What auditors actually look for — across SOC 2, ISO, FDA, and EU regulations. A practical checklist you can use before your next audit.
Last verified: 2026-04-17 · References: AICPA SOC 2 TSC (2017, revised 2022) · ISO/IEC 27001:2022 · 21 CFR Part 11 · EU AI Act (Regulation 2024/1689)
These items apply across every compliance framework. If you get these right, you’re ahead of most organizations. If you miss even one, an auditor will find it.
Beyond the universal checklist, each framework adds specific documentation requirements. This table shows what extra items each framework demands:
| Requirement | SOC 2 | ISO 27001 | FDA 21 CFR | EU AI Act |
|---|---|---|---|---|
| Formal ISMS / QMS scope document | — | Required | Required | — |
| Risk assessment tied to terminology | CC3.2 | 6.1.2 | — | Art. 9 |
| Electronic signature on approvals | — | — | Part 11 | — |
| Statement of Applicability (SoA) | — | 6.1.3(d) | — | — |
| Validated system (IQ/OQ/PQ) | — | — | Required | — |
| Continuous monitoring evidence | CC7.1 | 9.1 | — | Art. 72 |
| Third-party sub-processor documentation | CC9.2 | A.5.19 | Supplier QA | Art. 25 |
| AI system risk classification docs | — | — | — | Art. 6–7 |
| Human oversight documentation | — | — | — | Art. 14 |
| Incident response & breach notification plan | CC7.3 | A.5.24–26 | CAPA | Art. 73 |
Terminology inconsistency is the #1 overlooked audit weakness. Not because organizations don’t have glossaries — but because those glossaries aren’t controlled.
Here’s the pattern auditors see repeatedly:
When an auditor asks “what does critical mean in your organization?” and three department leads give three different answers, that’s not a terminology problem — it’s a control failure.
The fix isn’t “write better definitions.” The fix is a controlled glossary that serves as the single source of truth, with approval workflows, review cycles, and audit trails. Read our compliance guide for a detailed breakdown of how specific control weaknesses map to terminology gaps.
Use this 5-step process in the weeks before any audit to ensure your documentation is audit-ready:
Use the compliance scanner to check all Confluence spaces for terminology inconsistencies, undefined terms in policies, and terms used without their controlled definition. The scan produces a findings report showing exactly where terminology gaps exist.
Each finding links to the specific page and term. Assign owners to resolve findings: add missing terms to the glossary, update inconsistent definitions, or link existing terms to pages where they appear without context.
Export your complete glossary including all metadata: who created each term, who approved it, when it was last reviewed, every change with reasons. This is the evidence package auditors will review. Export to CSV for spreadsheet analysis. PDF export for formal evidence binders is on the 2026 roadmap; CSV export is live today.
Filter your glossary by last review date. Any term not reviewed within your review cycle (typically 6 months for regulated industries) needs immediate review. Overdue reviews are one of the most common audit findings — and one of the easiest to prevent.
Compile the complete audit package: glossary export, compliance scan results, resolution evidence, and review cycle compliance report. This package should answer every auditor question about your terminology management without requiring live system access.
Most teams spend weeks preparing for audits because their documentation tools weren’t designed for compliance. Compliance Glossary builds audit readiness into your daily workflow — so there’s nothing to scramble for when the auditor arrives.
Evaluate in Confluence Read the DocumentationCompliance for Confluence — approved terms, page scanning, and audit evidence for regulated teams in Confluence
Compliance Guide — what auditors check and how we help, mapped to real regulatory standards
ALCOA+ Documentation Principles — the data integrity framework behind every audit trail requirement
Four-Eyes Principle — why dual approval is mandated across finance, pharma, and InfoSec
Terminology Management Guide — how to build and maintain a controlled vocabulary for compliance, QA, GRC, legal, security, and regulatory teams
Glossary App Comparison — how Compliance Glossary compares to Smart Terms, VECTORS, and native Confluence