Skip to main content

Set Up a Monthly Compliance Audit

Configure Nexxis to automatically run a compliance audit each month, score your controls, and email a summary to your team.

5 min readUpdated 2026-02-01
auditautomationscheduledmonthly

Overview

A monthly compliance audit keeps your compliance posture up to date without manual effort. Nexxis will automatically evaluate your controls, surface any regressions, and deliver a report to your team.

Time to set up: ~10 minutes Prerequisites: At least one project created with a compliance framework selected


Step 1: Open Your Project

  1. From the home page, click the project you want to configure
  2. Navigate to Workflows in the left sidebar
  3. Click New Workflow → select Monthly Compliance Audit

Step 2: Configure Scope

Choose what the audit will evaluate:

  • All controls — full scan across every control in your framework
  • High-priority only — focus on Critical and High severity controls
  • Custom selection — cherry-pick specific control families
**Tip:** For your first audit, select "All controls" to get a full baseline.

Step 3: Set the Schedule

  1. Select Recurring under Schedule Type
  2. Choose Monthly
  3. Pick a day (e.g., the 1st of each month) and time (e.g., 09:00 NZST)
  4. The first run will execute immediately so you can validate the output

Step 4: Configure Notifications

  1. Add email recipients for the audit summary
  2. Choose notification conditions:
- **Always** — send a report every month regardless of findings - **Regressions only** — only notify when a control moves from Compliant to At Risk - **New critical findings** — only notify for Critical severity findings

Step 5: Review & Activate

  1. Click Preview to see a sample report
  2. Review the control scope and schedule
  3. Click Activate Workflow
The workflow is now live. You'll receive the first audit report within a few minutes.

Reading the Audit Report

The report includes:

SectionDescription
Overall ScorePercentage of controls passing
TrendScore vs. last month
New FindingsControls that regressed since last audit
Resolved FindingsControls that were fixed since last audit
Top RisksHighest-severity open findings

Troubleshooting

Workflow isn't running? Check that your integration credentials haven't expired under Settings → Integrations.

Report shows stale data? Make sure your evidence sources are connected. Disconnected sources show a warning badge in the Integrations panel.

Missing controls? Some controls require manual evidence uploads. Look for controls with the 📎 icon — those require a document attachment.