BLOG
How to Prepare for a Compliance Audit Without the Panic
Published 25 July 2026 · By P Larner
Security in Practice#control narratives#findings#ISO 27001#evidence#audit preparation#SOC 2
How to Prepare for a Compliance Audit Without the Panic
Illustration for: How to Prepare for a Compliance Audit Without the Panic
Most audit pain is self-inflicted, and almost all of it is inflicted in the eleven months before anyone books the auditor. Organisations that treat evidence as a year-round by-product of doing the work sail through, and organisations that treat the audit as an annual archaeology project suffer. This article covers what to do across the year, in the final month, and in the room itself.
Twelve-month audit timeline contrasting a calm pattern of year-round evidence gathering, an internal dry run, fieldwork and follow-up with a faded panic pattern of eleven empty months followed by frantic archaeology
The same twelve months spent two ways, where evidence as a year-round by-product beats an annual archaeology project.
Make evidence a by-product, not a project
The single biggest difference between a calm audit and a panicked one is whether evidence already exists in the place the control operates. If your quarterly access review happens in a ticketing system, the ticket is the evidence, because it is dated, attributed and complete. If it happens in a meeting and someone promises to write it up, you will be reconstructing history next July from calendar invites and guesswork.
Four habits cost almost nothing in the moment.
- Give every recurring control a ticket or workflow entry, even a simple one. Auto-created quarterly tickets for access reviews, restore tests and firewall rule reviews mean the schedule itself proves the cadence.
- Screenshot or export at the time of the activity, with the system date visible. Evidence generated retrospectively is obvious to any competent auditor, and it smells like fabrication even when it is not.
- Name files predictably, because access-review-finance-2026-Q2.xlsx beats review_final_v3.xlsx in a folder called stuff.
- Store evidence against the control, not against the person. When the engineer who “kept all that” leaves, their OneDrive leaves with them.
Here is a useful test. Pick three controls at random today and try to produce twelve months of evidence in under ten minutes each. If you cannot, the auditor certainly cannot, and the audit will run long.
Write control narratives before you need them
A control narrative is a half-page plain-language description of a control, covering what it is for, who operates it, how often, what systems are involved, and where the evidence lives. Auditors love them because they shorten interviews. You should love them because writing one exposes broken controls before the auditor does.
Annotated mock-up of a half-page control narrative for a quarterly access review, with callout arrows pointing to its purpose, named owner, frequency, systems involved and evidence location, and a footer stamp noting annual review by the control owner
A control narrative fits on half a page, covering purpose, named owner, frequency, systems and where the evidence lives.
Write one per control, keep them under a page, and have the actual control owner review it annually. The review takes fifteen minutes and regularly surfaces sentences like “we stopped doing that when we moved to the new HR system”, which is precisely the conversation you want to have in March rather than during fieldwork.
The findings auditors keep raising
After enough audits on both sides of the table, the same findings appear with depressing regularity. Check yourself against this list before anyone external does.
Stale access reviews
The review ran, but three leavers from January still had accounts in the June review, and nobody recorded why. Reviews that never find anything to remove also draw attention, because they suggest rubber-stamping.
Unowned exceptions
A risk acceptance signed two years ago by a director who has since left, with no expiry date and no review. Every exception needs a named current owner, an expiry, and a re-approval trail.
Policy and practice drift
The password policy mandates 90-day rotation, the identity provider was reconfigured to modern guidance eighteen months ago, and the document was never updated. Auditors do not care which is right, they care that they disagree. Diff your written policies against reality annually.
Joiner-mover-leaver gaps
Leavers disabled promptly, movers never re-reviewed, so five years of accumulated access follows people around the organisation.
Untested recovery
Backups run nightly, and the last documented restore test was in a previous office. A backup you have never restored is a hope, not a control.
Missing management review
The control operates, but there is no evidence that anyone senior looks at the results. Operation without oversight is half a control.
None of these are exotic. All of them are cheap to fix in advance and embarrassing to receive in a report your customers may ask to see.
Run an internal dry run
Six to eight weeks before the audit, run a genuine mock with the same scope, the same evidence requests, and ideally someone outside the team playing auditor. Internal audit, a colleague from another business unit, or a friendly consultant for a couple of days all work. Four rules make it worthwhile.
- Use the real request list. For ISO 27001 that means the Statement of Applicability, for SOC 2 the criteria mapping, and for a customer audit their actual questionnaire.
- Enforce real timescales. If evidence takes three days to find in the dry run, log that as a finding in itself.
- Interview control owners, not just the compliance team. Auditors go to the operator, and an operator hearing the questions for the first time in fieldwork will improvise, badly.
- Write the findings up formally and track them to closure like any other findings. A dry run whose output is a shrug was theatre.
Expect the first dry run to be humbling. That is the point, and it is far cheaper than the alternative.
Handling fieldwork in the room
- Appoint one coordinator who owns the evidence request list, tracks every item with a status, and is the single channel to the auditor. Chaos multiplies when six people answer independently.
- Answer the question asked, then stop. Volunteering adjacent information invites adjacent questions, and rambling answers have created more findings than weak controls ever did.
- “I do not know, but I will find out” is a perfectly good answer. Guessing in front of an auditor is not, because a wrong guess becomes an inconsistency they must now chase.
- Never obstruct or embellish. If a control failed in February, show the failure and the correction. Auditors deal in patterns, and an organisation that surfaces its own problems earns trust that pays off across every judgement call in the report.
- Log every request and response as you go. Disputes about what was provided are far easier to settle from a list than from memory.
Communication diagram for audit fieldwork with six control owners funnelling through a single audit coordinator holding a request tracker, one clean channel to the auditor, and a crossed-out tangle of direct lines above showing the chaos to avoid
One coordinator owns the request tracker and is the single channel between the team and the auditor.
After the report lands
Read draft findings carefully and challenge factual errors promptly with evidence, in writing, before the report is finalised. Do not argue with judgements you simply dislike, because it burns credibility you will want next year. Then treat agreed findings as free consultancy, so assign owners, set dates, and review progress monthly, because the first question at the next audit will be about this year’s findings.
The quiet-year checklist
If your next audit is months away, spend an afternoon on this now. Pick three controls and run the ten-minute evidence test, diff one policy against actual practice, list every open exception with its owner and expiry, and book the dry run in the calendar. Four small tasks, and next year’s audit becomes a review of work already done rather than a scramble to reconstruct it.
Run your GRC programme in your own network.
RaptorGRC Community Edition is free: every module, offline licence activation, nothing phones home.
Register / Download Contact us