Skip to content
atlas

Audit

Also known as: compliance audit, security audit, internal audit

An independent check of whether an organisation actually follows its own policies and the requirements it has signed up to.

“audit” also means something else in another field - see every meaning →

Draft - this entry has not been reviewed yet.

Formal

A planned, documented and impartial examination that gathers evidence - samples, records, interviews - to judge whether practice matches set criteria such as policies, contracts, laws or a standard, and reports each deviation as a finding.

In plain English

Like the regular car inspection - the owner may say the brakes are fine, but the inspector puts the car on the test bench and checks for real.

In practice

An internal auditor at a Danish region picks twenty staff who left last year and finds that four still have active accounts in the patient system; the report lists it as a finding with a deadline.

Why it matters

Written rules slowly drift away from what people actually do; without a regular, independent check, nobody notices until an incident or a customer exposes the gap.

Technical deep dive

Audits are classified by who performs them. First-party audits are internal audits performed by or on behalf of the organisation itself; second-party audits are performed by a customer or other interested party on a supplier, often based on a contractual audit right such as GDPR Art. 28(3)(h); third-party audits are performed by an independent body, for example a certification body or an auditing firm issuing an assurance report. The general method for management-system audits is ISO 19011:2018, which sets seven principles (integrity, fair presentation, due professional care, confidentiality, independence, evidence-based approach and risk-based approach) and describes managing an audit programme and conducting individual audits. ISO/IEC 27007 adds ISMS-specific guidance, and ISO/IEC TS 27008 covers the technical assessment of information security controls.

ISO/IEC 27001:2022 clause 9.2 requires internal audits at planned intervals to determine whether the ISMS conforms to the organisation's own requirements and to the standard, and whether it is effectively implemented and maintained. Clause 9.2.2 requires an audit programme with frequency, methods, responsibilities and reporting that take into account the importance of the processes and the results of previous audits, defined criteria and scope for each audit, auditors selected to ensure objectivity and impartiality, reporting of results to relevant management, and retained documented evidence. In practice objectivity means auditors do not audit their own work; small organisations often buy internal audit from an external consultant to meet this.

An audit compares audit evidence (records, configuration exports, system logs, interview statements, observation) against audit criteria (policy, standard clause, contract, law). Because full examination is rarely possible, auditors sample: for example, selecting leavers from the HR system and tracing whether accounts were disabled within the policy deadline. Findings are graded, typically as major nonconformity (absence or total breakdown of a required process), minor nonconformity (an isolated lapse), observation, or opportunity for improvement. Nonconformities feed clause 10.2 corrective action, which requires root-cause analysis and evaluation of effectiveness, not just a fix of the specific instance.

Several neighbouring terms are often conflated with audits. A gap analysis is a pre-implementation comparison, usually by the organisation itself, without an evidence standard. A penetration test or vulnerability scan tests technical exposure, not conformity to criteria. An assurance report such as ISAE 3402, ISAE 3000 or SOC 2 is issued by an auditing firm under assurance standards and, in its type 2 form, covers the operating effectiveness of controls over a period rather than at a point in time; Danish data processors commonly provide ISAE 3000 reports on GDPR compliance. Supervisory audits are a further category: NIS2 Art. 32 lets authorities impose regular and targeted security audits on essential entities.

What to learn first

Everything this builds on, foundations first.

  1. Compliance
  2. →Security policy
  3. →Audit

Relationships

Mandated by
ISO 27001

Sources & further reading

Standards & official texts

  • ISO/IEC 27001:2022, Clause 9.2 (Internal audit) · ISO/IEC

Course material

  • Cyber Security Fast Track - Ordliste

Where this data comes from

This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.

See the review queueSuggest a correction on GitHubThis term as JSON

Mentioned in

Check yourself

Loading…

Atlas is in beta.