IBRAHIM OJOYE Project Delivery · Cyber Security & GRC

Personal project Live SaaS beta Invite / waitlist access

Flagship project

AuditFlow OS: a digital audit management platform

AuditFlow OS is a multi-tenant audit management platform connecting audits, controls, evidence, findings, risks, actions, management responses and reports. I designed the operating model, data relationships, role structure and delivery roadmap, then progressed it from a Notion MVP to a working SaaS beta, live now at auditflowos.co.uk.

Problem

Audit work without a shared structure

Audit work becomes difficult to manage when it is split across spreadsheets, documents, folders and disconnected trackers: records are inconsistent, findings are written differently between auditors, evidence is difficult to trace back to controls, actions lose ownership, and reporting takes longer than it should. The key decision was to prove the operating model fully in Notion first, and only start SaaS development once the workflow was validated end to end.

Working product

Live in beta

AuditFlow OS Beta is deployed and organisation-scoped: each account has its own audits, findings, evidence, actions and controls, with owner and lead-auditor roles. Access is currently by invite or waitlist rather than open signup. What follows is the actual product, not a mockup.

Finding detail, close up

One finding, split into its parts: severity and risk scoring, the management response workflow, its linked controls and evidence, and the actions and risks it drives. Click any image to enlarge.

Finding severity, status and risk scoring in AuditFlow OS Beta
Severity and risk scoring · likelihood, impact and risk rating calculated per finding.
Management response workflow for a finding in AuditFlow OS Beta
Management response · agreement position, target date and comments, built into the finding, not bolted on afterwards.
Linked controls and linked evidence for a finding in AuditFlow OS Beta
Linked controls and evidence · the finding traces back to the specific control and evidence that support it.
Actions and risks linked to a finding in AuditFlow OS Beta
Actions and risks · remediation actions and any risks raised from the finding, tracked to closure.
AuditFlow OS Beta generated audit report showing executive summary, scope, approach, overall opinion, evidence summary, findings summary, detailed findings, management responses, recommendations and action plan, and appendix
Generated report · executive summary, scope, approach, overall opinion, evidence and findings summaries, detailed findings, management responses, a recommendations and action plan, and an appendix, exportable as a PDF, issued reports are locked and version-controlled.
AuditFlow OS Beta members and roles settings page showing organisation role and audit access per member, and ownership transfer
Members & roles · organisation-scoped access across eight roles: Owner, Admin, Lead Auditor, Auditor, Control Owner, Action Owner, Read-only and External Contributor.
Exported PDF of an AuditFlow OS Beta audit report
The same report, exported to PDF.
Core workflow & data relationships

How an audit moves through the system

AuditFlow OS covers the full audit lifecycle from scoping through evidence review, findings, actions and reporting. The SaaS beta currently maps audit content to five starting frameworks: ISO 27001, NIST CSF, NCSC CAF, HMG IS4 and the EU AI Act. The earlier Notion workspace explored a wider seven-framework model, additionally covering NIST AI RMF and ISO 42001, which may be added to the beta later.

Audit Planning
Evidence Management
Findings & Risk Assessment
Actions & Follow-up
Reporting & Dashboards

As a system: auditors, audit managers, stakeholders and auditees feed in policies, logs, documents and evidence. The core connects audit planning, evidence management, a workflow engine, risk assessment, findings & actions, reporting & dashboards, a controls library and framework mapping. It outputs audit reports, dashboards, action plans and compliance status.

Key product decisions

What shaped the build

Prove it in Notion first

The full audit lifecycle was validated end-to-end in a working Notion MVP before any SaaS code was written, so the SaaS build started from a proven data model rather than a blank page.

Traceability over speed

Every finding links back to the evidence and controls that support it, and forward to the action agreed to remediate it. Nothing is filed separately from what it proves.

A real management response workflow

Findings require an agreement position (agreed, partially agreed or disagreed), a target date and a risk-acceptance decision before moving to agreed remediation, not just a status flag.

Reports lock on issue

Issued reports are version-controlled: later changes to evidence or findings never alter a report once it has been issued.

Delivery phases

Notion to SaaS, in five phases

Currently operating across phases 3 and 4, live in beta.

PhaseWhat it covers
1. Notion MVPAudit, findings, evidence, actions and controls databases, dashboard, templates, reporting libraries and example audits.
2. Productised Notion templateSales page, product overview, how-to guide, glossary, example evidence and pricing structure.
3. SaaS foundationAuthentication, organisations, user roles, audit records, findings, evidence, actions, controls, dashboard and permissions.
4. SaaS workflow depthAudit lifecycle automation, management responses, evidence uploads, report generation, risk scoring and framework mapping.
5. Scale & refinementMulti-tenant controls, admin dashboard, audit trail, export options, integrations and usage analytics.
Current status and next steps

Live in beta, scaling deliberately

Core audit workflow, linked findings/evidence/actions, dashboard and reporting, framework mapping and role-based organisation access are all live. PDF export is live; broader automation and integrations are still ahead. Not yet built: supplier assurance module, wider control library, automated evidence reminders, audit trail history, a portfolio-level risk dashboard, and AI-assisted report drafting.

The full roadmap, backlog, risk register and lessons learned, along with the Notion workspace tour and the eight-week public build series, are on the build history page →

Artefacts

Product roadmapBacklogRisk registerRelease planFramework mapping docNotion audit database

What this demonstrates

Product & systems thinkingDelivery managementProcess mapping

Interested in AuditFlow OS or similar work?

Request beta access, or talk delivery