Mock Audit

Rehearse an audit against a framework, read the readiness score and findings Aegis produces, then answer the auditor's questions one by one before anyone from outside asks them.

A mock audit (a rehearsal of a real compliance audit) tests how your organisation would answer an auditor today. You choose a framework, Aegis works through a question bank for it, checks each question against the evidence (the proof a control works) in your Evidence Locker, and writes back a readiness percentage with findings, critical gaps and recommendations. Nothing is filed with a regulator and no compliance record changes. Audit Readiness counts how much of the work is done; Mock Audit asks how well that work would hold up under questioning.

This page is licensed and module-gated

Mock Audit needs the MOCK_AUDIT feature, included in the PROFESSIONAL and ENTERPRISE tiers, plus the matching MOCK_AUDIT module provisioned for your tenant. Without the module the menu item does not appear. With the module but without the feature, the route still opens, but the filter and table are replaced by a centred notice under the Mock Audits heading: "Mock audits are not available on your current plan. Upgrade to practice audit scenarios with AI-generated questions."

Who uses it

Reading a mock audit needs mock-audit:read, which every role holds, so the page is readable down to Viewer. Anyone without it is sent to /unauthorized rather than to the dashboard.

Raise non-conformity is gated separately, on the permission to create a non-conformity. A Contributor holds that permission without holding mock-audit:write, so they see that one action inside a result even though they cannot start or delete a run. A Viewer does not see it at all.

What's on this screen

The page lives at /compliance/mock-audit, listed as Mock Audit under AUDIT in the left menu beside Benchmarking, Audits and Audit Log. The header reads Mock Audits, with "Simulate audit scenarios to test compliance readiness across frameworks." beneath. For a Manager or Admin a Run Mock Audit button sits at the far right of that header. Below the header is one filter, an All Frameworks dropdown narrowing the list to NIS2, GDPR, CyFun or DORA. There is no search box. The rest of the screen is a single table, twenty rows to a page:

Column What it shows
Framework The framework the run targeted, in display form (CyFun, not the key).
Status In Progress while the evaluation runs, then Completed.
Readiness The score to one decimal place, or Pending until the run finishes.
Completed The date the evaluation finished, or a dash while it runs.
Created The date the run was started.

Readiness is colour-coded — green from 80%, amber from 60%, red below — but the number always carries the meaning. Under the table sit the count and pager: "Showing 1 to 1 of 1 mock audit", then Previous, the page number and Next. There are no per-row buttons.

  1. Open the AUDIT group in the left menu and choose Mock Audit. The list loads with every run recorded for your tenant.
  2. Select the Help ? button in the top bar to read this guide beside the screen. It opens the in-app User Guide at the chapter for the page you are on; your browser's Back returns you to the list.
  3. Check the account named at the top right — it decides what the header offers you. The capture was taken as Test Contributor 1, a Contributor, which is why no Run Mock Audit button sits opposite the title: the permission gate at work, not a missing control.
The Mock Audits list as a Contributor: framework filter, five columns, one completed NIS2 run — /compliance/mock-audit.
The Mock Audits list as a Contributor: framework filter, five columns, one completed NIS2 run — /compliance/mock-audit.

There are three things to do on the list itself. Narrow it with the All Frameworks dropdown to one framework's history — if the filter matches nothing, the table is replaced by "No results found" and a Clear filters button. Read the Readiness column to see where each rehearsal landed: in the capture the tenant holds one NIS2 run, Completed, readiness 41.7% in red, a normal score for a tenant with little evidence recorded yet. And select anywhere on a row to open the full result. On a tenant that has never run one, the table is replaced by an empty state reading "Nothing here yet" with "No items have been created yet." beneath.

Run a mock audit

  1. Select Run Mock Audit at the top right of the header. A small dialog of the same name opens, explaining that the system will evaluate your evidence and produce a readiness report.
  2. Choose the target from the Framework dropdown. It opens on NIS2.
  3. Select Run Audit. The button shows a spinner, both buttons disable and the dialog cannot be dismissed while the run is queued; it then closes and the table refreshes.
  4. Watch the new row. The evaluation happens in the background, so it starts as In Progress with a Pending score. Reload shortly after; once the evaluation lands, the badge turns Completed and the percentage appears.

Cancel closes the dialog without starting anything. Each run is its own row, so re-running a framework keeps the earlier result and you can watch the score move as gaps close.

Read a result

  1. Select any row. A large dialog opens in the centre of the screen, titled with the stored framework key and the words Mock Audit — so a CyFun run is headed CYFUN Mock Audit.
  2. Read its top row: the status badge, then — once the run has a score — a readiness badge repeating it on the same colour scale, reading for example "41.7% readiness". The actions available to you sit at the right-hand end of that row.
  3. Work down the report — Summary, a plain-language paragraph; Overview, the framework, total findings and timestamps; Findings Breakdown, a badge per finding type with its count; Critical Gaps, the most serious findings with question reference, type, explanation and suggested fix; Recommendations, a de-duplicated list drawn from those findings; and Metadata, the created and last-updated timestamps.
  4. Close the dialog. The list stays where you left it, filter and page included.

Overview and Metadata always show. Summary, Findings Breakdown, Critical Gaps and Recommendations appear only when the report has content for them, so a run with no serious findings has no Critical Gaps block. The finding types are standard audit language:

Finding What it means Score
Conforming Every piece of evidence the question expects was found. 100
Observation Half or more of the expected evidence was found, but not all of it. 75
Minor NC A minor non-conformity — some evidence found, but under half of what the question expects. 40
Major NC None of the expected evidence was found. 0

Readiness is the average of those scores across all findings, so the number is arithmetic rather than an opinion. Matching is done on words: each question names the evidence it expects, and the run compares those words against the name, type and tags of every item in your Evidence Locker. Descriptive evidence names therefore score better than a file called scan-final-v3. Critical Gaps collects every Major NC, plus any Minor NC raised against a question the framework marks as critical.

Rehearse question by question

The score tells you where you stand; the simulator makes you practise, walking the question bank one question at a time and evaluating each written answer into a finding.

  1. In an open result, select Run simulation. A dialog titled Interactive Audit Simulation opens, subtitled "Answer auditor questions and receive AI-evaluated findings".
  2. Read the progress line and bar at the top — for example "3 of 12 questions answered". If the framework has no question bank, a grey notice says so and there is nothing to answer.
  3. Choose an entry from the Remaining questions list; each shows its reference, category and any control it maps to. Until you pick one, the panel prompts you to select a question.
  4. Type into Your response — how your organisation addresses that question, as you would say it to an auditor. An empty answer is refused.
  5. Select Submit answer. A blue banner reads "Evaluating your answer..." while the evaluation runs in the background, and Aegis re-checks every few seconds.
  6. Read the finding under the Findings heading when it lands: a type badge, a description, a recommendation, and sometimes the follow-up a real auditor would ask next. Answer the next question, or close and return later. When the last one is answered, a green banner confirms the simulation is complete.
Two things the simulator tells you plainly

If an evaluation has not returned after about a minute, an amber notice says it is taking longer than expected, that it keeps running in the background, and that the finding will be there when you reopen the simulator. If your tenant has no AI credits left, the answer is refused and your response is not recorded — top up and submit it again.

Draft the questions an auditor would ask

  1. In an open result, select Generate AI questions. A dialog titled AI-Generated Audit Questions opens, subtitled with the framework, explaining that it will build context-aware questions from your control posture, recorded gaps and supporting policies and evidence. A blue note states that nothing is saved until you attach.
  2. Select Generate Questions. The dialog shows a spinner and "Drafting audit questions…", and cannot be closed while it works.
  3. Review the draft. A line at the top counts what came back; each question carries a severity badge of High, Medium or Low, its control domain and reference. The question and its "What good evidence looks like" note are editable text boxes — correct anything that does not fit your organisation.
  4. Select Reject on anything you do not want. It stays visible but fades, its two boxes lock and it drops out of the attach count — the line at the top still counts every question that came back. Restore puts it back. Run Again discards the whole batch and returns you to the opening screen, where Generate Questions drafts a fresh set.
  5. Select the attach button — it names the count, such as "Attach 6 questions". The approved set is saved to the run and appears at the top of the result, above the summary, under a heading that counts them ("6 AI-drafted questions").

If the framework has no seeded controls to reason over, nothing can be drafted; the dialog says so and asks you to add controls to the framework first.

Raise a non-conformity from a finding

  1. Select Raise non-conformity in the action row of an open result.
  2. A Create non-conformity dialog opens with its Source already set to INTERNAL_AUDIT, a prefilled title along the lines of "Non-conformity from NIS2 mock audit", and this run recorded as the record it was raised from. Both prefilled fields stay editable.
  3. Add the description and remaining fields from the finding you are acting on, then save. The new non-conformity stays traceable to the mock audit it came from.

Delete a run

  1. Open the result and select Delete, the outlined red button at the end of the action row. It appears only for roles with mock-audit:write.
  2. A confirmation asks "Delete this mock audit?" and warns that this permanently deletes the mock audit and its generated questions and report, and cannot be undone. It also takes that run out of your record of how readiness has moved over time, so keep old runs unless you have a reason not to.
  3. Select Delete to confirm. The result closes, a short confirmation appears and the table refreshes without that row. Cancel leaves everything untouched.

The AI assist

Two parts of this page use AI, and it is worth being precise about which. The run itself does not: the readiness score, findings and recommendations come from the rule-based evidence matching described above, which is why the same records always produce the same score. AI is used for the question drafting and for evaluating each answer typed into the simulator. Both read your own records — controls, gaps, policies, evidence — and write back an opinion for a person to judge. A person reviews and decides what it means. The AI never changes a control, an evidence item, a policy or your compliance status on its own, and drafted questions are stored only once you attach them. They are an internal preparation aid built from your own records, not a regulatory submission and not a pass or fail determination. Both AI actions draw on your tenant's monthly AI credit pool.

Tips and limits

Where this connects