,

Audit Software Due Diligence: Security, Data Residency, AI Data Use and Vendor Stability

Buying an internal audit platform is not an ordinary SaaS purchase. The system a bank or a public company selects will hold its audit universe, the risk assessments that name exactly where controls are weak, the workpapers that document what was tested and what failed, and the issues log that tracks unremediated findings by owner and due date. For a SOX-heavy company the same system may also carry the evidence behind the chief executive’s and finance chief’s certifications. A vendor breach, an unvetted subprocessor, or a sale to a buyer with different priorities does not just create the ordinary SaaS headache of downtime and support tickets. It can expose the one document that describes, in one place, exactly where an organization’s controls do not work.

This guide sets out what to actually check before signing: how to read the vendor’s own SOC 2 or ISO 27001 report rather than just noting that one exists, where the software is hosted and what a FedRAMP claim on a marketing page does and does not mean, how the 2026 wave of AI features handles your data, what access control and audit logging look like, what happens to your data when the contract ends, and who actually owns the company on the other side of the signature. It closes with a 40-question checklist and a worked example for a mid-size bank. The review method behind every page in this program, including the evidence used here, is described in full in how we review audit software; this guide complements the site’s general vendor due diligence by risk tier method with the questions specific to a system that will hold your audit universe, findings and workpapers.

How to read this guide

What this guide is for. A practitioner checklist for the security, data-handling and vendor-stability questions specific to internal audit and GRC software, to run alongside your organization’s normal SaaS or third-party risk process, not instead of it.

Evidence. Research-based: vendor trust and security pages, FedRAMP Marketplace listings, help-center documentation, public procurement records and this program’s own product reviews. We have not used any of the products named on this page hands-on.

Last verified. 27 September 2026.

In this guide

Why audit software gets different due diligence

Most SaaS due diligence asks a standard set of questions about a vendor that will process business data. An internal audit platform asks a harder version of the same questions, because what it holds is not ordinary business data. The risk assessment module names which processes and controls the organization itself considers weakest. The workpapers show exactly what evidence was tested and what an auditor concluded. The issues log tracks every finding not yet fixed, with a due date that, if missed, is itself a second finding. Put together, that is a curated map of an organization’s control weaknesses, updated continuously. Very few other systems concentrate that much risk-relevant information in one place.

For a company subject to SOX, the stakes are higher still. Several platforms reviewed in this program, including Optro (formerly AuditBoard), TeamMate and Archer, are used to document and evidence internal control over financial reporting. When that is true, the tool becomes part of the control environment it documents. Its own change management, access controls and backups belong in the scope of the company’s SOX ITGC scoping, and Standard 14.6 on engagement documentation applies to how the workpapers it stores are retained, not only to their content.

There is a credibility point too. Internal audit is usually the function that pushes back hardest on a business unit’s rushed SaaS purchase, the one asking for the SOC 2 report before anyone signs. The department’s own platform purchase deserves at least the same rigor, run by the same third-party risk process the department expects everyone else to use, covered later in this guide.

Vendor stability: who actually owns the product

Private equity has touched nearly every vendor named in this program in the past three to five years, and ownership shapes what a buyer is actually signing up for. A financial owner typically expects to sell again within five to seven years, which can mean faster roadmap moves, heavier acquisition activity, and pricing pressure ahead of that exit. A public-company subsidiary is steadier but competes internally for investment against its parent’s larger lines of business. A still-independent, venture-backed company carries the least buyout risk but the smallest balance sheet. None of this is automatically disqualifying. All of it changes what to ask.

ProductCurrent ownerOwnership typeWhat it means for buyers
Optro (formerly AuditBoard)Hg, agreed 23 May 2024, more than $3 billionPrivate equity, wholly owned subsidiaryFast acquisition pace (FairNow, Midship); ask what Hg’s other portfolio companies saw at renewal
TeamMateWolters Kluwer (NYSE: WKL)Public-company divisionSteadier than a PE-backed peer, but competes internally against Wolters Kluwer’s larger tax, legal and health lines
Diligent One Platform (formerly HighBond)Insight Partners since 2016; Clearlake and Blackstone since 2020Private equity, sale reported exploredA sale worth close to $7 billion was reported explored in November 2024; no completion found. Ask directly whether a process is active
OnspringCapital IP Investment Partners, since 9 May 2023Growth equityFounders reportedly keep control; lower buyout risk than a take-private, but small scale next to the enterprise suites
ArcherCinven, closed 10 July 2023Private equity, third owner since 2020Chain runs RSA/Dell to STG (2020) to a Clearlake/STG spin-out (2021) to Cinven; ask what changed at each step
SAI360Symphony Technology Group (STG), agreement 9 January 2023 from BPEA EQT, completed 28 March 2023Private equitySAI360’s own pages describe its cloud hosting differently from each other; treat an unreconciled claim as a question, not a settled fact
RiskonnectThoma Bravo since 2017; TA Associates named majority investor in a January 2024 releasePrivate equity, dual sponsorVentiv and Camms were folded in within six months of each other in 2024; ask which legacy product a quote is built on
LogicGatePSG and Greenspring Associates, 2021 Series CVenture and growth capitalSmallest balance sheet here; a new chief executive took over from July 2026, worth a question on roadmap continuity
ResolverKroll since 30 March 2022Subsidiary of a larger risk and investigations businessSits inside a company whose core business is not GRC software; ask how it is prioritized against Kroll’s other lines
ProtechtPSG Equity, a US$280 million growth investment in 2025Private equity growth capitalAcquired VISO TRUST in April 2026, under PSG’s ownership; ask how an acquisition made after a change of control is integrated, not just marketed alongside
AlteryxClearlake Capital and Insight Partners, take-private completed 19 March 2024Private equity, delisted from the NYSEQuarterly public disclosure is gone; ownership and financial detail now come only from what the company publishes

Two patterns are worth a direct question rather than an assumption. The first is a live or recent sale process, like Diligent’s above; ask any vendor directly whether one is under way, since a change of control can move faster than a normal renewal cycle. The second is a rebrand that has outrun a buyer’s own paperwork: AuditBoard became Optro on 9 March 2026, and StandardFusion became TeamMate Risk & Compliance on 9 January 2026; a vendor risk registry still listing the old name will not match the entity on a new contract. Ask for the ultimate parent entity, not just the product brand, and what an assignment or change-of-control clause in the contract actually says.

Certifications, hosting and FedRAMP: what the label does not tell you

A logo on a trust page is a claim, not evidence. The report behind a SOC 2 or ISO 27001 certification is where due diligence actually happens: whether the report is Type I (design only) or Type II (design and operating effectiveness over a period), which of the five Trust Services Criteria are in scope, what complementary user-entity controls the report assumes your organization performs, and whether the auditor’s opinion is qualified or carries a subservice-organization exception. A vendor willing to share only a summary or a bridge letter, not the full report under NDA, is itself a finding worth writing down. The site’s guides to reviewing a SOC 2 report and reviewing a SOC 1 report cover what to check in each; ask for a SOC 1 too if the platform evidences SOX or other financial-reporting controls, since SOC 2 does not cover that ground.

VendorCertifications foundHosting and regionsFedRAMP / public-sector status
OptroSOC 1 and SOC 2 Type II, ISO 27001, HIPAA, TX-RAMP, HECVAT, CSA STARAWS; a state bid names Oregon (us-west-2) as primary with Virginia (us-east-1) failover; general non-US hosting is not statedTrust pages say hosting “meets FedRAMP moderate impact requirements”, which is a requirements statement, not an authorization we could find
TeamMateISO 27001, SOC 2 Type 2, TISAX, HIPAA, CSA STARMicrosoft Azure (TeamCloud), including a Johannesburg region added 30 April 2025; on-premise and offline options existFedRAMP Marketplace lists TeamMate Audit and Controls as Authorized, Moderate, agency path, since 13 May 2022; the TeamMate Audit product page still says “FedRAMP options (upcoming)”
Diligent One PlatformISO 27001:2013, annual SOC 2 Type IINine AWS commercial regions plus a GovCloud environmentGovCloud holds FedRAMP Moderate and DoD IL5, but several apps and ACL AI Studio are not listed as supported there
OnspringSOC 2 Type II, CSA STAR Level OneA standard environment and a separate GovCloud editionGovCloud reached FedRAMP Moderate authorization on 27 March 2024, up from an “In Process” designation dated 19 January 2023; the security page does not detail SSO, MFA or general data residency
ArcherSOC 2 Type 2, ISO 27001, ISO 27017, ISO 27701AWS across seven regions, a 99.5 percent SLANo FedRAMP or GovRAMP authorization found despite a dedicated Public Sector module; a module name is not a certification
SAI360Certifications named on the trust page, not itemized on the pages we readThe platform page says “Built on Google Cloud”; the trust page separately describes AWS-plus-Google-Cloud toolingNo FedRAMP or GovRAMP claim found
RiskonnectSOC 2 Type 2; the security page also cites the older SSAE 16 standardData-center claims on the platform security page, not itemized by regionNo ISO or FedRAMP claim found
LogicGateSOC 2 Type II, ISO 27001, CSA STAR, EU-US Data Privacy Framework, 21 CFR Part 11Customer choice of AWS hosting location: US, UK, Australia or EUNo FedRAMP or StateRAMP listed
ResolverSOC 2, ISO 27001, ISO 27017, ISO 27701, CSA STAR, TISAXNot detailed on the pages we readNo FedRAMP, GovRAMP, StateRAMP or DoD IL authorization found; the linked ISO 27001 certificate showed a listed expiry of 29 November 2025, already passed when checked
ProtechtISO 27001, a SOC 2 assessmentNot detailed on the pages we readNo FedRAMP, GovRAMP, StateRAMP or IRAP authorization found, despite government being a named target sector

FedRAMP is where vendor-page wording and reality diverge most often. TeamMate is the clearest example: the FedRAMP Marketplace lists TeamMate Audit and Controls as Authorized at the Moderate impact level, agency path, since 13 May 2022, and Wolters Kluwer’s public-sector page says the product is “FedRAMP and GovRAMP Authorized”, yet the TeamMate Audit product page still describes FedRAMP as “upcoming”. Onspring shows the opposite direction: its GovCloud edition moved from an “In Process” designation, sponsored by the Tennessee Valley Authority, on 19 January 2023, to a Moderate authorization on 27 March 2024, so an older page can understate current status just as easily as a newer one can overstate it. Check the FedRAMP Marketplace directly rather than a single vendor page, and confirm which products sit inside the boundary: Diligent’s GovCloud environment holds FedRAMP Moderate and DoD IL5, but several named apps and its ACL AI Studio are listed as unsupported there, so a platform’s core workflow can be authorized while its newest AI feature is not.

Public procurement records are the most concrete evidence available. A West Virginia Department of Transportation bid response names Optro’s production environment; the University of California’s systemwide agreement, executed 23 December 2025, and the City of Norman, Oklahoma’s TeamMate quote both show what a real public-sector deployment looked like, in a way a marketing page does not. The site’s guides to auditing cloud security and auditing data privacy compliance go deeper on the underlying control questions once the hosting facts are in hand.

AI features and data use: opt-in, training and sub-processors

Every vendor in this program shipped an agentic AI feature in 2025 or 2026. Gartner’s Market Guide for Audit Management Software, published 13 April 2026, told buyers to be “particularly wary of agent-washing”, and the due-diligence answer to that warning is three specific questions, asked feature by feature rather than of the platform as a whole: is it opt-in or on by default; is your content used to train or fine-tune the underlying model, and for how long is it retained; and which model provider or subprocessor actually does the processing.

Vendor and featureModel or providerOn by default or opt-inTrains on customer dataWhat is not published
Optro AIIn-house machine learning plus Microsoft’s Azure OpenAI serviceOpt-in, per the vendor’s AI pageVendor states customer data is not used to train the modelWhich subprocessors the newer Accelerate and Midship features add
TeamMate+ AI EditorNot publishedNot stated as opt-in or defaultVendor states submitted content is not used to train the model and is discarded once suggestions are generatedModel provider and hosting region
Diligent ACL AI StudioAmazon Bedrock; Diligent’s own 17 September 2026 release notes name the Claude 4.6 modelNot statedVendor states no training on customer data by default, with labeled outputRetention period; whether the default can be changed by an admin
Onspring AI and Agentic GRCAnthropic’s Claude, per the vendor’s own releasesAdd-on requiring the Silver service tier or aboveNot statedRetention period, training use and hosting region for the AI feature specifically
Archer Evolv AI ComplianceAmazon Bedrock Guardrails, run inside the customer’s own AWS account and IAM roleArchitecturally separate from Archer’s environment by designPrompts and model weights are described as isolated from ArcherWhether this architecture covers Archer’s other, older AI features
LogicGate AINamed OpenAI models including gpt-4.1-mini and gpt-5-mini, with a bring-your-own-key optionOpt-in, enabled by an administratorVendor states data is not used to train models and is retained 30 days under LogicGate’s own keyLittle; this is the most complete public disclosure in the group, with a dated subprocessor list
Resolver AI (six named features)Anthropic and AWS models, per Resolver’s AI legal pageNot stated uniformlyNo blanket retention policy across all six featuresA single retention or training statement covering every feature
Protecht CognitaNo model provider namedNot statedVendor states single-tenant AWS hosting, no cross-customer sharing and no use to train third-party modelsWhich underlying model performs the work
Riskonnect (Agentforce and Intelligent Risk)Not namedNot statedNo data-use, training or retention statement found anywhere on the vendor’s siteEverything; treat as unknown until the vendor answers in writing
SAI360 (GRC Elevate 6.0 AI)Not namedNot statedNo data-use or training statement found on the AI overview pageEverything; same treatment as Riskonnect above

Optro’s is the most complete published commitment in the group, running on in-house machine learning plus Microsoft’s Azure OpenAI service. Archer’s Evolv AI Compliance feature, launched 15 September 2026, is worth understanding on its own terms: it runs Amazon Bedrock Guardrails inside the customer’s own AWS account and IAM role, so prompts and model weights are described as isolated from Archer’s environment entirely, rather than processed inside the vendor’s own infrastructure the way most of the table above is. At the other end, Riskonnect’s and SAI360’s current AI features carry no public data-use statement at all on the pages we read. Treat that silence as the finding, not as an assumption of safety: get the answer in writing before turning a feature on, and ask separately what happens to AI-generated content and any model artifacts derived from your data once the contract ends, a question the exit-terms section below returns to.

Access control, SSO and tenant separation

The baseline for enterprise software in this category is SAML single sign-on, SCIM provisioning, role-based access control fine enough to separate auditors, reviewers, auditees and administrators, and mandatory multi-factor authentication for administrators. Diligent One Platform documents SAML SSO, SCIM and OIDC; Optro documents SAML 2.0 and SCIM; LogicGate’s trust page describes a choice of hosting location alongside SSO and provisioning, role-based access and history logs. Two gaps in this program’s research are worth flagging directly rather than assuming away. SAI360’s own plans page shows that its entry-level Essentials edition excludes single sign-on entirely, along with the AI chat assistant and advanced analytics, so confirming SSO exists somewhere in the product line is not the same as confirming it is in the edition being quoted. Onspring’s public security page does not detail SSO, MFA or data residency at all; those answers have to be requested directly rather than read off the page.

  • Edition, not just product. Ask which specific tier includes SSO, SCIM and role-based access, since the lowest-priced edition is the one most likely to exclude them.
  • Tenant separation. Ask how your data is logically separated from other customers on shared infrastructure, and whether single-tenant hosting is available at a cost you would consider.
  • Vendor staff access. Ask who at the vendor can see your content by default, under what circumstances, and whether that access is itself logged.
  • A live test, not a slide. Before signing, provision a test user through your identity provider and confirm SSO and role restrictions actually work as described, rather than relying on the sales deck.

Audit trail, logging and retention

Two different things get called “audit trail” in an RFP, and it is worth separating them. The workpaper audit trail records who changed a test step, a conclusion or a risk rating, when, and what the prior value said; this is the version history this program’s product reviews generally find documented, at varying depth, across the platforms. The security audit log is a different record entirely: who logged in, from where, and what administrative actions, exports or permission changes they made. A vendor can have one well documented and say little about the other.

None of the vendors covered in this program publishes a specific retention period for its security logs on the pages we read. LogicGate’s trust page is the most explicit about the feature existing at all, naming history logs directly; Diligent One Platform publishes the closest thing to an operational commitment in the group, a one-hour recovery point objective and a 24-hour recovery time objective, which speaks to resilience more than to log retention specifically but is still the kind of number worth asking every other vendor to match. Where a number is not published, get one in writing: the retention period for security logs, whether administrative activity is logged separately from ordinary use, and whether logs can be exported to your own monitoring tools rather than viewed only inside the vendor’s console.

Exit terms and data export

The point in the relationship where a buyer has the least leverage is exactly when exit terms matter most: at the end of the contract, when a team negotiating a renewal has every incentive not to slow things down by pushing on data export. Most vendors in this market are silent on exit terms in anything publicly available, which means the handful that do publish something are worth using as a template for what to ask for.

VendorPublished exit termsFormat and window
OptroNot a general published policy; a state bid response specifies deliverables on requestZIP, PDF and CSV export, per that bid
LogicGateMaster Services Agreement, section 7.3A 30-day data-retrieval window after termination, then deletion; separately, 30 days’ notice is required to stop auto-renewal (section 3.6)
Diligent One PlatformTrust and compliance pageA 30-day post-termination extraction window
TeamMate, Onspring, Archer, SAI360, Riskonnect, Resolver, ProtechtNot published on the pages we readNegotiate a specific window and format into the order form; do not assume one

Three items are worth writing into the order form when the standard contract is silent, which for most vendors here it is: a defined post-termination data-retrieval window, in a stated export format, not left to an open-ended support request; advance notice of auto-renewal, since contracts in this market commonly renew automatically absent a specific notice period, as LogicGate’s Master Services Agreement does at 30 days; and what happens to AI-generated content and any model artifacts derived from your data, a question almost none of the standard exit clauses still in circulation address. A related question is continuity short of an orderly exit: what happens if the vendor itself fails or is acquired mid-contract, which the site’s guide to third-party resilience covers in more depth.

How a bank’s third-party risk program should classify this vendor

For a regulated institution, this purchase should not move through intake as a routine SaaS request, and internal audit does not get to size its own risk. The same third-party risk management program that reviews every other vendor should tier this one, using the site’s third-party risk management lifecycle and vendor due diligence by risk tier methods, and the Global Internal Audit Standards’ third-party topical requirement is a reasonable place to anchor why this vendor gets more scrutiny than its contract value alone would suggest.

What the due diligence findsTypical effect on tierWhy it matters here
The platform holds unremediated findings, control-weakness detail and SOX evidencePushes toward High or CriticalThis is a curated map of exactly where the organization is weakest; its value to an attacker is out of proportion to the software’s price
Multi-tenant SaaS with no single-tenant optionNeutral to slightly higherStandard for this category; ask about logical separation rather than treating multi-tenancy itself as disqualifying
An AI feature trains on customer data, or the vendor will not sayPushes toward Critical, or to “not approved until answered”An unanswered AI data-use question is itself the finding; do not default to assuming the answer is no
No FedRAMP, GovRAMP or equivalent claim, for a regulated buyerRaises the bar for compensating controls, does not automatically fail the vendorMost of this market has no such authorization; a bank can still use it with the right contract terms and monitoring
Recent or in-process change of ownershipAdds an annual reassessment trigger regardless of the contract’s renewal dateA new owner can change security investment, support staffing and roadmap faster than a standard review cycle would catch
No published exit or data-export termsRequires the terms to be negotiated into the contract before signing, not assumedMost vendors in this market are silent on this; silence is not consent to a favorable default

For a bank buying a platform that will hold SOX evidence and an unremediated-issues log, the resulting tier is typically High or Critical, on par with vendors adjacent to core banking rather than a scheduling or expense tool, even when the contract value looks modest by comparison. The practical consequence is usually threefold: annual reassessment rather than a review triggered only by renewal; visibility at the audit committee, consistent with the Global Internal Audit Standards’ Principle 8 on board oversight; and a documented compensating-control plan for any gap the due diligence turns up, rather than a simple pass or fail.

The 40-question due diligence questionnaire

Keep the vendor’s written answers to the questions below in the due diligence file alongside the SOC 2 report and the contract, not just in an email thread. Questions with no vendor answer at all, not a reassuring one, are the ones worth escalating.

Audit software due diligence questionnaire

Ownership and stability. Who is the ultimate parent entity, not just the product brand? Has the company changed hands, or explored a sale, in the past three years? Is the roadmap set by the operating company or the financial owner, and what has that owner changed at other portfolio companies after a deal? What happens to our contract on a change of control? Has the product been rebranded or merged with an acquired product recently, and does that match the legal name on the contract we are signing?

Certifications and audits. Will you provide the full current SOC 2 Type II report, not a summary or a bridge letter, under NDA? Which Trust Services Criteria are in scope, and does the report cover the module we are buying or only the platform in general? What complementary user-entity controls does it assume we perform? Does the report carry any qualified opinion, exception or subservice-organization carve-out? Is the ISO 27001 certificate current, and does its Statement of Applicability cover the environment we will use? Do you commission independent penetration testing, and will you share a summary of the results?

Hosting and data residency. In which cloud regions will our data be stored and processed, including any AI or analytics add-on? Is a US-only or EU-only hosting option available, and does it cover every module we are buying? If FedRAMP, GovRAMP or StateRAMP is claimed, what is the authorization level, and which products and modules are inside the boundary? Can we confirm that on the FedRAMP Marketplace rather than relying on your page? Is failover or backup hosted in a different jurisdiction than production? Do you publish a current subprocessor list, and will you notify us before adding one?

Access control and authentication. Does the edition we are quoted include SAML SSO and SCIM provisioning, or is that a higher tier only? Is role-based access granular enough to separate auditors, reviewers, auditees and administrators, and can we test that before signing? Is multi-factor authentication mandatory for administrators, and can we enforce it for every user? How is our tenant separated from other customers, and is single-tenant hosting available? Who at your company has access to our content by default, and can that access be restricted or logged?

AI and data use. Which AI features are on by default versus opt-in, module by module? Is our content used to train or fine-tune the model, for you or for the model provider? Which model provider processes the data for each feature, and is it named in your subprocessor list? How long is content retained, and can that be shortened or disabled? Can AI-generated output be distinguished from human-entered content for review purposes? What happens to AI-generated content and any derived model artifacts when the contract ends?

Audit trail and logging. Is every change to a workpaper, test step or conclusion logged with a user, timestamp and prior value? Is administrative activity, including permission changes, exports and deletions, logged separately from ordinary use? How long are security logs retained, and can that be extended or exported to our own monitoring tools? Can a full audit trail for a single engagement be produced on request, for our own quality assurance or an examiner?

Data retention, backup and continuity. What are your stated recovery point and recovery time objectives, and have they been tested this year? What is your backup frequency and retention period, and are backups stored in a separate region or account from production? What is your plan if a subprocessor or hosting provider you depend on fails or is breached? Do you carry cyber-liability insurance, at what level relative to our engagement?

Exit and incident response. On termination, what is the data-retrieval window, in what format, and is that written into the contract rather than left to a support request? Does the contract auto-renew, and how much notice must we give to prevent it? What is your breach-notification commitment, in hours or days, with a named contact? Has your company had a publicly disclosed security incident, and if so, what changed afterward?

Worked example: Lakeshore Bancorp scopes a due diligence review

Lakeshore Bancorp, the $9 billion regional bank used as a worked example across this site, is replacing the Excel workbook that has tracked its 212 key controls since before its last exam cycle. Two finalists remain after an RFP run on the site’s vendor-neutral RFP method. Before either gets a signature, the chief audit executive routes the purchase through the bank’s third-party risk management program rather than approving it inside the department, precisely because the platform will hold the bank’s SOX evidence and its full issues log.

Third-party risk sizes the engagement High, on par with vendors that touch core banking rather than the scheduling software it usually reviews, and sets an annual reassessment cycle with a line to the audit committee rather than the standard renewal-only review. The 40-question due diligence turns up two pictures. Platform A holds a FedRAMP Moderate authorization for its core workflow, but the newer AI issue-drafting module it demonstrated sits outside that boundary, hosted on general commercial cloud with no model provider named in writing; Lakeshore’s compensating control is to leave that module off in the order form and treat it, if ever turned on, as a separate, lower-trust fourth party requiring its own written data-use terms. Platform B carries no FedRAMP claim at all, which rules it out for one federal-adjacent exam relationship but not for internal use; its SOC 2 Type II report is current with a clean opinion, and it publishes a 30-day post-termination export window in a named format, unlike most of the market. The gap the questionnaire finds is that single sign-on sits behind a higher edition than the one first quoted.

Lakeshore selects Platform B. Three terms not offered in the standard order form get written into the contract before signing: a defined security-log retention period, matched to the bank’s own examiner expectations; a named contact and a stated hours-based commitment for breach notification; and the SSO-inclusive edition, priced in from the start rather than added later at a premium. Each one traces back to a specific gap the 40-question checklist caught, not to a general sense that the vendor seemed trustworthy.

Questions about audit software due diligence

What is the real difference between SOC 1 and SOC 2 for an audit-software vendor?

SOC 1 is scoped to controls relevant to a user entity’s financial reporting, which matters if the platform itself evidences SOX or other ICFR controls. SOC 2 is scoped to the Trust Services Criteria, security, availability, processing integrity, confidentiality and privacy, and is the one that answers most of the questions in this guide. Ask for both if the platform touches financial-reporting evidence; the site’s guides to reviewing a SOC 1 report and reviewing a SOC 2 report cover what to check in each.

Does a vendor’s FedRAMP claim mean it is actually authorized?

Not necessarily, and not on its own. TeamMate’s own pages disagree with each other: the FedRAMP Marketplace and the vendor’s public-sector page say Authorized, while the core product page still says “upcoming”. Check the FedRAMP Marketplace listing directly, and confirm which specific products and modules sit inside the authorization boundary, since an add-on like an AI or analytics module is sometimes excluded even when the core platform is authorized.

Should a private-equity-owned vendor be a dealbreaker?

No. Most of this market is PE-owned today, including Optro, Archer, SAI360, Riskonnect and Alteryx, and ownership alone predicts little about product quality. What matters is what changes after a deal: pricing pressure at renewal, support staffing, and whether a live sale process, like the one reported for Diligent in November 2024, is disclosed when you ask directly.

Can we let a vendor’s AI features touch real findings and workpapers?

Only once you have the vendor’s answers in writing on whether the feature is opt-in, whether your content trains the model, which model provider processes it, and how long it is retained, not from the marketing page but from the contract or data processing agreement. Where a vendor has published no data-use statement at all, as with Riskonnect’s and SAI360’s current AI features, treat that silence as a negotiation item, not an assumption of safety, before turning the feature on.

Who should own this due diligence: internal audit, IT security, procurement or third-party risk?

All four have a stake, but the accountable owner should be the same third-party risk function that reviews every other vendor, not internal audit alone, precisely because internal audit is the interested buyer here. Internal audit’s role is to bring the questions specific to this category into that process, not to certify its own tool.

How is this different from the site’s general vendor due diligence guide?

The site’s general vendor due diligence guide covers the mechanics that apply to any SaaS purchase, tiered by risk. This guide applies that method to one specific, higher-stakes case, a system that will hold your risk assessments, workpapers and unremediated findings, where the ownership, hosting and AI questions above are worth asking of every vendor in the market, not only the one you are closest to signing.

internalauditguide.com has no commercial relationship with any vendor named on this page. We take no vendor money, run no affiliate links and accept no sponsored placements, and no vendor saw this page before publication. Product and company names are the trademarks of their owners. Corrections: desk@internalauditguide.com.

Sources and verification

New guides & tools by email

Useful so far?

There are 400+ more guides where this came from. Get new guides, templates and free audit tools by email when they ship. No schedule, no filler.

Free. One confirmation email from WordPress.com, then you’re in. Unsubscribe anytime.

New guides & tools by email

Don’t lose this library.

400+ practitioner-written guides and free tools. Hear when new ones land.

One confirmation email from WordPress.com, then you’re in. Unsubscribe anytime.

Comments

Leave a Reply

Discover more from internalauditguide.com

Subscribe now to keep reading and get access to the full archive.

Continue reading