Risk: Going straight to audit without preparation leads to gaps being discovered too late.
Mitigation: Run an internal gap assessment (with a consultant or using a vendor platform). Fix gaps before engaging the auditor. [Before our evidence collection period] [Needs Attention]
2. Scope
Risk: Including too many systems/processes in scope → audit complexity + higher failure risk.
Mitigation: Define scope tightly (limit to customer-facing systems, main cloud infra, and critical processes). Avoid dragging in experimental tools or unused systems. (Defining our GCP scope is highly important and needs to get reviewed from the consultant) [Needs Attention]
3. Policy–Practice Mismatch [IMPORTANT: As everything revolved around this]
Risk: Having written policies but not following them → non-compliance findings.
Mitigation:
Write realistic policies (not just boilerplate). ->keep scope limited so that the renewal is easy, manageable
Train employees and ensure actual practices match.
4. Evidence Gaps
Risk: Inability to provide consistent evidence across the audit period (Type II).
Mitigation:
Vendor mostly do and must support and guide through this
Set up continuous monitoring instead of last-minute collection.
Create an evidence calendar to ensure periodic activities (e.g., access reviews every quarter)
No Comments