Checklist

Internal Audit Preparation Checklist

Run a dry run before anyone external looks: documentation, evidence freshness, owners, and open findings.

Intended audience
Compliance owners and managers
Difficulty
Intermediate
Estimated time
35 minutes
Access
Free
SOC 2
ISO 27001
NIST SP 800-171
All industries

Version v1.0.0 · Last reviewed 2026-08-01 · Document owner: ComplianceAnvil Content Team

What you will be able to do

  • Run a dry-run walkthrough where control owners explain their controls out loud before an external audit.
  • Sample controls and verify evidence actually supports the claim being made.
  • Confirm open findings each have an owner and a target date before an audit begins.
  • Prepare a short system description and boundary diagram in advance.

Practice the walkthrough

Auditors ask people, not documents. Have each control owner explain their control out loud before the real conversation happens.

Key takeaways

  • Auditors ask people, not documents, so control owners should practice explaining their controls out loud beforehand.
  • Sampling a handful of controls and checking the evidence against the claim reveals gaps before an outsider finds them.
  • Open findings need a named owner and a target date, not just a note that a problem exists.
  • Writing down known gaps ahead of time is preferable to having someone else discover them first.

Checklist

Progress0 of 10 (0%)

Progress is saved in this browser only. It is not a compliance record.

Sources

Written from these public, authoritative publications. ComplianceAnvil paraphrases and summarizes them; it does not reproduce copyrighted control text.

Earn a Certificate of Training Completion

Complete every section, acknowledge, and pass the knowledge check.

Sections opened0 of 1
Knowledge check

80% required to pass. Answers are graded on our servers.

1. Why does the checklist recommend practicing the walkthrough?

2. What should be done with a sample of controls before an audit?

3. What must every open finding have, per the checklist?

4. What does the checklist suggest doing with known gaps before the audit?

This certificate recognizes completion of educational training material only. It is not a professional certification, accreditation, license, compliance assessment, audit result, or attestation of compliance with any law, regulation, or contract requirement. ComplianceAnvil is not a certification authority, accreditation body, assessor, or law firm.

How this was written and reviewed

Published
Author
ComplianceAnvil Editorial Team
Technical reviewer
ComplianceAnvil Technical Review Board
Jurisdiction
United States (federal)
First published
2026-08-01
Last reviewed
2026-08-01
Next review due
2027-08-01

Version v1.0.0 · Document owner: ComplianceAnvil Content Team

Important

This resource is educational readiness material. ComplianceAnvil is not a certification authority, assessor, or law firm, and this content is not legal advice or a compliance assessment.

Matched on shared frameworks, topics, and program packs.

Guide

Preparing for a Security Assessment

The six weeks before an assessment, sequenced: documentation, evidence, owner rehearsal, and gap honesty.

Advanced
15 min
Premium
CMMC
NIST SP 800-171

Published · v1.0.0 · 2026-08-01

Exercise

Perform a Mock Evidence Review

Play the assessor: decide whether sample artifacts actually prove the control claimed.

Intermediate
20 min
Free
CMMC
SOC 2

Published · v1.0.0 · 2026-08-01

Checklist

Evidence Collection Checklist

Turn what you already do into evidence: what to capture, how to label it, and how long to keep it.

Intermediate
25 min
Free
CMMC
NIST SP 800-171

Published · v1.0.0 · 2026-08-01

Template

Access Review Worksheet

A repeatable quarterly review of who has access to what, with a decision recorded for each row.

Intermediate
25 min
Free
NIST SP 800-171
SOC 2

Published · v1.0.0 · 2026-08-01

Exercise

Classify Sample Data

Sort realistic records into classification levels and defend the handling rules that follow.

Intermediate
15 min
Free
NIST SP 800-171
ISO 27001

Published · v1.0.0 · 2026-08-01

Template

Data Classification Matrix

Define your data levels and the handling rules that follow from each one.

Intermediate
30 min
Premium
NIST SP 800-171
ISO 27001

Published · v1.0.0 · 2026-08-01

Put this into practice

Resources tell you what good looks like. A Program Pack does the work with you — generated documentation, tracked controls, training, and evidence in one workspace.