Its purpose is to determine the extent to which those criteria are met and to report findings that support accountability and corrective action. Audits may be conducted internally by personnel independent of the activity being audited, for a customer, or by an independent third party.
A credible audit defines its objectives, scope, criteria, methods, evidence needs, responsibilities, and reporting process in advance. Auditor competence, objectivity, conflicts of interest, sampling choices, and follow-up all affect the value of its conclusions.
Key points
CriteriaIdentify the policies, standards, contractual duties, control requirements, or regulatory provisions being tested and the systems, locations, periods, and organizations in scope.
Evidence gatheringReview records and configurations, interview responsible people, observe processes, sample transactions, and test selected controls using methods appropriate to the audit objective.
Reporting and follow-throughSeparate evidence from interpretation, describe conformity and findings clearly, assign corrective actions and owners, track resolution, and retain records needed for oversight.
Important limitationAn audit provides time-bounded assurance about defined criteria and sampled evidence. It cannot certify that no vulnerability, fraud, breach, or nonconformity exists outside the scope, nor that controls will remain effective after the audit.