User guide for the auditor
How to navigate the assessment module
Complyon is a compliance platform that can be used to collect documentation to be used in audits and other types of assessments.

LOGIN
Get an application password or for enhanced security, use your corporate login solution to access the Complyon platform.

Corporate Login
SINGLE SIGN-ON
After receiving the invite email to the Complyon system. Click on the appropriate Single Sign-On (SSO) button to login with your normal credentials.
- Go to system.complyon.com
- Click on Sign in with Microsoft or Google depending on your organization’s preference
- Login with your normal credentials
If login fails; you probably need your IT department to approve the Complyon app. Alternatively, you can ask the auditor setup password login.
Password Reset
GET A PASSWORD
- Go to system.complyon.com
- If this is your first time logging in with a password, click on ‘Forgot your password?’ and follow the instructions
- Input your email address and your Complyon password
- Click on Login
If you’re unable to reset your password, your user might not exist in the complyon system yet or your user is not permitted to login using a Complyon password, in which case you should login using Single Sign-On.

Home page
FIRST TIME LOGGING IN
- Make sure that you’re on the correct workspace (Client and Partition drop-downs in the upper left corner)
- If you like, you may give yourself a unique profile picture for easy recognition.
- You’re only expected to do something if you have open items under ‘My tasks’.
HOME PAGE

➊ Navigate between workspaces
➋ Notifications, Settings (if admin), activity log, user profile, and language selection
➌ Main menu – menu items will appear as assets are assigned to you. If you’re assigned a project or is an admin then you may navigate to audit projects through “Project management”.
➍ Profile cards – change profile picture, double-click to change name.
➎ List of assigned audit projects. Click on the title to open the project or on ‘Project status’ to see a project status overview.
➏ List of assigned tasks grouped by audits. Click on ‘Open tasks’ to see list of individual tasks.
Projects
How to create a project
A new project can be created from scratch by clicking on “Start project from either the Home page or on the Assessment projects page. Projects can be in a hierarchy with a parent project on top (also referred to as a “continuous” project) and any number of child projects below (also referred to as a “sub-projects” and “one-time” project).

Type: For audit projects, always select “Global assessment”.
Assessment template: Select the desired template which will form the starting point for your audit project.
Title: Will be pre-filled out after selecting a template but can be modified.
Project description: Is often used as the report title because the project title often contains datestamps or other internal indicators and is therefore unsuited for use in the report.
Continuous or One-time project: You will almost always want to make a continuous project unless it’s e.g. a one-time GAP analysis that you’ll never have to re-do for that customer.
Project responsibles: You may add the whole audit team as project responsibles, including the manager and partner. Do not add the customer users as project responsibles.
Tags: Optional – used for filter and search.
If you want to create a child project under a continuous project, then navigate to the continuous under Assessment projects and choose from the following options:

➊ List of parent projects and one-time projects that does not have a parent.
➋ Manage project owners, type, project configuration.
➌ Basic info: The description field will be used to populate the same description field on new child projects.
➍ Scope: Contact persons (for one-time projects, also project period.
➎ Schedule: For parent projects you can manage when to automatically have the system create a child project. For one-time projects it’s where project due dates are managed.
➏ Sub-projects: List of child (one-time) projects under this parent project.
➐ Click on “Run project manually” to create a child project from the template.
❽ Click on “Clone” to use a previous project as the template for a new project.
Projects ➤
System description
The system description can be made up of a free text field that the auditor is in control of and/or as a building-block section where components can be created, imported, and re-used across the customer workspace.

➊ System description: Free text field. May include an image file, for example a network drawing.
➋ Task responsibles: Assign the System measures section as a task to be filled out by the customer. The task will be accessable to the customer from the Home page only.
➌ System measures: Based on components called measures and measure categories or sections. This feature allows you to create a multi-tier page in the Word report that uses your own heading formating. The measures are stored centrally on the customer workspace and can thus be reused for multiple assessments.
➍ Add section: Add a new building block (see how generic building blocks can be imported into the customer workspace under Settings.)

System measures
Add section/measure
Each section and measure has a name and a description field. The section name will be displayed in the Word report as Heading 2 and the measure name will be displayed as Heading 3.
If you need to keep the System separated into two chunks, you may set some of the sections to Alternative reporting tag. Remember to then use the correct report tag in the Word report.
Projects ➤
Tasks

➊ Categories: List of control objectives. Click to filter the task table.
➋ Top bar: Displays the name and description of the selected category/control objective. To the far right you may click on the pen-icon to edit the control objective title, description, and status; or on the trash-icon to delete the entire control objective including all related tasks.
➌ Task settings: General task settings:
Task assignee: Bulk assign all documentation collection and/or main tasks to one or more users. The users will be notified and will receive status emails when their tasks change or chats are sent.
Send reminders: Send reminders to all users with unfinished tasks or to individual task responsibles.
Add tasks from template: Re-import tasks and control objectives that was previously removed from the project or import new controls that was added to the template since the project was first created. You can also create a new task that is unique to this project.
Filter: Set status filters.
➍ Tasks: Each task is represented by a row in the task table. The task status
Task status:
Documentation collection not started: The customer has not added a comment or attached any documents.
Documentation collection in progress: The customer has provided some input.
Documentation collection completed: The customer has finished their part of the task.
Task completed: The auditor has fully completed the task.
Response: Conclusion status of the task.
Quality control: Status on the QA/sign-off work:
Waiting: Task is still in progress.
In progress: Task is awaiting QA.
Rejected: The task is re-opened.
Accepted: Sign-off completed.
Assign users: Assign users to the individual documentation collection or main task.
Edit task: (Pen-icon) Open task for audit or QA work.
Remove task: The task can be re-imported from the assessment template. But all project specific changes will be lost.
Users and roles can be assigned either on the auditor workspace (client) or on the customer workspaces (partitions). Once a user is in the system, only the user itself can modify its name, profile picture etc. A user may have access to multiple clients/partitions. The user will remain in the Complyon system until its removed from its last instance. Users may be invited from several other screens as well, typically indicated by a + sign next to a select user drop-down.

Task description: Top bar.
Documentation collection: Customer input, control description, and collected evidence.
Testing: Testing notes, Test plan for the report, and OE testing.
Chat and notes: Chat with the customer and general notes.
Conclusion and observations: Response drop-down, conclusion, and observations.
Quality control: Log of QA activities.
Projects ➤ Tasks ➤ Audit tasks
Task description

The top bar display the auditor specific task description. It will either display the type 1 text or both the type 1 and type 2 text depending on the project setting.
It’s possible to adjust the AI results by adding a note directly to the AI assistant in these fields e.g. by writing “Note to AI: Disregard failed samples“

Projects ➤ Tasks ➤ Audit tasks
Documentation collection
Section for the initial documentation collection and writing the control description for the report.
- Status: Customer task status. If completed, a button to re-open the task appears.
- Documentation collection assignee: List of assigned customer users. There’s also a link-button to see the customer task.
- Documentation collection comment: Customers comment as provided on their task.
- Control description: For the report. Usually pre-populated from the assessment themplate.
- Attachments: See both attachments uploaded by the customer and by the auditor.
- Suggested attachments: List of attachments on related tasks (e.g. from another ongoing audit) that can be easily added to this task.
✨ Have the AI assistant write a customer specific control description based on the collected policies.

Projects ➤ Tasks ➤ Audit tasks
Testing
Section for the test plan and operational effectiveness testing.
- Testing notes: Internal notes specifically for the testing work. It’s possible to adjust the AI results by adding a note directly to the AI assistant in this field e.g. by writing “Note to AI: Disregard failed samples“
- Operational effectiveness testing: Take samples by clicking on “+ Create new test”. Give the first sample a title that includes the sample identifier (e.g. change request number) and add a description for the customer to know what to do. Set comment and attachment input options and click Save. The sample is added to the list but the Create test window stays open. Change the title and click save for each sample.
- Performed test: For the report. Usually pre-populated from the assessment themplate.
✨ Have the AI assistant write a customer specific test plan based on the control description and collected policies.

Projects ➤ Tasks ➤ Audit tasks
Chat and notes
Chat with the customer concerning the specific task. Only users directly assigned to the task will receive email notifications about chats.
- Notes: Internal general work notes. It’s possible to adjust the AI results by adding a note directly to the AI assistant in this field e.g. by writing “Note to AI: Disregard failed samples“

Projects ➤ Tasks ➤ Audit tasks
Conclusion and observations
Section for conclusion and reporting of any findings.
- Response: Conclusion drop-down that will be displayed on the task table.
- Conclusion: For the report. Usually pre-populated from the assessment themplate.
- Observations: [Optional] For the report. Often used to highlight certain high level observations in the report. Ask your manager before using this field.
✨ Have the AI assistant analyse all the evidence, compare it to the test plan (performed test) and report on any discrepancies.

Projects ➤ Tasks ➤ Audit tasks
Quality control
List of QA events. Click on “Quality control log” for more details.
When you open a completed task where the QA status is “In progress”, the task opens in read only mode and the bottom bar will have 2 buttons: Reject and re-open: to send the task back to the auditor. Accept and complete: to finish sign-off.

Projects ➤
Reporting
Users and roles can be assigned either on the auditor workspace (client) or on the customer workspaces (partitions). Once a user is in the system, only the user itself can modify its name, profile picture etc. A user may have access to multiple clients/partitions. The user will remain in the Complyon system until its removed from its last instance. Users may be invited from several other screens as well, typically indicated by a + sign next to a select user drop-down.

➊ Manage summary: Over all conclusion for the report.
The Observations button will open a list of all observations across all tasks.
➋ Generate new report: Section to generate or upload the report:
Download attachments to ZIP: Click to start a batch job that will generate a downloadable ZIP file with all the attached documents. You’ll receive an email when the ZIP file is ready for download and the download happens by clicking on the notification bell icon in the top right.
Generate new report: Click to generate Microsoft Word reports which will be added with a timestamp under Attachments.
Settings
Projects can be in a hierarchy with a parent project on top (also referred to as a “continuous” project) and any number of child projects below (also referred to as a “sub-projects” and “one-time” project).

➊ Users and roles: Invite and remove users or change user role.
➋ Measures: Building elements for the system description page on audit projects.
➌ Assessment templates: List of all audit programs available on this client/partition.
Settings ➤
Users and roles
Users and roles can be assigned either on the auditor workspace (client) or on the customer workspaces (partitions). Once a user is in the system, only the user itself can modify its name, profile picture etc. A user may have access to multiple clients/partitions. The user will remain in the Complyon system until its removed from its last instance. Users may be invited from several other screens as well, typically indicated by a + sign next to a select user drop-down.


List of all users and their assigned role.
You can lock out a user without deleting it.
Merge users: This will combine 2 users into 1 granting all assigned tasks and ownerships from both users to the remaining user.
Invite new user: Create a new user account.
Authentication:
Microsoft/Google: will force the user to login using SSO from the selected vendor. In some cases the admin of the user directory will have to approve for their SSO to be used to login to Complyon.
Application: the user may still use SSO; but will also be allowed to create a Complyon login, in which case login may be possible even if the user is locked or removed from the user directory.
UPN address: In some cases, e.g. when two Microsoft Active Directories have been merged, the user’s login name is not the same as the email address. In these cases you may type in the user’s UPN address.
Settings ➤
Measures
Measures are building blocks used to make the system description and is a general description of various organizational and security measures that the company uses. Once you change a measure, the changes are instantaneously updated everywhere the measure is linked. This feature makes it easy to keep the high level descriptions updated across multiple audits.

Categories: Modify the name and description. You may also assign a scope to the category. Only categories with the Assessment scope will appear on the System description task.
Measures: Modify the name and description.
Import measures: As the auditor you may import a predefined list of measures from another partition for the customer to draw inspiration from.
Settings ➤
Assessment templates
Assessment templates are the templates used to initially populate an audit project with tasks/controls and to define the baseline settings like if the system description should be included or not, maintain the Word report template, etc. You’ll generally manage your templates from the client/top workspace so that the template is shared across all workspaces. However, if you’re working with very customer specific work papers, you may consider creating the assessment template on the partition/customer workspace level.


