Audit Preparation

Compliance Documentation Checklist

What auditors actually look for — across SOC 2, ISO, FDA, and EU regulations. A practical checklist you can use before your next audit.

Last verified: 2026-04-17 · References: AICPA SOC 2 TSC (2017, revised 2022) · ISO/IEC 27001:2022 · 21 CFR Part 11 · EU AI Act (Regulation 2024/1689)

Universal Audit Checklist

These items apply across every compliance framework. If you get these right, you’re ahead of most organizations. If you miss even one, an auditor will find it.

  1. Document control system in placeVersions tracked, obsolete documents removed or clearly marked superseded. Auditors check whether you can identify the current version of any controlled document instantly.
  2. All controlled documents reviewed and approved before useNo draft documents in production use. Every document that governs a process must have a documented review and formal approval before it takes effect.
  3. Change history with reasons for each changeNot just “updated Q1 2026” — auditors want to see what changed, why it changed, and who authorized the change. Version diffs, not version numbers.
  4. Clear ownership assigned to every document, term, and controlEvery controlled artifact needs a named owner responsible for its accuracy, review schedule, and lifecycle. “The compliance team owns it” is not specific enough.
  5. Periodic review dates set and trackedDocuments and definitions must be reviewed at defined intervals (typically 6–12 months). Auditors check the review date — if it’s overdue, that’s a finding.
  6. Terminology consistent across all documentsIf your risk policy says “incident” and your SOC 2 report says “security event” for the same concept, that’s an inconsistency auditors will flag. A controlled glossary helps prevent this drift by making a single approved definition the reference across documents.
  7. Audit trail showing who changed what, whenEvery modification to a controlled document must be traceable to a specific person, timestamp, and action. Reconstructing this from email threads after the fact does not count.
  8. Four-eyes principle enforced on approvalsThe person who creates or modifies a controlled document cannot be the same person who approves it. This must be enforced by the system, not by policy alone.
  9. Evidence package exportable on demandWhen an auditor asks “show me all changes to your glossary in the last 12 months,” you need to produce that report in minutes, not days. Export-ready evidence is non-negotiable.
  10. Training records showing staff know the terminologyIt’s not enough to define terms — you must demonstrate that the people using them understand them. Auditors check training logs, acknowledgment records, or quiz results.
The spreadsheet trap: If your “document control system” is a spreadsheet with a “Status” column, you fail items 1, 3, 7, 8, and 9 automatically. Spreadsheets have no enforced workflows, no real version control, and no audit trail. Auditors know this.

Framework-Specific Additions

Beyond the universal checklist, each framework adds specific documentation requirements. This table shows what extra items each framework demands:

Requirement SOC 2 ISO 27001 FDA 21 CFR EU AI Act
Formal ISMS / QMS scope document Required Required
Risk assessment tied to terminology CC3.2 6.1.2 Art. 9
Electronic signature on approvals Part 11
Statement of Applicability (SoA) 6.1.3(d)
Validated system (IQ/OQ/PQ) Required
Continuous monitoring evidence CC7.1 9.1 Art. 72
Third-party sub-processor documentation CC9.2 A.5.19 Supplier QA Art. 25
AI system risk classification docs Art. 6–7
Human oversight documentation Art. 14
Incident response & breach notification plan CC7.3 A.5.24–26 CAPA Art. 73
Common thread: Every framework requires that terms used in these documents are defined, consistent, and controlled. An ISO 27001 Statement of Applicability that uses undefined acronyms is an audit finding. An FDA CAPA report that references “deviation” without a controlled definition is a documentation gap.

The Terminology Gap Auditors Find

Terminology inconsistency is the #1 overlooked audit weakness. Not because organizations don’t have glossaries — but because those glossaries aren’t controlled.

Here’s the pattern auditors see repeatedly:

When an auditor asks “what does critical mean in your organization?” and three department leads give three different answers, that’s not a terminology problem — it’s a control failure.

Typical audit consequence: Auditors commonly issue findings under CC3.2 (risk assessment) when risk registers use terminology that is not defined consistently with the organization’s information security policy. Inconsistent definitions can trigger a second finding under CC2.2 (internal communication) from the same root cause — uncontrolled terminology producing multiple control failures.

The fix isn’t “write better definitions.” The fix is a controlled glossary that serves as the single source of truth, with approval workflows, review cycles, and audit trails. Read our compliance guide for a detailed breakdown of how specific control weaknesses map to terminology gaps.

Pre-Audit Workflow

Use this 5-step process in the weeks before any audit to ensure your documentation is audit-ready:

Step 1Run compliance scan across all Confluence spaces
Step 2Review and resolve all findings
Step 3Export glossary with full audit trail
Step 4Verify all terms reviewed within 6 months
Step 5Generate evidence package

Step 1: Run compliance scan

Use the compliance scanner to check all Confluence spaces for terminology inconsistencies, undefined terms in policies, and terms used without their controlled definition. The scan produces a findings report showing exactly where terminology gaps exist.

Step 2: Review and resolve findings

Each finding links to the specific page and term. Assign owners to resolve findings: add missing terms to the glossary, update inconsistent definitions, or link existing terms to pages where they appear without context.

Step 3: Export glossary with full audit trail

Export your complete glossary including all metadata: who created each term, who approved it, when it was last reviewed, every change with reasons. This is the evidence package auditors will review. Export to CSV for spreadsheet analysis. PDF export for formal evidence binders is on the 2026 roadmap; CSV export is live today.

Step 4: Verify all terms reviewed within 6 months

Filter your glossary by last review date. Any term not reviewed within your review cycle (typically 6 months for regulated industries) needs immediate review. Overdue reviews are one of the most common audit findings — and one of the easiest to prevent.

Step 5: Generate evidence package

Compile the complete audit package: glossary export, compliance scan results, resolution evidence, and review cycle compliance report. This package should answer every auditor question about your terminology management without requiring live system access.

Timeline: Start this process at least 4 weeks before a scheduled audit. Steps 1–2 typically take 1–2 weeks depending on the number of findings. Steps 3–5 can be completed in a single day with Compliance Glossary.

Be Audit-Ready, Not Audit-Scrambling

Most teams spend weeks preparing for audits because their documentation tools weren’t designed for compliance. Compliance Glossary builds audit readiness into your daily workflow — so there’s nothing to scramble for when the auditor arrives.

Evaluate in Confluence Read the Documentation

Related Resources

Compliance for Confluence — approved terms, page scanning, and audit evidence for regulated teams in Confluence

Compliance Guide — what auditors check and how we help, mapped to real regulatory standards

ALCOA+ Documentation Principles — the data integrity framework behind every audit trail requirement

Four-Eyes Principle — why dual approval is mandated across finance, pharma, and InfoSec

Terminology Management Guide — how to build and maintain a controlled vocabulary for compliance, QA, GRC, legal, security, and regulatory teams

Glossary App Comparison — how Compliance Glossary compares to Smart Terms, VECTORS, and native Confluence