Skip to content
ISMS

Audit Preparation in 4 Weeks Instead of 4 Months: The Management Playbook

|
|
6 min read

Here is how audit prep often looks in mid-sized firms: 3 months of Excel work, 1 month of polish, 1 week of audit and 4 weeks of follow-up. Half of that effort exists because the evidence sits in 12 different tools. This playbook cuts the whole thing down to 4 weeks.

Why Classic Audit Prep Takes 4 Months

  • Evidence is scattered: the risk register is in Excel, controls are in Confluence, assets are in a third Excel file, suppliers in a fourth, and logs in 5 tools.
  • Version chaos: which policy is in force? Who signed it last? When?
  • Manual mapping: ISO 27001 A.5.34 ↔ which control ↔ which evidence ↔ which finding from the last audit.
  • Reviews are overdue: 30 % of policies are more than a year old and have no documented review.
  • Staff surveys as the source: "When did you last do this?" That is not audit-grade.

The 4-Week Playbook

Week 1: Pull the Inventory From the Platform

  • Statement of Applicability (SoA): export it from the ISMS module. Control ↔ status ↔ owner ↔ effectiveness rating.
  • Risk register: the current state, with treatment status and last review date for each risk.
  • Asset list: complete, with protection need, lifecycle and owner.
  • Supplier list: from the TPRM module, with risk score, contract status and last reassessment.
  • 12 months of incident history: from Wazuh + audit log. No cherry-picking.
  • Audit trail of all key approvals: risk acceptance, policy updates, change approvals.

If the platform can deliver these exports in one day, 75 % of the classic prep time is gone.

Week 2: Gap Analysis and Quick Wins

  • Close review gaps: find every policy, control and asset without a current review. Then run the review workflow and document it.
  • Add proof that controls work: each control you claim needs a concrete piece of evidence in the system. That can be a screenshot, a config export or a log excerpt.
  • Start supplier reassessments: any supplier not updated in more than 12 months gets a self-service request.
  • Awareness training evidence: training rates and the latest phishing test as a PDF report.

Week 3: Cross-Framework Mapping and Pre-Audit

  • Cross-framework mapping: the multi-framework module maps ISO 27001 ↔ NIS-2 ↔ GDPR on its own. A gap in one framework shows up in the others.
  • Internal pre-audit: 2 days of structured self-checks with the audit question list. You log findings right in the system.
  • Fix the top findings: usually 5–10 quick fixes, such as a missing signature, an old document or a missing owner.

Week 4: Support During the Audit

  • Auditor access: read access to the trust center or a dedicated auditor view. The auditor sees evidence live and does not wait for PDF packages.
  • Interviews are prepared: the owner of each control knows where the evidence lives.
  • Track findings live: each finding becomes a task in the system right away. Follow-up starts during the audit.

The Two Most Common Findings a Platform Avoids

  1. "Control claimed, but no proof that it works." With steady upkeep in the platform, effectiveness is a required field for each control.
  2. "Review cycle overdue." With review cycle management, the system starts and logs reviews before the auditor asks.

The Effort Table

PhaseClassicWith Platform
Collect evidence~40 PD~5 PD
Version/owner clarification~15 PD~2 PD
Cross-mapping~10 PD~1 PD
Gap closure~25 PD~10 PD
Pre-audit~10 PD~5 PD
Total~100 PD~25 PD

You save 75 PD (~€50,000 of internal effort) per audit cycle. With a yearly surveillance audit, the platform pays for itself through prep time alone.

What Management Does Not Want to Hear in the Audit

  • "I'm still looking for the evidence for this control."
  • "I can't reach the owner anymore, they left 6 months ago."
  • "We have the policy but don't know which version is current."
  • "The risk acceptance was decided verbally."

Each of these sentences leads to a finding. Findings in an ISO audit are costly. They mean re-checks, re-audits and, in the worst case, a delayed certificate.

Conclusion

Audit prep in 4 weeks instead of 16 is not magic. It is a matter of clean data. Keep your ISMS data in one source, with up-to-date reviews, an audit trail and cross-framework mapping. Then the audit becomes a single session, not a drama that lasts a quarter. The ROI comes from the saved prep time alone. The real security gains of the platform come on top.