🎉 New here? Use code WELCOME10 for 10% off any plan at checkout
audit trial · paid plan

Audit Trial — Find the Gaps

Two fictional clients submitted these documents for review, exactly as their own teams produced them. Some paragraphs and rows are clean; others hide a real, findable problem — a missing control, a contradiction, a broken cross-reference. Read each one like an auditor, flag what's wrong, and see how many you actually caught. It's a scored practice exercise, not an audit of your own organisation.

Opening a document to start scoring is part of a paid plan — any PlayCISO plan unlocks every case below.

See plans
About Solstice Regional Bank

A traditional 41-branch regional bank — policies, procedures, and the paperwork it generates buying outside security services.

Solstice Regional Bank is a fictional 41-branch regional bank with roughly 3,200 employees, built for Audit Trial as a client whose paperwork is deliberately imperfect. Where the GRC Starter Kit's Meridian Global Bank is written to be audit-ready, Solstice is written the way a real first-time internal-audit client actually looks: policies that were drafted by different teams over different years, procedures that contradict themselves in a second appendix nobody re-read, and documents that reference other documents that were renamed, retired, or never finished.

Solstice is entering its first formal internal-audit cycle ahead of a core-banking platform migration, and its documents have been submitted to you, the auditor, exactly as its security and operations teams produced them — gaps and all. Its procurement documents are included too: the paperwork a bank generates when it buys security services from someone else — a penetration-test statement of work, an MSSP contract, a cyber insurance renewal, a vendor questionnaire response — hides exactly the same kind of gaps as its internal policies do.

About Vantage Labs

A cloud-native SaaS/AI company — Kubernetes, multi-cloud, and the model card behind its AI feature.

Vantage Labs is a fictional Series C SaaS company with about 420 employees, built for Audit Trial as the cloud-native counterpart to Solstice's traditional-bank paperwork. Vantage runs its product on Kubernetes across two cloud providers and ships an AI-powered analytics feature to its customers — so its documents are the ones a modern engineering-led company actually produces: a Kubernetes RBAC standard, a multi-cloud IAM standard, an AI model card, a subprocessor register.

Vantage's documents were pulled together quickly to support a customer's security review, the way real scale-ups' documentation usually is — written by whichever engineer owned the system that quarter, reused from a template, and rarely re-read once shipped. Every document below is graded against the same kind of fixed answer key as Solstice's: some paragraphs and rows are genuinely fine, others hide a real, findable problem specific to running a modern, cloud-native, AI-enabled stack.

Solstice Regional Bank

Tier 2 — Medium

Firewall Rule Settable · 13 items

Firewall Rule Set — Core Segment

This is the active firewall rule base for Solstice’s core network segment, exported for review. Treat each row as a rule an auditor would trace end to end: does it have an owner, a justification, and does it conflict with any other rule?

Start audit · 6 gaps hidden
Access Entitlement Reviewtable · 12 items

Access Entitlement Review — Core Systems

This is an extract of the quarterly access entitlement review for Solstice’s core systems. Each row should reflect a currently valid, appropriately approved grant of access — check whether every row actually does.

Start audit · 5 gaps hidden
Assessmentprose · 12 items

Vendor Risk Assessment — Northgate Cloud Solutions

This is Solstice’s risk assessment of Northgate Cloud Solutions, engaged for statement archival and print fulfillment. Read it as an auditor checking whether the stated risk rating actually matches what the vendor is described as doing.

Start audit · 5 gaps hidden
Procedureprose · 12 items

Change Management Procedure

This procedure describes how changes move from request to production at Solstice. Trace each category of change through the process and see whether the rules actually hold together.

Start audit · 5 gaps hidden
Planprose · 12 items

Business Continuity Plan

This Business Continuity Plan describes how Solstice would keep operating through a major disruption. Check the recovery objectives, the priority list, and the escalation contacts against each other.

Start audit · 5 gaps hidden
Statement of Workprose · 12 items

Penetration Test Statement of Work — Cascade Security Partners

This is the Statement of Work governing Solstice’s annual penetration test, performed by an external vendor. Read the scope paragraphs against each other carefully.

Start audit · 6 gaps hidden
Questionnaire Responsetable · 12 items

Vendor Security Questionnaire Response — Standard SIG-Lite

A business partner sent Solstice a standard security questionnaire before signing a data-sharing agreement. This is Solstice’s own response — read each answer against its cited evidence, and against the other answers in the same table.

Start audit · 5 gaps hidden

Tier 3 — Hard

Procedureprose · 16 items

Privileged Access Management Procedure

This procedure governs how Solstice’s administrators check out and use privileged credentials through its PAM vault. It is dense and mostly well-written — the gaps here are the kind you only catch by holding the whole document in your head at once.

Start audit · 8 gaps hidden
Standardprose · 14 items

Cloud Configuration Standard

Solstice describes itself elsewhere as operating across more than one cloud provider. See whether this standard actually governs all of them, and whether its own requirements agree with each other.

Start audit · 8 gaps hidden
Standardprose · 13 items

Log Management Standard

This standard sets out how Solstice generates, collects, and retains security logs. The gaps here live in the space between what the policy statement promises and what the technical detail actually delivers.

Start audit · 7 gaps hidden
Finding Registertable · 13 items

Application Security Testing — Finding Register

This is the current finding register from Solstice’s application security testing program, covering the online banking platform and its supporting mobile app. Some rows describe individual findings; others describe how the testing program itself is run — both kinds can hide a gap.

Start audit · 8 gaps hidden
Assessmentprose · 16 items

Third-Party Due Diligence Report — Ashford Core Systems

Ashford Core Systems hosts and provides managed support for Solstice’s core banking platform — about as sensitive an engagement as a vendor relationship gets. This is the longest and hardest document in Audit Trial: read every paragraph against every other one.

Start audit · 8 gaps hidden
Contract Reviewprose · 13 items

MSSP Contract Review — Northline Security Operations

Solstice contracts Northline Security Operations for 24/7 SOC monitoring. This review reads the contract’s own SLA and retention commitments against each other.

Start audit · 7 gaps hidden
Insurance Applicationprose · 15 items

Cyber Insurance Application — Renewal Submission

This is Solstice’s annual cyber liability insurance renewal application. Insurance applications are legal representations — a false statement here is a real, serious problem, not just an inconsistency.

Start audit · 8 gaps hidden

Vantage Labs

Audit Trial — Find the Gaps · PlayCISO