Personal project Live SaaS beta Invite / waitlist access
Flagship projectAuditFlow OS: a digital audit management platform
AuditFlow OS is a multi-tenant audit management platform connecting audits, controls, evidence, findings, risks, actions, management responses and reports. I designed the operating model, data relationships, role structure and delivery roadmap, then progressed it from a Notion MVP to a working SaaS beta, live now at auditflowos.co.uk.
Audit work without a shared structure
Audit work becomes difficult to manage when it is split across spreadsheets, documents, folders and disconnected trackers: records are inconsistent, findings are written differently between auditors, evidence is difficult to trace back to controls, actions lose ownership, and reporting takes longer than it should. The key decision was to prove the operating model fully in Notion first, and only start SaaS development once the workflow was validated end to end.
Live in beta
AuditFlow OS Beta is deployed and organisation-scoped: each account has its own audits, findings, evidence, actions and controls, with owner and lead-auditor roles. Access is currently by invite or waitlist rather than open signup. What follows is the actual product, not a mockup.
Finding detail, close up
One finding, split into its parts: severity and risk scoring, the management response workflow, its linked controls and evidence, and the actions and risks it drives. Click any image to enlarge.
Built on the Cyber and GRC Readiness Pack Series
AuditFlow OS started with a four-part audit question pack series (IS4, ISO 27001, NCSC CAF, NIST CSF 2.0) built from my COMSEC audit work. The packs, with previews and downloads, now live on the Cyber & GRC page →
How an audit moves through the system
AuditFlow OS covers the full audit lifecycle from scoping through evidence review, findings, actions and reporting. The SaaS beta currently maps audit content to five starting frameworks: ISO 27001, NIST CSF, NCSC CAF, HMG IS4 and the EU AI Act. The earlier Notion workspace explored a wider seven-framework model, additionally covering NIST AI RMF and ISO 42001, which may be added to the beta later.
As a system: auditors, audit managers, stakeholders and auditees feed in policies, logs, documents and evidence. The core connects audit planning, evidence management, a workflow engine, risk assessment, findings & actions, reporting & dashboards, a controls library and framework mapping. It outputs audit reports, dashboards, action plans and compliance status.
What shaped the build
Prove it in Notion first
The full audit lifecycle was validated end-to-end in a working Notion MVP before any SaaS code was written, so the SaaS build started from a proven data model rather than a blank page.
Traceability over speed
Every finding links back to the evidence and controls that support it, and forward to the action agreed to remediate it. Nothing is filed separately from what it proves.
A real management response workflow
Findings require an agreement position (agreed, partially agreed or disagreed), a target date and a risk-acceptance decision before moving to agreed remediation, not just a status flag.
Reports lock on issue
Issued reports are version-controlled: later changes to evidence or findings never alter a report once it has been issued.
Notion to SaaS, in five phases
Currently operating across phases 3 and 4, live in beta.
| Phase | What it covers |
|---|---|
| 1. Notion MVP | Audit, findings, evidence, actions and controls databases, dashboard, templates, reporting libraries and example audits. |
| 2. Productised Notion template | Sales page, product overview, how-to guide, glossary, example evidence and pricing structure. |
| 3. SaaS foundation | Authentication, organisations, user roles, audit records, findings, evidence, actions, controls, dashboard and permissions. |
| 4. SaaS workflow depth | Audit lifecycle automation, management responses, evidence uploads, report generation, risk scoring and framework mapping. |
| 5. Scale & refinement | Multi-tenant controls, admin dashboard, audit trail, export options, integrations and usage analytics. |
Live in beta, scaling deliberately
Core audit workflow, linked findings/evidence/actions, dashboard and reporting, framework mapping and role-based organisation access are all live. PDF export is live; broader automation and integrations are still ahead. Not yet built: supplier assurance module, wider control library, automated evidence reminders, audit trail history, a portfolio-level risk dashboard, and AI-assisted report drafting.
The full roadmap, backlog, risk register and lessons learned, along with the Notion workspace tour and the eight-week public build series, are on the build history page →
Artefacts
Product roadmapBacklogRisk registerRelease planFramework mapping docNotion audit database
What this demonstrates
Product & systems thinkingDelivery managementProcess mapping