Back to blog
Audit

Audit and assurance: the complete guide

What auditors test and how, what evidence actually counts, how findings are graded, and how to run the internal audit and management review cycle that certification depends on.
GRC Copilot Team
Audit and assurance: the complete guide

Audit is not an exam you revise for — it is a test of whether the system you described has been running. Organisations that treat it as an event prepare for weeks and still struggle; organisations that treat it as a by-product of operating properly hand over what already exists.

The two questions every audit asks

Design: is this control capable of achieving its objective? Operation: did it actually happen, consistently, throughout the period? They are independent, they fail differently, and they need completely different fixes — a design failure means changing the control; an operating failure means fixing ownership and cadence. Rewriting a sound control because someone skipped a quarter is the most common wasted remediation.

How controls are tested

Four methods, ascending in strength: inquiry (asking — never sufficient alone), observation (watching), inspection (examining records — the workhorse), and reperformance (independently re-executing the control — the strongest, because it does not rely on your record being complete).

Before sampling anything, a competent auditor establishes that the population is complete. A perfect sample drawn from a filtered list proves nothing, which is why you hand over raw exports rather than curated ones — including the rows you would rather explain.

What counts as evidence

Dated, attributable, and produced by a system the performer cannot silently alter. That is why a ticket beats a spreadsheet, and a system export beats a screenshot. The most common finding of all is not a missing control — it is a control that genuinely operates and leaves no record, which auditors treat as not having happened.

The corollary matters for planning: evidence that must accumulate cannot be created retrospectively. Four quarters of access reviews take four quarters, whatever the budget.

Make evidence a by-product, not a project

GRC Copilot schedules recurring control activities, files the dated output against the right control, and shows what is missing before fieldwork does.

Findings and what they cost

  • Major nonconformity — a systemic failure or an absent process. Blocks certification until resolved.
  • Minor nonconformity — an isolated lapse. Certification proceeds with an accepted corrective action plan.
  • Observation / opportunity for improvement — no formal obligation, but it is the auditor telling you where they will look next year.

SOC 2 uses different language: exceptions appear in the report your customers read, and a qualified opinion is commercially serious. The distinction matters — an ISO nonconformity is resolved privately; a SOC 2 exception is published for twelve months.

Closing findings properly

Find the real root cause. "The reminder was not sent" is proximate; "the control has no owner and no scheduled trigger" is root. Then check whether the same weakness exists elsewhere — auditors sample, so a finding in one system frequently exists in three, and extending the fix yourself is far better than having it found next year.

Internal audit and management review

Both are mandatory for certification and both must happen before Stage 1 — the single most common reason a first certification stumbles. Internal audit must be independent of the area examined, which in a small organisation means cross-auditing or an external party rather than pretending. Management review is a decision-making meeting whose minutes are the evidence.

The cycle after certification

Surveillance in years one and two, recertification in year three. Year two is where programmes decay — the certificate is on the website, the project team has moved on, and the recurring activities quietly stop. Surveillance exists precisely to detect that.

Detailed guidance

Audit

Checklists

Comparisons

Frameworks

Guides

US & Americas

Frequently asked questions

Can we choose the audit sample?

No — selection must be the auditor's, or the test provides no assurance. You provide the complete population promptly.

Who can perform internal audit?

Someone independent of the area audited. Cross-functional auditing or an external provider both work; auditing your own work does not.

Are screenshots acceptable evidence?

Weakly, for configuration. Undated and croppable, so system exports and tickets are far stronger. If you must, capture the full screen including the timestamp.

What if evidence for a sampled item genuinely does not exist?

Say so immediately and explain why. Reconstructing or backdating turns a control exception into an integrity issue, which is categorically worse.

Key takeaways

  • Design and operation are separate tests with different remediations.
  • Population completeness is checked before sampling — hand over raw exports.
  • A control that leaves no record is treated as not having happened.
  • Internal audit and management review must precede Stage 1.
#audit #assurance #complete-guide #pillar #internal-audit #evidence #findings