Security Audit Programme and Reporting

Manish Garg
Manish Garg Associate of (ISC)² · RingSafe
Apr 26, 2026
4 min read
Read as

Last updated: April 29, 2026

Three lines of defence, audit calendar, continuous control monitoring, working papers, common-control framework across ISO/SOC2/PCI/RBI/SEBI, audit-fatigue management.

A Kolkata cooperative bank passed its annual ISO 27001:2022 surveillance audit four years in a row. Then a real incident — a phishing-led BEC fraud — exposed that change-management evidence had been fabricated for two of those four years by a junior IT-ops person under pressure to “make audit go away.” The certification was suspended; the bank’s reputation took years to recover. Audit isn’t a thing that happens once a year; it is a continuous control programme. This module covers running a security audit function that produces real assurance, not theatre.

Three lines of defence

The standard model:

  • 1st line — operating teams running controls (engineering, IT-ops, business)
  • 2nd line — security/risk function defining controls and monitoring 1st line
  • 3rd line — independent internal audit; reports to audit committee, not to CISO

The Kolkata bank had collapsed 2nd and 3rd lines into the same team. Self-attestation passed external audit because nobody independent verified. Real assurance requires actual independence.

The internal audit calendar

A 2026 mid-sized Indian enterprise audit calendar typically covers:

Audit Cadence Scope
VAPT (external) Annual + on major change Internet-facing surface
Internal VAPT Bi-annual Internal network, AD, sensitive apps
Configuration audit Quarterly Hardening drift, CIS benchmarks
Access review Quarterly User entitlements, SoD violations
Privileged-access audit Quarterly PAM coverage, session reviews
Patch compliance Monthly SLA adherence, exception tracking
Backup verification Monthly Tested restores, recovery proofs
Vendor assessment Annual + onboarding SOC 2 / ISO certs, contracts
BCP/DR drill Bi-annual Full failover, RTO/RPO measurement
Tabletop exercise Quarterly IR scenarios with leadership
SOC efficacy Quarterly Detection coverage, MTTD/MTTR
External certification audit Annual ISO 27001, PCI DSS, SOC 2

Continuous control monitoring

Annual audit cycles are insufficient. Modern audit programmes layer continuous monitoring:

  • Drift detection — IaC scans (Terraform Cloud, Bridgecrew, Wiz) flag config drift in cloud
  • Posture management — CSPM tools (Wiz, Prisma, Defender for Cloud) check 800+ controls daily
  • Compliance-as-code — tools like Drata, Vanta, Sprinto continuously verify SOC 2 / ISO controls and produce audit evidence
  • Log-based control attestation — log shows the control fired (not just that the policy exists)

The shift: from “last quarter we had this state” to “right now we have this state, and we’ll know if it changes within minutes.”

The audit working paper

Each audit produces working papers documenting:

  • Scope — what was tested, what wasn’t, why
  • Sample method — how items were selected (random? risk-weighted? stratified?)
  • Test procedure — exact steps performed
  • Evidence collected — screenshots, log extracts, configuration exports, with hash and timestamp
  • Findings — control failures, exceptions, observations
  • Risk rating — likelihood × impact of each finding
  • Recommendation — what to fix, target date, owner

Working papers should be reviewable by an external auditor and produce the same conclusions.

The Kolkata bank rebuild

After certification suspension:

  • Internal audit function spun out as separate team, reporting to audit committee chair
  • Drata deployed for continuous control monitoring; eliminated screenshot-based evidence collection for 70% of controls
  • Quarterly attestation cycle replaced annual; controls tested year-round
  • Sample size increased — instead of 5 changes/quarter, 25 random changes verified end-to-end
  • Whistle-blower channel made anonymous and managed by external counsel — broke the “make audit go away” pressure pattern
  • External CA-firm audit re-engaged; certification restored after 11 months

Standards Indian organisations get audited against

  • ISO 27001:2022 — most common; 93 controls; surveillance audit annually, recertification every 3 years
  • SOC 2 Type II — for B2B SaaS; 12-month observation period
  • PCI DSS 4.0 — payment card processing; quarterly ASV scans, annual on-site or self-assessment based on transaction volume
  • RBI Cyber Framework — annual cyber-resilience self-assessment + RBI-led inspection
  • SEBI CSCRF — annual cyber-resilience review for Q-RE / MII
  • UIDAI compliance — for AUA / KUA / Sub-AUA, annual third-party audit
  • NPCI — for UPI / IMPS / NACH participants
  • ISO 22301 — business continuity
  • HIPAA (for organisations serving US healthcare) — covered by Indian IT/BPO providers

Audit fatigue and how to manage it

A regulated Indian financial institution can be audited 12-15 times per year. Mitigations:

  • Common control framework — map ISO, SOC 2, PCI, RBI requirements to a single set of underlying controls; one test serves multiple audits
  • Evidence repository — single source of truth for control evidence (Drata, Vanta, ServiceNow GRC, Archer)
  • Audit calendar coordination — sequence audits to share findings; one ISMS audit informs the next
  • Auditor education — give external auditors a guided tour of your tooling so they don’t ask for re-extracted reports

Common mistakes

  • Audit theatre — controls “documented” but never operationally tested
  • Sample size of 1 — auditor sees one good change ticket; assumes process works
  • Manager-attestation without verification — tick the box, no test
  • Findings closed without remediation — “accepted risk” abused as a workaround
  • External auditors as adversaries — withhold information; auditors miss context; report is wrong; nobody learns
  • Audit findings as KPI for blame rather than systemic improvement signal

Try this in your environment

  1. Pull last year’s external audit report. How many findings? How many remediated? How many recurring from the prior year?
  2. Pick one control listed as “implemented.” Pull 5 random samples. Does the evidence support the claim?
  3. Map your top 10 controls to: which audit standards each satisfies. The overlap is your common-control opportunity.
  4. Run a tabletop with leadership: “external auditor asks for evidence of X by EOD.” Time how long evidence collection takes.
  5. Evaluate continuous-monitoring platforms (Drata, Vanta, Sprinto) for your scale.

A real audit programme produces unwelcome findings — that’s how you know it’s working. The Kolkata bank’s certification looked great until it cost them years. Better to find your gaps in audit than in incident.

🧠
Check your understanding

Module Quiz · 6 questions

Pass with 80%+ to mark this module complete. Unlimited retries. Each question shows an explanation.

DPDP Act in your stack?

Get a DPDP gap assessment

Free 30-minute call. We map your data flows against DPDP §8 obligations and tell you exactly which gaps to fix first. Auditor-defensible output.

Book DPDP scoping call Replies in 4 working hrs · India-only · Senior consultants