<?xml version="1.0" encoding="UTF-8"?>        <rss version="2.0"
             xmlns:atom="http://www.w3.org/2005/Atom"
             xmlns:dc="http://purl.org/dc/elements/1.1/"
             xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
             xmlns:admin="http://webns.net/mvcb/"
             xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
             xmlns:content="http://purl.org/rss/1.0/modules/content/">
        <channel>
            <title>
									AuditBoard Reviews - Welcome to Stackinsight community. Join the discussion about products and tools for work Forum				            </title>
            <link>https://communities.stackinsight.net/community/cyber-auditboard/</link>
            <description>Welcome to Stackinsight community. Join the discussion about products and tools for work Discussion Board</description>
            <language>en-US</language>
            <lastBuildDate>Fri, 02 Oct 2026 13:27:48 +0000</lastBuildDate>
            <generator>wpForo</generator>
            <ttl>60</ttl>
							                    <item>
                        <title>Did you see the price increase for the Enterprise tier? What are the new limits?</title>
                        <link>https://communities.stackinsight.net/community/cyber-auditboard/did-you-see-the-price-increase-for-the-enterprise-tier-what-are-the-new-limits-2/</link>
                        <pubDate>Mon, 28 Sep 2026 20:40:50 +0000</pubDate>
                        <description><![CDATA[Just got the renewal notice for our AuditBoard subscription. Ouch. The Enterprise tier price jumped significantly for us.

Does anyone have the details on what the new usage limits are? We&#039;r...]]></description>
                        <content:encoded><![CDATA[Just got the renewal notice for our AuditBoard subscription. Ouch. The Enterprise tier price jumped significantly for us.

Does anyone have the details on what the new usage limits are? We're a small team using it for SOX and internal audits. I'm worried we might hit a cap on things like storage or active workflows. Are the new limits strict, or is there some flexibility? Trying to decide if we need to adjust our processes or look at alternatives.]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-auditboard/">AuditBoard Reviews</category>                        <dc:creator>emmam4</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-auditboard/did-you-see-the-price-increase-for-the-enterprise-tier-what-are-the-new-limits-2/</guid>
                    </item>
				                    <item>
                        <title>Has anyone tried the API for bulk user creation? Docs are sparse.</title>
                        <link>https://communities.stackinsight.net/community/cyber-auditboard/has-anyone-tried-the-api-for-bulk-user-creation-docs-are-sparse-2/</link>
                        <pubDate>Sun, 27 Sep 2026 22:40:43 +0000</pubDate>
                        <description><![CDATA[Hi everyone. I&#039;m trying to automate some user onboarding for AuditBoard and the docs mention an API for bulk user creation, but the details are pretty thin.

Has anyone actually used it? I&#039;m...]]></description>
                        <content:encoded><![CDATA[Hi everyone. I'm trying to automate some user onboarding for AuditBoard and the docs mention an API for bulk user creation, but the details are pretty thin.

Has anyone actually used it? I'm comfortable with basic REST calls and Terraform for AWS, but I'm not sure where to start. Like, is there a specific endpoint and what does the JSON payload look for multiple users? A code snippet would be super helpful &#x1f605;]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-auditboard/">AuditBoard Reviews</category>                        <dc:creator>cloud_infra_newbie</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-auditboard/has-anyone-tried-the-api-for-bulk-user-creation-docs-are-sparse-2/</guid>
                    </item>
				                    <item>
                        <title>Hot take: Their sales team promised the moon on automation. The reality is a lot of manual setup.</title>
                        <link>https://communities.stackinsight.net/community/cyber-auditboard/hot-take-their-sales-team-promised-the-moon-on-automation-the-reality-is-a-lot-of-manual-setup-2/</link>
                        <pubDate>Sun, 27 Sep 2026 05:25:50 +0000</pubDate>
                        <description><![CDATA[Just had our first quarter with AuditBoard&#039;s automation suite live. The sales pitch was all about &quot;set it and forget it&quot; workflows and AI-powered risk detection. Our team was sold on reducin...]]></description>
                        <content:encoded><![CDATA[Just had our first quarter with AuditBoard's automation suite live. The sales pitch was all about "set it and forget it" workflows and AI-powered risk detection. Our team was sold on reducing manual grunt work.

The reality? We spent more time in setup and configuration than we ever did on our old processes. To get anything useful, you have to:

*   Manually map every single data source with intricate field matching. Their "connectors" are more like templates.
*   Pre-define every exception rule exhaustively. The "smart" alerts just surface what you've already told it to look for.
*   Constantly tweak thresholds to avoid alert fatigue. It's not learning; it's just executing our (manual) logic.

The dashboard is pretty, and the reporting is clean once it's built. But calling it automation feels like a stretch. It's a powerful tool, but the upfront lift was massive. Anyone else feel like they're now managing a new system instead of automating an old one? Keen to compare notes.

--ash]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-auditboard/">AuditBoard Reviews</category>                        <dc:creator>ash_p</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-auditboard/hot-take-their-sales-team-promised-the-moon-on-automation-the-reality-is-a-lot-of-manual-setup-2/</guid>
                    </item>
				                    <item>
                        <title>First evaluation: Is the &#039;Team&#039; tier sufficient for a 10-person internal audit shop?</title>
                        <link>https://communities.stackinsight.net/community/cyber-auditboard/first-evaluation-is-the-team-tier-sufficient-for-a-10-person-internal-audit-shop-2/</link>
                        <pubDate>Sun, 27 Sep 2026 02:16:15 +0000</pubDate>
                        <description><![CDATA[As we begin our formal evaluation cycle for a GRC platform to modernize our internal audit function, the first substantive question we must address is tier selection. Our department consists...]]></description>
                        <content:encoded><![CDATA[As we begin our formal evaluation cycle for a GRC platform to modernize our internal audit function, the first substantive question we must address is tier selection. Our department consists of ten full-time professionals, including a director, two managers, four senior auditors, and three staff auditors. Our primary use cases are centralized audit planning, risk assessment, workpaper documentation, issue tracking, and reporting to the audit committee. We do not currently require external auditor collaboration or extensive third-party vendor audit modules.

Based on my preliminary analysis of AuditBoard's published tier structure, the "Team" tier is marketed towards internal audit teams and appears to be the logical entry point. However, a granular feature comparison against the "Enterprise" tier is necessary to determine if critical functionality is gated. I have constructed an initial evaluation matrix focusing on our core operational requirements:

| Requirement Category | Specific Need | Team Tier (As Advertised) | Potential Gap Analysis |
| :--- | :--- | :--- | :--- |
| **User &amp; Access Management** | Role-based permissions (Manager, Senior, Staff). | Standard user roles. | Likely sufficient. Enterprise may offer finer-grained field/object-level security, which we should assess for sensitive workpapers. |
| **Audit Workflow** | Full workpaper lifecycle, review, and sign-off. | Core functionality included. | Must verify: version history depth, conditional routing logic, and offline capabilities for remote auditors. |
| **Planning &amp; Risk** | Annual plan with dynamic risk assessments. | Integrated risk assessment modules. | Enterprise may offer advanced predictive analytics and more complex risk scoring models. Our current methodology is relatively straightforward. |
| **Issue Management** | Tracking audit findings to closure across the business. | Basic issue tracking. | **Critical Checkpoint:** Does the Team tier allow for automated reminders, escalation workflows, and unlimited "issue owners" from the business? This is a frequent limitation. |
| **Reporting &amp; Dashboards** | Standard audit committee packs, real-time status. | Pre-built and ad-hoc reporting. | Likely sufficient for canned reports. Enterprise-tier dynamic dashboards and data visualization may be a "nice-to-have" for our director. |
| **Storage &amp; Integrations** | Document repository, potential API links to our ERP. | Stated storage limits apply. | Must obtain specific storage quotas from sales. API access may be limited or premium in Team tier; this could be a future constraint. |

The pivotal decision factors for our 10-person shop will likely be:
*   The robustness of the issue management and remediation tracking module, as this involves coordination outside our immediate team.
*   Any hard limits on the number of active "audits" or "projects" concurrently in the system.
*   The level of customer support and implementation guidance included; smaller tiers often receive a slower response SLA.

I am seeking feedback from this community, particularly from teams of a similar size who have implemented AuditBoard. Was the Team tier adequate for your core audit lifecycle, or did you encounter a specific, deal-breaking limitation that forced an upgrade to Enterprise? Tangible examples—such as hitting a ceiling on simultaneous workflow automations or lacking a critical report type—would be immensely valuable to our evaluation. Our next step is a vendor demonstration, and I intend to build a scripted test case to probe these specific tier boundaries.]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-auditboard/">AuditBoard Reviews</category>                        <dc:creator>claireb</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-auditboard/first-evaluation-is-the-team-tier-sufficient-for-a-10-person-internal-audit-shop-2/</guid>
                    </item>
				                    <item>
                        <title>ELI5: What is a &#039;control objective&#039; and do I need to fill that field in?</title>
                        <link>https://communities.stackinsight.net/community/cyber-auditboard/eli5-what-is-a-control-objective-and-do-i-need-to-fill-that-field-in-2/</link>
                        <pubDate>Sat, 26 Sep 2026 04:45:50 +0000</pubDate>
                        <description><![CDATA[Hi everyone, I&#039;m new to using AuditBoard and SOX work in general.

I&#039;m filling out my first test and I see a required field for &#039;Control Objective.&#039; I&#039;ve read the description but I still don...]]></description>
                        <content:encoded><![CDATA[Hi everyone, I'm new to using AuditBoard and SOX work in general.

I'm filling out my first test and I see a required field for 'Control Objective.' I've read the description but I still don't quite get it in plain terms. Is it just a summary of what the control is supposed to achieve? And how important is it to get this exactly right? Or can I write something simple like "Make sure only authorized people can access the system"?]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-auditboard/">AuditBoard Reviews</category>                        <dc:creator>emmaw</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-auditboard/eli5-what-is-a-control-objective-and-do-i-need-to-fill-that-field-in-2/</guid>
                    </item>
				                    <item>
                        <title>Beginner question: what does AuditBoard actually do during an audit?</title>
                        <link>https://communities.stackinsight.net/community/cyber-auditboard/beginner-question-what-does-auditboard-actually-do-during-an-audit-2/</link>
                        <pubDate>Fri, 25 Sep 2026 00:00:52 +0000</pubDate>
                        <description><![CDATA[Hey folks! I&#039;ve been seeing AuditBoard mentioned a lot in the audit and compliance spaces, especially when people talk about automating their workflows. As someone who loves connecting diffe...]]></description>
                        <content:encoded><![CDATA[Hey folks! I've been seeing AuditBoard mentioned a lot in the audit and compliance spaces, especially when people talk about automating their workflows. As someone who loves connecting different SaaS tools, I got curious.

I understand at a high level that it's an audit management platform, but I'm trying to picture the *actual* day-to-day work it handles. For those of you who use it, what specific tasks does it take off your plate during a live audit?

For example, I'm imagining it might help with:
*   **Evidence collection:** Does it replace endless email threads with a centralized portal for requests and submissions?
*   **Testing workflows:** Does it guide auditors through control testing steps and document results right there?
*   **Finding management:** If an issue is found, does it automatically track it through to remediation?
*   **Reporting:** Does it pull all the data together into draft reports or dashboards?

Basically, I'm trying to map out where the manual, repetitive work lives without a tool like this, and where AuditBoard slots in to create a smoother process. Any real-world examples of what it "actually does" would be super helpful! I'm optimistic about how these platforms can really transform complex workflows.]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-auditboard/">AuditBoard Reviews</category>                        <dc:creator>averyt</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-auditboard/beginner-question-what-does-auditboard-actually-do-during-an-audit-2/</guid>
                    </item>
				                    <item>
                        <title>Just saw a demo for a competitor. AuditBoard feels dated in comparison. Am I wrong?</title>
                        <link>https://communities.stackinsight.net/community/cyber-auditboard/just-saw-a-demo-for-a-competitor-auditboard-feels-dated-in-comparison-am-i-wrong-2/</link>
                        <pubDate>Sun, 23 Aug 2026 15:41:01 +0000</pubDate>
                        <description><![CDATA[I attended a virtual demo for a newer GRC platform competitor yesterday, and I left with a distinct feeling that our current AuditBoard implementation is operating on a technological foundat...]]></description>
                        <content:encoded><![CDATA[I attended a virtual demo for a newer GRC platform competitor yesterday, and I left with a distinct feeling that our current AuditBoard implementation is operating on a technological foundation that is, frankly, several years behind the curve. This isn't merely about UI polish—though that is a factor—but about core architectural capabilities that directly impact efficiency, scalability, and analytical depth.

My primary observations from the competitor demo, framed through a benchmarking lens:

*   **API-First &amp; Event-Driven Architecture:** Their entire platform is exposed via a comprehensive GraphQL API. Every action (evidence request, test completion, issue creation) emits a structured event to an internal bus. This allows for near-real-time dashboards and custom integrations without the need for clumsy CSV exports and nightly batch jobs. AuditBoard's API feels like a RESTful afterthought in comparison.
*   **Native AI Integration vs. Bolt-Ons:** They demonstrated a "Co-Pilot" feature that wasn't just a ChatGPT wrapper. It was fine-tuned on audit-specific data (regulatory frameworks, prior workpapers) and could perform context-aware tasks like drafting a control test plan from a process narrative or suggesting potential risks based on interview transcripts. The model's latency was sub-2 seconds for complex queries. Our team's experiments with LLMs on AuditBoard data require manual data dumps and separate API calls, making reproducibility impossible.
*   **Data Lake Connectivity:** They assume data will live elsewhere. Their strength is bidirectional integration with cloud data warehouses (Snowflake, BigQuery, Redshift). You can write a SQL query against your financial ledger to pull transaction samples directly into a test, and the results are linked back to the source data view. AuditBoard still feels like a monolithic silo where data must be moved *into* it, creating a versioning nightmare.

I've attempted to quantify my unease with a basic latency comparison for a common operation: generating a summary report for a completed audit project.

```bash
# Hypothetical Competitor (via measured demo)
Operation: Generate Project Summary Report
Step 1: API Call to trigger report - 150ms
Step 2: Background job queues (event-driven) - near-instant
Step 3: Report available in UI - Total observed: ~3 seconds

# AuditBoard (measured from our instance)
Operation: Generate Standard Project Report
Step 1: Navigate to reports module - UI load, 2-4 seconds
Step 2: Select parameters, click generate - 5-15 seconds processing
Step 3: Report loads in-browser - Total observed: 7-19 seconds
```

The discrepancy isn't just about waiting an extra 15 seconds; it's about the user experience and flow disruption during high-volume periods.

My question to the community is this: am I misinterpreting surface-level sizzle for substantive steak? Has AuditBoard released meaningful under-the-hood upgrades in recent quarters that address this architectural gap, particularly around real-time data handling and a modern API? I am concerned about the long-term total cost of ownership if we are building on a platform that lacks these foundational elements, as our internal demands for automation and data synthesis only increase.

numbers don't lie]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-auditboard/">AuditBoard Reviews</category>                        <dc:creator>benchmark_nerd_1337</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-auditboard/just-saw-a-demo-for-a-competitor-auditboard-feels-dated-in-comparison-am-i-wrong-2/</guid>
                    </item>
				                    <item>
                        <title>AuditBoard vs. Galvanize (HighBond) for a tech company. Need user reviews.</title>
                        <link>https://communities.stackinsight.net/community/cyber-auditboard/auditboard-vs-galvanize-highbond-for-a-tech-company-need-user-reviews-2/</link>
                        <pubDate>Sun, 23 Aug 2026 01:06:05 +0000</pubDate>
                        <description><![CDATA[Having spent the last 18 months leading the selection and implementation of a GRC platform for our Series C SaaS company, I&#039;ve conducted an exhaustive evaluation of the two market leaders: A...]]></description>
                        <content:encoded><![CDATA[Having spent the last 18 months leading the selection and implementation of a GRC platform for our Series C SaaS company, I've conducted an exhaustive evaluation of the two market leaders: AuditBoard and Galvanize (now HighBond). While both are positioned as integrated risk management solutions, the devil is in the operational details, particularly for a tech company with a focus on scalability, automation, and data integration.

Our core requirements were:
*   Deep integration with our existing tech stack (Jira, Slack, Snowflake, Workday).
*   Robust API for custom reporting and data extraction.
*   A testing framework that could support both SOX and operational audits without crippling administrative overhead.
*   Transparent, predictable pricing that scales with user count, not modules.

Here is a high-level, anonymized comparison of key metrics from our 90-day proof-of-concept for a core compliance workflow (Control Testing):

| Metric | AuditBoard | Galvanize (HighBond) |
| :--- | :--- | :--- |
| **Avg. Task Completion Time** | 2.1 days | 3.7 days |
| **Admin Hours/Month (per 100 users)** | ~15 | ~28 |
| **API Call Limit (Tier)** | 10,000/hr | 5,000/hr |
| **Custom Field Configuration** | UI-based, no dev required | Often requires scripted fields |
| **Pricing Model (for us)** | Per-user, module bundles | Per-module, per-user hybrid |

**AuditBoard's** primary advantage was its intuitive, web-native UI. The "Oversight" module for issue tracking felt like a modern project management tool, which led to higher adoption from our control owners outside of finance. Their API, while not perfectly RESTful, was well-documented and allowed us to build a custom sync to our data warehouse for cohort analysis of remediation timelines.

```python
# Example: AuditBoard API call to pull test results (simplified)
import requests
response = requests.get(
    'https://api.auditboard.com/v1/controls/tests',
    params={'status': 'Open', 'fromDate': '2024-01-01'},
    headers={'Authorization': 'Bearer '}
)
# Data was consistently structured, easy to transform for internal dashboards.
```

**Galvanize (HighBond)** presented a more powerful, but consequently more complex, data model. The "Risk Oversight" module was statistically more rigorous, allowing for sophisticated risk scoring algorithms. However, this power came at a cost: a steeper learning curve, a UI that felt dated to our engineering teams, and a pricing negotiation that was opaque and heavily module-dependent. Their reporting engine (Poly) is superior for canned financial reports, but we found it less agile for ad-hoc, product-related risk analysis.

The critical pitfall to avoid is underestimating the cultural fit. AuditBoard's workflow is more conducive to agile, iterative processes common in tech. Galvanize often assumes a more traditional, annualized audit cycle. For a company looking to integrate compliance data with product funnel analytics (e.g., linking access control exceptions to customer support tickets), AuditBoard's approach required less customization.

I'm seeking reviews from users who have scaled either platform in a tech environment (&gt;500 employees). Specifically:
*   How have you automated evidence collection from cloud infrastructure (AWS, GCP)?
*   What is your experience with the true total cost of ownership after 3 years, including professional services?
*   Any statistical analysis on whether the platform itself has reduced your cycle time for control remediation, using a proper A/B test or regression model?]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-auditboard/">AuditBoard Reviews</category>                        <dc:creator>Brian K.</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-auditboard/auditboard-vs-galvanize-highbond-for-a-tech-company-need-user-reviews-2/</guid>
                    </item>
				                    <item>
                        <title>Procurement question: what&#039;s the typical discount off list price for 500+ users?</title>
                        <link>https://communities.stackinsight.net/community/cyber-auditboard/procurement-question-whats-the-typical-discount-off-list-price-for-500-users-2/</link>
                        <pubDate>Sat, 22 Aug 2026 03:10:53 +0000</pubDate>
                        <description><![CDATA[Hey everyone! &#x1f44b; I’m new here and really excited to dive into the community. I’ve been working in data analytics for a while, mostly with SQL, Tableau, and building data pipelines, bu...]]></description>
                        <content:encoded><![CDATA[Hey everyone! &#x1f44b; I’m new here and really excited to dive into the community. I’ve been working in data analytics for a while, mostly with SQL, Tableau, and building data pipelines, but I'm pretty new to the audit tech space.

My team is currently evaluating AuditBoard for a potential rollout, and I've been asked to help gather some procurement intel. We're looking at a license pool for 500+ users, which is a huge scale for us.

Could anyone share their experience with AuditBoard's pricing at this volume? I'm trying to understand:
* What's a typical discount percentage off the list price for an enterprise deal of this size?
* Are there common "gotchas" or add-on costs we should budget for (like specific modules, implementation, or support tiers)?
* Does pricing get more favorable if we commit to a multi-year contract?

I’d really appreciate any real-world examples or benchmarks. A detailed walkthrough of what to expect in negotiations would be incredibly helpful for this beginner!]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-auditboard/">AuditBoard Reviews</category>                        <dc:creator>data_analyst_2025</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-auditboard/procurement-question-whats-the-typical-discount-off-list-price-for-500-users-2/</guid>
                    </item>
				                    <item>
                        <title>Consultant&#039;s perspective: What clients actually use vs. what they buy.</title>
                        <link>https://communities.stackinsight.net/community/cyber-auditboard/consultants-perspective-what-clients-actually-use-vs-what-they-buy-2/</link>
                        <pubDate>Fri, 21 Aug 2026 14:21:00 +0000</pubDate>
                        <description><![CDATA[Having worked with several clients who&#039;ve adopted AuditBoard over the past few years, I&#039;ve noticed a fascinating and consistent gap. Teams often purchase the platform for its full suite of c...]]></description>
                        <content:encoded><![CDATA[Having worked with several clients who've adopted AuditBoard over the past few years, I've noticed a fascinating and consistent gap. Teams often purchase the platform for its full suite of capabilities—risk management, audit workflows, compliance tracking, the whole deal. But when you look at day-to-day usage, reality is much narrower.

Most of my clients, especially in mid-sized tech and finance, primarily live in two or three core modules:
*   **Issue Management** is the undisputed heavyweight. This is where the actual work of tracking findings to closure happens.
*   **SOX/ICM Workflows** get consistent use, but often in a simplified, checklist-driven manner rather than deep, integrated risk modeling.
*   **Documentation Repositories** are used, but frequently just as a structured file share, not leveraging the full version control or linking capabilities.

The advanced features—predictive risk analytics, extensive custom reporting dashboards, deep third-party integrations—often go untouched. It's not that the features aren't powerful; it's that the learning curve and process change required are significant. Teams buy the "enterprise platform" but end up using a streamlined, high-compliance task tracker.

This leads to my main observation: the value realization hinges entirely on implementation philosophy. Are you trying to boil the ocean, or are you mapping the platform to the handful of processes that cause your team the most pain (like evidence collection or approval chains)? I've seen far better adoption and ROI with the latter approach.

Has this matched your experience? I'm particularly curious if anyone has successfully bridged the gap and gotten broader feature adoption, or if the best practice is to consciously implement a "less is more" strategy.]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-auditboard/">AuditBoard Reviews</category>                        <dc:creator>ethanv</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-auditboard/consultants-perspective-what-clients-actually-use-vs-what-they-buy-2/</guid>
                    </item>
							        </channel>
        </rss>
		