Skip to main content
Version: 1.0.0-beta

Follow-Up Testing

Follow-up testing validates that action plans have been effectively implemented. The auditor re-executes test procedures against the original finding criteria to confirm the control gap has been closed.

Creating a Follow-Up Test

  1. Open the finding from Findings module
  2. Navigate to the Follow-Up Tests tab
  3. Click + New Follow-Up Test
  4. The form pre-fills with context from the original finding

Follow-Up Test Fields

FieldDescriptionSource
Finding ReferenceThe finding being re-testedAuto-linked
Test DescriptionWhat procedures will be performedAuditor
Result SummaryOutcome of the re-testAuditor
EvidenceSupporting files proving the resultUploaded
ConclusionPass / Fail / PartialAuditor

Testing Process

Step-by-Step

  1. Review the original finding — understand the CCCER components
  2. Review remediation evidence — examine what the action owner submitted
  3. Design follow-up test — determine what to re-test
  4. Execute the test — perform the verification procedure
  5. Document results — record what was found
  6. Upload evidence — attach screenshots, reports, or exports
  7. Set conclusion — Pass, Fail, or Partial

Evidence for Follow-Up Tests

Follow-up test evidence follows the same chain-of-custody rules as engagement evidence:

  • Files are virus-scanned on upload
  • SHA-256 hash computed and stored
  • Uploader ID and timestamp recorded
  • Files linked via follow_up_test_id on the Evidence model
  • Evidence is immutable after upload

Automated Reminders

When a follow-up test is due:

  • The auditor receives a notification
  • The finding appears in the "Pending Follow-Up" filter
  • Dashboard metrics include follow-up testing completion rates

Permissions

ActionPermission
Create follow-up testsfinding:update (Auditor, Manager, CAE)
Execute and record resultsfinding:update (Auditor, Manager, CAE)
Upload follow-up evidenceevidence:upload (Auditor, Manager)
Close finding after verificationfinding:close (Manager, CAE)