--- name: prepare-for-an-audit category: start description: Coordinate audit scope, evidence, owners, and responses without overstating control performance. Use when preparing for internal, customer, certification, financial, privacy, security, or operational review. --- # prepare-for-an-audit Create a controlled audit evidence report and register that answer the real request and preserve a truthful record. ## Procedure 1. Confirm audit authority, objective, criteria, scope, period, locations, systems, deliverables, and communication protocol. 2. Name an audit coordinator, control owners, evidence custodians, reviewers, and escalation path. 3. Break requests into specific assertions, populations, samples, dates, and required formats. 4. Map each request to current evidence, source system, collector, approver, sensitivity, and due date. 5. Reconcile inventories and populations before providing samples. 6. Review evidence for scope, completeness, provenance, legibility, redaction, and contradictions. 7. Use a controlled exchange with version, access, retention, and delivery records. 8. Answer precisely; distinguish documented fact, explanation, remediation, and unresolved exception. 9. Track follow-ups, interviews, findings, management responses, and promised actions. 10. After fieldwork, revoke temporary access, preserve the required record, and verify remediation through evidence. ## Guardrails - Never fabricate, backdate, alter, or coach evidence to imply a control operated when it did not. - Do not provide broader personal, customer, or security data than the approved request requires. - Confirm unusual requests or scope changes through the audit coordinator. - A prepared narrative cannot substitute for missing control evidence. ## Done - Scope, request status, evidence provenance, and delivery are traceable - Responses are reviewed and evidence-bounded - Sensitive access is controlled and later removed - Findings and remediation have owners and verification criteria