A compliance audit checklist is a structured list of the policies, controls, and evidence an auditor will ask for, reviewed before the audit so the gaps surface while they are still cheap to fix. Here are 30 points, grouped into the six areas where audits most often go sideways, that you can review internally this week.
One framing note before the list: working through a checklist like this is a readiness exercise. It tells you how prepared you are and what to fix. It is diagnostic input, not a certified audit, and it does not certify you against SOC 2, ISO 27001, or any other framework. Only an accredited auditor can do that. The point of the checklist is to walk into that audit without surprises.
1. Policies and documentation (points 1-6)
| # | Check | What good looks like |
|---|---|---|
| 1 | Information security policy exists and is current | Reviewed within the last 12 months, version history kept |
| 2 | Data retention policy is approved, not just drafted | Signed off by an owner, with retention periods per data type |
| 3 | Acceptable use policy is acknowledged by staff | Signature or click-through recorded for every employee |
| 4 | Privacy policy matches what you actually do with data | Legal review after any product or vendor change |
| 5 | Policy owners are named people, not departments | Each policy lists one accountable owner |
| 6 | Exceptions to policy are logged with expiry dates | An exceptions register that gets reviewed quarterly |
2. Access control (points 7-12)
| # | Check | What good looks like |
|---|---|---|
| 7 | Access reviews run on a schedule | Quarterly reviews completed on time, results recorded |
| 8 | Offboarding removes access the day someone leaves | A checklist tied to HR offboarding, spot-checked |
| 9 | Admin rights are limited and justified | A short, current list of admins per system with a reason each |
| 10 | Multi-factor authentication is enforced, not optional | MFA required on email, VPN, and production systems |
| 11 | Shared accounts are eliminated or vaulted | No password spreadsheets; shared credentials in a managed vault |
| 12 | Third parties with access are inventoried | A vendor access list reviewed with the same cadence as staff |
3. Data handling (points 13-17)
| # | Check | What good looks like |
|---|---|---|
| 13 | You know where regulated data lives | A data map covering systems, owners, and data classes |
| 14 | Retention periods are enforced, not aspirational | Old data actually gets deleted on schedule, with logs |
| 15 | Backups exist, are encrypted, and restore | A restore test performed and documented in the last 6 months |
| 16 | Data subject requests have a documented path | A named owner and a tracked turnaround time |
| 17 | Data shared with processors is under contract | Processing agreements on file for every vendor touching personal data |
4. Incident response (points 18-22)
| # | Check | What good looks like |
|---|---|---|
| 18 | An incident response runbook exists | Steps, severity levels, and communication templates written down |
| 19 | The runbook has a named owner | One person accountable for keeping it current |
| 20 | You have run a dry run in the last year | A tabletop exercise with notes on what broke |
| 21 | Incidents are logged, even small ones | A register with dates, impact, and follow-up actions |
| 22 | Breach notification duties are mapped | Who must be told, in what timeframe, per regulation that applies to you |
5. Vendors and third parties (points 23-26)
| # | Check | What good looks like |
|---|---|---|
| 23 | A vendor inventory exists and is current | Every vendor with data access listed, with a risk tier |
| 24 | High-risk vendors are assessed before signing | Security review or questionnaire on file |
| 25 | Vendor incidents reach you contractually | Notification clauses in contracts for data-touching vendors |
| 26 | Offboarded vendors lose access and return data | A vendor offboarding step mirroring employee offboarding |
6. People and training (points 27-30)
| # | Check | What good looks like |
|---|---|---|
| 27 | Security awareness training runs annually | Completion tracked, laggards chased |
| 28 | Role-specific training exists where risk is higher | Engineers, finance, and support get targeted modules |
| 29 | New hires are trained within the first month | Onboarding includes the security and privacy basics |
| 30 | Someone owns compliance as part of their job | A named role, even fractional, not "everyone and no one" |
How to score yourself honestly
Go through the 30 points and mark each one green (evidence exists and is current), amber (exists but stale or partial), or red (missing). Two rules keep the exercise honest. First, "we could produce that if asked" counts as amber at best; auditors ask for evidence, not intentions. Second, rate the worst case across your systems, not the best one: an access review done religiously on one system and never on another is amber, not green.
Most companies doing this for the first time land around 15 to 20 green. That is normal, and it is exactly the information you want three months before an audit rather than three days. Cluster your reds by section: a section with two or more reds is a workstream, not a task, and belongs on the quarterly plan with an owner.
From checklist to readiness score
A spreadsheet checklist works for one pass. What it does not give you is a comparable score over time, a view across departments, or any sense of how your posture compares to companies your size. A structured compliance readiness assessment turns the same questions into a scored dimension: you see readiness as a number, watch it move as gaps close, and get the gap list ranked by impact. If your compliance push is part of a wider look at how the company is running, the organizational health guide covers how compliance readiness fits alongside culture, process, digital, and skills.
Assessmentcloud includes compliance readiness as one of its five assessment dimensions (CR-05): a question set built on checkpoints like the 30 above, scored 0 to 100, benchmarked against your industry, with the open gaps ranked in a prioritized action plan. It is flat-priced from $49 a month for the whole company, and the result is explicitly diagnostic input to prepare for an audit, not a certified audit or a substitute for one. See how the compliance readiness assessment works before you spend on audit automation or auditor hours. If this compliance review is one piece of a broader look at the people function, an HR audit self-assessment scores compliance readiness alongside culture, process, and skills, and our HR audit checklist walks the employment-side items (I-9 files, handbook currency, classification) that sit outside the security checkpoints above.
RUN IT, NOT JUST READ IT
Score this dimension for your company
The interactive sample readout on the homepage shows exactly what you get: scored dimensions, industry benchmarks, and a prioritized action plan. Flat pricing from $49 a month.