Audit Trial — Find the Gaps
Two fictional clients submitted these documents for review, exactly as their own teams produced them. Some paragraphs and rows are clean; others hide a real, findable problem — a missing control, a contradiction, a broken cross-reference. Read each one like an auditor, flag what's wrong, and see how many you actually caught. It's a scored practice exercise, not an audit of your own organisation.
Opening a document to start scoring is part of a paid plan — any PlayCISO plan unlocks every case below.
See plansAbout Solstice Regional Bank
A traditional 41-branch regional bank — policies, procedures, and the paperwork it generates buying outside security services.
Solstice Regional Bank is a fictional 41-branch regional bank with roughly 3,200 employees, built for Audit Trial as a client whose paperwork is deliberately imperfect. Where the GRC Starter Kit's Meridian Global Bank is written to be audit-ready, Solstice is written the way a real first-time internal-audit client actually looks: policies that were drafted by different teams over different years, procedures that contradict themselves in a second appendix nobody re-read, and documents that reference other documents that were renamed, retired, or never finished.
Solstice is entering its first formal internal-audit cycle ahead of a core-banking platform migration, and its documents have been submitted to you, the auditor, exactly as its security and operations teams produced them — gaps and all. Its procurement documents are included too: the paperwork a bank generates when it buys security services from someone else — a penetration-test statement of work, an MSSP contract, a cyber insurance renewal, a vendor questionnaire response — hides exactly the same kind of gaps as its internal policies do.
About Vantage Labs
A cloud-native SaaS/AI company — Kubernetes, multi-cloud, and the model card behind its AI feature.
Vantage Labs is a fictional Series C SaaS company with about 420 employees, built for Audit Trial as the cloud-native counterpart to Solstice's traditional-bank paperwork. Vantage runs its product on Kubernetes across two cloud providers and ships an AI-powered analytics feature to its customers — so its documents are the ones a modern engineering-led company actually produces: a Kubernetes RBAC standard, a multi-cloud IAM standard, an AI model card, a subprocessor register.
Vantage's documents were pulled together quickly to support a customer's security review, the way real scale-ups' documentation usually is — written by whichever engineer owned the system that quarter, reused from a template, and rarely re-read once shipped. Every document below is graded against the same kind of fixed answer key as Solstice's: some paragraphs and rows are genuinely fine, others hide a real, findable problem specific to running a modern, cloud-native, AI-enabled stack.
Solstice Regional Bank
Tier 1 — Easy
Access Control Policy
Solstice submitted this Access Control Policy ahead of its first internal-audit cycle. Read it the way an auditor would, paragraph by paragraph, and flag anything that would not survive a real review.
Start audit · 5 gaps hiddenIncident Response Plan
The Incident Response Plan is the document Solstice’s security team says it follows during a live event. Check whether it would actually hold up during one.
Start audit · 3 gaps hiddenData Retention Policy
This Data Retention Policy sets how long Solstice keeps different categories of records. Read closely for numbers that don’t agree with each other.
Start audit · 4 gaps hiddenPhysical Security Standard
This Physical Security Standard covers badge access, visitor management, and data center controls across Solstice’s 41 branches and single data center.
Start audit · 3 gaps hiddenSecurity Awareness Training Program
This document describes how Solstice trains its workforce on security topics. Check whether the stated requirements would actually cover everyone with access to bank systems.
Start audit · 3 gaps hiddenTier 2 — Medium
Firewall Rule Set — Core Segment
This is the active firewall rule base for Solstice’s core network segment, exported for review. Treat each row as a rule an auditor would trace end to end: does it have an owner, a justification, and does it conflict with any other rule?
Start audit · 6 gaps hiddenAccess Entitlement Review — Core Systems
This is an extract of the quarterly access entitlement review for Solstice’s core systems. Each row should reflect a currently valid, appropriately approved grant of access — check whether every row actually does.
Start audit · 5 gaps hiddenVendor Risk Assessment — Northgate Cloud Solutions
This is Solstice’s risk assessment of Northgate Cloud Solutions, engaged for statement archival and print fulfillment. Read it as an auditor checking whether the stated risk rating actually matches what the vendor is described as doing.
Start audit · 5 gaps hiddenChange Management Procedure
This procedure describes how changes move from request to production at Solstice. Trace each category of change through the process and see whether the rules actually hold together.
Start audit · 5 gaps hiddenBusiness Continuity Plan
This Business Continuity Plan describes how Solstice would keep operating through a major disruption. Check the recovery objectives, the priority list, and the escalation contacts against each other.
Start audit · 5 gaps hiddenPenetration Test Statement of Work — Cascade Security Partners
This is the Statement of Work governing Solstice’s annual penetration test, performed by an external vendor. Read the scope paragraphs against each other carefully.
Start audit · 6 gaps hiddenVendor Security Questionnaire Response — Standard SIG-Lite
A business partner sent Solstice a standard security questionnaire before signing a data-sharing agreement. This is Solstice’s own response — read each answer against its cited evidence, and against the other answers in the same table.
Start audit · 5 gaps hiddenTier 3 — Hard
Privileged Access Management Procedure
This procedure governs how Solstice’s administrators check out and use privileged credentials through its PAM vault. It is dense and mostly well-written — the gaps here are the kind you only catch by holding the whole document in your head at once.
Start audit · 8 gaps hiddenCloud Configuration Standard
Solstice describes itself elsewhere as operating across more than one cloud provider. See whether this standard actually governs all of them, and whether its own requirements agree with each other.
Start audit · 8 gaps hiddenLog Management Standard
This standard sets out how Solstice generates, collects, and retains security logs. The gaps here live in the space between what the policy statement promises and what the technical detail actually delivers.
Start audit · 7 gaps hiddenApplication Security Testing — Finding Register
This is the current finding register from Solstice’s application security testing program, covering the online banking platform and its supporting mobile app. Some rows describe individual findings; others describe how the testing program itself is run — both kinds can hide a gap.
Start audit · 8 gaps hiddenThird-Party Due Diligence Report — Ashford Core Systems
Ashford Core Systems hosts and provides managed support for Solstice’s core banking platform — about as sensitive an engagement as a vendor relationship gets. This is the longest and hardest document in Audit Trial: read every paragraph against every other one.
Start audit · 8 gaps hiddenMSSP Contract Review — Northline Security Operations
Solstice contracts Northline Security Operations for 24/7 SOC monitoring. This review reads the contract’s own SLA and retention commitments against each other.
Start audit · 7 gaps hiddenCyber Insurance Application — Renewal Submission
This is Solstice’s annual cyber liability insurance renewal application. Insurance applications are legal representations — a false statement here is a real, serious problem, not just an inconsistency.
Start audit · 8 gaps hiddenVantage Labs
Tier 2 — Medium
SaaS Subprocessor & DPA Register
This is Vantage Labs’ register of subprocessors — third parties that touch customer data on Vantage’s behalf. Check whether every subprocessor with real data access actually has a signed Data Processing Addendum.
Start audit · 5 gaps hiddenKubernetes RBAC & Network Policy Standard
This standard governs access control and network segmentation inside Vantage Labs’ Kubernetes clusters. Read the Pod Security Standard claims especially carefully — they don’t agree with each other.
Start audit · 6 gaps hiddenMulti-Cloud IAM Standard
Vantage Labs runs across AWS and GCP. This standard is meant to govern identity and access consistently across both — check whether the practice described matches the policy.
Start audit · 5 gaps hiddenTier 3 — Hard
AI Model Card & Red-Team Summary — Insight Assistant
Insight Assistant is Vantage Labs’ AI feature that answers natural-language questions about a customer’s own analytics data. This model card is the densest document in Audit Trial — read every claim against every other one.
Start audit · 6 gaps hiddenKubernetes Secrets & Workload Identity Standard
This standard governs how secrets and workload credentials are handled inside Vantage Labs’ clusters. Its own blanket claims and its own named exceptions don’t agree with each other — that’s the exercise.
Start audit · 7 gaps hiddenAI Data Pipeline & Training Data Governance Standard
This standard governs how customer data flows into Vantage Labs’ machine learning pipeline. Its own contract-compliance claim and its own opt-in requirement don’t line up — and neither has a control behind it.
Start audit · 7 gaps hiddenCloud & AI Incident Response Runbook
This runbook is meant to cover incident response across Vantage Labs’ cloud-native and AI-enabled estate. Notice what it actually covers versus what its title promises — and check its own SLA claims against each other.
Start audit · 7 gaps hidden