Completing an Assessment in Assuredly for your SMB Audit
To provide evidence to your auditor you can use one of the following processes:
- send your auditor evidence as a secure document package via email
- upload your evidence in the Documents module in Assuredly; or
- complete a self-assessment in the Assuredly platform uploading evidence as you go.
If you decide to provide your auditor with evidence by completing a self-assessment in the Assuredly platform please follow this guide:
Before You Start
- You'll receive an audit post kick off email - this gives you a link straight to the assessment in the Assuredly platform.
- You can move between questions at any time using the question navigation panel - you do not need to answer them in order.
- You can save your progress and return later. Nothing is looked at until you tell your auditor you are ready.
Step 1: Review Each Question
Read the question carefully. Each question relates to a specific control (e.g. password policy, backup procedures, access management).
Select the Help Guide button (top right of the question) if you're unsure what the control means or what's expected. This opens:
- An overview of what the control is.
- Suggestions for how to test or measure whether you meet the control.
- Helpful tools and templates to help you put the control in place if you don't already have it.
- A list of evidence types an auditor would typically expect to see for this control.
Select your response to the question based on your organisation's actual current practice.
Use Flag if you want to come back to a question later (e.g. you need to check something internally first).
Use Note to add any context an auditor or reviewer should know - for example, if a control is partially in place or a compensating control exists.
Tip: Always check the Help Guide before answering if you're not 100% sure what the question is asking - it tells you exactly what "good" looks like and what evidence will back it up.
Step 2: Add Supporting Evidence
Evidence is what an auditor uses to confirm your answer is accurate. The suggested evidence list in the Help Guide is based on what real auditors ask for, so use it as your checklist for each question.
- Select Add Evidence on the question.
- Choose Upload or Link:
- Upload — add a new file (e.g. a policy document, screenshot, or report) to your document store and attach it to this question.
- Link — attach a document that's already in your document store (useful if the same evidence supports more than one question).
- Repeat for every question that requires evidence. You can attach more than one piece of evidence to a single question if needed.
Tip: If a piece of evidence supports several questions (e.g. an Information Security Policy), upload it once and use Link to attach it to each relevant question - no need to upload the same file multiple times.
Good Evidence to Have Ready
Common evidence types requested across most SMB Standard questions include:
- Policies and procedures (e.g. password policy, acceptable use policy, backup policy).
- Screenshots of system configurations or security settings.
- Records or logs (e.g. access reviews, patch logs, training records).
- Reports from third-party tools (e.g. vulnerability scan results, backup reports).
- Signed or dated documents showing a process has actually been carried out — not just that a policy exists.
The exact evidence expected varies question to question - always check the Help Guide on that specific question rather than relying on this general list.
Quick Checklist
- Read the question and check the Help Guide if unsure.
- Select the response that reflects your actual practice.
- Upload or link evidence that supports your answer.
- Add a Note if extra context is needed.
- Flag any questions you need to revisit.
- Repeat for every question
- Let your auditir know when you are ready for them to review.
Need Help?
If you get stuck on a specific question, use the Help Guide on that question first. For anything else, reach out to your auditor for support.