Audit readiness means you can produce, on request, evidence that your IT and security controls exist, operate and are reviewed. Build a small standing evidence pack, give each item an owner and a review date, and test it with a mock audit before a regulator, auditor or client does it for you.
The questions are similar each time, which is the good news: one well-kept evidence pack answers most of them.
Auditors test three layers. The policy says what you intend (“all administrators use multi-factor authentication”). The procedure says how it is done. The record proves it happened (a report showing MFA coverage, dated last month). Firms usually have the first layer and are missing the third.
| Control area | Evidence | How often |
|---|---|---|
| Asset management | Hardware and software register, cloud service list | Reviewed quarterly |
| Access control | Joiner, mover and leaver tickets; access review sign-offs; admin role list | Reviews quarterly |
| Authentication | MFA coverage report and list of exceptions with reasons | Monthly |
| Patching | Patch compliance report for devices and servers | Monthly |
| Backup and recovery | Backup success reports and a restore test record | Backups daily; restore test at least quarterly |
| Testing | Penetration test report and remediation tracker | Annually and after major change |
| Incident response | Response plan, exercise record, incident log | Plan reviewed and tested annually |
| Awareness | Training completion records and phishing exercise results | Annually, with refreshers |
| Third parties | Provider register, due diligence files, review notes | Reviewed by risk tier |
| Governance | Minutes showing the governing body or committee reviewed cyber risk | At least annually |
| Change management | Change records with approvals | Ongoing |
Pick five controls at random and ask the owner to produce the evidence within a day. Record how long each took, what was missing and who fixed it. Repeat annually and after any major change. The exercise usually finds problems no checklist does, such as evidence that exists only in one person’s inbox.
A good managed service provider can supply much of this as a by-product of running your IT: monthly patch, backup, MFA and ticket reports, access review data, and change records. Make that a term of the service agreement, not a favour. Our vendor management guide covers what to put in the contract.
Last reviewed 19 September 2026. This guide is general information, not legal or regulatory advice. Rules change, so check the current text and take advice from your compliance officer or legal adviser before relying on it.
