Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Create an observation for an engagement

Create an audit observation to present a summary of problems, discoveries, and recommendations. The audit team can then review the observations to determine if the observation is a reportable issue.

Before you begin

Role required: sn_audit.manager, sn_audit_ws.supervisor, sn_audit.user, sn_audit_ws.auditor

Procedure

  1. Navigate to All > Audit > Audit Workspace.

  2. Select the lists icon (

Image omitted: ListsIcon.jpg
List icon\).
  1. Select All engagements in the Execution list.

  2. Select the link to the engagement record in the Name column.

  3. Select the Observations tab.

  4. Select New.

  5. On the form, fill in the fields.

FieldDescription
NumberUnique identification number.
NameName of the observation.
EngagementEngagement associated with this observation.
SourceSource or origin of the observation.
Issue typeReason for creating the observation. The choices are:- Control design effectiveness failure - Control operative effectiveness failure - Control does not exist - Control doesn’t meet requirement - Other observation
StateState of the observation.
SubstateSubstate of the observation.
PriorityPriority of the observation. Choices are:- 1 — Critical - 2 — High - 3 — Moderate - 4 — Low
DescriptionDetailed description of the observation.
Action planPlan for resolving the resulting issue.
Assignment
OwnerUser who creates and is responsible for the observation.
Peer reviewerOne of the auditors responsible for peer review.
RespondentUser responsible for completion of the action plan.Respondent can be the owner of the entity or control associated with the parent engagement.
Reviewer groupGroup assigned to review the observation.
ReviewerUser responsible for reviewing the observation.
Watch listUsers interested in following updates to the observation.
Details
ControlControl associated with the observation.
Control ObjectiveControl objective associated with the observation.
EntityEntity associated with the observation.
Audit taskAudit task associated with the observation.
Results
ResultResult of the observation. The choices are as follows:- Track as an observation - Track as a recommendation - Track as a best practice - Confirmed as a new issue - Confirmed as an existing issue - No action required
ExplanationExplanation for the selected result.
Activity
Work notes \(Private\)Notes about the observation. Work notes are visible to users who are assigned to the observation.
Additional commentsPublic information about the observation.
Security
ConfidentialOption to enable confidentiality of the record. Only the assigned confidential users or confidential groups of users can access the record.
-   **Confidentiality flag to control access of audit records**

    You can set the confidentiality flag at the record level for an issue, engagement, observation, control test, activity, interview, and walkthrough records. The users whom you determine to view and update these records are confidential users.

    When the **Confidentiality** option is selected, a list of users who can be an engagement lead, auditors, and approvers are auto-populated as **Confidential users**.

    You can add more audit users or GRC business users to the list or remove some of the existing users based on your access control criteria and can set them as confidential users.

    Additionally, you can also add random users to the record, who are neither audit users nor GRC business users. However, an email notification is sent to all confidential users who have neither an audit user nor a GRC business user role intimating them to acquire the confidential role \(sn\_grc.confidential\_user\) from the admin if they are to access the record.

    You can also select groups as **Confidential groups** who can access the record as well. For more information, see Confidential records in GRC common features.

    To enable the Confidentiality property at the system level:

    1.  Navigate to **System Properties** > **All Properties**.
    2.  Select **sn\_grc.enable\_record\_confidentiality** system property.
    3.  Enter **true** in the **Value** field. This action enables record level confidentiality.
    4.  Select **Update**.
  1. Select Save.

    You can monitor the state of the observation record in the State banner of the default Overview page as the record progresses through the different states.