← Back to blog

Audit readiness assessment: checklist and go/no-go guide

August 6, 2026
Audit readiness assessment: checklist and go/no-go guide

An audit readiness assessment is a structured pre-audit review that identifies control and evidence gaps before a formal auditor sets foot in your organisation. Start today by mapping every in-scope control to a required evidence item and a named owner. That single action surfaces more gaps in a short time than most teams find in extended periods of unstructured preparation.

Three outcomes the assessment delivers:

  • A complete evidence gap register, showing which controls have no supporting documentation
  • Named owners for every evidence item, so chasing stops being a management task
  • A prioritised remediation plan with deadlines, ready to present to your audit committee

Three things you can do before the end of today: pull your most recent control framework or risk register and list every control; beside each control, note what documentary evidence currently exists; and appoint one named individual (not a team) responsible for each gap. That is your starting point.


Table of Contents

What is an audit readiness assessment, and how does it differ from an audit?

A readiness assessment is a diagnostic exercise. Its purpose is to evaluate whether your organisation's controls, processes, and evidence are in a state that will withstand scrutiny from an external or internal auditor. It is preparatory and remedial. An audit, by contrast, is an independent opinion-forming exercise: the auditor tests and concludes. The readiness assessment is what you run on yourself first, so the auditor finds fewer surprises.

Common types of readiness assessment include:

  • Financial statement readiness: reconciliations, trial balance, year-end journals, and supporting schedules
  • Regulatory readiness: compliance with sector-specific obligations (FCA, Ofwat, Environment Agency, HMRC)
  • Certification readiness: ISO 27001, ISO 9001, SOC 2, or PCI DSS control evidence and policy documentation
  • IT and security readiness: access controls, patch records, incident logs, and vendor assurance documentation

The audit readiness guidance from Linford & Co summarises the distinction well: a readiness assessment helps teams evaluate controls, fix gaps, and prepare evidence to improve audit outcomes, whereas the audit itself produces an independent opinion. One is internal and corrective; the other is external and conclusive.


Team discussing audit readiness documents

Why run an audit readiness assessment in a UK organisation?

Infographic outlining audit readiness assessment process

Preparation shortens fieldwork. When auditors arrive to find a well-organised evidence package, they spend less time chasing documents and more time testing. That translates directly into cost savings and smoother audit completion. Audit readiness guidance from the WA Office of the Auditor General confirms that better preparation leads to timelier audits and reduced burden on entities, particularly those with limited internal capacity.

The concrete benefits for UK organisations:

  • Reduced audit fees: less auditor time spent on document retrieval means fewer billable hours
  • Fewer post-audit queries: a complete, self-explanatory evidence pack cuts the number of follow-up requests
  • Improved control maturity: the gap analysis process itself strengthens controls, not just the evidence trail
  • Regulatory confidence: demonstrating a structured approach satisfies FCA, Ofwat, and other UK regulators that governance is active, not reactive
  • Customer and contractual trust: many UK infrastructure and utility contracts now require evidence of audit readiness as a condition of procurement or renewal

UK-specific drivers add urgency. The Companies Act 2006 places statutory audit obligations on qualifying entities, and UK regulators have increased their scrutiny of governance frameworks in regulated sectors. For organisations in utilities, water, energy, and financial services, the cost of an unplanned audit finding is rarely just the fee: it can trigger regulatory investigation, reputational damage, or contract termination.


When should you carry out a readiness assessment?

Start formal preparation well in advance before expected fieldwork. Moxo's audit preparation guidance recommends beginning the process 8–12 weeks before fieldwork, following a phased approach that includes scoping (weeks 8–12), active evidence collection (weeks 4–8), quality review (weeks 2–4), and pre-audit verification (week 1). Starting with only two or three weeks to go forces reactive scrambling and increases both findings and fees.

Several triggers should prompt an immediate readiness assessment regardless of the calendar:

  • A new regulator request or enforcement notice
  • A material change to systems, processes, or financial reporting
  • Your organisation's first formal audit
  • Significant personnel change in finance, IT, or compliance leadership
  • A merger, acquisition, or restructuring
  • Approaching certification renewal cycles for ISO 27001, ISO 9001, or SOC 2

On cadence: a full formal readiness assessment once a year (or before each major audit) is the minimum. Leading assurance practitioners go further, treating readiness as a continuous governance function with lightweight monthly control validations sitting alongside the annual deep-dive. The Head of Assurance or Chief Risk Officer should own the cadence decision, with the audit committee receiving a readiness status update at each quarterly meeting.

For first audits or resource-constrained teams, bringing in specialist support early can relieve internal pressure and reduce disruption, particularly where documentation is sparse or controls have never been formally tested.


Step-by-step audit readiness checklist: practical preparation work

The checklist below follows a multi-week timeline. Each phase builds on the last; skipping a phase does not save time, it just moves the problem later.

The five phases

  1. Scoping (weeks 8–12): Define the audit boundary. Which entities, systems, processes, and periods are in scope? Align with your auditor on the framework (e.g., FRS 102, ISO 27001 Annex A, PCI DSS v4.0). Produce a written scope statement signed off by the audit sponsor.
  2. Framework alignment and control mapping (weeks 6–8): Map every in-scope control to its required evidence item. Use a risk control matrix to record the control objective, the test approach, and the evidence type. Assign a named owner to each row.
  3. Evidence gathering (weeks 4–6): Owners collect and upload evidence. Apply consistent naming conventions (see folder structure guidance below). Validate completeness at upload, not at review.
  4. Stakeholder coordination and gap analysis (weeks 2–4): Run a structured gap analysis. Record each gap, assign a remediation owner, set deadlines, and track closure. Escalate unresolved critical gaps to the audit sponsor promptly.
  5. Pre-audit quality review (week 1): A second reviewer (not the evidence owner) checks that every item is present, legible, and self-explanatory. Confirm the PBC list is complete and hand it to the auditor.

Evidence items auditors commonly request

Evidence categoryTypical itemsMinimum acceptable format
Financial statementsTrial balance, P&L, balance sheet, cash flowSigned, dated, reconciled to GL
ReconciliationsBank, intercompany, balance sheet accountsSigned by preparer and reviewer
Internal controlsControl descriptions, test results, sign-off logsWritten procedure + evidence of operation
Contracts and agreementsKey supplier, customer, and financing contractsExecuted copy with key dates highlighted
Payroll and HRPayroll reports, starters/leavers, authorisation logsPeriod-end reports, authorised by HR lead
IT and accessUser access lists, change logs, patch recordsSystem-generated, dated within audit period
Policies and proceduresInformation security policy, financial controls policyVersion-controlled, approved by board or exec
Sector-specificQA records, CAPA logs, supplier audits (life sciences)As required by applicable standard

For sector-specific evidence, Qualio's life sciences readiness checklist illustrates how regulated product organisations tailor their PBC lists to include change control records, supplier management evidence, and CAPA documentation.

The HelpfulCFO audit readiness checklist makes a point worth taking seriously: prepare documentation as if a complete stranger will review it. Signed reconciliations, supporting schedules, and a one-line written explanation for any large variance save hours of auditor queries.

Roles and responsibilities

Every evidence item needs one named individual as owner, not a team or a department. The table below sets out the typical ownership model.

RoleResponsibility
Audit sponsor (CFO / Head of Assurance)Scope sign-off, go/no-go decision, escalation authority
Control owners (process leads)Evidence collection, gap remediation, deadline adherence
IT leadSystem-generated evidence, access control records
Finance leadReconciliations, financial statements, journal documentation
Compliance leadPolicy documentation, regulatory correspondence, certification evidence
Readiness coordinatorTracks completeness, chases owners, manages the evidence folder

Gap analysis and folder structure

Record every gap in a simple log: control reference, gap description, remediation action, owner, deadline, and status (open/closed/escalated). Review the log weekly during the evidence-gathering phase.

For the folder structure, use a top-level folder named [Entity]_[Audit type]_[Period]_Evidence, with subfolders mirroring the evidence categories in the table above. File names follow the convention [Category]_[Description]_[Date]_v[Version]. A new reviewer should be able to navigate the package without any verbal briefing.


Common pitfalls and what not to do during readiness preparation

Leaving everything to the last three weeks is the single most common error. Evidence owners are busy. Chasing them in the final fortnight produces incomplete, unreviewed documents and forces the readiness coordinator into a firefighting role. The mitigation is structural: set evidence submission deadlines four weeks before fieldwork, not one.

Unclear ownership compounds the time problem. When a control is owned by "the finance team" rather than a named individual, nobody feels accountable. Every gap gets discussed in meetings and resolved by nobody. Name one person per control, confirm it in writing, and make it visible on the tracking log.

Undocumented reconciliations are a persistent source of audit queries. A reconciliation that exists only in someone's head, or as an unlabelled spreadsheet with no sign-off, fails the auditor's test of completeness and authorisation. Every reconciliation needs a preparer signature, a reviewer signature, and a date.

Assuming auditors know your internal context is a subtler problem. Auditors rotate. The person who reviewed your accounts last year may not be the same person this year. A variance explanation that made sense to last year's auditor means nothing without the written context. One sentence explaining why a balance moved is worth more than a follow-up meeting.

Centric Consulting's audit preparation checklist reinforces this: auditors want GL transactions, reconciliations, contracts, and internal control evidence packaged with an agreed timeline. The packaging is as important as the content.

Pro Tip: Validate evidence at the point of submission, not at the quality review stage. Ask owners to confirm that each document is signed, dated, and covers the correct period before they mark it complete. Catching a missing signature four weeks before fieldwork takes five minutes. Catching it the day before takes a crisis.


What does a sample audit readiness assessment agenda look like?

A readiness review meeting typically runs a couple of hours. The agenda below is reusable across financial, regulatory, and certification audits.

TimeTopicOwnerExpected output
Scope confirmation and audit objectivesAudit sponsorAgreed scope statement
Control-by-control evidence walkReadiness coordinatorUpdated gap register
Gap analysis review and prioritisationControl ownersPrioritised remediation list
Remediation plan: owners, deadlines, escalationAudit sponsorSigned remediation log
Governance decisions: go/no-go criteriaCFO / Head of AssuranceDocumented decision
PBC list finalisation and auditor communicationReadiness coordinatorFinal PBC list issued

Questions auditors will ask during fieldwork

Preparing answers to these in advance removes the most common sources of delay:

  • "Can you walk me through how this reconciliation was prepared and who reviewed it?"
  • "What is the authorisation process for journal entries above a certain threshold?"
  • "How do you evidence that this control operated throughout the period, not just at year-end?"
  • "Who has access to this system, and how is that access reviewed?"
  • "What changed in this process during the year, and where is that change documented?"

Deliverables from the readiness assessment

The assessment produces four documents: a PBC (Prepared by Client) list confirming every evidence item is ready; a readiness report summarising control status, gaps, and remediation progress; a remediation log with owners and deadlines; and written owner commitments confirming accountability. For guidance on structuring the readiness report itself, the audit report format guide covers committee-ready layouts for UK regulated organisations.


How do you score readiness and make a go/no-go decision?

A RAG (Red, Amber, Green) scoring model is the most practical approach for most UK organisations. Assign a RAG status to each control based on evidence completeness and control effectiveness.

Close-up of hands reviewing audit RAG status

RAG statusDefinitionThreshold rule
GreenEvidence complete, control operating effectivelyNo action required
AmberEvidence partially complete or control has minor gapsRemediation plan required; 30-day check
RedEvidence absent or control failingImmediate escalation; no-go trigger

Weighted scoring approach

For organisations that need a more granular score, weight each control by its criticality (high, medium, low) and calculate a weighted completion percentage. A simple approach:

  1. Assign each control a weight: critical = 3, significant = 2, standard = 1
  2. Score each control: complete = 1, partial = 0.5, absent = 0
  3. Calculate: (sum of weighted scores) / (sum of maximum weights) × 100

Go/no-go decision rules

  • Go: no red items; amber items have a documented remediation plan with deadlines within the audit window
  • Conditional go: amber items represent fewer than 15% of critical controls; remediation is underway with a named owner and a confirmed completion date before fieldwork
  • No-go: any red item in a critical control; or amber items represent more than 15% of critical controls without a credible remediation plan

The go/no-go decision requires sign-off from the CFO or Head of Assurance, with the audit committee notified of any conditional or no-go outcome. Document the decision, the rationale, and the remediation commitments in writing. A verbal agreement is not a governance record.


Turning readiness into a continuous governance function

A one-off readiness sprint before each audit is better than nothing, but it is not a governance function. The organisations that consistently pass audits with minimal findings treat readiness as a year-round activity: controls are validated on a rolling schedule, evidence is collected as it is created, and gaps are remediated as they arise rather than in a panic six weeks before fieldwork.

The continuous model has five stages: plan (define the control testing schedule for the year), test (validate controls against evidence on a rolling basis), remediate (fix gaps as they surface), report (produce a readiness status dashboard for governance), and escalate (flag critical gaps to the audit sponsor immediately, not at the next quarterly meeting). Real-time compliance monitoring tools make this cycle practical by automating evidence collection triggers and surfacing control failures as they happen rather than at year-end.

Metrics worth tracking in a continuous model:

  • Control pass rate: percentage of controls with complete, current evidence
  • Open remediation ageing: number of open gaps older than 30 days
  • Evidence completeness by control: percentage of required evidence items present for each control
  • Average time to close: mean number of days from gap identification to remediation sign-off

Pro Tip: Embed the continuous readiness cycle into your existing governance calendar. Attach a 15-minute control validation update to your monthly risk committee agenda. It takes less time than a standing agenda item on "any other business" and produces a running evidence trail that makes the annual readiness sprint a formality rather than a crisis.

For AI-assisted approaches to continuous evidence validation and automated executive summaries, the AI in internal audit guide covers practical applications for UK assurance teams.


Key takeaways

A structured audit readiness assessment, run 8–12 weeks before fieldwork with named owners and a RAG-scored gap register, is the single most effective way to reduce audit findings, shorten fieldwork, and lower fees.

PointDetails
Start well before fieldworkPhased preparation prevents last-minute scrambling and reduces audit findings and fees.
Name one owner per controlTeam ownership produces no accountability; named individuals close gaps faster.
Use RAG scoring for go/no-goRed items in critical controls trigger a no-go; amber items require a documented remediation plan.
Continuous readiness beats annual sprintsRolling control validation and real-time dashboards remove the year-end scramble entirely.
Intelligentassessments digitises the processThe platform replaces spreadsheets with structured frameworks, evidence management, and automated RAG roll-ups for repeatable readiness.

The part most readiness guides get wrong

Most audit readiness guides treat the assessment as a document collection exercise. Gather the files, tick the boxes, hand them over. That framing misses the point entirely.

The real value of a readiness assessment is not the evidence pack. It is the organisational behaviour change that happens when you assign named owners, set deadlines, and make gaps visible. The evidence pack is a by-product. The governance discipline is the product.

The organisations that consistently perform well in audits are not the ones with the best filing systems. They are the ones where control ownership is clear, where gaps are surfaced and fixed as a matter of routine, and where the audit is treated as a confirmation of what leadership already knows, not a discovery exercise. That requires a continuous governance function, not a six-week sprint.

There is also a subtler point about documentation quality that most checklists understate. A complete evidence pack full of unsigned reconciliations, undated screenshots, and spreadsheets with no version history is not a good evidence pack. It is a liability. Auditors will query every item that lacks a clear preparer, reviewer, and date. Each query costs time and money. The HelpfulCFO checklist makes the point plainly: one sentence explaining a large variance often saves hours of fieldwork. That is not an exaggeration.

The organisations that get this right have usually learned it the hard way, after an audit where the evidence existed but was not usable. The ones that have not learned it yet are still treating readiness as a filing task.


Intelligentassessments makes audit readiness repeatable, not reactive

Spreadsheets and shared drives are how most UK organisations run their readiness process. They work until they do not: version conflicts, missing sign-offs, no audit trail, and a readiness coordinator spending more time chasing emails than reviewing evidence.

Intelligentassessments

Intelligentassessments replaces that process with a structured assurance platform built for regulated UK organisations. Assign named owners to every control, automate evidence submission reminders, and validate completeness at upload rather than at review. The platform's weighted RAG scoring rolls up automatically across your control framework, so the go/no-go decision is based on live data, not a manually updated spreadsheet. AI-generated executive summaries turn your gap register into a committee-ready readiness report in minutes, and instant PDF reporting means your audit package is always one click from being shareable.

For teams preparing for ISO 27001, SOC 2, regulatory, or financial statement audits, Intelligentassessments turns a six-week scramble into a continuous governance function. Book a demo to see how the platform handles evidence management, RAG roll-ups, and readiness reporting for organisations like yours.


Useful sources and further reading

  • Audit Readiness Tool, Office of the Auditor General (WA) — provides PBC listing templates, questionnaires, and guidance on building an entity financial audit file; directly applicable to public sector and regulated organisations building their evidence package.
  • Audit Readiness Checklist, HelpfulCFO — a practical, downloadable checklist covering reconciliations, financial statements, and documentation standards; useful as a starting template for finance teams.
  • Audit Preparation Checklist, Moxo — covers the 8–12 week phased timeline, ownership assignment, and automation patterns for evidence collection; good for readiness coordinators planning the workflow.
  • External Accounting Audit Readiness Checklist, Centric Consulting — groups evidence items by category (GL, reconciliations, contracts, internal controls) with a practical PBC list format.
  • Audit Readiness Tips, Linford & Co — high-level best practice guide covering common mistakes and preparation strategies for certification and compliance audits.
  • Audit Readiness Checklist, Qualio — sector-specific checklist for life sciences and regulated product organisations; covers QA, CAPA, change control, and supplier management evidence requirements.
  • Healthcare data storage audit guide, Island Edge Tech — covers data storage audit expectations for healthcare organisations, including evidence requirements for regulated data environments.
  • Companies Act 2006, legislation.gov.uk — the primary statutory reference for UK audit obligations; confirms which entities are subject to statutory audit requirements.