What Is a Compliance Audit?

Related problems: A customer wants proof we meet a security standard before signing; Auditors are coming and we don't know what evidence they need; Preparing for an IPO or a regulator's examination; Not sure whether we need an internal review, a certification or an attestation

A compliance audit is a structured, evidence-based review of whether an organization meets the requirements of a specific law, regulation, industry standard, contract or internal policy. The auditor compares what the requirements say against what the organization actually does, using documents, system records, interviews and tests, and reports where the two match and where they don’t. In IT, compliance audits commonly cover security frameworks, privacy rules and financial reporting controls.

At a glance

  • A compliance audit measures you against a defined set of requirements, such as a standard, regulation or contract clause.
  • It can be internal, run by a customer or partner, or performed by an independent third party, depending on what the audience will accept.
  • Results range from internal findings to formal outputs such as certifications, attestation reports or regulatory examination results.
  • Evidence matters as much as practice: auditors usually need records showing a control worked, not just a policy saying it exists.

What problem it solves

Saying you are secure or compliant isn’t enough for customers, regulators, insurers or investors. They want someone to have checked. A compliance audit turns claims into tested evidence, so a customer can rely on your report instead of interviewing your team, and leadership can see gaps before an outsider finds them.

For mid-market companies, compliance audits often arrive as a sales requirement (“send us your SOC 2 report”), a regulatory duty or a step toward going public. Done well, they also expose controls that exist on paper but not in practice, such as access reviews nobody performs or backups nobody tests.

How it works

Scoping. Decide which framework applies, which systems, locations, services and time period are in scope, and which parts are handled by providers. Scope drives cost and effort more than anything else.

Readiness or gap review. Many organizations run an internal or consultant-led review first, compare current practice to the requirements and fix gaps before the formal audit.

Fieldwork. The auditor requests evidence: policies, configurations, tickets, access reviews, logs and audit trails. They interview staff and test samples, for example checking that a selection of new hires completed onboarding steps or that changes were approved. For financial reporting audits, testing of IT general controls (ITGCs) is a standard part.

Reporting. Findings are rated and documented. Depending on the framework, the output may be a certification, an attestation report with an opinion, a report on compliance, or an internal memo.

Remediation and follow-up. Gaps get owners and deadlines, and recurring audits check that fixes held.

Audit types

Compliance audits differ mainly in who performs them and what the output is. Which one you need depends on the requirement and the audience; confirm with the party asking.

Type Who performs it What triggers it Typical output
Internal audit or self-assessment Your internal audit team, compliance staff or a consultant Your own program, a readiness check, or a framework that allows self-assessment Internal findings, self-assessment questionnaire, remediation plan
Customer or second-party audit A customer or partner, or a firm they hire Contract rights, onboarding of a critical supplier Questionnaire results, audit letter, corrective action requests
Independent attestation A licensed CPA firm Customer demand for assurance, such as SOC reports Attestation report with the auditor’s opinion
Certification audit An accredited certification body Pursuit of a certifiable standard such as ISO/IEC 27001 Certificate, with periodic surveillance audits
Qualified assessor review An assessor qualified by the standard’s owner Requirements such as PCI DSS at certain levels Report on compliance, attestation of compliance
Regulatory examination A government regulator Licensing, supervision or an incident Examination findings, required actions

When it matters for buyers

  • When choosing a provider that will hold your data. Their audit reports are often your best evidence, so check what was audited, by whom and when.
  • When your own customers ask for evidence. Knowing which audit type they accept saves you buying the wrong one.
  • Before an IPO, acquisition or new regulatory obligation. Readiness work takes time, so start early.
  • When a provider’s audit scope doesn’t match the service. A certified data center doesn’t mean the managed service running in it was audited.

Our governance, risk and compliance overview covers audit readiness help and compliance management tools.

Questions to ask vendors

  • Which audits, certifications or attestation reports cover the exact service we would buy?
  • Who performed the most recent audit, when, and what period did it cover?
  • Were there exceptions or findings, and how were they remediated?
  • Which controls does your report expect us, the customer, to operate?
  • Will you support our own audits, for example by providing evidence or answering auditor questions?
  • How do your subcontractors’ audits fit into your scope?

How it differs from a risk assessment

A risk assessment asks what could go wrong and how much it matters, so you can decide where to invest. A compliance audit asks whether you meet a defined set of requirements, so someone else can rely on the result. The two connect: many frameworks require a risk assessment, and auditors check that you did one. But passing an audit doesn’t mean every significant risk is handled, and a sound risk assessment doesn’t by itself prove compliance. Both feed a wider governance, risk and compliance (GRC) program.

Frequently Asked Questions

What is the difference between an audit and an assessment?
The words are used loosely, but an audit usually tests evidence against defined requirements and produces a formal opinion or finding, while an assessment is often broader and more advisory. Which one you need depends on who is asking and what they will accept.
Who performs a compliance audit?
It depends on the framework. Internal audit teams can review anything; some frameworks require an independent party, such as a CPA firm for SOC reports, an accredited certification body for ISO/IEC 27001 or a qualified assessor for PCI DSS. Regulators run their own examinations.
How long does a compliance audit take?
It varies widely with scope and framework. A focused internal review might take weeks; a first certification or attestation often follows months of readiness work, and some reports cover controls operating over an observation period.
What happens if the auditor finds problems?
Findings are usually documented with a severity and a remediation plan. Depending on the framework, serious gaps can delay a certification, appear as exceptions in a report or trigger regulatory follow-up, so many organizations run a readiness review first.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.