Audit readiness · 10 min read · Updated 2026-07-06

Audit preparation checklist: what to review first

A review-week preparation checklist for evidence freshness, owners, policies, vendors, access reviews and audit packs.

Direct answer

An audit preparation checklist tells your team what to review before evidence is shared: scope, control owners, policy approvals, risk decisions, vendor records, access reviews, training evidence, open exceptions and the final audit pack. Prioritise freshness and ownership, because old evidence without context creates avoidable follow-up during review week.

Small SaaS teams can work backwards from the audit date. Use 30 days to fix ownership and stale records, 14 days to close evidence gaps, and 7 days to prepare exports, explanations and open-issue notes. General information only; this is not legal advice.

30-day audit preparation plan

  • Confirm scope and framework boundary.
  • Assign owners for every control, policy, vendor and risk.
  • Identify stale evidence and missing approvals.
  • Create remediation tasks for known gaps.

14-day plan

  • Review current evidence and mark anything that needs owner approval.
  • Check policy versions and approval records.
  • Review accepted risks and exceptions.
  • Ask vendor owners for missing supplier documents.

7-day plan

  • Freeze the audit pack structure.
  • Export evidence with dates and owners.
  • Prepare explanations for open gaps.
  • Confirm who will answer reviewer questions.

Evidence freshness review

  • Check evidence collection date and scope.
  • Make sure screenshots include enough context.
  • Replace stale exports where systems changed.
  • Label manual evidence clearly.

Policy approval review

  • Confirm policy owner and approval date.
  • Check next review date.
  • Make sure policy commitments match actual practice.
  • Keep exception notes visible.

Risk and exception review

  • Review high and accepted risks.
  • Confirm treatment owners and due dates.
  • Prepare a summary of open exceptions.
  • Record management review decisions.

Vendor evidence review

  • Check critical vendor reviews first.
  • Keep SOC reports, security overviews, DPAs and subprocessor notes.
  • Record reassessment dates and accepted issues.

Access review evidence

  • Export privileged users for critical systems.
  • Record who reviewed access.
  • Track removals or follow-up tasks.
  • Keep MFA and identity settings evidence where relevant.

Training evidence

  • Keep training completion reports.
  • Record onboarding security training.
  • Track overdue staff and exceptions.
  • Review awareness content annually.

How to assemble an audit pack

Audit pack checklist
AreaWhat to checkEvidence to keepOwnerReview frequencyStatus
ScopeBoundary is agreedScope statementISMS ownerBefore auditNot started
PoliciesApproved versions are currentPolicy list, approvalsPolicy ownerBefore auditNot started
RisksOpen risks are explainableRisk register, treatment notesRisk ownerBefore auditNot started
VendorsCritical supplier reviews are currentVendor register, DPAsVendor ownerBefore auditNot started
AccessAdmin access has been reviewedAccess exports, sign-offIT ownerBefore auditNot started
FindingsOpen gaps have ownersCorrective action logSecurity leadWeeklyNot started

Common audit preparation mistakes

  • Preparing files without confirming scope.
  • Hiding gaps instead of recording treatment work.
  • Sharing policies that have not been approved.
  • Forgetting vendor and access evidence until the final week.

Common questions

Is this guide legal or certification advice?

No. This guide is for general information and is not legal advice. Use qualified legal, privacy or audit advisers for formal interpretation and assurance decisions.

Can a small SaaS team use this without a GRC team?

Yes. The workflows are designed for lean teams, but each record still needs a named owner, a review date and evidence that matches the actual scope.