I would like to propose to not only allow linking affected Compliance Items in an External Audit Finding, but to extend that and allow linking Policies, Internal Controls, Projects, … so that this could be visible through the Dynamic Status of said items.
While it is the most obvious to link affected Compliance Items, in contrast to major or minor deviations, there are smaller audit findings (think observations or recommendations) that won’t result in a Compliance Item turning “non-compliant” and that mainly provide insights/thoughts/ideas to improve other things (that of course correlate with Compliance Items) like policies, internal controls, projects, …
As these “recommendation” findings are prioritized less, it is easy to miss in e.g. a policy review, that there were recommendations for said policy in an audit finding.