Compliance Audit and Procedure
A compliance audit is a comprehensive review of an organization's adherence to regulatory guidelines. Independent accounting, security or IT consultants evaluate the strength and thoroughness of compliance preparations. Auditors review security policies, user access controls and risk management procedures over the course of a compliance audit.
What, precisely, is examined in a compliance audit will vary depending upon whether an organization is a public or private Company, what kind of data it handles and if it transmits or stores sensitive financial data.
We, as Compliance Auditors, will generally ask CIOs, CTOs and IT administrators a series of pointed questions over the course of an audit. These may include what users were added and when, who has left the Company, whether user IDs were revoked and which IT administrators have access to critical systems. IT administrators prepare for compliance audits using event log managers and robust change management software to allow tracking and documentation, authentication and controls in IT systems.
The growing category of GRC (governance, risk management and compliance) software enables CIOs to quickly show auditors that the organization is in compliance and will not be subject to costly fines or sanctions.