Blog

What auditors check, and how to be ready.

Guides to the frameworks, the audits behind them, and the engagement itself. Written for the people who have to pass, not for the people who sell.

RSS feed
4 min read

ISO/IEC 42001, Explained for People Who Have to Pass It

The first certifiable standard for managing AI. What it asks for, how it relates to ISO 27001 and the EU AI Act, and what an audit against it actually checks.

GuideISO 42001AIRead
5 min read

DORA: What Financial Entities and Their ICT Suppliers Must Show

The Digital Operational Resilience Act has applied since January 2025. Its five pillars, who it reaches, and the evidence an auditor asks for under each.

GuideDORAEUFinancial servicesRead
5 min read

SOC 2 Type I or Type II: Which Report to Get First

The two report types test different things over different periods. When a Type I is the right first step, when it is wasted money, and how the observation window works.

GuideSOC 2USRead
4 min read

ISO 27001:2022: What Changed, and What Auditors Test Now

The 2022 edition restructured Annex A into four themes and 93 controls and added eleven new ones. The transition deadline has passed; here is what a current audit expects to see.

GuideISO 27001Read
5 min read

When GDPR Requires a DPIA, and How to Run One That Holds Up

Article 35 makes a data protection impact assessment mandatory for high-risk processing. The nine criteria regulators use, the structure of a defensible assessment, and what an audit checks.

GuideGDPREUPrivacyRead
5 min read

The 90-Day Audit Readiness Checklist

What to do in the three months before an ISO or SOC 2 audit, week by week, so the auditor's first request list is answered before it arrives.

GuideISO 27001SOC 2ChecklistRead
4 min read

How an Escrow-Backed Audit Engagement Works

Why we put money in the middle of every Auditly engagement, what a milestone is, and what happens when the two sides disagree.

ProductEscrowContractsRead
4 min read

Stage 1, Stage 2, Surveillance, Recertification: The ISO Audit Cycle

An ISO certificate is not one audit but a three-year cycle of them. What each stage checks, how nonconformities are graded, and how to keep a certificate rather than just win one.

GuideISO 27001ISO 42001Read
5 min read

NIS2, DORA or the Cyber Resilience Act: Which One Reaches You

Three EU cyber laws with overlapping vocabulary and different scopes. How to tell which applies to your organisation, and where they stack.

GuideNIS2DORACyber Resilience ActEURead
3 min read

Why Your Consultant Cannot Certify You

Independence rules decide who is allowed to sign your certificate. Understanding them before you buy saves an engagement.

Guideindependenceiso-17021Read
4 min read

ISO 27001 or SOC 2: Which One Does Your Buyer Actually Want?

The two frameworks answer different questions and are checked in different ways. Here is how to tell which one your customers are asking for.

GuideISO 27001SOC 2Read
4 min read

NIS2: How to Tell If You Are In Scope

The directive applies by sector and company size, and it reaches suppliers who never read it. A practical way to work out whether it applies to you.

GuideNIS2EURead
4 min read

What an Auditor Will Ask For, and Why

The evidence requests that arrive in week one of most engagements, what each is really testing, and how to have it ready.

Guideaudit-preparationevidenceRead
3 min read

How to Choose an Auditor

A practical framework for evaluating and selecting an auditor for your next compliance engagement.

GuidecomplianceRead
2 min read

Introducing Auditly

Why we are building a marketplace that matches companies with vetted auditors.

AnnouncementProductRead