What auditors check, and how to be ready.
Guides to the frameworks, the audits behind them, and the engagement itself. Written for the people who have to pass, not for the people who sell.
ISO/IEC 42001, Explained for People Who Have to Pass It
The first certifiable standard for managing AI. What it asks for, how it relates to ISO 27001 and the EU AI Act, and what an audit against it actually checks.
DORA: What Financial Entities and Their ICT Suppliers Must Show
The Digital Operational Resilience Act has applied since January 2025. Its five pillars, who it reaches, and the evidence an auditor asks for under each.
SOC 2 Type I or Type II: Which Report to Get First
The two report types test different things over different periods. When a Type I is the right first step, when it is wasted money, and how the observation window works.
ISO 27001:2022: What Changed, and What Auditors Test Now
The 2022 edition restructured Annex A into four themes and 93 controls and added eleven new ones. The transition deadline has passed; here is what a current audit expects to see.
When GDPR Requires a DPIA, and How to Run One That Holds Up
Article 35 makes a data protection impact assessment mandatory for high-risk processing. The nine criteria regulators use, the structure of a defensible assessment, and what an audit checks.
The 90-Day Audit Readiness Checklist
What to do in the three months before an ISO or SOC 2 audit, week by week, so the auditor's first request list is answered before it arrives.
How an Escrow-Backed Audit Engagement Works
Why we put money in the middle of every Auditly engagement, what a milestone is, and what happens when the two sides disagree.
Stage 1, Stage 2, Surveillance, Recertification: The ISO Audit Cycle
An ISO certificate is not one audit but a three-year cycle of them. What each stage checks, how nonconformities are graded, and how to keep a certificate rather than just win one.
NIS2, DORA or the Cyber Resilience Act: Which One Reaches You
Three EU cyber laws with overlapping vocabulary and different scopes. How to tell which applies to your organisation, and where they stack.
Why Your Consultant Cannot Certify You
Independence rules decide who is allowed to sign your certificate. Understanding them before you buy saves an engagement.
ISO 27001 or SOC 2: Which One Does Your Buyer Actually Want?
The two frameworks answer different questions and are checked in different ways. Here is how to tell which one your customers are asking for.
NIS2: How to Tell If You Are In Scope
The directive applies by sector and company size, and it reaches suppliers who never read it. A practical way to work out whether it applies to you.
What an Auditor Will Ask For, and Why
The evidence requests that arrive in week one of most engagements, what each is really testing, and how to have it ready.
How to Choose an Auditor
A practical framework for evaluating and selecting an auditor for your next compliance engagement.
Introducing Auditly
Why we are building a marketplace that matches companies with vetted auditors.
