Audit, Documents, and Evidence
Prepare audit evidence without the scramble.
Audit Centre helps teams create audit sessions, upload and release evidence, invite auditors, track requests, and review access activity.
Before you begin
Before creating an audit session, make sure you have prepared your documentation. Preparing your evidence before inviting auditors will help create a smoother and more efficient audit process.
- Uploaded all relevant Staff, Participant, Site and Organisation documents.
- Reviewed your documentation for completeness and accuracy.
- Identified the evidence required for the audit.
- Decided which documents and records should be shared with the auditor.
Recommended setup order
For the best experience, we recommend preparing your Audit Centre in the following order.
1 Run your readiness checks
Open the Readiness tab and run the readiness checks. BondiByte scores your organisation across domains such as worker compliance, participant records, service delivery, incidents, and document control.
Every issue comes with a plain-language explanation of how to fix it, and the score updates itself as records change.
Fix the items under Fix these first before an audit. Critical checks cap the score until they are resolved.
2 Choose your enforced documents
Open Settings in the Audit Centre and tick the document types every staff member must hold. Unticked types are still available, but nobody is chased for them.
Staff see their own checklist in the staff portal and app under My Compliance, get weekly digests, and can upload renewals themselves. Screening documents wait for a manager to verify them.
3 Prepare your evidence
Review and organise all documents required for the audit before creating your audit session. This may include:
- Organisation policies
- Staff records
- Participant documentation
- Site documentation
- Operational records
- Supporting evidence
Having your documentation prepared in advance reduces delays during the audit.
4 Create an audit session
Create a new Audit Session for the upcoming audit.
Each session acts as a dedicated workspace where you can manage evidence, auditor access and audit-related communication.
5 Organise evidence
Create Evidence Groups to organise your documents into logical categories. Examples include:
- Organisation
- Operations
- Workforce
- Participants
- Compliance
- Governance
Grouping evidence makes it easier for auditors to locate the information they require.
6 Upload or release evidence
Upload any additional documentation required for the audit and select which evidence will be made available to auditors.
Only release documents that are relevant to the specific audit session.
7 Invite auditors
Invite auditors using BondiByte's secure Auditor Invite feature.
Auditor access is separate from standard user accounts and provides controlled access only to the evidence you choose to share.
8 Respond to evidence requests
During the audit, auditors may request additional information.
You can respond by uploading further documentation or releasing additional evidence directly through the Audit Centre.
This keeps all audit communication and supporting documentation together in one secure location.
9 Review access & close the audit
Once the audit has concluded:
- Review auditor activity through the Access Log.
- Confirm access end dates.
- Remove or expire auditor access where appropriate.
This helps maintain security while ensuring external users only have access for the required period.
Understanding the Audit Centre
Audit Session
A dedicated workspace used to organise and manage documents, evidence and auditor access for a specific audit.
Evidence Group
A category used to organise audit evidence into logical sections (e.g. Organisation, Operations, Workforce, Participants), making documentation easier to review.
Auditor Invite
A secure invitation that provides auditors with limited, session-specific access to audit evidence. This is separate from normal user accounts and helps protect sensitive organisational information.
Evidence Request
A request from an auditor asking for additional documentation or supporting evidence during the audit process. Requests can be managed directly within the Audit Centre.
Access Log
A record of auditor activity, showing when evidence has been viewed or accessed during the audit, providing greater transparency and accountability throughout the audit process.
Access End Date
The date when auditor access automatically expires. Using access end dates helps maintain security by ensuring temporary access does not remain active longer than necessary.
Readiness Score
A live score built from automatic checks over your operational records, broken down by domain, with plain-language fixes for every issue. Warnings and dismissed exceptions are visible, never hidden.
My Compliance
The staff portal and app screen where each staff member sees the documents they must hold, their right-to-work status, and what needs renewing, with uploads handed straight to the right document type.
Sample
A reproducible selection of records (for example staff files or shifts) generated for an audit session so auditors can review a fair slice of your operations.
Finding
An auditor-raised observation or non-conformity on an audit session. You respond in the workspace and can attach corrective actions with owners and due dates.
Complaints Register
A simple register of complaints with acknowledgement and resolution tracking. Feeds the readiness checks and gives auditors the register they usually ask for.
Best practice
- Keep the readiness score green all year rather than fixing everything the month before an audit.
- Let staff clear their own compliance items from My Compliance instead of chasing them by email.
- Prepare and organise documentation before creating your audit session.
- Share only the evidence required for the specific audit.
- Use Evidence Groups to keep documentation organised and easy to navigate.
- Invite auditors using secure Auditor Invites rather than standard workspace accounts.
- Review auditor access regularly and remove access once the audit has been completed.
Common mistakes to avoid
- Assuming organised evidence guarantees compliance or a successful audit outcome.
- Inviting auditors before your documentation has been reviewed and prepared.
- Uploading documents without releasing them to the relevant audit session.
- Sharing broader workspace access instead of using scoped Auditor Invites.
- Forgetting to expire auditor access once the audit has concluded.
What to do next
Related guides
Documents
Upload and manage documents linked to staff, clients, sites, or organisation areas, with expiry dates and audit evidence readiness.
Automation and NotificationsEmail Notifications
Understand platform-managed email: sender profiles, your Reply-To settings, workflow notifications, email readiness, and troubleshooting checks.
Security, Roles, and AccessRoles and Access
Understand Owner, Admin, Manager, Staff, Staff Portal access, auditor access, and platform administration separation.
Need help applying this setup path?
Book a BondiByte demo and we can walk through the right setup order for your provider.