Skip to content
atlas

Don't confuse these

Audit vs Self-assessment

Audit

Compliance & regulation

An independent check of whether an organisation actually follows its own policies and the requirements it has signed up to.

Formal

A planned, documented and impartial examination that gathers evidence - samples, records, interviews - to judge whether practice matches set criteria such as policies, contracts, laws or a standard, and reports each deviation as a finding.

In plain English

Like the regular car inspection - the owner may say the brakes are fine, but the inspector puts the car on the test bench and checks for real.

In practice

An internal auditor at a Danish region picks twenty staff who left last year and finds that four still have active accounts in the patient system; the report lists it as a finding with a deadline.

Why it matters

Written rules slowly drift away from what people actually do; without a regular, independent check, nobody notices until an incident or a customer exposes the gap.

Self-assessment

Compliance & regulation

An organisation checking its own security against a set list of questions or criteria, without an outside inspector.

Formal

A structured review the organisation carries out on itself, using a questionnaire or criteria from a standard, label or law - such as the D-mærket tool - to map its practice, find gaps and pick improvements.

In plain English

Like going through a home safety checklist on a Sunday - you walk round with the list yourself to see what needs fixing, before anyone official ever comes by.

In practice

A family-owned furniture maker answers the D-mærket questions over two afternoons and finds it has no written plan for what to do if its systems go down.

Why it matters

It is a cheap first step for smaller organisations to see where they stand against NIS2 and similar demands before spending money on outside help.

Shared connections

Atlas is in beta.