FS-DOC-03Operations
Process Runbook / SOP
Audit Preparation Workflow
[YourCompany.com] · Legal Department · Prepared by FullSpec · [Today's Date]
This runbook is the day-to-day operating guide for the Compliance Manager running the automated Audit Preparation Workflow. It describes what the system does automatically, what your team does, how to handle exceptions, and who to contact when something needs attention. FullSpec has built and configured everything described here. Your responsibility is to log new audit records correctly, review flagged documents, and keep the contact list and configuration up to date between audit cycles.
01Process overview
The Audit Preparation Workflow begins the moment a new audit record is created in Notion with a confirmed engagement date. From that point, two automated agents handle evidence collection, stakeholder assignment, status monitoring, overdue chasing, document validation, DocuSign signature routing, and folder organisation. The Compliance Manager's only required action is to review any documents the system flags as ambiguous or incomplete, and to confirm auditor access once the evidence pack is verified. Approximately 120 document requests are processed per audit cycle, across two to four cycles per year.
Process name
Audit Preparation Workflow
Trigger
A new audit record is created in Notion with a confirmed engagement date and audit scope
Final output
A verified, organised evidence pack in Google Drive with a Slack completion alert sent to the Compliance Manager and leadership channel
Agents running
Evidence Collection Agent; Document Review and Organisation Agent
Tools involved
Notion, Gmail, Slack, Google Drive, DocuSign
Weekly volume
Approximately 120 document requests per audit cycle; 2 to 4 cycles per year
Human checkpoint
Compliance Manager reviews documents flagged by the Document Review and Organisation Agent before auditor access is granted
Process owner
Compliance Manager
Process Runbook / SOPPage 1 of 4
FS-DOC-03Operations
02Step-by-step: what happens and who acts
What you actually need to do: Your only required action in this process is to open the Notion flagged-items queue, review any documents marked as incomplete or ambiguous by the Document Review and Organisation Agent, and decide whether to accept, re-request, or escalate each item. Everything else, including assignment emails, checklist monitoring, overdue reminders, DocuSign routing, folder organisation, and completion alerts, is handled automatically.
Step
What happens
Who acts
Type
1
An audit record is created in Notion with the confirmed engagement date, audit scope, and assigned compliance owner. This record is the trigger that starts the entire workflow.
Compliance Manager
Human
2
The Evidence Collection Agent reads the audit type from the Notion record and generates a structured evidence checklist, pre-populating each line item with the document name, the responsible internal owner, and the internal due date.
Evidence Collection Agent
Automated
3
Each stakeholder named on the checklist receives a personalised Gmail message listing their specific document requests, the required file format, and the internal submission deadline. No manual drafting is required.
Evidence Collection Agent
Automated
4
A structured Google Drive folder is created for the audit cycle, with sub-folders pre-named by evidence category. Stakeholder access permissions are set automatically based on the checklist assignments.
Evidence Collection Agent
Automated
5
The Evidence Collection Agent checks the Drive submission folder on a daily schedule and updates each Notion checklist item with its current status: received, pending, or overdue. No manual tracker review is needed.
Evidence Collection Agent
Automated
6
When a submission passes its internal deadline, the overdue stakeholder receives an automated Slack nudge and a follow-up Gmail message flagging the outstanding item. This repeats at configured intervals until the item is submitted.
Evidence Collection Agent
Automated
7
As files arrive in the submission folder, the Document Review and Organisation Agent checks each file against the expected evidence list. Files that are correctly named and complete are moved to the verified evidence pack folder. Files that appear incomplete, mislabelled, or incorrect are queued in Notion for Compliance Manager review.
Document Review and Organisation Agent
Automated
8
The Compliance Manager opens the Notion flagged-items queue and reviews each document the agent could not verify automatically. For each item, the manager decides whether to accept it, request a corrected version from the stakeholder, or escalate it. This is the single human decision point in the workflow.
Compliance Manager
Human
9
Documents identified as requiring a director or department-head signature are automatically sent to the nominated signatory via DocuSign. When the signed document is returned, a completion webhook updates the corresponding Notion checklist item to verified.
Document Review and Organisation Agent
Automated
10
Once all checklist items reach a verified status, the Document Review and Organisation Agent posts a completion alert to the designated Slack channel, notifying the Compliance Manager and leadership that the evidence pack is ready for auditor access.
Document Review and Organisation Agent
Automated
Process Runbook / SOPPage 2 of 4
FS-DOC-03Operations
03Handling exceptions
Situation
What the system does
What you do
A required checklist field is missing when the audit record is created in Notion (for example, no engagement date or audit scope selected)
The automation detects the incomplete trigger record and does not proceed. It posts an alert to the Compliance Manager via Slack identifying which fields are missing.
Open the Notion audit record, complete the missing fields, and save. The workflow will re-trigger automatically once the record is valid.
A stakeholder uploads a file that appears to be a duplicate of one already received
The Document Review and Organisation Agent detects a filename or content match, retains the most recently uploaded version, and flags the duplicate in the Notion checklist with a note for review.
Check the flagged item in Notion to confirm which version is correct. Archive or delete the duplicate from the Drive folder. Update the checklist item status to verified if the correct file is present.
A document is uploaded but does not match any item on the evidence checklist (unexpected file)
The agent cannot map the file to a checklist line item and moves it to an unmatched files sub-folder in Drive. It flags the item in Notion with the status unmatched and queues it for Compliance Manager review.
Open the unmatched files folder in Drive and the Notion flagged-items queue. Determine whether the file belongs to an existing checklist item and rename and move it accordingly, or request the correct document from the stakeholder.
A stakeholder does not respond to overdue reminders after two escalation rounds
The Evidence Collection Agent logs the item as escalation required in Notion and sends an alert to the Compliance Manager via Slack, including the stakeholder name, the outstanding document, and the number of reminders sent.
Contact the stakeholder directly by phone or in person. If the stakeholder is unable to provide the document, escalate to their department head or reassign the request within Notion to an alternative owner.
A DocuSign signature request is sent but the signatory does not complete it before the audit deadline
The Document Review and Organisation Agent monitors the DocuSign envelope status. If the envelope remains unsigned past the configured reminder period, it sends an additional DocuSign reminder and posts a Slack alert to the Compliance Manager.
Contact the signatory directly to confirm they received the DocuSign request and are able to sign. If the signatory is unavailable, work with your legal lead to identify an authorised substitute and update the DocuSign recipient within the automation configuration.
Google Drive, Notion, DocuSign, or another connected tool is unavailable or returns an error
The automation platform retries the failed action up to three times at five-minute intervals. If all retries fail, the workflow pauses that branch and sends a Slack alert to the Compliance Manager and an email to support@gofullspec.com with the error details.
Check the Slack alert for the affected step. If the outage is a known service disruption, wait for the tool to recover and the automation will resume from the paused step. If the issue persists beyond one hour, email support@gofullspec.com with the alert details for FullSpec to investigate. For time-critical items, continue manually using the tool directly until the automation resumes.
Process Runbook / SOPPage 3 of 4
FS-DOC-03Operations
04Who to contact and when
Fill in the rows below once your team is confirmed. Keep this table updated whenever roles change so that escalations reach the right person without delay.
Role
Name
How to reach them
Process owner (Compliance Manager)
[Your name]
[Rep email]
Legal Ops Lead (escalation for unsigned declarations or disputed evidence)
[Your name]
[Rep email]
IT or system administrator (tool access and permission issues)
[Your name]
[Rep email]
Department head contact (escalation for non-responsive stakeholders)
[Your name]
[Rep email]
FullSpec builder (automation configuration changes, agent updates, logic changes)
FullSpec team
support@gofullspec.com
FullSpec support (errors, outages, unexpected behaviour, general questions)
FullSpec support
support@gofullspec.com
Contact FullSpec support at support@gofullspec.com for any automation behaviour that does not match this runbook, including unexpected Slack alerts, missed trigger events, checklist items stuck in the wrong status, or DocuSign routing errors. Do not attempt to reconfigure the automation platform directly unless FullSpec has confirmed the change in writing.
05Ongoing maintenance
Before each new audit cycle
Review and update the Notion audit record template to reflect any changes to the evidence list, document categories, or stakeholder assignments for the upcoming audit type. Confirm Drive folder naming conventions have not changed.
Compliance Manager
When email or Slack templates need updating (tone, deadline dates, format requirements)
Contact FullSpec at support@gofullspec.com with the revised wording. FullSpec will update the assignment and reminder message templates within the automation and confirm the change before the next cycle.
Compliance Manager, FullSpec team
Monthly spot-check (recommended)
Open the Notion dashboard and confirm the automation is running as expected. Check that the last cycle's checklist items closed correctly and that no items are stuck in an open or pending status after the audit was completed.
Compliance Manager
Monthly error-log review
Review any Slack alerts or error notifications received during the past month. Forward unresolved alerts to support@gofullspec.com for investigation. Confirm that all DocuSign envelope completions updated Notion correctly.
Compliance Manager, FullSpec team
When a team member joins, leaves, or changes role
Update the contact table in this runbook. Notify FullSpec at support@gofullspec.com so that Slack alert recipients, Gmail sender permissions, and DocuSign signatory mappings can be updated in the automation configuration before the next cycle.
Compliance Manager, FullSpec team
Quarterly volume review
At the end of each quarter, review the number of audit cycles run, the average evidence pack turnaround time, and the volume of flagged or unmatched documents. If volumes have grown significantly or the audit scope has expanded, contact FullSpec to assess whether the automation configuration needs adjustment.
Compliance Manager, FullSpec team
The most common maintenance issue for this process is a mismatch between the Notion evidence checklist template and the actual document list required for a new audit type. If a new audit framework is added (for example, moving from an annual financial audit to a SOC 2 review), the Notion schema and the agent's checklist generation logic must be updated before the new audit record is created. Triggering the workflow against an outdated template will produce incorrect assignments and checklist items. Contact FullSpec before creating a new audit record of a new type.
Process Runbook / SOPPage 4 of 4