Auditors do not fail organisations for weak controls nearly as often as for controls that cannot be evidenced.
An audit readiness assessment runs the audit before the auditor does. Same scope, same questions, same evidence requests, with the difference that the findings arrive while there is still time to fix them and nobody is writing anything down for a report.

- Same questionsAsked before somebody external asks
- Evidence firstBecause that is what fails, not controls
- Time to fixThe entire value of doing it early
- RehearsedThe people as well as the paperwork
Eight things that determine whether an audit goes well.
Whether the evidence exists at all
The most common finding, and it is rarely because the control was absent. Access reviews were performed and the record was an email. Backups were tested and nobody wrote down when. Changes were approved verbally. The control operated correctly and left no artefact, which from an audit perspective is the same as not operating.
Whether it covers the whole period
Audits look at a period rather than a moment. Evidence that a control operates today does not demonstrate it operated in month four. Where a control was implemented partway through the period, or where the evidence only exists from the point somebody started retaining it, that gap is visible and it is not fixable retrospectively.
Whether it covers the whole scope
Evidence for the main environment and nothing for the branch, the acquired entity or the system a business function runs. Auditors sample, and samples reach the parts of the estate nobody was thinking about. Testing scope coverage before the audit is what prevents a comfortable position collapsing on one sampled item.
Whether it is in a form the auditor will accept
A screenshot with no date, a report with no system identifier, a list with no indication of how it was generated. Evidence that requires the auditor to trust its provenance tends to generate follow-up requests, and follow-up requests consume the time budget that would otherwise have covered the harder questions.
Whether the people can answer for the control
An auditor asks the control owner how it works, and the answer either matches the documentation and the evidence or it does not. Rehearsing that conversation is unglamorous and it is the difference between an interview that establishes confidence and one that generates a line of enquiry nobody anticipated.
Whether the documentation matches what happens
The procedure says access reviews are quarterly and they happen twice a year. The policy says thirty day patching and the standard practice is different. Each discrepancy is a finding on its own, and it also invites the auditor to test whether other documents are equally aspirational, which widens the audit considerably.
Whether exceptions are recorded as decisions
Every organisation has exceptions and auditors expect them. What they look for is whether each was decided by somebody with the authority, recorded with a reason, and reviewed. An exception recorded that way is evidence of governance. The same exception undocumented is evidence of a control that does not operate as described.
Whether the platform can produce what you will be asked for
Some evidence requires the platform to have been configured to retain it. Retention configuration and retention actions are auditable, and disposition review with proof of disposition for up to seven years is a label capability rather than a policy one. Access reviews are described as providing auditors with proof that policy exceptions are reviewed regularly. Whether those capabilities were switched on determines whether the evidence exists.
Evidence for a period you did not retain evidence for cannot be created afterwards.
This is why readiness work has to happen early. Almost every other finding is fixable in the weeks before an audit. This one is not.
- An audit covers a period. If the control operated throughout but the artefact only exists from month eight, the position for months one to seven is unevidenced and no amount of effort in month eleven changes that.
- The categories where this recurs are consistent: access reviews performed by email, change approvals given verbally, restore tests conducted and not recorded, log data retained for less than the audit period, and privileged activity that was never logged in the first place.
- Some of it depends on platform configuration made in advance. Auditing of retention configuration and retention actions has to be enabled. Disposition review producing proof of disposition is a label capability that must have been in place when the disposition occurred. Access review records exist because the reviews were run in the platform rather than by email.
- The practical implication is that readiness assessment belongs several months before the audit rather than several weeks. The findings that can be fixed in weeks are the less serious ones. The one that matters needs the period ahead of it, not behind it.
Four things that make readiness work rather than reassure.
We request the evidence rather than asking whether it exists
With a deadline, exactly as an auditor would. The answer to does the evidence exist is almost always yes. The answer to please provide it within two working days is frequently different, and the difference is precisely what the audit will expose. Asking the second question is the whole method.
We test the period, not the moment
Evidence that a control operates today is easy to produce and demonstrates very little about an audit period. Testing whether the evidence exists for the beginning of the period, the middle and a randomly selected month is what finds the gap that cannot be closed later, which is why we do it first.
We rehearse the control owners
An auditor interview is a conversation with somebody who owns the control, and the answer either matches the documentation and the evidence or it opens a line of enquiry. Walking each owner through how their control works, how they know it operated, and what they would say about an occasion when it did not, is an hour that changes fieldwork substantially.
We look for the discrepancy between document and practice
Where a procedure says quarterly and practice is twice a year, that is a finding on its own and it also invites the auditor to test whether other documents are equally aspirational. Aligning documentation to practice, or practice to documentation, before the audit is far cheaper than explaining the difference during it.
Four phases, and the timing matters more than the depth.
- 01Months 6 to 5 before
Establish scope, period and evidence expectations
What the audit covers, over what period, which entities and systems, and what evidence the auditor is likely to request for each control. Then which of that evidence the organisation is currently generating and retaining, because anything not being retained needs to start now to cover the period.
- Audit scope and period confirmed
- Expected evidence request mapped per control
- Evidence currently generated and retained identified
- Retention and logging changes started immediately
- 02Months 4 to 3 before
Test the evidence as an auditor would
Request the evidence, receive it, and assess whether it demonstrates what it needs to. Does it cover the period, does it cover the scope, is its provenance clear, and could somebody unfamiliar with the environment follow it. Findings here are still comfortably fixable.
- Evidence requested and assessed rather than assumed
- Period and scope coverage tested per control
- Form and provenance issues identified
- A remediation list with owners and dates
- 03Months 2 to 1 before
Close the gaps and rehearse the people
Remediation completed and the evidence regenerated to confirm it. Then control owners walked through the conversation they will have: how the control works, how they know it operated, and what they would say if it did not on a particular occasion. That last question is the one that catches people.
- Remediation completed and evidence verified
- Control owners rehearsed on their controls
- Documentation aligned with what actually happens
- Exceptions recorded as decisions with approvers
- 04The audit
Support delivery and capture what comes next
Coordinating evidence requests during fieldwork so responses are consistent and timely, tracking what is asked for beyond expectation, and recording every request that was difficult so next year preparation starts from a better position rather than from the same one.
- A single coordinated response to evidence requests
- Unexpected requests logged for next time
- Findings understood before the report lands
- Next year evidence retention adjusted immediately
Six audit situations where readiness work changes the outcome.
A regulated firm facing a supervisory examination
Where the examination is scheduled and the scope is published, readiness work is straightforward to target. The findings that matter are evidence coverage across the period and the alignment between what the policy set commits to and what the organisation demonstrably does, since both are examined closely.
An organisation pursuing a certification for the first time
First certifications fail on evidence of operation rather than on control design. A management system standard requires demonstrable operation over a period, and organisations that implemented controls recently frequently have excellent controls and insufficient history. Establishing that early is the difference between certifying on schedule and deferring.
A business facing a customer-led audit
Customer audits are increasingly common in UAE supply chains and they are frequently more specific than framework audits, because the customer asks about the controls protecting their data in particular. Readiness here means being able to evidence the controls for that scope rather than for the estate generally.
An operator whose scope includes sites and operational technology
Auditors sample, and samples reach the site nobody was thinking about. Where the scope includes plants, remote facilities or operational technology, evidence coverage across those environments is the thing most likely to be missing and least likely to have been checked before fieldwork begins.
An organisation with findings outstanding from last time
Prior findings are the first thing an auditor checks, and an unclosed finding from the previous cycle is materially worse than a new one because it demonstrates that findings do not get closed. Readiness work should start with the prior report, and frequently that alone justifies the engagement.
A group being audited across several entities
Where several entities are in scope, consistency is what fails. One entity evidences well and another cannot, and the finding is written at group level. Testing each entity to the same evidence standard before the audit is the only way to know which one determines the group outcome.
How UAE organisations approach an upcoming audit.
| Feature | Readiness assessed months ahead | Preparation starts on announcement | No preparation |
|---|---|---|---|
Evidence expectations known in advance | Yes | Partly | No |
Retention adjusted before the period | Yes | Too late | No |
Period coverage tested | Yes | No | No |
Scope coverage tested | Yes | No | No |
Evidence form checked | Yes | On submission | No |
Control owners rehearsed | Yes | No | No |
Documentation aligned with practice | Yes | Partly | No |
Exceptions recorded as decisions | Yes | Rarely | No |
Surprises during fieldwork | Few | Several | Many |
Effort during the audit itself | Low | High | Very high |
Ten control areas, and the evidence an auditor typically wants.
| Control area | What is usually asked for | |
|---|---|---|
| User access provisioning and removal | A sample of joiners and leavers, with dates and approvals | |
| Periodic access review | The review records themselves, with reviewer, date and outcome per item | |
| Privileged access | Who holds it, how it was approved, and what activity was logged | |
| Change management | A sample of changes with approvals, testing evidence and back-out plans | |
| Patching and vulnerability management | Coverage against the asset inventory, and remediation timelines met | |
| Backup and recovery | Test records with dates, scope and outcomes, not schedules | |
| Incident management | A sample of incidents with timeline, decisions and closure | |
| Logging and monitoring | What is logged, retention period, and evidence of review | |
| Third parties | Due diligence records, contract terms and ongoing assurance | |
| Data retention and disposal | Policy configuration, and where required proof of disposition |
Five steps, and the earlier it starts the more it can fix.
- 1
Confirm scope, period and the likely evidence requests
What is being audited, over what period, across which entities and systems, and what evidence each control will require. Where the auditor has published a request list or a prior year list exists, that is the starting point. Where neither does, we work from the framework and from experience of what is asked.
- 2
Establish what is being generated and retained now
The most time-critical step, because anything not currently being retained needs to start immediately to cover as much of the period as possible. Log retention, access review records, change approvals, restore test records and privileged activity logging are the recurring gaps.
- 3
Request the evidence and test it properly
With deadlines, as an auditor would. Then assessed for whether it covers the period, covers the scope, is in an acceptable form and could be followed by somebody unfamiliar with the environment. Findings are recorded as remediation items with owners rather than as observations.
- 4
Remediate, and align documents with practice
Evidence gaps closed where possible and recorded honestly where not. Documentation corrected where it describes something the organisation does not do, or practice corrected where the documentation is right. Exceptions recorded as decisions with named approvers and reasons rather than left implicit.
- 5
Rehearse the people and support the fieldwork
Control owners walked through their controls and the questions they will face. Then during the audit, a coordinated response to evidence requests, a log of anything asked that was not anticipated, and immediate adjustment of retention and record keeping so next year starts from a better position.
What organisations ask about audit readiness.
Fifteen evidence requests to make of your own team.
Access
- The last access review, with outcomes per itemNot a statement that it happened.
- Leaver access removal for five named leaversWith dates.
- Current privileged account list with approvalsIncluding service accounts.
- Evidence privileged activity is loggedAnd retained for the period.
- Exception records with approversThey exist whether recorded or not.
Operations
- Five changes with approval and testing evidenceChosen by you, not by them.
- Patch coverage against the asset inventoryCoverage needs a denominator.
- The last restore test recordWith date, scope and outcome.
- Three incidents with timeline and closureIncluding minor ones.
- Log retention configurationAgainst the audit period.
Governance
- Current policy set with review datesCheck the dates.
- Evidence policy was communicatedAnd acceptance recorded.
- Supplier due diligence for three suppliersIncluding the critical one.
- Risk register with owners and review datesAnd evidence of review.
- Prior audit findings and their closureThe first thing an auditor checks.
The pages around this one.
Ask for your last access review record, with a two day deadline.
Not whether reviews happen. The record itself, with reviewer, date and outcome per item. What arrives, and how quickly, tells you more about your audit position than any amount of preparatory discussion.
Related Services
Explore more solutions that work great with this service
Continuous Compliance Monitoring
Control state tested daily, not annually
Gap Assessment
Distance to a target you actually have to meet
IT General Controls
What your external auditor tests, and the evidence they sample
Compliance as a Service
Keeping the position true between assessments
ISO 27001 Certification UAE
The 2022 edition, and whether you should certify at all
SOC 2 Readiness UAE
Type II preparation, and when ISO 27001 fits better
Access Rights Review
Certification that removes access, not one that gets approved
IT Audit Services Dubai
Assessment, technical test or certification, scoped properly