Finding it in the sidebar
Open the Compliance module and click Audit Requests in the left sidebar. Direct URL:/compliance/audit-requests.
The Compliance sidebar is long. Audit Requests sits below the controls
section under a small uppercase caption that reads
EVIDENCE & REPORTING — the caption is a visual divider, not a
clickable group. The siblings under the same caption are
Control Tests, Audit Periods, Issues, Reports,
Evidence Collection, Questionnaires, and Audit Trail.
If you can’t see Audit Requests at all, you’re probably in the PSA
module — switch to Compliance in the top-left module switcher.
When to use this vs. compliance issues
Request types
Status workflow
Every request moves through a five-state machine. Three are working states; two are terminal.Cadence (recurring requests)
Requests can be one-time or recurring:Creating a request
Open Audit Requests
Link to an audit period (recommended)
Optionally tag the auditor invite
Capture the request metadata
- External ID — the auditor’s reference (e.g.
IRL-042). Not unique in Regentra because the same code may recur across audits. - Title + Description — what the auditor wants.
- Type — Document, Test, Observation, or Inquiry.
- Cadence — one-time or recurring.
- Owner — the operator responsible for gathering the evidence.
- Due date — for SLA tracking.
Link controls (optional but high-value)
Save in NOT_READY
Attaching evidence
Evidence is added inside the request:- Files — direct uploads (PDFs, screenshots, CSV exports)
- Links — URLs to dashboards, monitoring tools, or live runbooks
- Existing controls’ evidence — reference an evidence record that is already attached to a linked control (no second upload)
- Existing test results — pull a control-test run directly into the request
Comments and the back-and-forth
Each request has a comment thread visible to both sides once the request is AUDIT_READY. Internal comments (visible only to the customer side) are also supported for the back-channel “is this the right version?” conversation that should not be in the auditor view. The thread is preserved when a request is FLAGGED → re-attached → pushed back to AUDIT_READY, so the auditor sees the full history of the loop.Status transitions and who can drive them
What the auditor sees
External auditors interact with Audit Requests through their token-scoped portal at/audit/{token} — they never receive a login
to the main Regentra app. Through that portal they can:
- See every request currently in AUDIT_READY, APPROVED, or FLAGGED (NOT_READY and INTERNAL_REVIEW requests are hidden — they’re customer-side prep)
- Download attachments
- Read the linked controls and their evidence
- Comment on a request
- Approve or flag the request
- Download a per-request CSV and the full audit-package ZIP for the audit period
Status dashboard
The Audit Requests page surfaces five lanes (NOT_READY, INTERNAL_REVIEW, AUDIT_READY, APPROVED, FLAGGED) with counts and a list of requests in each. Filters: by audit period, by owner, by cadence, by type, by “overdue only”. A request is “overdue” when its due date is past and its status is NOT_READY, INTERNAL_REVIEW, AUDIT_READY, or FLAGGED — APPROVED requests never show as overdue regardless of their original due date.Frequently asked questions
What's the difference between a FLAGGED request and a Compliance Issue?
What's the difference between a FLAGGED request and a Compliance Issue?
Can I bulk-import an IRL from a spreadsheet the auditor sent me?
Can I bulk-import an IRL from a spreadsheet the auditor sent me?
What happens to a recurring request when the audit period ends?
What happens to a recurring request when the audit period ends?
Can the auditor see who on my team uploaded each piece of evidence?
Can the auditor see who on my team uploaded each piece of evidence?
A request was approved by the auditor. Can I edit it?
A request was approved by the auditor. Can I edit it?