensive description of the issue.
Assignment
Assignment groupGroup to which the issue is assigned. Each member receives a notification when an activity occurs on this issue.
Assigned toMember of the group assigned to resolve the issue.
Issue manager groupGroup responsible for managing and reviewing the issue.
Issue managerUser responsible for managing and reviewing the issue.
Watch listUsers added to view the issue.
Schedule
Due dateDue date is auto-populated based on a GRC property, Auto populate due date based on issue rating. If it is set to Yes, the field is auto-populated based on the predefined remediation time frame for the issue's risk rating. Otherwise, you can manually enter a due date.When an issue transitions to the Respond state, an entry in this field is mandatory.
Confirmed dateDate on which the issue is confirmed. This field is read-only, and displays the current date when the issue is moved from New to any of the following states:- Analyze - Review - Respond Note: If a triage issue is converted to an actual issue, this field displays the date it was converted.
CreatedDate and time the issue was created.
ClosedDate and time the issue was closed.
Planned start dateDate and time when the work on the issue is expected to begin.
Planned end dateDate and time when the work on the issue is expected to end.
Planned durationEstimated duration of work time. Calculated using the Planned start date and Planned end date.
Actual start dateTime when work began on the issue.
Actual end dateTime when work on the issue was completed.
Actual durationDuration of work time. Calculated using the Actual start date and Actual end date.
Details
Control/RiskControl or risk associated with the issue.
Control Objective/Risk statementControl objective or risk statement related to this issue.
EntityRelated entity.
Configuration itemItem associated with the issue. If all child issues have the same configuration item, it gets copied over to the parent issue.
LocationLocation where the issue occurred.
Risk eventRelated risk event.
EngagementRelated engagement.
PolicyPolicy associated with the issue.
Authority documentAuthority document associated with the issue.
Issue grouping
Parent issueParent issue to which the issue belongs.
Issue group ruleGroup rule assigned to the issue.Issue group rule is used to group similar issues together into a parent issue based on conditions defined in the rule. This allows you to work on similar issues simultaneously and close out the parent issue after all issues are resolved. This closes out all the child issues.
Action plan
RecommendationResolution actions recommended by the risk, compliance, or audit teams.
Action planPlan for remediating the issue.
Confidentiality
ConfidentialOption to enable confidentiality of the record. Only the assigned confidential users or confidential groups of users can access the record. For more information on confidential option, see Confidentiality flag for audit and compliance records.
Activity
Work notes \(Private\)Information about how to resolve the issue, or steps already taken to resolve it, if applicable. Work notes are visible to users who are assigned to the issue.
Additional commentsPublic information about the issue.
  1. Click Save.