A compliance audit is an independent review that checks whether an organization is following the specific laws, industry standards, or internal policies that apply to it. The stakes are concrete. Failed audits can trigger penalties from a few hundred dollars per violation to more than $2 million a year, and in serious cases an organization can lose the ability to process card payments, treat patients, or stay listed on a public exchange. The process itself is predictable, and knowing each phase is most of what separates a smooth audit from a painful one.
What Gets Audited and Why
The source of the requirement shapes everything else: who runs the audit, what evidence they want, and what happens if you fail. Most compliance audits trace back to one of three sources.
Regulatory Requirements
Regulatory audits verify adherence to government-mandated laws, and they carry the heaviest penalties because the government both writes and enforces the rules. The Sarbanes-Oxley Act requires every publicly traded company to include in its annual report both management’s own assessment of its internal controls over financial reporting and an independent auditor’s attestation of those controls.1SEC. Sarbanes-Oxley Section 404 – A Guide for Small Business Executives who knowingly certify false financial reports face fines up to $5 million and up to 20 years in prison.
Environmental audits assess whether a facility follows emissions limits, waste disposal rules, and permit conditions. The EPA runs compliance monitoring programs across 44 regulatory programs authorized by seven environmental statutes, using on-site inspections, records reviews, and stack testing to determine whether a facility meets its obligations.2US EPA. Monitoring Compliance Workplace safety audits under OSHA follow a similar enforcement model, with penalties for willful or repeated violations reaching $165,514 per violation.3Occupational Safety and Health Administration. OSHA Penalties
Newer laws are adding regulatory audits in areas that used to be self-policed. Under regulations finalized in September 2025, the California Consumer Privacy Act now requires certain businesses to complete annual cybersecurity audits, with the first certifications due to the California Privacy Protection Agency starting April 1, 2028 for larger businesses.4California Privacy Protection Agency (CPPA). California Finalizes Regulations to Strengthen Consumers Privacy
Industry Standards
Industry audits are driven by standards created within a sector, often by a trade body or governing council. Failing one usually means losing the ability to do business with partners who require compliance rather than paying a government fine.
HIPAA sets the standard for protecting sensitive patient health information. Covered entities, meaning health care providers, health plans, and health care clearinghouses, must comply with rules on the privacy and security of that information.5HHS.gov. Covered Entities and Business Associates Penalties scale with culpability. A violation where the organization did not know and could not reasonably have known about the problem starts at $145, while willful neglect that goes uncorrected can reach $73,011 per violation with an annual cap above $2.1 million.6Federal Register. Annual Civil Monetary Penalties Inflation Adjustment
The Payment Card Industry Data Security Standard applies to any organization that stores, processes, or transmits cardholder data.7PCI Security Standards Council. PCI Security Standards Overview Non-compliant merchants face fines from the major card brands, and in serious cases can lose the ability to accept card payments entirely. ISO/IEC 27001, published jointly by the International Organization for Standardization and the International Electrotechnical Commission, provides a voluntary framework for information security management.8NSF. ISO/IEC 27001 – Information Security Management Certification Voluntary in law, often mandatory in procurement contracts.
Internal Policies
Internal audits measure whether people inside the organization are actually following its own written policies. Management might review the travel and expense policy for missing documentation, or check training records and conflict-of-interest disclosures against the ethics code. The point is to find problems before an external auditor or regulator does, and the findings often work as an early warning about where controls need reinforcement.
A Boundary Case: Federal Funding
One category catches organizations that don’t think of themselves as regulated. Any entity that spends $1,000,000 or more in federal awards during a fiscal year must undergo a Single Audit under the federal Uniform Guidance.9eCFR. 2 CFR Part 200 Subpart F – Audit Requirements Many nonprofits, universities, and state and local governments cross that threshold through grants and cooperative agreements. A Single Audit examines both the financial statements and compliance with the terms of each federal program, and first-timers are often surprised by how much documentation is required.
Preparing Before Auditors Arrive
Preparation is where most of the real work happens. Audits typically run about three months from start to finish: roughly four weeks of planning, four weeks of fieldwork, and four weeks of report compilation. That timeline compresses fast if the planning phase turns into a scramble for documents.
Defining the Scope
Preparation starts with nailing down exactly what the auditors will test. That means identifying the specific regulations or standards in play and the exact time period under review. For a SOX audit, the scope might focus on the general ledger, accounts payable, and accounts receivable processes for a single fiscal year. The right approach depends on the company’s size, complexity, and organizational structure.1SEC. Sarbanes-Oxley Section 404 – A Guide for Small Business Locking down scope early prevents the audit from creeping into areas nobody budgeted for.
Testing Your Own Controls First
A pre-audit self-assessment is the single most valuable thing an organization can do. Walk through each key control using the same methodology an external auditor would: pick a sample, test it, document what you find. If a purchase order over $5,000 is supposed to require two management signatures, pull a sample and check. Deficiencies you catch now cost a fraction of what they cost when an auditor finds them and writes them into a report.
Just as important, make sure the people who own those controls can explain them. Auditors interview control owners, and someone who can’t articulate what they do or why raises immediate red flags even when the control itself is working fine.
Gathering Documentation
Documentation is the concrete evidence of compliance. Every relevant policy, procedure, and record of control execution needs to be organized and accessible before the auditors arrive. For an IT controls audit, that means access logs, change management records, and evidence that terminated employees had access removed promptly. For HIPAA, it means workforce training records. On that point, the HIPAA Privacy Rule requires covered entities to train all workforce members on privacy policies and procedures, with additional training required whenever those policies materially change.10eCFR. 45 CFR 164.530 – Administrative Requirements The regulation does not actually specify annual frequency, which surprises many organizations that assume it does. Contracts with third-party vendors should also be organized to show that required compliance clauses are in place.
Selecting the Audit Team
If you’re engaging an external firm, look for auditors with direct experience in the framework being tested. A firm that does excellent financial statement audits may be the wrong choice for HIPAA or PCI DSS. Individual credentials matter too. A Certified Information Systems Auditor signals expertise in IT controls and security; a Certified Internal Auditor focuses on risk management and governance; for SOX and financial reporting, a Certified Public Accountant is the baseline.
Independence is non-negotiable. The audit firm cannot have provided consulting, bookkeeping, or other non-audit services that would compromise its objectivity. Under SOX this is explicit: the firm that audits your financial controls cannot also design them. The engagement letter should state the audit standards being applied and the deliverables expected.
What Happens During the Audit
The formal process begins with a kickoff meeting where the audit team and management finalize the plan, confirm the timeline, and sort out logistics like workspace, system access, and key contacts. This is when the auditors lay out exactly which controls they plan to test and how, so nothing about the coming weeks should be a surprise.
Fieldwork is the testing phase. Auditors interview control owners, observe employees performing control activities, and examine samples of transactions to determine whether they were processed according to policy. Sample sizes are usually driven by statistical methods designed to make the results representative of the full population.
Auditors also perform walk-throughs, tracing a single transaction from start to finish through every control point. A walk-through of purchasing would follow a purchase order from initial request through approval, receipt of goods, invoice matching, and final payment. The point is to confirm that the controls actually operate at each step, not just on paper.
Throughout fieldwork, auditors collect and index evidence supporting their conclusions: signed policies, screenshots of system configurations, electronic copies of sampled transactions. Every item gets tied back to a specific control objective and the test performed against it.
Before fieldwork wraps up, the team shares draft findings with management. This is your chance to correct factual errors, provide evidence the auditors may have missed, and discuss disagreements about how an observation was characterized. Experienced audit teams treat this step as collaborative. Disagreements about severity are common and usually get resolved here, before anything is formalized.
Reading the Findings
Not all findings carry the same weight, and the classification determines how urgently you have to act and what you’re required to disclose.
A material weakness is the most severe classification. It means there is a reasonable possibility that a significant error in the organization’s financial statements or compliance obligations would not be caught or prevented by existing controls.11PCAOB. AS 1305 – Communications About Control Deficiencies in an Audit of Financial Statements For publicly traded companies, a material weakness in internal controls must be disclosed publicly, which often brings a stock price decline and heightened regulatory scrutiny.
A significant deficiency is less severe than a material weakness but still important enough to warrant attention from the board or audit committee.11PCAOB. AS 1305 – Communications About Control Deficiencies in an Audit of Financial Statements The auditor must communicate both categories in writing to management and the audit committee, clearly distinguishing between the two. A minor observation, by contrast, might note poor documentation of a control that is otherwise functioning. Worth fixing, but not a fundamental breakdown.
The Four Audit Opinions
The final report includes the auditor’s formal opinion, which tells readers how much confidence to place in the organization’s compliance or financial reporting.
- Unqualified (clean) opinion: the statements or controls are presented fairly in all material respects. This is the outcome everyone wants.
- Qualified opinion: the auditor found material issues, but they are limited in scope and don’t undermine the overall picture. Mostly compliant, with specific exceptions.
- Adverse opinion: the problems are both material and pervasive. The financial statements or compliance posture cannot be relied upon. This can trigger regulatory action.
- Disclaimer of opinion: the auditor could not obtain enough evidence to form any opinion. This usually happens when the organization restricted access or when circumstances made a thorough review impossible.
A qualified opinion is survivable. An adverse opinion or disclaimer is a crisis, and organizations that receive either should expect follow-up scrutiny from regulators, lenders, and business partners.
What You Owe After the Report
Once the final report lands, the organization is responsible for building a formal, time-bound remediation plan that addresses every identified gap. Each item needs a named owner, a specific corrective action, and a target completion date. Vague commitments like “we will improve segregation of duties” do not satisfy auditors. A credible plan spells out the new access controls, who will implement them, and when.
Follow-up audits verify that corrective actions were actually implemented and are working consistently. Keep detailed records of every remediation step, because external auditors will review that documentation during the next engagement. The clearest measure of success is straightforward: the same findings should not appear in the next audit report.