Here is how audit prep often looks in mid-sized firms: 3 months of Excel work, 1 month of polish, 1 week of audit and 4 weeks of follow-up. Half of that effort exists because the evidence sits in 12 different tools. This playbook cuts the whole thing down to 4 weeks.
Why Classic Audit Prep Takes 4 Months
- Evidence is scattered: the risk register is in Excel, controls are in Confluence, assets are in a third Excel file, suppliers in a fourth, and logs in 5 tools.
- Version chaos: which policy is in force? Who signed it last? When?
- Manual mapping: ISO 27001 A.5.34 β which control β which evidence β which finding from the last audit.
- Reviews are overdue: 30 % of policies are more than a year old and have no documented review.
- Staff surveys as the source: "When did you last do this?" That is not audit-grade.
The 4-Week Playbook
Week 1: Pull the Inventory From the Platform
- Statement of Applicability (SoA): export it from the ISMS module. Control β status β owner β effectiveness rating.
- Risk register: the current state, with treatment status and last review date for each risk.
- Asset list: complete, with protection need, lifecycle and owner.
- Supplier list: from the TPRM module, with risk score, contract status and last reassessment.
- 12 months of incident history: from Wazuh + audit log. No cherry-picking.
- Audit trail of all key approvals: risk acceptance, policy updates, change approvals.
If the platform can deliver these exports in one day, 75 % of the classic prep time is gone.
Week 2: Gap Analysis and Quick Wins
- Close review gaps: find every policy, control and asset without a current review. Then run the review workflow and document it.
- Add proof that controls work: each control you claim needs a concrete piece of evidence in the system. That can be a screenshot, a config export or a log excerpt.
- Start supplier reassessments: any supplier not updated in more than 12 months gets a self-service request.
- Awareness training evidence: training rates and the latest phishing test as a PDF report.
Week 3: Cross-Framework Mapping and Pre-Audit
- Cross-framework mapping: the multi-framework module maps ISO 27001 β NIS-2 β GDPR on its own. A gap in one framework shows up in the others.
- Internal pre-audit: 2 days of structured self-checks with the audit question list. You log findings right in the system.
- Fix the top findings: usually 5β10 quick fixes, such as a missing signature, an old document or a missing owner.
Week 4: Support During the Audit
- Auditor access: read access to the trust center or a dedicated auditor view. The auditor sees evidence live and does not wait for PDF packages.
- Interviews are prepared: the owner of each control knows where the evidence lives.
- Track findings live: each finding becomes a task in the system right away. Follow-up starts during the audit.
The Two Most Common Findings a Platform Avoids
- "Control claimed, but no proof that it works." With steady upkeep in the platform, effectiveness is a required field for each control.
- "Review cycle overdue." With review cycle management, the system starts and logs reviews before the auditor asks.
The Effort Table
| Phase | Classic | With Platform |
|---|---|---|
| Collect evidence | ~40 PD | ~5 PD |
| Version/owner clarification | ~15 PD | ~2 PD |
| Cross-mapping | ~10 PD | ~1 PD |
| Gap closure | ~25 PD | ~10 PD |
| Pre-audit | ~10 PD | ~5 PD |
| Total | ~100 PD | ~25 PD |
You save 75 PD (~β¬50,000 of internal effort) per audit cycle. With a yearly surveillance audit, the platform pays for itself through prep time alone.
What Management Does Not Want to Hear in the Audit
- "I'm still looking for the evidence for this control."
- "I can't reach the owner anymore, they left 6 months ago."
- "We have the policy but don't know which version is current."
- "The risk acceptance was decided verbally."
Each of these sentences leads to a finding. Findings in an ISO audit are costly. They mean re-checks, re-audits and, in the worst case, a delayed certificate.
Conclusion
Audit prep in 4 weeks instead of 16 is not magic. It is a matter of clean data. Keep your ISMS data in one source, with up-to-date reviews, an audit trail and cross-framework mapping. Then the audit becomes a single session, not a drama that lasts a quarter. The ROI comes from the saved prep time alone. The real security gains of the platform come on top.