/Manage & operate/Audit readiness checklist

Getting ready for your audit

A checklist to make sure your compliance program is audit-ready

Audit-readiness checklist

0%
  1. Run your gap analysis

    Start with the scoping questions. OptiTech uses your answers to determine which frameworks apply and produces a gap analysis that shows, control by control, where you stand today. Everything else on this checklist works against that baseline.

    Keep reading: Why OptiTech?

  2. Activate the frameworks that apply

    Turn on the frameworks that apply to your organization. Controls are cross-mapped between NIS2, DORA, GDPR, ISO 27001, and the EU AI Act, so the work you do for one framework satisfies the overlapping controls in the others.

    Keep reading: Compliance frameworks

  3. Assign an owner to every control

    Every control needs a responsible owner and a due date. Unowned controls are the ones that quietly fall out of compliance. Assign owners from your team so accountability is clear and drift has somewhere to land.

  4. Connect integrations for continuous evidence

    Connect the systems where your evidence already lives — Microsoft 365, Entra ID, Google Workspace, AWS, Azure, GitHub, and Swedish systems like Fortnox, Visma, and BankID. OptiTech then verifies controls around the clock instead of you gathering screenshots before the audit.

    Keep reading: Connecting OptiTech to your stack

  5. Document your policies and procedures

    Draft the policies each framework requires with the AI copilot, grounded in the legal text and your own data. Every draft goes through human review, and published documents keep an approval trail.

    Keep reading: Get started with the AI copilot

  6. Set up incident reporting

    Make sure the incident flows are ready before you need them: the NIS2 early warning within 24 hours, incident report within 72 hours, and final report within one month to MSB, and the GDPR 72-hour flow to IMY. Each comes with pre-filled forms, deadline countdowns, and communication templates.

  7. Build your vendor register

    Add the suppliers the law makes you responsible for and send them the questionnaires you need. Supply-chain controls are part of NIS2, so your vendors' posture is part of yours.

  8. Schedule board reporting

    NIS2 makes your board responsible for active governance, with personal liability attached. Set up the board report so you can produce the proof of oversight in one click.

  9. Clear open findings and control drift

    Work down your findings list and resolve any drift alerts. When an integration reports that a control has stopped passing, fix it and let OptiTech re-verify, so your posture is green before an assessor looks.

  10. Export your audit package

    When you're ready, generate the audit export. It gives an assessor your controls, evidence, and per-framework status in one place, so the review is a read-through rather than a scramble.

    Keep reading: Tour the OptiTech Console

Need help?

Join our Discord Server to ask questions or see what others are doing with OptiTech. For paid plan support options, see Support.

Was this page helpful?