A compliance audit follows the same six steps whether you’re working through SOX, a SOC engagement, or an internal policy review. The depth changes and the final deliverable changes, but the path from scope to monitoring holds. 

This article walks through that process step by step: the six phases, who owns each one, and where engagements tend to slow down.

Who Owns Each Step of the Compliance Audit Process

A compliance audit pulls in four groups, and the handoffs between them are where momentum lives. Here’s the rough map of stakeholders that are involved in the process:

  • Define scope: controller or accounting leadership
  • Assess risk and map controls: internal audit, often with external auditor input
  • Gather evidence: accounting and finance team
  • Test controls and transactions: external auditor, or internal audit for internal engagements
  • Document findings and remediate: auditor classifies, control owner fixes
  • Report and monitor: auditor issues the deliverable, leadership receives it, control owners follow through

Ownership shifts depending on whether the audit is internal or external. Our pillar covers that internal-versus-external split in more detail. The short version: in an external audit, the firm runs the testing and the accounting team supports. In an internal audit, your own audit function does both.

The Compliance Audit Process, Step by Step

1. Define the audit scope and objectives

The controller or accounting leadership owns this step, working with whoever asked for the audit. That might be a regulator, a customer, or the board.

Start by naming the regulations, standards, or frameworks that apply. Confirm the audit period and the materiality threshold before anything else moves. Then confirm the deliverable. An audit opinion, a certification, and an internal report each call for a different level of rigor, and that choice shapes every step downstream.

One practical move can make a real difference here: assign a single audit liaison. When auditors have to chase answers through three or four people, the engagement slows to the speed of the least available person. One point of contact keeps requests and responses moving.

2. Assess risk and map controls

Internal audit or accounting leadership owns risk assessment, often with input from external auditors during planning.

The goal is to find the areas carrying the most risk. Revenue recognition, lease accounting, payroll, and related-party transactions tend to top the list. Map your existing controls to the relevant framework, then flag what’s changed since the last audit period. New systems, recent M&A activity, and new entities all introduce risk the previous audit never touched.

This step earns its keep by directing where testing effort lands in Step 4. Skip it, and the team spreads fieldwork evenly across areas that don’t deserve equal attention. Done well, risk mapping prevents wasted hours later.

3. Gather documentation and evidence

The accounting and finance team owns this step, working against requests from the audit liaison.

The backbone here is the PBC list, short for provided-by-client. It names the specific documents, reconciliations, and approvals auditors will ask for: account reconciliations, approval logs, system access reports, policy documents, and prior-period workpapers. 

Then centralize all your documents in one place auditors can reach directly, with clear version control so they review the final, approved version rather than a draft from three weeks ago.

This is the slowest step in most audits, and the reason is almost always the same. When documentation lives across spreadsheets, email threads, and individual inboxes, gathering it becomes a scavenger hunt under deadline.

4. Test controls and transactions (fieldwork)

The external auditor owns fieldwork for external audits. For internal audits, the internal audit team runs it. Either way, the accounting team supports.

Fieldwork runs on a few methods. 

Walkthroughs confirm that controls operate the way the documentation says they do. Operating effectiveness gets tested through sampling, reperformance, or inspection. Sampling pulls a subset of transactions to test, reperformance redoes a control to confirm it works, and inspection examines the underlying documents. Substantive testing goes straight at account balances and transactions, used where relying on controls alone won’t cut it.

Every test needs a documented sample, a method, and a conclusion. That documentation is what makes the audit defensible when an inspection or peer review comes back to it later.

5. Document findings and build a remediation plan

The auditor documents and classifies findings. The accounting or control owner remediates them.

Findings get sorted by severity to prioritize next steps. A control deficiency is a gap that, on its own, won’t lead to a material misstatement. A significant deficiency is serious enough to warrant attention from those charged with governance. A material weakness means a reasonable chance exists that a material misstatement won’t be caught.

Every finding should have an owner and a target date to ensure it gets actioned. It’s also worth telling apart a one-time error from a sign of a broader control gap: one needs a correction, the other needs a redesign.

6. Report results and monitor going forward

The auditor issues the deliverable. The audit committee or leadership receives it. Control owners handle the follow-through.

The final deliverable goes out: an audit opinion, a certification, or a management letter. From there, remediation tracking has to run year-round. Findings that get logged and then forgotten until the next cycle come back as repeat findings, and a repeat finding reads worse to an auditor than a first-time one. It signals a control environment that doesn’t learn.

Findings also feed back into the risk assessment in Step 2 for the next cycle. That’s what closes the loop and turns a one-time audit into an actual process.

How Long Each Step Typically Takes

Audit length varies too much for a single number to mean anything, so think in rough ranges per step instead. 

Scoping and planning often run one to two weeks. Risk assessment and control mapping take another one to three. Evidence gathering stretches anywhere from two to six weeks, depending almost entirely on how centralized the documentation already is. Fieldwork is usually the longest stretch, running three to eight weeks on a mid-sized engagement. Findings and reporting add two to four more.

Treat these as ranges, not guarantees. Several variables stretch any given step: the number of frameworks in scope, the volume of prior-year findings, whether documentation sits in one system or scattered across many, and how much multi-entity complexity the audit has to account for.

Where the Process Breaks Down

The same failure points show up again and again:

  • Scope defined too late. The team is still confirming what applies while evidence requests are already landing.
  • No single liaison. Auditors get different answers from different people and lose time reconciling them.
  • Evidence trickling in. When documents come one at a time instead of against a PBC list built up front, fieldwork stretches.
  • Findings without an owner or a date. Remediation never actually starts.
  • Treating the six steps as an annual event. A process meant to run continuously becomes a once-a-year scramble.

Notice how many of these trace back to Step 1. Late scope and missing liaisons set the tone for everything after.

How Trullion Supports the Compliance Audit Process

The six steps happen with or without software. What changes is how long each one takes and how much manual reconstruction work piles up under deadline.

Trullion’s Platform accelerates the path from data ingestion to validated outputs, which lands squarely on Steps 3 and 4. 

Trulli, the platform’s AI agent, ties outputs back to source documentation, so evidence gathered in Step 3 stays traceable through testing and reporting in Steps 4 through 6. 

Knowledge Room keeps standards and firm methodology structured and queryable, which supports the control-mapping work in Step 2. 

And Substantive Testing Automation, paired with Data Match, cuts the manual reconciliation work that drives so many findings in Step 4.

None of this replaces the auditor’s judgment. It removes the manual overhead around it.

The strongest compliance audit process is the one that runs continuously; scope is clear, evidence stays centralized, and findings carry owners from the day they’re logged.

If you want to see how a connected platform supports that kind of process from source data through reporting, take a look at how Trullion approaches it.

FAQs

What are the steps in a compliance audit?

A compliance audit moves through six steps: define the scope and objectives, assess risk and map controls, gather documentation and evidence, test controls and transactions, document findings and build a remediation plan, then report results and monitor going forward. The same skeleton holds across frameworks like SOX, SOC, GAAP, and IFRS, though the depth and the final deliverable change.

Who is responsible for a compliance audit?

Responsibility is shared. Accounting leadership usually defines scope, internal audit assesses risk, the accounting team gathers evidence, and the auditor (external or internal) runs testing and documents findings. Leadership or the audit committee receives the final report. In an external audit, the firm runs testing. In an internal audit, your own audit function handles it.

What is a PBC list in an audit?

PBC stands for provided-by-client. It’s the list of specific documents, reconciliations, and approvals the auditor requests from the accounting team, things like account reconciliations, approval logs, system access reports, and prior-period workpapers. Building it early and gathering against it is one of the most reliable ways to keep fieldwork on schedule.

What’s the difference between a control deficiency and a material weakness?

A control deficiency is a gap that won’t, on its own, lead to a material misstatement. A material weakness means a reasonable chance exists that a material misstatement won’t be caught. A significant deficiency sits between the two, serious enough to warrant attention from those charged with governance. The classification drives how urgently a finding gets remediated.

Testing and fieldwork eat up more time than any other part of the compliance audit process. See what changes when AI handles evidence extraction and reconciliation instead of your team.

Read Now: Fieldwork Automation