What separates a useful audit from an expensive formality
Two audits can cost the same, take the same fortnight, and produce documents of similar length, while one changes how an organisation operates and the other is filed and forgotten.
The difference is not effort or expertise. It comes down to a small number of practices, all of them procedural, most of them decided before any examination starts.
These are the ones I hold to in an it audit services engagement, and the first two do most of the work.
One: criteria before evidence
Agree what constitutes a pass before anyone sees what the evidence shows.
Criteria written afterwards are unfalsifiable — the bar can move to accommodate whatever turned up, in either direction. Written first, they make the finding a matter of fact rather than a matter of opinion, and they remove the end-of-review argument almost entirely.
Two: verified and reported never blend
Every statement carries which it is. Verified means the reviewer established it directly. Reported means somebody said so.
Blending them is the single most common way a review becomes theatre, because the reader cannot tell a fact from a claim and will assume the flattering reading. It also protects the reviewer: a reported finding that turns out to be false was recorded correctly.
Three: findings carry a consequence
“Shared administrative account” is an observation. “Shared administrative account, so no production change can be attributed to an individual, which defeats the change-control evidence” is a finding.
The test is whether a reader would do anything differently. Observations that fail that test belong in an appendix or nowhere, because their presence trains readers to skim.
Four: prioritise rather than enumerate
Three to seven findings that would change a decision, then a separate list of things that should be fixed but change nothing.
A report with forty items ranked equally has delegated the prioritisation back to the reader, who has less context than the reviewer and will do it worse. Long reports are usually a sign that this step was skipped.
Five: the sample is chosen by the reviewer
And the method is stated. A sample selected by the team being reviewed is not a sample, and one whose method is unstated cannot be reasoned about later.
This sounds like a small procedural point. It is the difference between a finding that generalises and an anecdote.
Six: re-test before closing
A finding closed because someone said it was fixed is reported, not verified — the same distinction applied to remediation.
Re-requesting the same evidence three months later takes an hour. It is the cheapest practice on this list and the most frequently skipped, and it is what separates an audit that changed something from one that produced a list.
Two practices for the audited side
Nominate one point of contact. Six engineers answering the same question produce six answers, and the inconsistency becomes a finding about control rather than about knowledge.
Record accepted risks with a named accepter. Findings you consciously decide not to fix are decisions, and decisions with an owner are legitimate. The same finding left unaddressed with nobody named is an oversight, and the next review will treat the two very differently.
Three habits that quietly ruin a review
Answering more than was asked. A question about backup frequency answered with an account of the whole infrastructure surfaces material nobody had asked about and extends the exercise. Scope exists for a reason on both sides.
Fixing things silently during the review. The temptation is strong and it muddies the evidence. Note the issue, let the finding be recorded, fix it afterwards. A finding remediated during the audit and recorded as such is a good signal; one that quietly vanished is a problem for everybody.
Treating findings as accusations. Almost every organisation fails several items, usually for sensible reasons under time pressure years ago. Teams that receive findings as criticism become defensive, defensive teams give worse answers, and worse answers produce more findings.
The useful sequence is to agree whether each finding is accurate, and discuss consequence separately. Merged, those two conversations both go badly.
What these practices cannot fix
An audit run against the wrong questions is executed impeccably and answers nothing. Every practice above improves the quality of the answer; none improves the quality of the question, and that is decided in the plan.
I also cannot claim these practices produce more findings. They frequently produce fewer, because prioritisation removes the padding. The measure worth watching is not finding count but how many findings had an owner and a date ninety days later, and that number is usually uncomfortable.
Related reading: internal audit covers how these practices hold up when the reviewer is a colleague, the audit process covers the stages they apply to, and the audit experience covers the same practices from the side being reviewed.