GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

GOV-021 Audit and Assurance Policy

Tier 2+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

A documented audit and assurance policy exists that defines the scope, frequency, independence requirements, and reporting responsibilities for the organisation's internal audit function. The policy is reviewed at least annually.

Rationale

The audit function requires its own governance to ensure it operates with appropriate independence, scope, and authority. Without a policy, audit activities may be inconsistent, under-resourced, or captured by the functions being audited.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredcore
NIS2 Cloud Provider (EU)stablerequiredcore

Framework Mappings (6)

A&A-01Audit and Assurance Policy and Proceduresfull
A&A-01Audit and Assurance Policy and Proceduresfull
DORA-Art.28.6Exercise of access, inspection and audit rightsinformative
8.34Protection of information systems during audit testinginformative
NIS2-CIR-2.3Independent Review of Information and Network Securityinformative
CA-1Policy and Proceduresfull

Evidence (2)

policydocumentmanual

Audit and assurance policy document defining scope, frequency, independence requirements, and reporting responsibilities for the internal audit function.

Example: Internal Audit Policy (Confluence / policy management system), specifying: audit scope, audit cycle frequency (e.g. annual), independence requirement (auditor not responsible for the function audited), reporting line (e.g. to CISO or Audit Committee), and retention period for audit records.

Test: Request the audit and assurance policy. Verify: (1) audit scope is defined and covers information security, (2) audit frequency is stated, (3) independence requirements are explicit: auditors must not audit their own function, (4) reporting line to management or audit committee is specified, (5) the policy is approved and dated within the last 12 months.

recorddocumentmanual

Annual internal audit plan showing scheduled audits for the year aligned to the policy.

Example: Annual Audit Plan (Confluence or PDF), dated at the start of the audit year, listing audit subjects, scheduled dates, assigned auditors, and the approval signature of the CISO or Audit Committee chair.

Test: Request the current annual audit plan. Verify: (1) the plan exists and was approved before the start of the audit year, (2) scheduled audits cover the domains defined in the policy, (3) assigned auditors are named and independent of the functions being audited, (4) completion status against the plan is trackable.

Questions (2)

boolean

Does your organisation have a documented audit and assurance policy?

The policy should explicitly state that auditors cannot audit their own function, define the reporting line (e.g. to CISO or Audit Committee), and be approved within the last 12 months.

multi

Which of the following does the audit and assurance policy define?

The scope of the internal audit functionThe frequency of audit cyclesThe independence requirements placed on auditorsThe reporting line and reporting responsibilitiesAn annual audit plan approved before the audit year beginsCompletion status tracked against that planNone of the above

Options run from the most commonly defined to the least. Independence is the limb that decides what the audit is worth: a policy that lets a function audit itself produces a report nobody outside the organisation can rely on.