Audit is not an exam you revise for — it is a test of whether the system you described has been running. Organisations that treat it as an event prepare for weeks and still struggle; organisations that treat it as a by-product of operating properly hand over what already exists.
The two questions every audit asks
Design: is this control capable of achieving its objective? Operation: did it actually happen, consistently, throughout the period? They are independent, they fail differently, and they need completely different fixes — a design failure means changing the control; an operating failure means fixing ownership and cadence. Rewriting a sound control because someone skipped a quarter is the most common wasted remediation.
How controls are tested
Four methods, ascending in strength: inquiry (asking — never sufficient alone), observation (watching), inspection (examining records — the workhorse), and reperformance (independently re-executing the control — the strongest, because it does not rely on your record being complete).
Before sampling anything, a competent auditor establishes that the population is complete. A perfect sample drawn from a filtered list proves nothing, which is why you hand over raw exports rather than curated ones — including the rows you would rather explain.
What counts as evidence
Dated, attributable, and produced by a system the performer cannot silently alter. That is why a ticket beats a spreadsheet, and a system export beats a screenshot. The most common finding of all is not a missing control — it is a control that genuinely operates and leaves no record, which auditors treat as not having happened.
The corollary matters for planning: evidence that must accumulate cannot be created retrospectively. Four quarters of access reviews take four quarters, whatever the budget.
Make evidence a by-product, not a project
GRC Copilot schedules recurring control activities, files the dated output against the right control, and shows what is missing before fieldwork does.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
Findings and what they cost
- Major nonconformity — a systemic failure or an absent process. Blocks certification until resolved.
- Minor nonconformity — an isolated lapse. Certification proceeds with an accepted corrective action plan.
- Observation / opportunity for improvement — no formal obligation, but it is the auditor telling you where they will look next year.
SOC 2 uses different language: exceptions appear in the report your customers read, and a qualified opinion is commercially serious. The distinction matters — an ISO nonconformity is resolved privately; a SOC 2 exception is published for twelve months.
Closing findings properly
Find the real root cause. "The reminder was not sent" is proximate; "the control has no owner and no scheduled trigger" is root. Then check whether the same weakness exists elsewhere — auditors sample, so a finding in one system frequently exists in three, and extending the fix yourself is far better than having it found next year.
Internal audit and management review
Both are mandatory for certification and both must happen before Stage 1 — the single most common reason a first certification stumbles. Internal audit must be independent of the area examined, which in a small organisation means cross-auditing or an external party rather than pretending. Management review is a decision-making meeting whose minutes are the evidence.
The cycle after certification
Surveillance in years one and two, recertification in year three. Year two is where programmes decay — the certificate is on the website, the project team has moved on, and the recurring activities quietly stop. Surveillance exists precisely to detect that.
Detailed guidance
Audit
- Audit preparation guide: a 90-day plan — A structured 90-day audit preparation plan - what to fix first, how to organise evidence, how to run the fieldwork week, and how to handle f…
- Common audit mistakes - and how to avoid them — The mistakes that turn a manageable audit into a painful one: last-minute evidence, over-broad scope, policies nobody follows, unprepared in…
- Correction vs corrective action: closing findings so they stay closed — Fixing the instance an auditor found is a correction. Fixing why it happened is corrective action. Confusing the two is why the same finding…
- Design vs operating effectiveness: the distinction that decides your audit — A control can be perfectly designed and still fail an audit, or operate flawlessly and still be judged inadequate. Two separate tests, two s…
- Firewall rule review: finding the any-any rule from 2019 — Rule bases grow, never shrink, and eventually nobody knows what half of them are for. What a review should look for, how to remove rules saf…
- How auditors actually test controls: inquiry, observation, inspection, reperformance — Four testing methods of very different strength, plus sampling and the population question that decides whether your sample means anything.…
- Major, minor, observation: what each audit finding actually costs you — The grade determines whether you have a certificate, a deadline, or a suggestion. What separates the categories, how to respond to each, and…
- Purple teaming: testing whether your detections actually fire — A red team tells you that you were beaten. A purple team tells you exactly which detection failed and why. The cheaper, more repeatable exer…
- Running an internal audit programme that is worth doing — Internal audit is mandatory for ISO 27001 and valuable everywhere else - but only if it is independent and finds things. How to plan, staff,…
- SOC 2 bridge letters: what they cover, and what they cannot — Your report period ended in March and a customer is asking in September. A bridge letter covers the gap - but it is management's assertion,…
- SOC 2 carve-out vs inclusive: the part of the report customers misread — Your cloud provider's controls are either carved out of your report or included in it. The choice changes what your report actually proves -…
- SOX IT general controls: what external auditors actually test — ITGCs underpin every automated control an auditor relies on, which is why a weakness in access or change management can cascade into a mater…
- Stage 1, Stage 2 and surveillance: the three-year certification cycle explained — Certification is not one audit, it is a cycle - and the years after the certificate is issued are where programmes quietly decay. What happe…
- The compliance evidence matrix: what each framework actually asks you to produce — Auditors do not ask for controls, they ask for artefacts. A control-domain-by-framework matrix of the evidence ISO 27001, SOC 2, the NCA ECC…
- The Essential Eight assessment: what an assessor actually checks — Assessors test rather than take your word for it. How the assessment works, the evidence that satisfies each strategy, the sampling that cat…
- The management review: the meeting that certifies your ISMS — A mandatory ISO 27001 clause that most organisations treat as a formality - and then fail on. What inputs are required, what outputs must be…
- User access reviews: the control auditors fail you on most — Access reviews are the most-sampled and most-failed control in security audits. How to run one that holds up - scope, cadence, reviewer sele…
- What evidence auditors expect (and what they reject) — The evidence auditors actually accept for the most-tested controls, the four properties every artefact needs, and the common submissions tha…
- Working with your external auditor without losing weeks — Fieldwork drags when evidence requests bounce around email. How to run the auditor relationship - the PBC list, a single request queue, scop…
Checklists
- Pre-audit evidence checklist: what to assemble before fieldwork — Audits go badly when evidence is assembled during them. What to gather in advance, what cannot be produced late, and the dry run that finds…
Comparisons
- Certification, attestation, audit, pen test: which one does your customer mean? — A customer asking for "your security certification" may want any of six different things, with wildly different cost and lead time. What eac…
Frameworks
- SOC 2 readiness: what to fix before the auditor arrives — A practical SOC 2 readiness guide - Type I versus Type II, choosing your Trust Services Criteria, the observation window, and the control ga…
Guides
- Continuous compliance: why the annual audit scramble fails — Point-in-time compliance tells you where you stood on one day. Continuous compliance monitors controls as they operate - catching drift, spr…
US & Americas
- CJIS Security Policy: what contractors handling criminal justice data must do — Any organisation touching criminal justice information inherits a prescriptive control set, personnel screening obligations and audit exposu…
Frequently asked questions
Can we choose the audit sample?
No — selection must be the auditor's, or the test provides no assurance. You provide the complete population promptly.
Who can perform internal audit?
Someone independent of the area audited. Cross-functional auditing or an external provider both work; auditing your own work does not.
Are screenshots acceptable evidence?
Weakly, for configuration. Undated and croppable, so system exports and tickets are far stronger. If you must, capture the full screen including the timestamp.
What if evidence for a sampled item genuinely does not exist?
Say so immediately and explain why. Reconstructing or backdating turns a control exception into an integrity issue, which is categorically worse.
Key takeaways
- Design and operation are separate tests with different remediations.
- Population completeness is checked before sampling — hand over raw exports.
- A control that leaves no record is treated as not having happened.
- Internal audit and management review must precede Stage 1.