Set Up a Monthly Compliance Audit
Configure Nexxis to automatically run a compliance audit each month, score your controls, and email a summary to your team.
Overview
A monthly compliance audit keeps your compliance posture up to date without manual effort. Nexxis will automatically evaluate your controls, surface any regressions, and deliver a report to your team.
Time to set up: ~10 minutes Prerequisites: At least one project created with a compliance framework selected
Step 1: Open Your Project
- From the home page, click the project you want to configure
- Navigate to Workflows in the left sidebar
- Click New Workflow → select Monthly Compliance Audit
Step 2: Configure Scope
Choose what the audit will evaluate:
- All controls — full scan across every control in your framework
- High-priority only — focus on Critical and High severity controls
- Custom selection — cherry-pick specific control families
**Tip:** For your first audit, select "All controls" to get a full baseline.
Step 3: Set the Schedule
- Select Recurring under Schedule Type
- Choose Monthly
- Pick a day (e.g., the 1st of each month) and time (e.g., 09:00 NZST)
- The first run will execute immediately so you can validate the output
Step 4: Configure Notifications
- Add email recipients for the audit summary
- Choose notification conditions:
Step 5: Review & Activate
- Click Preview to see a sample report
- Review the control scope and schedule
- Click Activate Workflow
Reading the Audit Report
The report includes:
| Section | Description |
|---|---|
| Overall Score | Percentage of controls passing |
| Trend | Score vs. last month |
| New Findings | Controls that regressed since last audit |
| Resolved Findings | Controls that were fixed since last audit |
| Top Risks | Highest-severity open findings |
Troubleshooting
Workflow isn't running? Check that your integration credentials haven't expired under Settings → Integrations.
Report shows stale data? Make sure your evidence sources are connected. Disconnected sources show a warning badge in the Integrations panel.
Missing controls? Some controls require manual evidence uploads. Look for controls with the 📎 icon — those require a document attachment.