Skip to content

Audit

What is Audit?

A systematic, independent examination of an organisation's activities, processes, or financial records to verify compliance with standards, regulations, or internal policies.

Audit

What the standards actually require on audit

Requirements naming audit across 6 standards, quoted from the control text.

ISO 19011:201834 controls

Requirement defined in ISO 19011:2018, clause 6.6 (Completing audit). See licensed source for normative text. Implementation focus is to demonstrate conformity with the obligations of this clause through the artefacts listed in evidence_requirements.

iso-19011-2018::6.6 · Completing audit
FedRAMP High21 controls

Allocate audit log storage capacity to accommodate FedRAMP-defined retention period.

AU-4 · Audit Log Storage Capacity

Guidance on determining audit time based on effective number of personnel concept

27006-C · Audit time guidance

Plan ISMS audit, prepare documents and verify objectives, scope, criteria and risks.

27007-6.2 · Preparing Audit Activities

Allocate audit log storage capacity to accommodate FedRAMP-defined retention period.

AU-4 · Audit Log Storage Capacity

Cross-organizational Audit Logging. Employ [organization-defined] for coordinating [organization-defined] among external organizations when audit information is transmitted across organizational boundaries

NIST800-AU-16 · Cross-organizational Audit Logging. Employ [organization-defined] for coordinating [organization-defined] among external organizations when audit information is transmitted across organizational boundaries

Questions people ask about audit

What is Audit?
A systematic, independent examination of an organisation's activities, processes, or financial records to verify compliance with standards, regulations, or internal policies.
Why is Audit important for compliance?
Audit is a key concept in Audit. Understanding audit helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
What concepts are related to Audit?
Key concepts related to Audit include Internal Audit, Nonconformity. Understanding these interconnected concepts provides a more comprehensive view of Audit requirements and helps organizations build holistic compliance programs.
Which compliance frameworks address Audit?
Audit appears in the requirement text of ISO 19011:2018, FedRAMP High, ISO/IEC 27006:2024, ISO/IEC 27007:2020, NIST SP 800-53 Revision 5.1 HIGH. Across these standards we have identified 125 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Audit?
Explore our compliance framework pages to see how audit applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Audit applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.