Most audits are not failed on the day. They are failed in the months before, when the evidence that would have satisfied the auditor was never recorded, or when the scope was set so loosely that the auditor could reasonably ask about anything. The ninety days before an audit are where readiness is decided, and they are far more useful when they are planned than when they are spent reacting.
This checklist assumes a certification or attestation audit against a management-system or control framework: ISO 27001, ISO 42001, SOC 2, or similar. It scales down for a surveillance audit and up for a first certification.
Days 90 to 61: scope, ownership and the gap
Fix the scope in writing. The scope statement decides what the auditor can ask about. Name the legal entities, the locations, the services, the systems and the people in scope, and, just as importantly, what is out. A scope that says "the organisation" invites questions about the sales team's laptops. A scope that says "the SaaS platform and the teams that build and operate it" does not.
Name a control owner for every control. Not a department, a person. The auditor will interview them. If the same name appears against forty controls, that person is your single point of failure and your bottleneck in fieldwork.
Run a gap assessment against the current edition. Take the framework, control by control, and for each one write two things: what we do, and where the record is. Anything with a blank in the second column is a gap, even if the first column is convincing. Rate the gaps by effort and by how visible they are to the auditor.
Book the auditor. Certification bodies and CPA firms schedule weeks or months ahead. Confirm the dates, the team, the number of days, and whether any of it is remote. Ask what they will want in advance; most send a document request list a few weeks before.
Decide what you will fix and what you will accept. Some gaps close in a week. Some need budget and a quarter. For the second kind, a documented risk acceptance or a treatment plan with dates is itself evidence, and it is better than pretending the gap is closed.
Days 60 to 31: build the evidence habit
Turn every "periodic" control into a calendar entry. Quarterly access reviews, monthly vulnerability scans, annual policy reviews, semi-annual restore tests: each one needs a date, an owner and an artefact. Backfill nothing; start the cadence now so at least one cycle is on record before fieldwork.
Collect the populations. An auditor testing change management asks for the list of all changes in the period, then samples from it. Testing onboarding asks for all joiners. Testing incidents asks for all incidents. Know where each population lives, know that it is complete, and know how to export it with dates.
Review the policies, and mean it. Every policy should carry an owner, a version, a review date and an approval. If the last review was three years ago, review it now and record the review. If the policy says something you do not do, change the policy or change the practice, but do not leave the contradiction for the auditor to find.
Run the internal audit. Management-system standards require one before certification, and it must be done by someone independent of the area audited. An internal audit that finds nothing is a red flag to a certification auditor; one that finds a handful of issues with corrective actions in progress is exactly what they expect.
Hold the management review. ISO clause 9.3 lists the inputs. Have the meeting, use the list as the agenda, and minute it. Decisions and actions with owners are what the auditor reads.
Test something for real. Restore a backup and record the outcome. Run the incident process on a tabletop scenario. Walk through the business continuity plan. Auditors distinguish sharply between a plan and a tested plan.
Days 30 to 8: rehearse
Answer the request list before it arrives. Build a folder per control, or per criterion, with the evidence already in it. Name files so the auditor can find them without asking. Where evidence is a screenshot, make sure it shows the date and the system.
Brief the people who will be interviewed. Not to script them, but so they know what the auditor is testing and where the evidence is. The two worst interview outcomes are the owner who cannot find their own records and the owner who improvises an answer that contradicts the documentation.
Do a mock audit on your weakest area. Have someone who did not build the control pick samples and ask for the evidence, in the same way the auditor will. Fix what breaks.
Check the previous audit's findings. If this is a surveillance or a renewal, every finding from last time must show a completed corrective action with evidence. An auditor who sees the same finding twice escalates it.
Confirm logistics. Rooms, remote access, screen-sharing tools, who greets the auditor, who is the single point of contact, how requests will be tracked during fieldwork. A shared request tracker with status and owner saves days.
Days 7 to 1: settle
Freeze what you can. Do not roll out a new identity provider the week before the audit. If a change must happen, document it as a planned change with a risk assessment; that is evidence too.
Walk the physical scope. Clear desks, locked cabinets, visitor logs, server room access lists. Physical controls are the easiest to test and the most embarrassing to fail.
Read your own statement of applicability one more time. Every applicable control should have an owner who knows it is applicable, and every excluded control should have a justification that still holds.
Set expectations internally. Findings are normal. Minor nonconformities are normal. The goal is a credible system with a credible response to whatever the auditor finds, not a perfect score.
During fieldwork
Answer what is asked, with the record, promptly. Do not volunteer tours of areas outside scope. When you do not know, say so and find out; guessing wrong costs more than a delay. Keep the request tracker current so the auditor's open items and yours agree at the end of every day. Ask for a daily summary, so a finding is never a surprise at the closing meeting.
Afterwards
Close every finding with a root cause, not just a fix. Put the next audit's dates in the calendar now. And keep the evidence habit running; the difference between an organisation that dreads audits and one that treats them as routine is entirely whether the records exist before anyone asks for them.
