Skip to main content

Audit Preparation: Initial Touchpoint

J
Written by Jaquez Hodo
Updated this week

When first connecting with your auditor, consider the following questions as you work toward audit readiness in Vanta.

What should be considered in scope for our audit?

Include people, locations, assets, and processes. It's important to consider what stakeholders expect to be included in the program, as well as clearly state what is excluded. Be transparent by listing all exclusions.

What level of progress should we have in Vanta (e.g., 75% of tests passing) before we reach out to schedule our audit?

The required level of progress depends on the type of audit:

  • Point-in-time audits (e.g., ISO): These may not require full implementation but should demonstrate preparedness.

  • Audit period-based audits (e.g., SOC, HITRUST): These often require a "soaking period" of up to 90 days, during which controls must be operational.

  • PCI audits: All controls must be fully implemented and functioning. Remediation, implementation, training, and documentation efforts may need to be completed before scheduling.

  • PEN testing: A clean PEN test must be completed when required (e.g., for PCI). This is often a blocker for receiving the final Report on Compliance (ROC), as all findings must be fully remediated before the ROC can be issued.

What evidence will we need to provide to satisfy vulnerability scanning requirements?

Evidence may include:

  • Configuration settings that demonstrate how vulnerability scanning is implemented.

  • Ticketing or issue management documentation that shows how vulnerabilities are tracked and resolved.

  • Policies that define severity levels and alerting procedures.

In some cases, a pentest may also be required. Penetration testing is mandatory for some audit types (e.g., certain PCI levels) but is only a best practice for some others (e.g., SOC 2). As a general best practice, an annual application penetration test is strongly recommended.

SOC 2

(Type II) When should I upload specific documents and evidence to ensure the audit stays on track?

Early sharing allows for:

  • Thorough auditor review before interviews.

  • Reduced follow-up questions.

  • More efficient and focused interview sessions.

    • After interviews, prioritize responding to any outstanding requests during the same audit week.

Should I include any additional Trust Services Criteria (TSCs) based on my business or audit scope?

Yes, depending on your business needs:

  • Security and Confidentiality: Highly recommended for all organizations.

  • Availability: Consider if your product or service depends on consistent uptime.

  • Adding relevant TSCs strengthens the audit scope and highlights key areas of control effectiveness.