Preparing For An Audit

Explore top LinkedIn content from expert professionals.

  • View profile for Poonath Sekar

    100K+ Followers I TPM l 5S l Quality l VSM l Kaizen l OEE and 16 Losses l 7 QC Tools l COQ l SMED l Policy Deployment (KBI-KMI-KPI-KAI), Macro Dashboards,

    110,252 followers

    KEY 5S AUDIT POINTS AND AUDIT SHEET 1. Sort (Seiri) Identify Unnecessary Items: Separate items that are not required for current tasks. Red-tagging: Use red tags to mark and remove unnecessary items. Free Up Space: Clear clutter and create a clean workspace. Minimize Waste: Reduce excess inventory and non-essential materials. Simplify Work Areas: Ensure only essential tools and equipment are present. 2. Set in Order (Seiton) Organize Tools and Materials: Arrange items in a logical order based on usage frequency. Label Items Clearly: Use labels or color codes to make identification easier. Create Storage Locations: Assign specific places for each item to reduce searching. Visual Controls: Implement visual cues like shadow boards to guide proper storage. Optimize Workflow: Design the workspace for maximum efficiency and minimal movement. 3. Shine (Seiso) Regular Cleaning: Perform daily cleaning of the work environment, machines, and equipment. Inspect Equipment: Look for signs of wear, damage, or malfunction during cleaning. Maintain Cleanliness: Keep floors, tools, and surfaces tidy to avoid contamination. Eliminate Dirt and Debris: Ensure all work areas are free from dust and waste materials. Preventive Maintenance: Develop a routine for maintaining and cleaning machinery to avoid breakdowns. 4. Standardize (Seiketsu) Create SOPs (Standard Operating Procedures): Develop written procedures to standardize tasks. Implement Visual Cues: Use color codes, labels, and signs for consistency. Ensure Consistency: Make sure practices are uniform across shifts and teams. Documentation: Keep records of standards to track adherence. Training and Awareness: Ensure all employees are trained on standardized procedures. 5. Sustain (Shitsuke) Develop Discipline: Foster a culture of self-discipline to maintain 5S practices. Regular Audits: Conduct routine audits to ensure 5S principles are followed. Continuous Improvement: Encourage feedback and constant updates to the 5S system. Management Commitment: Ensure leadership supports and promotes 5S initiatives. Employee Engagement: Involve employees in maintaining and improving 5S practices.

  • View profile for Joanne Traice

    Group Chief Internal Audit Officer – DP World | Executive Sponsor - Women @ DP World | PwC Alumni | FCA | QIAL

    12,653 followers

    Over the years, I’ve learned that the most valuable insights don’t just sit in reports—they emerge from conversations. Audits that truly drive impact don’t happen because we asked more questions; they happen because we asked better ones. That’s why my team and I dedicate time to engaging with stakeholders at every level. We’ve found that the most powerful questions: Challenge assumptions – Are we following this process because it works, or just because it’s always been done this way? (We recently found a control weakness buried under a “legacy” practice—one no one had questioned in years!) Reveal blind spots – What risks are hiding in plain sight? (One of our audits uncovered language barriers in employee surveys, leading to 72% of workers being unintentionally excluded from providing feedback!) Drive meaningful conversations – How can we turn compliance into a strategic advantage? (I’ve seen firsthand how shifting the conversation from “compliance burden” to business enabler opens doors for better governance.) This is why I see internal audit as more than just oversight—it’s a catalyst for innovation. This year, my focus has been on reinforcing our role as trusted business partners. Moving from checklists to collaborative discussions. Turning audits from a retrospective exercise into a forward-looking strategy. Ensuring our insights don’t just highlight risks—they drive value. And it all starts with asking the right questions. #InternalAudit #RiskManagement #Leadership #StrategicValue

  • View profile for Alkit Jain

    CA | Internal Auditor | CSOXE | Youtuber

    11,390 followers

    Many Auditors face problems in gathering data from the auditee. If someone is not sharing data required for audit purposes, handling the situation diplomatically and professionally is important while ensuring the audit objectives are met. Here are some strategies one can follow. 1. Clarify the Request Please make sure your request is clear, specific, and documented. Misunderstandings can arise if the person does not fully understand what you need or why it’s essential. Specify the format, timeline, and purpose of the data. 2. Explain the Purpose Communicate the importance of the requested data in the context of the audit. Emphasize that the audit process is not punitive but aims to identify risks, improve controls, and enhance operations. 3. Engage Leadership If the person continues to withhold data, escalate the issue to their supervisor or relevant management. Sometimes, a clear directive from leadership can resolve such roadblocks. 4. Leverage Audit Authority Reference the audit charter or mandate that grants you the authority to access necessary information. If applicable, remind them of organizational policies or regulatory requirements mandating cooperation. 5. Document the Issue Record all instances of non-cooperation, including details of the requests, responses received, and any actions taken. This documentation can be included in the audit report or shared with senior management for resolution. it is recommended to have a tracker of all data requirements. 6. Explore Alternative Sources If the primary source is uncooperative, consider obtaining the required information through alternative channels or systems. 7. Maintain Professionalism Avoid confrontations or assigning blame. Maintain a neutral and professional tone in all interactions. Focus on problem-solving and collaboration to achieve your audit objectives. 8. Leverage Risk Implications Highlight how withholding data could negatively impact the organization, such as increased exposure to risks, compliance issues, or inaccurate reporting. 9. Seek Legal/Compliance Support If non-cooperation persists and the data is critical, involve legal or compliance teams to assess the situation and provide guidance. 10. Report as a Limitation If all attempts fail, document the lack of cooperation as a limitation in the audit report. Clearly state the potential impact of the missing data on audit conclusions. #Internalaudit #riskmanagement #Auditor

  • View profile for Jitendra Pareek

    GRC | ISO 27001:2022 Lead Auditor | GDPR | TPRM | IT Risk I ISO 42001:2023 Implementer

    3,321 followers

    🚨 Identifying AI risks is only half the job. The real question is: 👉 What controls should exist? 👉 How do we test whether those controls actually work? This is where AI governance moves from theory to assurance. While studying AI Controls & Control Testing, I realized that every AI risk should be linked to: Risk → Control → Evidence → Test → Finding Without this chain, it becomes difficult to demonstrate trust, accountability, and compliance. 🧠 Top AI controls every auditor should know: ✔ Human Oversight Control ✔ Bias Testing Control ✔ Explainability Control ✔ Hallucination Control ✔ Prompt Injection Control ✔ Data Privacy Control ✔ Access Control (RBAC) ✔ Model Change Control ✔ Monitoring Control ✔ Vendor Risk Control 📊 A control is not effective because it exists. It is effective when: ✔ Evidence is available ✔ Results are reproducible ✔ The control operates consistently ✔ The risk is actually reduced 💡 One of the most valuable lessons for auditors: Always assess both: 🔹 Design Effectiveness Does the control exist and address the risk? 🔹 Operating Effectiveness Is the control consistently working in practice? A beautifully documented control that is never executed is still a failed control. 🎯 Golden Rule: Don't only ask: "Does the model work?" Ask: "What impact can it create, and are the controls sufficient to keep that impact within acceptable limits?" This mindset is helping me connect AI Governance, ISO/IEC 42001, ISO/IEC 42005, NIST AI RMF, and real-world audit execution into a single practical framework. #AIAudit #AIGovernance #AIControls #AIRiskManagement #ISO42001 #ISO42005 #NISTAIRMF #AICompliance #CyberSecurity #GRC #AIGP #AIASM #ResponsibleAI #Audit #LearningJourney

  • View profile for Martin Ruddy [SAP Freelancer GRC IAM] 🌐 AI / LeanIX / SIGNAVIO / MES / CISA ISO AUDITOR

    “Freiberuflicher und Auftragnehmer 120 CHF pro stunde. Strategischer Leiter für regulatorische Compliance | SAP S/4HANA Enterprise Architect | GRC-Experte”

    4,398 followers

    I used to think Internal Audit was my enemy. I was wrong. Early in my career as a CISO, I treated the Internal Audit team like a high-stakes exam I had to "pass." My strategy was simple: Provide the bare minimum information. Defend every "finding" as if my life depended on it. Treat the final report as a grade on my personal performance. Then came the audit that changed everything. We had a significant finding regarding our third-party risk management. My first instinct? Defensiveness. I had a 10-slide deck ready to explain why the auditor didn't "understand the technical context." But instead of presenting it, I stopped. I asked the auditor: "What is the actual business risk you're seeing here?" The answer wasn't about the tech; it was about a gap in our vendor termination process that could lead to a massive compliance fine—something I had been trying to get budget for but couldn't justify. That’s when it clicked. Internal Audit wasn't there to catch me making a mistake. They were there to provide the independent validation I needed to get the Board’s attention on critical gaps. Here are 3 things I learned that changed my relationship with IA: Be transparent about your "Known Gaps": If you know something is broken, tell them. They can help you document the risk and the path to remediation, which often helps you secure the necessary resources. Standardize your "Evidence Locker": Don't scramble for screenshots during an audit. Build a culture where evidence is collected as part of the daily workflow. Internal Audit is your megaphone: They have a direct line to the Audit Committee and the Board. If you want a security project prioritized, having it listed as a "finding" in an audit report is often the fastest way to get it funded. Today, my relationship with IA is a partnership. We align on the audit plan before it starts, and we treat findings as a shared roadmap for maturity. CISOs: Stop fighting your auditors. They are the best allies you have for building a resilient organization.

  • View profile for Dr. Shilpi Pandey

    Head DQA | HETERO | TEVA | CDRI | IIM-I | Temple Univ | R&D Quality Assurance | Documentation Governance | Scientific Review Systems | DMF / Regulatory Readiness | Compliance & Digital Transformation | DIAGEO |

    4,601 followers

    SOPs Alone Do Not Create Compliance. Execution Does. One of the biggest misconceptions is: 👉 “We have SOPs, so we are compliant.” But auditors do not only check whether SOPs exist. They evaluate whether the system is actually working. They ask: ✔ Is the SOP being followed? ✔ Is the activity documented in real time? ✔ Is the record complete and traceable? ✔ Can batch, equipment, analyst, method, raw data, and result be connected? ✔ Is implementation consistent across people, shifts, batches, and sites? ✔ Is the process scientifically justified? ✔ Is the review system strong enough to detect gaps before an auditor does? In most organizations, SOPs, formats, checklists, and procedures are already available. Yet audit observations still occur because of gaps in: ❌ Implementation ❌ Documentation practices ❌ Traceability ❌ Review systems ❌ Training effectiveness ❌ Compliance discipline ❌ Data integrity culture Very often, the issue is not a missing SOP. It is because: • SOP says one thing, but actual practice follows another • Activity is performed, but not documented contemporaneously • Employees are trained, but execution varies person-to-person • Controlled documents exist, but are not reviewed properly • SOPs are not updated after process or system changes • Traceability between batch, equipment, analyst, and raw data is weak • GDP practices are ignored, overwriting, blank spaces, improper corrections, missing dates/signatures How to avoid such audit observations? ✅ Follow SOPs as written. If practice has changed, revise the SOP. ✅ Document activities in real time, accurately and completely. ✅ Strengthen traceability from sample to final decision. ✅ Verify training effectiveness, not only training completion. ✅ Review records with intent, not as a formality. ✅ Keep SOPs current after method, process, equipment, or system changes. ✅ Reinforce GDP discipline: no overwriting, no unexplained blanks, no backdating, no unsigned corrections. ✅ Monitor repeated issues as trends before they become deviations, OOT, OOS, or audit findings. ✅ Embed ALCOA+ in daily work, not only in training slides. Key Insight An SOP alone does not ensure compliance. Compliance comes from: Consistent Execution + Strong Documentation + Review Culture A strong quality system is not built only by writing procedures. It is built by proving that procedures are followed, records are reliable, and decisions are scientifically justified. The real audit question is not: “Do we have an SOP?” The real question is: “Can we prove that the SOP is followed correctly, consistently, and completely?” Document it right. Follow it right. Prove it right. #PharmaQuality #GMP #GDP #DataIntegrity #AuditReadiness #QualitySystems #Compliance #ALCOA #QA #QC #RegulatoryCompliance #SOP #CAPA

  • View profile for Tim Buckley

    Founder, Beyond the Lines™ | Integral Assurance | Helping audit, risk & controls professionals turn insight into decisions, ownership & outcomes | Join 5,000+ newsletter subscribers | ACA, CIA

    13,468 followers

    Internal audit does not need to work harder. It needs to stop making its own life harder. A lot of audit teams are busy for reasons that have very little to do with impact. 👉 The audit universe keeps expanding. 👉 Old risks are never removed. 👉 Audit follows the process, but misses where key decisions are made. 👉 Findings are written because something was observed, not because something needs to change. 👉 Controls keep accumulating. 👉 Testing volume is treated as comfort. 👉 Planning starts before the process, ownership and decision points are properly understood. That is how audit becomes busy, stretched and frustrated. Not because audit teams are lazy. Because too many audit operating models still reward activity over judgement, volume over relevance and output over impact. High-impact audit teams work differently. They do not try to assure everything. They filter harder. They prioritise materiality, exposure and commercial consequence. They challenge whether the process is actually understood and identify where decisions are made before fieldwork starts. They focus findings on root cause, ownership and decision relevance, not just symptoms. They help the business retire outdated controls instead of layering more work on top. They test what matters. They understand the business context early enough to challenge with relevance, evidence and credibility. The point is not to do less for the sake of doing less. It is to stop spending audit energy on work that does not move decisions, ownership or outcomes. A useful test for audit leaders: Before adding something to the plan, report or tracker, ask: Does this change a decision? Does this clarify ownership? Does this reduce exposure? Does this improve how the business operates? Does this matter enough to compete for management attention? If the answer is no, audit may not be adding value. It may be adding noise. And that's the real problem. Not audit being too slow. Not audit being too stretched. Not audit needing more templates, trackers or meetings. But audit spending too much time producing work that looks like assurance and too little time shaping the decisions that actually reduce risk. That is where the profession has to get sharper. 📌 Save this as a practical audit planning and reporting checklist. 📩 I write the Beyond the Lines™ newsletter for audit leaders who want less control theatre and more decisions, ownership and outcomes. Subscribe here: https://lnkd.in/eaKkwQar INTEGRAL assurance #InternalAudit #AuditLeadership #RiskManagement #Governance #Audit

  • View profile for Paakhhi G.

    Helping Professionals Break into Data Privacy & Startups Get DPDP Compliant

    13,462 followers

    Your enterprise client sent you a 47-question DPDP compliance questionnaire. You have 7 working days. Your privacy expert is on holiday. You have never done this before. Here is the exact sprint to get through it without losing the contract: DAY 1: READ THE QUESTIONNAIRE END TO END Do not start answering. Categorise every question into three buckets: questions you can answer right now with confidence, questions that require internal investigation, and questions you genuinely do not know the answer to. This triage determines your entire strategy for Days 2 to 7. DAY 2: BUILD YOUR DATA INVENTORY (FAST VERSION) You need to know: what personal data your company holds, where it is stored, what it is used for, and which vendors touch it. You do not need a perfect data map — you need a workable one. A spreadsheet with five columns (data type, location, purpose, legal basis, vendor) completed in one afternoon is better than a perfect mapping project that takes three weeks. DAY 3: LOCATE YOUR EXISTING LEGAL DOCUMENTS Gather your current privacy policy, any data processing agreements with vendors, your Terms of Service, and any previous compliance certifications or audit reports. These are your evidence base for answering policy-related questions. If they do not exist — Day 3 is when you start writing a one-page summary of current practices as an interim document. DAY 4: ANSWER THE EASY QUESTIONS FIRST Work through your Bucket 1 questions. Write clear, specific, honest answers. Enterprise questionnaires are designed to identify vague or evasive responses. An answer that says 'we store customer data in AWS ap-south-1 with AES-256 encryption and access limited to three named engineers' is worth ten times more than 'we maintain appropriate security measures.' DAY 5: TACKLE THE INVESTIGATION QUESTIONS Work through Bucket 2 with your engineering and operations leads. For each question, document what your current practice actually is — then check whether it satisfies the requirement. Where it does not, note the gap and the remediation plan. Clients do not expect perfection. They expect honesty about current state and a credible plan. DAY 6: HANDLE THE UNKNOWNS PROFESSIONALLY For Bucket 3 questions — the ones you genuinely cannot answer — do not leave them blank and do not fabricate. Write: 'This requirement is under active review. We will provide a documented response within [X] days of contract signature.' This is professional. It is also honest. Most enterprise legal teams respect it more than a confident wrong answer. DAY 7: REVIEW, PACKAGE, AND SEND Review for consistency. Make sure your answers to related questions do not contradict each other. Package any supporting documents as clearly labelled attachments. Send with a brief cover note acknowledging the questionnaire and offering a follow-up call if needed. Has a compliance questionnaire ever delayed or cost your startup a deal? Drop Yes/No in the comments! (1:1 Discussion link in comment)

  • View profile for Brian Levine

    Cybersecurity, Privacy & AI Leader | Former DOJ Cybercrime Prosecutor | Executive Director & Cyber Counsel, Former Gov

    16,146 followers

    Last week, I posted a District Court decision in SEC v. SolarWinds (SW). See https://lnkd.in/esRfTmJF. One key takeaway from that decision for CISOs and SEC Registrants is that if organizations state publicly that they have particular security controls, courts may find an implied assumption that those controls are fully enforced, working effectively, and have no notable exceptions.   For example, on its website security statement, SW described its "access controls," including standard statements about having "role based access controls" (RBAC) and the "principle of least privilege." Op. at 53. The Court, however, found these statements would be materially misleading if SW "was routinely promiscuous in freely granting administrative rights . . . and conferring access rights way beyond those necessary." Id.    In other words, even though SW may have legitimately had the stated controls in place generally, it was sufficient for the SEC to allege that these controls were not fully effective or uniformly enforced, and contained notable exceptions. It is this takeaway that may cause some concern to the security community, because it may be the exception, rather than the rule, to find a flawless security control (i.e., one that is fully enforced with no exceptions, and no weaknesses). Give this reality, here are five practical steps one can take to mitigate legal risk:    1. AVOID UNECESSARY PUBLIC STATEMENTS ABOUT SECURITY: If you are public company, anything discussed on your website, blog, or other public location may be the basis for a securities fraud claim. Op. at 51. Consider providing detailed security information directly to customers and potential customers on request, rather than making it public.   2. INCLUDE APPOPRIATE CAVEATS: Consider routinely including statements like, "While the organization has implemented different security controls, it is always an ongoing effort to improve the effectiveness, enforcement, and consistency of application of these controls." See also https://lnkd.in/gTNU5kaK.   3. AVOID PUFFERY: The Court did dismiss certain claims where the statements constituted "non-actionable corporate puffery"--statements "too general to cause a reasonable investor to rely on them." Op. at 68. Be careful, however, because reasonable minds can disagree about whether a statement is general "puffery" or an actionable misstatement, and the question is sometimes left for juries.   4. BE THOUGHTFUL WITH INTERNAL COMMUNICATIONS: Much of the SEC's case was made by corporate emails, slide decks, and other internal communications that may not have been worded as carefully as possible. I provided guidance on internal communications here: https://lnkd.in/gtn4TXbb 5. PROVIDE CISOS WITH PROPER PROTECTIONS: Litigating such enforcement actions can cost millions of dollars and have significant consequences. Make sure your CISO is adequately protected. See my specific guidance here: https://lnkd.in/eadkTEdG.

Explore categories