RISKORIA ADVISING & PROFESSIONAL SERVICES D.O.O. · ZAGREB+385 97 737 1345INFO@RISKORIA.EU

Audit readiness

An auditor does not ask for good intentions, but for records. We assemble the documentation, review it the way an auditor will and prepare the management board for the conversation.

LEGAL FRAMEWORKZKS NN 14/2024REGULATION NN 135/2024, ANNEX II

Why preparation rather than improvisation

An audit does not check whether you have documents, but whether you can show they are followed.

Preparation is work on records rather than on documents, because the auditor asks for proof that the document was actually followed. How the auditor scores, on what deadline the audit comes and how the procedure itself runs is set out on the page on the cyber security audit.

We keep going until every piece of evidence has a date, a name and a place in the set, because until then there is no way to show when it was produced or who answers for it.

What the preparation looks like

Seven steps, from a review of what exists to an internal check using the same formulas the auditor uses.

01

Review of existing documentation and records

We go through everything you have and separate documents from evidence of application. This is usually the point where it becomes clear there are enough documents and almost no records behind them.

INVENTORY OF WHAT EXISTSDOCUMENT VERSUS EVIDENCE
02

Gap analysis at control level

For every control that binds you we score documentation and implementation on the same 1 to 5 scale the auditor uses, and compare that against the thresholds for your level of measures. The result is a list of controls that would fail today.

CONTROL LEVEL ANALYSISDOCUMENTATION AND IMPLEMENTATION MARKSCOMPARISON WITH THRESHOLDS
03

List of missing evidence, ordered by urgency

We order the gaps by how long they take and what they cost, because some are fixed in a week while others need a new training cycle or a contract amendment. The list gets an owner and a date, otherwise it stays a wish.

GAP LISTPRIORITIESOWNER AND DEADLINE
04

Arranging the evidence by measure and sub-measure

We arrange the evidence the way an auditor will ask for it, by measure and sub-measure, rather than by the folders it happened to be created in. Each item states which control it covers, who produced it and when.

EVIDENCE SETMAPPING TO CONTROLSEVIDENCE REGISTER
05

Closing the largest gaps

We write what is missing and, more importantly, start the things that must leave a trail: access rights reviews, backup testing, training, a simulation exercise. A document without that trail does not pass.

MISSING DOCUMENTSSTARTING THE PROCESSESFIRST RECORDS
06

Internal readiness check

We walk through the evidence the way the auditor will, with the same scoring formulas and the same questions. The findings go to you, not to the authority, so there is time to fix things.

INTERNAL FINDINGSSCORING BY SUB-MEASUREREMEDIATION PLAN
07

Preparing management and measure owners for the interviews

We go through the typical questions measure by measure and help owners know where their evidence is and how to present it, without improvising in front of the auditor.

QUESTIONS BY MEASUREMOCK INTERVIEWSOWNER BRIEFING

What the auditor asks for first

The auditor asks for the first three straight away. If those hold up, the rest of the conversation goes calmly. If they do not, everything else gets questioned.

  • Critical asset inventory, with an owner and a location
  • Risk register with owner, likelihood and impact
  • Incident records and records of reports made within the legal deadlines
  • Strategic security policy, with a date of adoption
  • Minutes of the meeting where management approved the measures
  • List of direct suppliers and the security clauses in their contracts
  • Records of the access rights review in the latest cycle
  • Records of backup and recovery plan testing
  • Attendance lists and dates of the training delivered
  • Records of vulnerability scans and patching
  • Logs covering the retention period required by sub-measure 5.6
  • Record of the annual report to management on the state of cyber security

Frequently asked questions

The questions we are asked most often before we start.

Do you carry out the audit?

No. Riskoria does not hold the national security certificate for auditing and does not perform compliance audits. We do the preparation, which is a separate role and avoids a conflict of interest. We also help you find an auditor.

How long does preparation take?

Two to three weeks for the picture of the current state, and two to six months to close the gaps, depending on size and on what is already in place. Anything that needs a new cycle, an annual review or plan testing for example, cannot be accelerated.

When should we start?

At least six months before the audit, and a year in public administration, because procurement and budgeting take time. Last-minute preparation comes down to writing documents with no records behind them, and that is exactly what is easiest to spot.

How much documentation is usually missing?

The analysis almost always shows that most of the required records are missing, and more often the evidence of application than the documents themselves. That is why we run preparation from the records towards the document, not the other way round.

Who takes part in the internal check?

The owners of the individual measures and management. Each of them goes through their own part of the evidence and the questions that come with it.

Does an ISO 27001 certificate help us?

It helps, but it does not replace the scoring. The auditor still scores every control, and your certificate, statement of applicability and internal audit reports feed into that scoring as evidence. ISO 22301 helps the same way for the continuity measure.

Do we have to notify anyone that we are preparing?

No. Preparation is your internal work, and it is the auditor who announces the audit itself, not you.

Where to go next

The terms, the deadlines and the audit procedure itself are explained on these pages.

Let us check your evidence before the auditor does.

Half an hour, no obligation. You tell us what you have on paper and we tell you how it will look to an auditor.

Book a callINFO@RISKORIA.EU · +385 97 737 1345