Assessmentcloud
CR-05 COMPLIANCE TEMPLATES

Compliance Audit Checklist: 30 Points to Review

JUNE 2026 · 11 MIN READ · BY THE ASSESSMENTCLOUD TEAM

A compliance audit checklist is a structured list of the policies, controls, and evidence an auditor will ask for, reviewed before the audit so the gaps surface while they are still cheap to fix. Here are 30 points, grouped into the six areas where audits most often go sideways, that you can review internally this week.

One framing note before the list: working through a checklist like this is a readiness exercise. It tells you how prepared you are and what to fix. It is diagnostic input, not a certified audit, and it does not certify you against SOC 2, ISO 27001, or any other framework. Only an accredited auditor can do that. The point of the checklist is to walk into that audit without surprises.

1. Policies and documentation (points 1-6)

#CheckWhat good looks like
1Information security policy exists and is currentReviewed within the last 12 months, version history kept
2Data retention policy is approved, not just draftedSigned off by an owner, with retention periods per data type
3Acceptable use policy is acknowledged by staffSignature or click-through recorded for every employee
4Privacy policy matches what you actually do with dataLegal review after any product or vendor change
5Policy owners are named people, not departmentsEach policy lists one accountable owner
6Exceptions to policy are logged with expiry datesAn exceptions register that gets reviewed quarterly

2. Access control (points 7-12)

#CheckWhat good looks like
7Access reviews run on a scheduleQuarterly reviews completed on time, results recorded
8Offboarding removes access the day someone leavesA checklist tied to HR offboarding, spot-checked
9Admin rights are limited and justifiedA short, current list of admins per system with a reason each
10Multi-factor authentication is enforced, not optionalMFA required on email, VPN, and production systems
11Shared accounts are eliminated or vaultedNo password spreadsheets; shared credentials in a managed vault
12Third parties with access are inventoriedA vendor access list reviewed with the same cadence as staff

3. Data handling (points 13-17)

#CheckWhat good looks like
13You know where regulated data livesA data map covering systems, owners, and data classes
14Retention periods are enforced, not aspirationalOld data actually gets deleted on schedule, with logs
15Backups exist, are encrypted, and restoreA restore test performed and documented in the last 6 months
16Data subject requests have a documented pathA named owner and a tracked turnaround time
17Data shared with processors is under contractProcessing agreements on file for every vendor touching personal data

4. Incident response (points 18-22)

#CheckWhat good looks like
18An incident response runbook existsSteps, severity levels, and communication templates written down
19The runbook has a named ownerOne person accountable for keeping it current
20You have run a dry run in the last yearA tabletop exercise with notes on what broke
21Incidents are logged, even small onesA register with dates, impact, and follow-up actions
22Breach notification duties are mappedWho must be told, in what timeframe, per regulation that applies to you

5. Vendors and third parties (points 23-26)

#CheckWhat good looks like
23A vendor inventory exists and is currentEvery vendor with data access listed, with a risk tier
24High-risk vendors are assessed before signingSecurity review or questionnaire on file
25Vendor incidents reach you contractuallyNotification clauses in contracts for data-touching vendors
26Offboarded vendors lose access and return dataA vendor offboarding step mirroring employee offboarding

6. People and training (points 27-30)

#CheckWhat good looks like
27Security awareness training runs annuallyCompletion tracked, laggards chased
28Role-specific training exists where risk is higherEngineers, finance, and support get targeted modules
29New hires are trained within the first monthOnboarding includes the security and privacy basics
30Someone owns compliance as part of their jobA named role, even fractional, not "everyone and no one"

How to score yourself honestly

Go through the 30 points and mark each one green (evidence exists and is current), amber (exists but stale or partial), or red (missing). Two rules keep the exercise honest. First, "we could produce that if asked" counts as amber at best; auditors ask for evidence, not intentions. Second, rate the worst case across your systems, not the best one: an access review done religiously on one system and never on another is amber, not green.

Most companies doing this for the first time land around 15 to 20 green. That is normal, and it is exactly the information you want three months before an audit rather than three days. Cluster your reds by section: a section with two or more reds is a workstream, not a task, and belongs on the quarterly plan with an owner.

From checklist to readiness score

A spreadsheet checklist works for one pass. What it does not give you is a comparable score over time, a view across departments, or any sense of how your posture compares to companies your size. A structured compliance readiness assessment turns the same questions into a scored dimension: you see readiness as a number, watch it move as gaps close, and get the gap list ranked by impact. If your compliance push is part of a wider look at how the company is running, the organizational health guide covers how compliance readiness fits alongside culture, process, digital, and skills.

Assessmentcloud includes compliance readiness as one of its five assessment dimensions (CR-05): a question set built on checkpoints like the 30 above, scored 0 to 100, benchmarked against your industry, with the open gaps ranked in a prioritized action plan. It is flat-priced from $49 a month for the whole company, and the result is explicitly diagnostic input to prepare for an audit, not a certified audit or a substitute for one. See how the compliance readiness assessment works before you spend on audit automation or auditor hours. If this compliance review is one piece of a broader look at the people function, an HR audit self-assessment scores compliance readiness alongside culture, process, and skills, and our HR audit checklist walks the employment-side items (I-9 files, handbook currency, classification) that sit outside the security checkpoints above.

RUN IT, NOT JUST READ IT

Score this dimension for your company

The interactive sample readout on the homepage shows exactly what you get: scored dimensions, industry benchmarks, and a prioritized action plan. Flat pricing from $49 a month.

See a sample readout