Buying an internal audit platform is not an ordinary SaaS purchase. The system a bank or a public company selects will hold its audit universe, the risk assessments that name exactly where controls are weak, the workpapers that document what was tested and what failed, and the issues log that tracks unremediated findings by owner and due date. For a SOX-heavy company the same system may also carry the evidence behind the chief executive’s and finance chief’s certifications. A vendor breach, an unvetted subprocessor, or a sale to a buyer with different priorities does not just create the ordinary SaaS headache of downtime and support tickets. It can expose the one document that describes, in one place, exactly where an organization’s controls do not work.
This guide sets out what to actually check before signing: how to read the vendor’s own SOC 2 or ISO 27001 report rather than just noting that one exists, where the software is hosted and what a FedRAMP claim on a marketing page does and does not mean, how the 2026 wave of AI features handles your data, what access control and audit logging look like, what happens to your data when the contract ends, and who actually owns the company on the other side of the signature. It closes with a 40-question checklist and a worked example for a mid-size bank. The review method behind every page in this program, including the evidence used here, is described in full in how we review audit software; this guide complements the site’s general vendor due diligence by risk tier method with the questions specific to a system that will hold your audit universe, findings and workpapers.
How to read this guide
What this guide is for. A practitioner checklist for the security, data-handling and vendor-stability questions specific to internal audit and GRC software, to run alongside your organization’s normal SaaS or third-party risk process, not instead of it.
Evidence. Research-based: vendor trust and security pages, FedRAMP Marketplace listings, help-center documentation, public procurement records and this program’s own product reviews. We have not used any of the products named on this page hands-on.
Last verified. 27 September 2026.
In this guide
- Why audit software gets different due diligence
- Vendor stability: who actually owns the product
- Certifications, hosting and FedRAMP: what the label does not tell you
- AI features and data use: opt-in, training and sub-processors
- Access control, SSO and tenant separation
- Audit trail, logging and retention
- Exit terms and data export
- How a bank’s third-party risk program should classify this vendor
- The 40-question due diligence questionnaire
- Worked example: Lakeshore Bancorp scopes a due diligence review
- Questions about audit software due diligence
- Sources and verification
- Related guides
Why audit software gets different due diligence
Most SaaS due diligence asks a standard set of questions about a vendor that will process business data. An internal audit platform asks a harder version of the same questions, because what it holds is not ordinary business data. The risk assessment module names which processes and controls the organization itself considers weakest. The workpapers show exactly what evidence was tested and what an auditor concluded. The issues log tracks every finding not yet fixed, with a due date that, if missed, is itself a second finding. Put together, that is a curated map of an organization’s control weaknesses, updated continuously. Very few other systems concentrate that much risk-relevant information in one place.
For a company subject to SOX, the stakes are higher still. Several platforms reviewed in this program, including Optro (formerly AuditBoard), TeamMate and Archer, are used to document and evidence internal control over financial reporting. When that is true, the tool becomes part of the control environment it documents. Its own change management, access controls and backups belong in the scope of the company’s SOX ITGC scoping, and Standard 14.6 on engagement documentation applies to how the workpapers it stores are retained, not only to their content.
There is a credibility point too. Internal audit is usually the function that pushes back hardest on a business unit’s rushed SaaS purchase, the one asking for the SOC 2 report before anyone signs. The department’s own platform purchase deserves at least the same rigor, run by the same third-party risk process the department expects everyone else to use, covered later in this guide.
Vendor stability: who actually owns the product
Private equity has touched nearly every vendor named in this program in the past three to five years, and ownership shapes what a buyer is actually signing up for. A financial owner typically expects to sell again within five to seven years, which can mean faster roadmap moves, heavier acquisition activity, and pricing pressure ahead of that exit. A public-company subsidiary is steadier but competes internally for investment against its parent’s larger lines of business. A still-independent, venture-backed company carries the least buyout risk but the smallest balance sheet. None of this is automatically disqualifying. All of it changes what to ask.
| Product | Current owner | Ownership type | What it means for buyers |
|---|---|---|---|
| Optro (formerly AuditBoard) | Hg, agreed 23 May 2024, more than $3 billion | Private equity, wholly owned subsidiary | Fast acquisition pace (FairNow, Midship); ask what Hg’s other portfolio companies saw at renewal |
| TeamMate | Wolters Kluwer (NYSE: WKL) | Public-company division | Steadier than a PE-backed peer, but competes internally against Wolters Kluwer’s larger tax, legal and health lines |
| Diligent One Platform (formerly HighBond) | Insight Partners since 2016; Clearlake and Blackstone since 2020 | Private equity, sale reported explored | A sale worth close to $7 billion was reported explored in November 2024; no completion found. Ask directly whether a process is active |
| Onspring | Capital IP Investment Partners, since 9 May 2023 | Growth equity | Founders reportedly keep control; lower buyout risk than a take-private, but small scale next to the enterprise suites |
| Archer | Cinven, closed 10 July 2023 | Private equity, third owner since 2020 | Chain runs RSA/Dell to STG (2020) to a Clearlake/STG spin-out (2021) to Cinven; ask what changed at each step |
| SAI360 | Symphony Technology Group (STG), agreement 9 January 2023 from BPEA EQT, completed 28 March 2023 | Private equity | SAI360’s own pages describe its cloud hosting differently from each other; treat an unreconciled claim as a question, not a settled fact |
| Riskonnect | Thoma Bravo since 2017; TA Associates named majority investor in a January 2024 release | Private equity, dual sponsor | Ventiv and Camms were folded in within six months of each other in 2024; ask which legacy product a quote is built on |
| LogicGate | PSG and Greenspring Associates, 2021 Series C | Venture and growth capital | Smallest balance sheet here; a new chief executive took over from July 2026, worth a question on roadmap continuity |
| Resolver | Kroll since 30 March 2022 | Subsidiary of a larger risk and investigations business | Sits inside a company whose core business is not GRC software; ask how it is prioritized against Kroll’s other lines |
| Protecht | PSG Equity, a US$280 million growth investment in 2025 | Private equity growth capital | Acquired VISO TRUST in April 2026, under PSG’s ownership; ask how an acquisition made after a change of control is integrated, not just marketed alongside |
| Alteryx | Clearlake Capital and Insight Partners, take-private completed 19 March 2024 | Private equity, delisted from the NYSE | Quarterly public disclosure is gone; ownership and financial detail now come only from what the company publishes |
Two patterns are worth a direct question rather than an assumption. The first is a live or recent sale process, like Diligent’s above; ask any vendor directly whether one is under way, since a change of control can move faster than a normal renewal cycle. The second is a rebrand that has outrun a buyer’s own paperwork: AuditBoard became Optro on 9 March 2026, and StandardFusion became TeamMate Risk & Compliance on 9 January 2026; a vendor risk registry still listing the old name will not match the entity on a new contract. Ask for the ultimate parent entity, not just the product brand, and what an assignment or change-of-control clause in the contract actually says.
Certifications, hosting and FedRAMP: what the label does not tell you
A logo on a trust page is a claim, not evidence. The report behind a SOC 2 or ISO 27001 certification is where due diligence actually happens: whether the report is Type I (design only) or Type II (design and operating effectiveness over a period), which of the five Trust Services Criteria are in scope, what complementary user-entity controls the report assumes your organization performs, and whether the auditor’s opinion is qualified or carries a subservice-organization exception. A vendor willing to share only a summary or a bridge letter, not the full report under NDA, is itself a finding worth writing down. The site’s guides to reviewing a SOC 2 report and reviewing a SOC 1 report cover what to check in each; ask for a SOC 1 too if the platform evidences SOX or other financial-reporting controls, since SOC 2 does not cover that ground.
| Vendor | Certifications found | Hosting and regions | FedRAMP / public-sector status |
|---|---|---|---|
| Optro | SOC 1 and SOC 2 Type II, ISO 27001, HIPAA, TX-RAMP, HECVAT, CSA STAR | AWS; a state bid names Oregon (us-west-2) as primary with Virginia (us-east-1) failover; general non-US hosting is not stated | Trust pages say hosting “meets FedRAMP moderate impact requirements”, which is a requirements statement, not an authorization we could find |
| TeamMate | ISO 27001, SOC 2 Type 2, TISAX, HIPAA, CSA STAR | Microsoft Azure (TeamCloud), including a Johannesburg region added 30 April 2025; on-premise and offline options exist | FedRAMP Marketplace lists TeamMate Audit and Controls as Authorized, Moderate, agency path, since 13 May 2022; the TeamMate Audit product page still says “FedRAMP options (upcoming)” |
| Diligent One Platform | ISO 27001:2013, annual SOC 2 Type II | Nine AWS commercial regions plus a GovCloud environment | GovCloud holds FedRAMP Moderate and DoD IL5, but several apps and ACL AI Studio are not listed as supported there |
| Onspring | SOC 2 Type II, CSA STAR Level One | A standard environment and a separate GovCloud edition | GovCloud reached FedRAMP Moderate authorization on 27 March 2024, up from an “In Process” designation dated 19 January 2023; the security page does not detail SSO, MFA or general data residency |
| Archer | SOC 2 Type 2, ISO 27001, ISO 27017, ISO 27701 | AWS across seven regions, a 99.5 percent SLA | No FedRAMP or GovRAMP authorization found despite a dedicated Public Sector module; a module name is not a certification |
| SAI360 | Certifications named on the trust page, not itemized on the pages we read | The platform page says “Built on Google Cloud”; the trust page separately describes AWS-plus-Google-Cloud tooling | No FedRAMP or GovRAMP claim found |
| Riskonnect | SOC 2 Type 2; the security page also cites the older SSAE 16 standard | Data-center claims on the platform security page, not itemized by region | No ISO or FedRAMP claim found |
| LogicGate | SOC 2 Type II, ISO 27001, CSA STAR, EU-US Data Privacy Framework, 21 CFR Part 11 | Customer choice of AWS hosting location: US, UK, Australia or EU | No FedRAMP or StateRAMP listed |
| Resolver | SOC 2, ISO 27001, ISO 27017, ISO 27701, CSA STAR, TISAX | Not detailed on the pages we read | No FedRAMP, GovRAMP, StateRAMP or DoD IL authorization found; the linked ISO 27001 certificate showed a listed expiry of 29 November 2025, already passed when checked |
| Protecht | ISO 27001, a SOC 2 assessment | Not detailed on the pages we read | No FedRAMP, GovRAMP, StateRAMP or IRAP authorization found, despite government being a named target sector |
FedRAMP is where vendor-page wording and reality diverge most often. TeamMate is the clearest example: the FedRAMP Marketplace lists TeamMate Audit and Controls as Authorized at the Moderate impact level, agency path, since 13 May 2022, and Wolters Kluwer’s public-sector page says the product is “FedRAMP and GovRAMP Authorized”, yet the TeamMate Audit product page still describes FedRAMP as “upcoming”. Onspring shows the opposite direction: its GovCloud edition moved from an “In Process” designation, sponsored by the Tennessee Valley Authority, on 19 January 2023, to a Moderate authorization on 27 March 2024, so an older page can understate current status just as easily as a newer one can overstate it. Check the FedRAMP Marketplace directly rather than a single vendor page, and confirm which products sit inside the boundary: Diligent’s GovCloud environment holds FedRAMP Moderate and DoD IL5, but several named apps and its ACL AI Studio are listed as unsupported there, so a platform’s core workflow can be authorized while its newest AI feature is not.
Public procurement records are the most concrete evidence available. A West Virginia Department of Transportation bid response names Optro’s production environment; the University of California’s systemwide agreement, executed 23 December 2025, and the City of Norman, Oklahoma’s TeamMate quote both show what a real public-sector deployment looked like, in a way a marketing page does not. The site’s guides to auditing cloud security and auditing data privacy compliance go deeper on the underlying control questions once the hosting facts are in hand.
AI features and data use: opt-in, training and sub-processors
Every vendor in this program shipped an agentic AI feature in 2025 or 2026. Gartner’s Market Guide for Audit Management Software, published 13 April 2026, told buyers to be “particularly wary of agent-washing”, and the due-diligence answer to that warning is three specific questions, asked feature by feature rather than of the platform as a whole: is it opt-in or on by default; is your content used to train or fine-tune the underlying model, and for how long is it retained; and which model provider or subprocessor actually does the processing.
| Vendor and feature | Model or provider | On by default or opt-in | Trains on customer data | What is not published |
|---|---|---|---|---|
| Optro AI | In-house machine learning plus Microsoft’s Azure OpenAI service | Opt-in, per the vendor’s AI page | Vendor states customer data is not used to train the model | Which subprocessors the newer Accelerate and Midship features add |
| TeamMate+ AI Editor | Not published | Not stated as opt-in or default | Vendor states submitted content is not used to train the model and is discarded once suggestions are generated | Model provider and hosting region |
| Diligent ACL AI Studio | Amazon Bedrock; Diligent’s own 17 September 2026 release notes name the Claude 4.6 model | Not stated | Vendor states no training on customer data by default, with labeled output | Retention period; whether the default can be changed by an admin |
| Onspring AI and Agentic GRC | Anthropic’s Claude, per the vendor’s own releases | Add-on requiring the Silver service tier or above | Not stated | Retention period, training use and hosting region for the AI feature specifically |
| Archer Evolv AI Compliance | Amazon Bedrock Guardrails, run inside the customer’s own AWS account and IAM role | Architecturally separate from Archer’s environment by design | Prompts and model weights are described as isolated from Archer | Whether this architecture covers Archer’s other, older AI features |
| LogicGate AI | Named OpenAI models including gpt-4.1-mini and gpt-5-mini, with a bring-your-own-key option | Opt-in, enabled by an administrator | Vendor states data is not used to train models and is retained 30 days under LogicGate’s own key | Little; this is the most complete public disclosure in the group, with a dated subprocessor list |
| Resolver AI (six named features) | Anthropic and AWS models, per Resolver’s AI legal page | Not stated uniformly | No blanket retention policy across all six features | A single retention or training statement covering every feature |
| Protecht Cognita | No model provider named | Not stated | Vendor states single-tenant AWS hosting, no cross-customer sharing and no use to train third-party models | Which underlying model performs the work |
| Riskonnect (Agentforce and Intelligent Risk) | Not named | Not stated | No data-use, training or retention statement found anywhere on the vendor’s site | Everything; treat as unknown until the vendor answers in writing |
| SAI360 (GRC Elevate 6.0 AI) | Not named | Not stated | No data-use or training statement found on the AI overview page | Everything; same treatment as Riskonnect above |
Optro’s is the most complete published commitment in the group, running on in-house machine learning plus Microsoft’s Azure OpenAI service. Archer’s Evolv AI Compliance feature, launched 15 September 2026, is worth understanding on its own terms: it runs Amazon Bedrock Guardrails inside the customer’s own AWS account and IAM role, so prompts and model weights are described as isolated from Archer’s environment entirely, rather than processed inside the vendor’s own infrastructure the way most of the table above is. At the other end, Riskonnect’s and SAI360’s current AI features carry no public data-use statement at all on the pages we read. Treat that silence as the finding, not as an assumption of safety: get the answer in writing before turning a feature on, and ask separately what happens to AI-generated content and any model artifacts derived from your data once the contract ends, a question the exit-terms section below returns to.
Access control, SSO and tenant separation
The baseline for enterprise software in this category is SAML single sign-on, SCIM provisioning, role-based access control fine enough to separate auditors, reviewers, auditees and administrators, and mandatory multi-factor authentication for administrators. Diligent One Platform documents SAML SSO, SCIM and OIDC; Optro documents SAML 2.0 and SCIM; LogicGate’s trust page describes a choice of hosting location alongside SSO and provisioning, role-based access and history logs. Two gaps in this program’s research are worth flagging directly rather than assuming away. SAI360’s own plans page shows that its entry-level Essentials edition excludes single sign-on entirely, along with the AI chat assistant and advanced analytics, so confirming SSO exists somewhere in the product line is not the same as confirming it is in the edition being quoted. Onspring’s public security page does not detail SSO, MFA or data residency at all; those answers have to be requested directly rather than read off the page.
- Edition, not just product. Ask which specific tier includes SSO, SCIM and role-based access, since the lowest-priced edition is the one most likely to exclude them.
- Tenant separation. Ask how your data is logically separated from other customers on shared infrastructure, and whether single-tenant hosting is available at a cost you would consider.
- Vendor staff access. Ask who at the vendor can see your content by default, under what circumstances, and whether that access is itself logged.
- A live test, not a slide. Before signing, provision a test user through your identity provider and confirm SSO and role restrictions actually work as described, rather than relying on the sales deck.
Audit trail, logging and retention
Two different things get called “audit trail” in an RFP, and it is worth separating them. The workpaper audit trail records who changed a test step, a conclusion or a risk rating, when, and what the prior value said; this is the version history this program’s product reviews generally find documented, at varying depth, across the platforms. The security audit log is a different record entirely: who logged in, from where, and what administrative actions, exports or permission changes they made. A vendor can have one well documented and say little about the other.
None of the vendors covered in this program publishes a specific retention period for its security logs on the pages we read. LogicGate’s trust page is the most explicit about the feature existing at all, naming history logs directly; Diligent One Platform publishes the closest thing to an operational commitment in the group, a one-hour recovery point objective and a 24-hour recovery time objective, which speaks to resilience more than to log retention specifically but is still the kind of number worth asking every other vendor to match. Where a number is not published, get one in writing: the retention period for security logs, whether administrative activity is logged separately from ordinary use, and whether logs can be exported to your own monitoring tools rather than viewed only inside the vendor’s console.
Exit terms and data export
The point in the relationship where a buyer has the least leverage is exactly when exit terms matter most: at the end of the contract, when a team negotiating a renewal has every incentive not to slow things down by pushing on data export. Most vendors in this market are silent on exit terms in anything publicly available, which means the handful that do publish something are worth using as a template for what to ask for.
| Vendor | Published exit terms | Format and window |
|---|---|---|
| Optro | Not a general published policy; a state bid response specifies deliverables on request | ZIP, PDF and CSV export, per that bid |
| LogicGate | Master Services Agreement, section 7.3 | A 30-day data-retrieval window after termination, then deletion; separately, 30 days’ notice is required to stop auto-renewal (section 3.6) |
| Diligent One Platform | Trust and compliance page | A 30-day post-termination extraction window |
| TeamMate, Onspring, Archer, SAI360, Riskonnect, Resolver, Protecht | Not published on the pages we read | Negotiate a specific window and format into the order form; do not assume one |
Three items are worth writing into the order form when the standard contract is silent, which for most vendors here it is: a defined post-termination data-retrieval window, in a stated export format, not left to an open-ended support request; advance notice of auto-renewal, since contracts in this market commonly renew automatically absent a specific notice period, as LogicGate’s Master Services Agreement does at 30 days; and what happens to AI-generated content and any model artifacts derived from your data, a question almost none of the standard exit clauses still in circulation address. A related question is continuity short of an orderly exit: what happens if the vendor itself fails or is acquired mid-contract, which the site’s guide to third-party resilience covers in more depth.
How a bank’s third-party risk program should classify this vendor
For a regulated institution, this purchase should not move through intake as a routine SaaS request, and internal audit does not get to size its own risk. The same third-party risk management program that reviews every other vendor should tier this one, using the site’s third-party risk management lifecycle and vendor due diligence by risk tier methods, and the Global Internal Audit Standards’ third-party topical requirement is a reasonable place to anchor why this vendor gets more scrutiny than its contract value alone would suggest.
| What the due diligence finds | Typical effect on tier | Why it matters here |
|---|---|---|
| The platform holds unremediated findings, control-weakness detail and SOX evidence | Pushes toward High or Critical | This is a curated map of exactly where the organization is weakest; its value to an attacker is out of proportion to the software’s price |
| Multi-tenant SaaS with no single-tenant option | Neutral to slightly higher | Standard for this category; ask about logical separation rather than treating multi-tenancy itself as disqualifying |
| An AI feature trains on customer data, or the vendor will not say | Pushes toward Critical, or to “not approved until answered” | An unanswered AI data-use question is itself the finding; do not default to assuming the answer is no |
| No FedRAMP, GovRAMP or equivalent claim, for a regulated buyer | Raises the bar for compensating controls, does not automatically fail the vendor | Most of this market has no such authorization; a bank can still use it with the right contract terms and monitoring |
| Recent or in-process change of ownership | Adds an annual reassessment trigger regardless of the contract’s renewal date | A new owner can change security investment, support staffing and roadmap faster than a standard review cycle would catch |
| No published exit or data-export terms | Requires the terms to be negotiated into the contract before signing, not assumed | Most vendors in this market are silent on this; silence is not consent to a favorable default |
For a bank buying a platform that will hold SOX evidence and an unremediated-issues log, the resulting tier is typically High or Critical, on par with vendors adjacent to core banking rather than a scheduling or expense tool, even when the contract value looks modest by comparison. The practical consequence is usually threefold: annual reassessment rather than a review triggered only by renewal; visibility at the audit committee, consistent with the Global Internal Audit Standards’ Principle 8 on board oversight; and a documented compensating-control plan for any gap the due diligence turns up, rather than a simple pass or fail.
The 40-question due diligence questionnaire
Keep the vendor’s written answers to the questions below in the due diligence file alongside the SOC 2 report and the contract, not just in an email thread. Questions with no vendor answer at all, not a reassuring one, are the ones worth escalating.
Audit software due diligence questionnaire
Ownership and stability. Who is the ultimate parent entity, not just the product brand? Has the company changed hands, or explored a sale, in the past three years? Is the roadmap set by the operating company or the financial owner, and what has that owner changed at other portfolio companies after a deal? What happens to our contract on a change of control? Has the product been rebranded or merged with an acquired product recently, and does that match the legal name on the contract we are signing?
Certifications and audits. Will you provide the full current SOC 2 Type II report, not a summary or a bridge letter, under NDA? Which Trust Services Criteria are in scope, and does the report cover the module we are buying or only the platform in general? What complementary user-entity controls does it assume we perform? Does the report carry any qualified opinion, exception or subservice-organization carve-out? Is the ISO 27001 certificate current, and does its Statement of Applicability cover the environment we will use? Do you commission independent penetration testing, and will you share a summary of the results?
Hosting and data residency. In which cloud regions will our data be stored and processed, including any AI or analytics add-on? Is a US-only or EU-only hosting option available, and does it cover every module we are buying? If FedRAMP, GovRAMP or StateRAMP is claimed, what is the authorization level, and which products and modules are inside the boundary? Can we confirm that on the FedRAMP Marketplace rather than relying on your page? Is failover or backup hosted in a different jurisdiction than production? Do you publish a current subprocessor list, and will you notify us before adding one?
Access control and authentication. Does the edition we are quoted include SAML SSO and SCIM provisioning, or is that a higher tier only? Is role-based access granular enough to separate auditors, reviewers, auditees and administrators, and can we test that before signing? Is multi-factor authentication mandatory for administrators, and can we enforce it for every user? How is our tenant separated from other customers, and is single-tenant hosting available? Who at your company has access to our content by default, and can that access be restricted or logged?
AI and data use. Which AI features are on by default versus opt-in, module by module? Is our content used to train or fine-tune the model, for you or for the model provider? Which model provider processes the data for each feature, and is it named in your subprocessor list? How long is content retained, and can that be shortened or disabled? Can AI-generated output be distinguished from human-entered content for review purposes? What happens to AI-generated content and any derived model artifacts when the contract ends?
Audit trail and logging. Is every change to a workpaper, test step or conclusion logged with a user, timestamp and prior value? Is administrative activity, including permission changes, exports and deletions, logged separately from ordinary use? How long are security logs retained, and can that be extended or exported to our own monitoring tools? Can a full audit trail for a single engagement be produced on request, for our own quality assurance or an examiner?
Data retention, backup and continuity. What are your stated recovery point and recovery time objectives, and have they been tested this year? What is your backup frequency and retention period, and are backups stored in a separate region or account from production? What is your plan if a subprocessor or hosting provider you depend on fails or is breached? Do you carry cyber-liability insurance, at what level relative to our engagement?
Exit and incident response. On termination, what is the data-retrieval window, in what format, and is that written into the contract rather than left to a support request? Does the contract auto-renew, and how much notice must we give to prevent it? What is your breach-notification commitment, in hours or days, with a named contact? Has your company had a publicly disclosed security incident, and if so, what changed afterward?
Worked example: Lakeshore Bancorp scopes a due diligence review
Lakeshore Bancorp, the $9 billion regional bank used as a worked example across this site, is replacing the Excel workbook that has tracked its 212 key controls since before its last exam cycle. Two finalists remain after an RFP run on the site’s vendor-neutral RFP method. Before either gets a signature, the chief audit executive routes the purchase through the bank’s third-party risk management program rather than approving it inside the department, precisely because the platform will hold the bank’s SOX evidence and its full issues log.
Third-party risk sizes the engagement High, on par with vendors that touch core banking rather than the scheduling software it usually reviews, and sets an annual reassessment cycle with a line to the audit committee rather than the standard renewal-only review. The 40-question due diligence turns up two pictures. Platform A holds a FedRAMP Moderate authorization for its core workflow, but the newer AI issue-drafting module it demonstrated sits outside that boundary, hosted on general commercial cloud with no model provider named in writing; Lakeshore’s compensating control is to leave that module off in the order form and treat it, if ever turned on, as a separate, lower-trust fourth party requiring its own written data-use terms. Platform B carries no FedRAMP claim at all, which rules it out for one federal-adjacent exam relationship but not for internal use; its SOC 2 Type II report is current with a clean opinion, and it publishes a 30-day post-termination export window in a named format, unlike most of the market. The gap the questionnaire finds is that single sign-on sits behind a higher edition than the one first quoted.
Lakeshore selects Platform B. Three terms not offered in the standard order form get written into the contract before signing: a defined security-log retention period, matched to the bank’s own examiner expectations; a named contact and a stated hours-based commitment for breach notification; and the SSO-inclusive edition, priced in from the start rather than added later at a premium. Each one traces back to a specific gap the 40-question checklist caught, not to a general sense that the vendor seemed trustworthy.
Questions about audit software due diligence
What is the real difference between SOC 1 and SOC 2 for an audit-software vendor?
SOC 1 is scoped to controls relevant to a user entity’s financial reporting, which matters if the platform itself evidences SOX or other ICFR controls. SOC 2 is scoped to the Trust Services Criteria, security, availability, processing integrity, confidentiality and privacy, and is the one that answers most of the questions in this guide. Ask for both if the platform touches financial-reporting evidence; the site’s guides to reviewing a SOC 1 report and reviewing a SOC 2 report cover what to check in each.
Does a vendor’s FedRAMP claim mean it is actually authorized?
Not necessarily, and not on its own. TeamMate’s own pages disagree with each other: the FedRAMP Marketplace and the vendor’s public-sector page say Authorized, while the core product page still says “upcoming”. Check the FedRAMP Marketplace listing directly, and confirm which specific products and modules sit inside the authorization boundary, since an add-on like an AI or analytics module is sometimes excluded even when the core platform is authorized.
Should a private-equity-owned vendor be a dealbreaker?
No. Most of this market is PE-owned today, including Optro, Archer, SAI360, Riskonnect and Alteryx, and ownership alone predicts little about product quality. What matters is what changes after a deal: pricing pressure at renewal, support staffing, and whether a live sale process, like the one reported for Diligent in November 2024, is disclosed when you ask directly.
Can we let a vendor’s AI features touch real findings and workpapers?
Only once you have the vendor’s answers in writing on whether the feature is opt-in, whether your content trains the model, which model provider processes it, and how long it is retained, not from the marketing page but from the contract or data processing agreement. Where a vendor has published no data-use statement at all, as with Riskonnect’s and SAI360’s current AI features, treat that silence as a negotiation item, not an assumption of safety, before turning the feature on.
Who should own this due diligence: internal audit, IT security, procurement or third-party risk?
All four have a stake, but the accountable owner should be the same third-party risk function that reviews every other vendor, not internal audit alone, precisely because internal audit is the interested buyer here. Internal audit’s role is to bring the questions specific to this category into that process, not to certify its own tool.
How is this different from the site’s general vendor due diligence guide?
The site’s general vendor due diligence guide covers the mechanics that apply to any SaaS purchase, tiered by risk. This guide applies that method to one specific, higher-stakes case, a system that will hold your risk assessments, workpapers and unremediated findings, where the ownership, hosting and AI questions above are worth asking of every vendor in the market, not only the one you are closest to signing.
internalauditguide.com has no commercial relationship with any vendor named on this page. We take no vendor money, run no affiliate links and accept no sponsored placements, and no vendor saw this page before publication. Product and company names are the trademarks of their owners. Corrections: desk@internalauditguide.com.
Sources and verification
- FedRAMP Marketplace: TeamMate FedRAMP (FR2207643307) — Moderate, agency authorization since 13 May 2022, covering Audit and Controls (accessed 27 September 2026).
- FedRAMP Marketplace: Onspring GovCloud (FR2231648178) — Moderate authorization dated 27 March 2024, up from a 2023 In Process listing (accessed 27 September 2026).
- Wolters Kluwer: TeamMate Audit product page — FedRAMP described as upcoming, deployment options (accessed 27 September 2026).
- Wolters Kluwer: TeamMate privacy and security certifications — ISO 27001, SOC 2 Type 2, TISAX, HIPAA, CSA STAR, FedRAMP and GovRAMP wording (accessed 27 September 2026).
- Optro: trust and security page and trust center — certifications, hosting, encryption, SSO and SCIM, FedRAMP wording (accessed 27 September 2026).
- Optro: AI platform page — the opt-in, no-training and logging statements (accessed 27 September 2026).
- Diligent One Platform: Trust and Compliance — ISO 27001, SOC 2 Type II, hosting regions, recovery objectives, extraction window (accessed 27 September 2026).
- Diligent help center: Commercial and GovCloud regions and limitations — FedRAMP Moderate and DoD IL5 statements, unsupported apps (accessed 27 September 2026).
- Diligent help center: ACL AI Studio release notes — the Claude 4.6 statement dated 17 September 2026 (accessed 27 September 2026).
- Reuters via U.S. News, 14 November 2024 — the reported exploration of a sale of Diligent (accessed 27 September 2026).
- Onspring: Security page — SOC 2 Type II, CSA STAR, FedRAMP wording (accessed 27 September 2026).
- Archer: SaaS Security and Trust — certifications, encryption, hosting and SLA detail (accessed 27 September 2026).
- Archer: Archer launches Archer Evolv AI Compliance — the Bedrock Guardrails architecture (accessed 27 September 2026).
- Clearlake: Clearlake and STG complete sale of Archer to Cinven — the close date and the RSA/STG/Clearlake ownership chain (accessed 27 September 2026).
- SAI360: Symphony Technology Group enters agreement to acquire SAI360 — the 9 January 2023 agreement date and the seller, BPEA EQT (accessed 27 September 2026).
- SAI360: Trust and Security — certifications and the AWS-plus-Google-Cloud hosting description, against the platform page’s separate “Built on Google Cloud” claim (accessed 27 September 2026).
- SAI360: Plans — feature gating showing SSO excluded from the Essentials edition (accessed 27 September 2026).
- Riskonnect: Platform Security page — SOC 2 Type 2, SSAE 16, encryption claims (accessed 27 September 2026).
- Riskonnect: AI page — AI branding with no data-use statement found (accessed 27 September 2026).
- LogicGate: Master Services Agreement — the 30-day data-retrieval and auto-renewal terms (accessed 27 September 2026).
- LogicGate help center: LogicGate AI — opt-in enablement, model names, retention and the no-training statement (accessed 27 September 2026).
- Resolver: Artificial Intelligence legal page — the six named AI features and their model providers (accessed 27 September 2026).
- Resolver: Trust and Compliance page — certifications and the ISO 27001 certificate’s listed expiry date (accessed 27 September 2026).
- Protecht: Cognita page — single-tenant hosting and the no-third-party-training statement (accessed 27 September 2026).
- AuditBoard bid response to West Virginia DOT — production hosting regions and export formats (accessed 27 September 2026).
- City of Norman, Oklahoma: council agenda attachment — the TeamMate quote and hosting bundle (accessed 27 September 2026).
- University of California: AuditBoard (now Optro) UC-wide agreement — the December 2025 systemwide agreement (accessed 27 September 2026).
- Wolters Kluwer: Gartner Market Guide for Audit Management Software summary — the 13 April 2026 report and its agent-washing warning (accessed 27 September 2026).
Related guides
- Internal audit software: the independent buyer’s guide — every review, comparison and buying guide in one place.
- How we review audit software — the evidence levels, the scorecard and the fit-by-situation method.
- The audit software shortlist finder — eight questions, a shortlist with the reasons from each review.
- The requirements matrix — 156 weighted requirements and vendor scoring in a free Excel workbook.
- Best Internal Audit Software — every platform in this program ranked by situation.
- Internal Audit Software Pricing — real numbers and how to negotiate them down.
- Types of Internal Audit Software — which category you need before you evaluate a vendor.
- GRC Suite vs Standalone Audit Management Software — the build decision this due diligence assumes is already made.
- Internal Audit Software vs Compliance Automation — a different category, a different risk profile.
- Evaluating AI in Audit Software — the feature-by-feature companion to the AI section above.
- The Business Case for Audit Software — how to fund the project this due diligence protects.
- The Audit Software Demo Script — scripted questions for before the due diligence stage.
- Audit Software vs Excel and SharePoint — whether you need this category yet.
- Implementing Audit Management Software — what happens once the contract is signed.
- 15 Mistakes Internal Audit Teams Make When Buying Software — the broader list these questions help avoid.
- Selecting an Audit Management System — where due diligence fits into a full selection process.
- Audit Software for Small Internal Audit Teams — due diligence scaled for a one-to-five-person function.
Leave a Reply