Critical or important functions
Scope services, assets, suppliers and controls with MTPD, RTO and RPO for the relevant functions.
Operational registers
AuditReady separates exercises from operational incidents: both generate learning, findings and evidence, but they remain two separate registers.
Scope services, assets, suppliers and controls with MTPD, RTO and RPO for the relevant functions.
Record resilience tests, disaster recovery, backup/restore, penetration tests and reusable tabletop scenarios, with PDF or JSON export per run.
Keep a register of impact, severity, affected services, root cause and status, with notification stages for DORA, NIS2, GDPR or AI Act profiles.
A real incident and a simulation remain separate registers, even though both can generate findings and evidence.
Define MTPD, RTO, RPO and links to systems, assets and suppliers.
Organise tabletop scenarios, disaster recovery, backup/restore and penetration tests.
Follow the steps, timeline and any gaps that emerge during the run.
Track severity, root cause, notification stage and status, kept separate from exercises.
Assess likelihood and impact before and after controls, assign a treatment and bring the rationale and available evidence into review.
ExploreAn operational repository for documents and proof: not an isolated archive, but the connection point between a control, policy, supplier, audit and register.
ExploreFrom entity profiling to board attestations, from policies to assets: AuditReady connects the elements that define the scope you need to govern.
ExploreNo, they remain two separate registers, even though they can generate shared findings and evidence.
Yes, every run can be exported as PDF or JSON with steps, timeline and identified gaps.
Yes, an operational incident can be classified under a DORA, NIS2, GDPR, AI Act, or other profile.