Executive boardroom overlooking the Toronto skyline

Insights · Compliance Best Practices

Audit readiness as an operating posture, not a project

If preparing for an audit requires a project, the control environment is not the thing being tested — the ability to reconstruct it is.

01

The cost of the fire-drill model

In the fire-drill model, evidence is assembled retrospectively: teams reconstruct approvals from email, rebuild reconciliations from memory and negotiate over what a control was intended to achieve. The direct cost is weeks of senior time each cycle. The indirect cost is worse — reconstructed evidence invites doubt about whether the control operated at all, which converts a minor observation into a significant finding.

The alternative is not more documentation. It is designing controls so that performing them generates a durable, dated, attributable record as a by-product.

02

Design controls that leave a trail

  • Every control has a named owner, a defined frequency and a defined evidence artifact
  • Evidence is produced by the system of record, not recreated in a document afterwards
  • Records carry date, performer, population tested and outcome, including exceptions
  • Exceptions have a defined disposition path with sign-off and closure evidence
  • Evidence is stored in a known location with defined retention, not in personal mailboxes

03

Maintain one control inventory, not several

Most institutions accumulate parallel control lists: one for financial reporting, one for regulatory compliance, one for technology, one for privacy, one for third-party oversight. The same control is then tested repeatedly with different evidence formats and inconsistent conclusions.

A single inventory mapped to multiple obligations allows one test to satisfy several requirements. It also reveals genuine coverage gaps, which fragmented lists systematically hide.

04

Test continuously, at the frequency the risk deserves

Continuous does not mean constant. It means the testing calendar is driven by risk and control frequency, spread across the year, and performed by people independent of the control operator. High-risk controls may be sampled monthly; stable low-risk controls may be tested annually with automated monitoring in between.

05

Treat findings as a managed portfolio

  • One register for internal audit, second-line, regulatory and external audit findings
  • Root cause recorded in terms of process, capability or accountability — not 'human error'
  • Actions with owners, dates and interim risk mitigation while open
  • Ageing and extension requests reported to the audit or risk committee
  • Validation by an independent party before a finding is closed

06

Prepare the narrative, not just the file

Supervisors and auditors form a view about management competence as well as control operation. Being able to explain clearly what the institution knew, when it knew it, what it decided and why is frequently the difference between a finding characterized as isolated and one characterized as systemic.

What good looks like

  • A single control inventory mapped to every obligation it satisfies
  • Evidence generated as a by-product of control performance and retained systematically
  • A risk-based annual testing calendar performed independently of control owners
  • One consolidated findings register with root cause, ageing and independent closure
  • Quarterly committee reporting on control health, not just audit results
  • No reconstruction exercise required when a request arrives

This article reflects common assurance practice for Canadian regulated organizations. Specific audit and record-keeping obligations vary by regulator, sector and charter — confirm with counsel, internal audit and your principal regulator.

Frequently asked questions

What does audit readiness actually mean?

+

That the evidence demonstrating a control operated as designed is produced by the process itself, retained systematically, and retrievable on request without a special exercise. Readiness is a property of the operating model, not a period of preparation before fieldwork.

How is control evidence different from control documentation?

+

Documentation describes how a control is supposed to work. Evidence proves it operated on a specific date, over the population in scope, with the intended outcome — for example, a dated approval record, a reconciliation with sign-off, or a system log showing the exception was cleared.

How do the three lines of defence support readiness?

+

The first line performs controls and produces evidence, the second line sets standards and independently challenges results, and internal audit provides assurance over the whole design. Readiness deteriorates fastest where second-line testing is replaced by first-line self-attestation.

What is a reasonable evidence retention approach?

+

Retention should be defined by regulatory requirement, limitation periods and business need, documented in a records schedule, and enforced systematically. Indefinite retention creates privacy and disclosure exposure; ad hoc deletion destroys the evidence trail.

How should repeat findings be handled?

+

Treat a repeat finding as a governance issue rather than a control issue. Re-examine whether the original root cause was correctly identified, whether the remediation was resourced, and whether the accountable owner had the authority to fix it. Repeat findings escalate supervisory attention quickly.

Ready when you are

Bring clarity, control and confidence to your risk and compliance program.

Explore Our Services