Skip to main content

Audit Preparation

Use this playbook to prepare for external or internal audits using Compliance Engine data.

Determine Scope and Frameworks

  1. Identify which accounts, environments, and services are in audit scope.
  2. Map audit requirements to frameworks and controls (for example, CIS, PCI, HIPAA).

Validate Control Coverage

  1. Confirm that relevant policy packs and custom controls are enabled.
  2. Check dashboards for coverage gaps (for example, assets not evaluated by key policies).

Generate Evidence

  1. Create reports and dashboards that show control pass rates and open violations.
  2. Extract finding details for sample‑based testing where auditors select specific assets.
  3. Capture policy revision history and exception records for key controls.

Compile and Store Artifacts

  1. Organize evidence by framework, control, or audit request.
  2. Store artifacts in your designated evidence repository with appropriate access and retention.

Run Pre‑Audit Reviews

  1. Conduct internal reviews using the same data that auditors will see.
  2. Address any obvious gaps or outliers ahead of time.
  3. Document any exceptions and compensating controls clearly.