GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

GOV-011 Compliance Monitoring and Internal Audit

Tier 2+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

An audit plan defines the information security policies, controls and requirements checked in each cycle and the interval between cycles. An audit or compliance check report exists for each cycle the plan defines, stating its scope, the work performed and each finding with a severity and a named owner. Every report carries a management response. Findings are tracked in a register to a recorded closure date.

Rationale

A control that is never tested provides assurance only that somebody wrote it down. Internal verification finds the gap before an external audit, a regulator or an incident does. GOV-012 is the monitoring that runs between these cycles and GOV-020 is the independent assessment; the distinction that matters to an assessor is who performed the work and how far they sit from the function under review.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredrole duty

RTS 2024/1773 Art. 6(3), point (c), makes the provider's internal audit report one of the five assurance elements a financial entity may rely on. Art. 8(3), point (f), requires any report relied on to test the operational effectiveness of key controls rather than their design.

HIPAA Business Associate (US)stablerequiredrole duty

164.308(a)(8) makes a periodic technical and nontechnical evaluation against the requirements of the subpart a standard in its own right. The audit plan GOV-011 requires has to name Subpart C as a checked requirement set, not only the organisation's own policies.

NIS2 Cloud Provider (EU)stablerequiredrole duty

Annex point 2.2.2 asks for something a cyclical audit does not provide: a standing compliance reporting system, appropriate to the entity structure, operating environment and threat landscape, capable of giving the management bodies an informed view of the current state of risk management. Point 2.2.3 adds significant incidents and significant changes as triggers for the monitoring.

Framework Mappings (20)

A&A-03Risk Based Planning Assessmentfull
A&A-05Audit Management Processfull
A&A-03Risk Based Planning Assessmentfull
A&A-05Audit Management Processfull
DORA-RTS-2024/1773-Art.6.1Due diligence assessment of the prospective providerinformative
DORA-RTS-2024/1773-Art.6.3Assurance elements used in due diligenceinformative
GDPR-Art.32.1Technical and Organisational Security Measurespartial
HIPAA-164.306.eMaintenanceinformative
HIPAA-164.308.a.1.ii.DInformation System Activity Reviewinformative
HIPAA-164.308.a.8Evaluationfull
5.35Independent review of information securityfull
5.36Compliance with policies, rules and standards for information securityfull
NIS2-Art.21.2.fAssessment of the Effectiveness of Risk-Management Measuresinformative
NIS2-Art.21.4Corrective Measures on Non-Complianceinformative
NIS2-CIR-2.2Compliance Monitoringpartial
NIS2-CIR-7Policies and Procedures to Assess the Effectiveness of Cybersecurity Risk-Management Measuresinformative
CA-2Control Assessmentsfull
CA-7Continuous Monitoringinformative
CC4.1COSO Principle 16: Conducts Ongoing or Separate Evaluationsfull
CC4.2COSO Principle 17: Evaluates and Communicates Deficienciespartial

Evidence (2)

reportdocumentmanual

Internal audit report documenting the scope, findings, and management responses for the most recent compliance and controls review.

Example: Internal Audit Report (PDF / Confluence), dated within the last 12 months, covering one or more security domains, listing findings by severity, and including a management response with agreed remediation actions and owners.

Test: Request the most recent internal audit report. Verify: (1) the report is dated within the defined audit interval, (2) scope is stated and covers information security controls, (3) findings are categorised by severity, (4) each finding has a management response with a named owner and target remediation date, (5) the audit was conducted by someone independent of the function being audited.

system_exporttechnicalautomated

Audit finding remediation records showing corrective actions tracked to closure.

Example: Remediation tracker (Jira / ServiceNow / GRC platform) with tickets linked to audit findings, showing each finding's status (open/in-progress/closed), owner, and closure date or current target date.

Test: Request the remediation tracker for findings from the most recent audit. Verify: (1) all findings from the audit report appear in the tracker, (2) each has a named owner and target date, (3) closed findings have a documented closure date and verification step, (4) no findings are overdue without a documented extension and approver.

Questions (3)

boolean

Does your organisation conduct internal audits or compliance checks of information security controls at a defined interval?

An internal audit report should state scope, list findings by severity, include a management response with owners and target dates, and be produced by someone independent of the function audited.

select

How frequently does your organisation conduct information security internal audits?

Annually or more frequentlyEvery 2 yearsOnly when required by a customer or regulatorNo formal internal audit cadence exists

Most frameworks expect at least annual internal audit activity. Findings should feed directly into the remediation tracker.

multi

Which of the following does each internal audit or compliance check report carry?

Its scopeThe work performedEach finding with a severityA named owner for each findingA management responseA closure date recorded in a findings registerNone of the above

Options run from the most commonly present to the least. A report with findings and no management response records an opinion rather than a commitment. Findings with no register behind them close by being forgotten.