
CONSULT CIRCLE | SECURITY & COMPLIANCE
What auditors look for, what they find, and a week-by-week plan for the month before the audit.
Audits rarely fail on sophisticated technical weaknesses. They fail on missing evidence, stale access, undocumented processes and controls that exist in principle but cannot be demonstrated.
Thirty days is enough to fix most of what is commonly found, provided you work in the right order. This roadmap prioritises findings that are both frequently raised and realistically fixable in the time available.
Week 1: Establish what is true
You cannot remediate what you have not measured. This week is assessment, not fixing.
- Confirm audit scope, the framework, the period covered and the evidence format expected.
- Produce an asset inventory: endpoints, servers, cloud resources, network devices, applications and data stores.
- Extract a full user access list, including privileged accounts, service accounts and any external or third-party access.
- Run a vulnerability scan across the estate.
- Collect existing policy documents and note which are missing, out of date or unapproved.
- Identify where evidence lives for each control, and where no evidence exists at all.
Week 2: Access and identity
Access findings are the most commonly raised and among the quickest to resolve.
- Disable accounts for leavers. Reconcile the user list against the HR record; the gap is usually larger than expected.
- Review privileged accounts and remove administrative rights that are not required.
- Enforce multi-factor authentication, prioritising administrators, remote access and anything internet-facing.
- Inventory service accounts, identify their owners, and document what each is for.
- Remove or review shared accounts, and where one genuinely cannot be removed, document the compensating control.
- Review third-party and vendor access, and remove anything dormant.
- Evidence a completed access review with dates and approvers. The review itself is frequently the control being tested.
Our Active Directory health check guide covers the identity hygiene most of this depends on.
Week 3: Technical controls
- Patch critical and high-severity vulnerabilities on internet-facing and business-critical systems first.
- Confirm endpoint protection is deployed everywhere, reporting correctly, and that gaps are investigated rather than tolerated.
- Verify backups run successfully, and test a restore. A backup that has never been restored is not evidence of anything.
- Confirm logging is enabled on key systems and retained for the period the framework requires.
- Review firewall rules and remove anything permissive, temporary or unexplained.
- Check encryption at rest and in transit for systems holding sensitive data.
- Confirm change control is being followed and that recent changes have records.
Week 4: Documentation and rehearsal
The week where evidence is assembled and the process is tested, rather than assumed.
- Update policies: acceptable use, access control, incident response, business continuity, data retention.
- Ensure policies are approved and dated. An unapproved policy is a draft, and auditors treat it as one.
- Assemble the evidence pack, organised by control so nothing has to be searched for during the audit.
- Run a tabletop incident response exercise and record it. The record is itself evidence.
- Brief the people who will be interviewed on scope and on which documents apply to them.
- Complete a dry run against the control list and note anything still unevidenced.
- Document remaining gaps with an owner and a target date. A known, planned gap is treated very differently from one discovered by the auditor.
What auditors most often find
| Finding | Why it happens | Fix time |
|---|---|---|
| Leaver accounts still active | No reliable link between HR and identity management | Days |
| Excessive administrative privilege | Rights granted for a task and never removed | Days to weeks |
| No evidence of access reviews | Reviews happen informally and are not recorded | Days |
| Backups never restore-tested | Backup success is monitored; restore capability is assumed | Days |
| Missing or unapproved policies | Written once, never reviewed or formally approved | Days |
| Unpatched systems | No consistent patching cycle, or exceptions never revisited | Weeks |
| Insufficient log retention | Defaults left in place, shorter than the framework requires | Days to configure, longer to accumulate |
| No tested incident response plan | Plan exists on paper and has never been exercised | Days for a tabletop |
| Undocumented third-party access | Granted during a project and never reviewed | Days |
Table 1 — Common audit findings and realistic fix times.
Where to go next
Frequently Asked Questions
How do we prepare for an IT security audit?
Establish the scope and framework, assess against it to produce a gap list, then remediate in priority order: access and identity first, then technical controls, then documentation and evidence. Thirty days is enough for most commonly raised findings.
What do auditors look for most?
Evidence that controls operate, not just that they exist. Access reviews with dates and approvers, tested restores, approved policies, and records of changes and incidents.
What if we cannot fix everything in time?
Document the remaining gaps with an owner, a plan and a target date, and put a compensating control in place where you can. A known and managed gap is treated far more favourably than one the auditor discovers.
How long should we retain logs?
Whatever your control framework or regulator specifies, which is often longer than the default configuration. Check the requirement rather than assuming, because retention cannot be applied retrospectively.
Is a tabletop exercise enough for incident response?
For most audits, a documented tabletop exercise demonstrates the plan has been tested and that participants know their roles. It is far better than an untested plan, and it can be arranged within the month.
Talk to Consult Circle
We help organisations prepare for security audits, from gap assessment through remediation to the evidence pack. Book a free 30-minute call - 0203 916 5593 - info@consultcircle.com