External auditors need documents. They do not need a living shared Drive that still contains last year’s drafts, HR side quests, and a “final” folder that is never final.
This playbook shows how to share documents with external auditors using sealed packets—controlled access, clear versions, and close-out— without pretending a vault replaces your audit program.
What goes wrong with the forever folder
- Scope creep: auditors see materials outside the engagement letter
- Version confusion: v3 and v7_final both sit in the same tree
- Access immortality: the folder outlives fieldwork
- Weak answers to “who could open this?”—especially after staff churn
Sealed-packet workflow for fieldwork
- Map requests to document classes (policies, samples, exports)
- Stage only in-scope artifacts; strip drafts and unrelated customer data
- Upload via client-side encryption into a vault dedicated to the engagement
- Mint sealed shares per audience (lead auditor vs specialists) with expiry aligned to fieldwork + report window
- Notify with links only—no bulk ZIP email
- Revoke or expire when the report is issued; archive your exports
Compliance Locker supports sealed shares and exportable activity for that packet layer. Read what auditors ask for so you do not over-promise cryptographic theater.
Packet design tips
One request → one sealed set
Prefer small, labeled packets (“Access control samples — Q2”) over a single mega-folder. Easier to revoke, easier to version.
Separate counsel and auditor materials when required
Privilege and engagement boundaries matter. Do not dump legal strategy memos into the same share as operational evidence.
Align expiry with the calendar
Default to fieldwork end + a short buffer. Exceptions need an owner. Publish the rule in your share expiry policy.
What this does not solve
- Incomplete samples or weak controls in the underlying systems
- Auditor tools and PBC trackers
- Legal privilege strategy—talk to counsel
- Certification outcomes—a vault does not “make you compliant”
FAQ
Should auditors get a forever shared Drive folder?
Usually no. Auditors need a time-boxed, complete packet—not an eternal folder that accumulates drafts and out-of-scope files. Prefer sealed sets with clear versions and expiry after fieldwork.
What evidence do auditors typically want about document access?
Who had access, when material was shared or viewed, and that sensitive packets were controlled. See our guide on document audit trails for what reviewers actually ask for.
Can we use the same room for customers and auditors?
Separate audiences. Customer diligence and external audit fieldwork have different scopes, NDAs, and close-out needs. Mint distinct sealed packets.
Does a vault replace our GRC or audit tool?
No. It holds and shares sealed source documents. Your audit workflow, sampling, and issue tracking stay in whatever system your auditor and internal team use.
What about live interviews and walkthroughs?
Those still happen in meetings. The vault is for artifacts—policies, screenshots, configs, evidence exports—not for replacing conversation.
Related: vendor diligence rooms, ZIP vs sealed vault.