Step 1: Confirm what you're actually being reviewed against

Before touching anything technical, get precise about what "audit" means in your specific case — a partner's security questionnaire, an internal governance requirement, an investor's due diligence request, or preparation for a genuine statutory audit are four different things with four different bars to clear. Ask whoever is requesting this what standard or framework, if any, it's being measured against. If the answer is vague ("just want to know we're secure"), that's useful information too — it means you're likely looking at an advisory-style review, not a formal audit.

Step 2: Gather documentation before you fix anything

This is the step most organisations skip, and it's usually the fastest win available. A reviewer — internal or external — spends a disproportionate amount of time simply establishing what controls exist, because that information isn't written down anywhere. Before any technical remediation, assemble:

  • Your current security policy documents, even if they're outdated — outdated-but-existing is still more useful than nothing
  • A list of who has administrative access to your core systems, and why
  • Records of your last vulnerability scan or penetration test, if any exist
  • Your incident response plan, if one exists — and honestly, if it doesn't
  • A list of third-party vendors and integrations with access to your systems or data

Organisations that do this first consistently move faster through a review than organisations that start with technical fixes, because half the review process is simply establishing current state.

Step 3: Fix the gaps you already know about

Every organisation has a mental list of "things we know we should fix" that never gets prioritised until an external deadline forces the issue. Multi-factor authentication not enforced everywhere it should be. A departed employee's account that was never disabled. A shared admin password nobody's rotated. These are almost always faster and cheaper to fix than anything a formal review would find on its own, and fixing them before the review reduces both the findings count and the review's duration.

Step 4: Understand the difference between advisory review and statutory audit

This distinction matters more than most preparation guides admit. An advisory-style review — the kind RETIS and similar providers deliver — evaluates your posture against good practice and gives you a prioritised roadmap. A statutory audit is a formal, regulated process with legal standing, conducted by a specifically licensed provider. Preparing for one doesn't automatically prepare you for the other, though the underlying work (documentation, access hygiene, incident readiness) overlaps significantly. If you're not sure which one you're actually facing, that's worth clarifying before you spend a week preparing for the wrong thing.

Common mistakes organisations make preparing for a review

  • Focusing entirely on technical controls while governance and documentation — often the fastest wins — go untouched
  • Assuming a previous penetration test or vulnerability scan covers governance and third-party risk too, when it was scoped narrowly to technical systems only
  • Waiting until days before the review to start, rather than treating preparation as a 2-4 week process
  • Not looping in leadership early — a review that surfaces governance gaps needs leadership buy-in to fix, and that takes longer to arrange under time pressure

A practical preparation checklist

  • Do you know precisely what standard or expectation this review is being measured against?
  • Is your security documentation gathered in one place, even if imperfect?
  • Have you fixed the access-control issues you already knew about before the review starts?
  • Does leadership know a review is happening and what might be asked of them?
  • Have you allowed at least 2-4 weeks of preparation time, not a few days?

Frequently asked questions