In-app audit finding tracker
Tracking audit findings in an Excel sheet feels disconnected - I would like to be able to do this directly within Secfix.
Tracking audit findings in an Excel sheet feels disconnected - I would like to be able to do this directly within Secfix.
Log in to comment and vote
Comments12
Ghada Shebl
Sep 14
PinnedThanks everyone for the detail in the comments here, it's helping us a lot with the design.
The non-conformities tracker is the most requested feature on our roadmap, and it's high on our list for this quarter. We're starting on the design very soon.
Once we have a first prototype, we'll reach out to everyone who has upvoted or commented here to gather your early feedback.
We'll be in touch soon :)
Thanh Schrader-Nguyen
Aug 18
“I've mentioned the NC and CAPA tracker a few times already...and we really hate our current setup using tables in Confluence and / or Jira. It also got flagged in our last surveillance audit. It currently just does not scale because I don't get easy reminders about which CAPA/NC needs to be reviewed by when. Do you happen to have a solution for this on your Secfix product backlog? I envision it working like your risk register—using NCs as risks and CAPAs as treatment tasks. It would work perfectly like that, wouldn't it? :)”
Max Vogt
Oct 30, 2025
Similar feedback from Katrien De Wolf - It would be great to have a centralized Non-Conformities Tracker directly in Secfix, instead of managing findings across Jira, Google Drive, and Confluence. This would let us track audit findings, assign responsibilities, attach evidence, and monitor remediation progress all in one place. It would make audit preparation much easier and keep everything related to compliance consolidated within the platform.
Max Vogt
Mar 26, 2025
Similar feedback from Sander A. - Having a NC tracker within the platform would be a very useful feature rather than documenting this on an Excel Sheet or creating a separate space in a task Management tool to track these findings.
Alper
Apr 26, 2024
That's great idea Amir!
This should not only be for external audit, I think it should also be for the findings of internal audit or pentest.
Grigory Emelianov
Apr 26, 2024
hey everyone, thanks for your feedback! I think it's a great idea to track the findings on Secfix and to be able to show their resolution during surveillance audits!
@Julian Handl Paulo So. Martin Trachsel Alper Martin Amir
2 quick questions for you:
Where are you saving your findings at the moment?
On which page would you expect to see such a tracker on Secfix?
Julian Handl
Apr 26, 2024
Grigory Emelianov Good idea! We are currently doing that in the Risk Register (using comment section for Root Cause Analysis and Treatment Tasks of course) as well as in our own MS Planner to keep everyone up2date. I think that would be important enough to have it's own page instead of being part of a different section, but just my opinion :)
Grigory Emelianov
Apr 26, 2024
Awesome! thanks for the prompt feedback! We are planning a new quarter and could review this.
Usually, auditors expect auditees to add their findings as risks, you are doing it well! But I also understand it would give you some closure to close them individually ;)
At the moment there is no audit-related page on Secfix, but maybe it could become a part of something bigger for all-things audit :)
Julian Handl
Sep 14
It's been quite a while (2 years) so maybe time for another 'up-vote' comment :)
Honestly, I'm quite surprised this hasn't been implemented yet, given the importance of the topic, especially since you already have everything needed within the platform:
It could work just like the risk register, and with the new mapped elements, you could even link them together → thats perfect!
You also already have the auditor role in the platform, so why not add a remediation evidence section to the NC form, so auditors can review it as part of audit preparation? It genuinely feels disconnected to upload evidence screenshots to a separate auditor storage space when it should really be tracked and monitored centrally within the platform.