Skip to content

The Audit You Are Dreading Is The One You Need

You cannot audit yourself, for the same reason a barrister cannot sit on the jury for their own case. A good auditor walks in cold, asks you to show rather than tell, and the gap between what you believe is true and what you can evidence is the most useful gap in IT.

There is a particular look that crosses an IT Director's face when the auditors are due in. Resignation, mostly. A bit of mild dread. The mental calculation of how many evenings will be lost reconciling spreadsheets and digging out evidence that absolutely exists, somewhere. I used to wear the same expression. I do not anymore.

What the Coal Face Cannot See

When you run IT, you are inside the machine. Your day is patches, tickets, change requests, an outage that came from nowhere, and the leadership update due at four. You know your environment better than anyone, and that is precisely the problem. You cannot audit yourself for the same reason a barrister cannot sit on the jury for their own case. You know what you meant to do, what you would do if there were time, and which compromises were sensible. None of that is visible to the next person who picks up the work, and none of it is visible in the controls.

The gap between what we believe is true and what we can evidence is, in my experience, the most useful gap in IT.

The Difference Between Doing and Evidencing

Most IT teams do far more than they get credit for. Backups run nightly. Patching cadence is solid. Account reviews happen. Then the auditor asks for evidence of the last twelve restore tests, and the room goes quiet. The work being done and the work that can be proven are two different things, and only one of them protects the business when something goes wrong. An auditor is the person who reminds you, politely and persistently, that "we do this" needs to mean "we can show this". That is not bureaucracy. That is the discipline that gets you through an incident or a regulator's enquiry without wishing you had three more weeks to find the screenshots.

Certifications Are a Floor, Not a Ceiling

There is a fair criticism of certifications: done badly, they reward paperwork over outcomes and become theatre. Done properly, they are something else. A standard, whether Cyber Essentials Plus, ISO 27001, SOC 2, or NIST CSF, is a baseline the business has publicly agreed to meet. The business almost never sets a clear bar for IT and security on its own. Ask a board what level of control assurance they expect and you get a thoughtful pause; hand them ISO 27001 and they understand. The certification gives the business a language for the floor it expects you to stand on, and gives you a defensible answer when someone asks why you spend money on logging, monitoring, and identity hygiene.

Audit as Air Cover

The work that prevents disasters does not show up in product launches or quarterly results. It is hard to fund, hard to staff, and easy to defer. An audit finding changes that. When the auditor writes that your privileged access controls need work, the meeting you have been trying to get for six months happens that week. The roadmap you have been quietly trying to deliver acquires the magic words: "the auditors have raised this". If you are running IT well, an audit is not a threat. It is the leverage you have been waiting for.

The Working Relationship

The best auditors have seen fifty organisations try to solve the same problem; you have seen one. The relationship works when you treat the audit as a conversation rather than an exam, are honest about what is not yet in place, and push back on a wrong finding with evidence rather than annoyance. The worst posture you can adopt is defensive. The next worst is performative. The right one is curious: what did they see that you missed, and where is the gap between your model of the environment and theirs?

What I Take From It

Every audit I have been through has shown me something I did not know about my own environment. Sometimes a control was weaker than I thought. Sometimes a process I assumed was running had quietly stopped. None of it was failure; all of it was useful. The teams that get the most from audit are the ones who stopped treating the auditor as an inspector and started treating them as a second pair of eyes the business has paid for. When something goes wrong, and something always goes wrong eventually, the difference between a bad week and a career-ending one is usually the work that audit forced you to keep doing when you would rather have been doing something else.

Share this article: