Skip to main content
Audit Readiness Assessment, India

Run the audit before the auditor does. Find every gap while there is still time to close it.

A structured gap assessment against the framework you are being audited on: ISO 27001, SOC 2, DPDP Act, or a customer security questionnaire. Control mapping, evidence inventory, staff preparation, and a remediation plan sequenced to your audit date. Remote-first, 1-3 weeks.

Compliance lead reviewing an audit evidence checklist against a control framework
  • 1-3 weeksAssessment duration
  • 6Frameworks covered
  • Mock auditIncluded in scope
  • Remote-firstAnywhere in India
How this differs from a security audit

This is not our security audit. It is a dry run of somebody else's.

Our cybersecurity audit finds technical weaknesses: misconfigurations, vulnerabilities, exploitable paths. This engagement answers a different question: when your certifying body, your customer, or your regulated client audits you against their framework, will you pass? The two compose well, but they are different engagements with different outputs.

  • A security audit asks "where are you weak?" A readiness assessment asks "can you evidence what their checklist demands?"
  • The readiness output is framed in the auditor's language: control references, evidence requests, nonconformity risk, not CVSS scores.
  • Most clients who fail a first external audit fail on evidence and documentation, not on technology. This engagement exists for exactly that reason.
  • If the assessment surfaces deep technical weaknesses, we scope a security audit or remediation separately rather than padding this engagement.
See the full security audit service
What the assessment covers

Eight workstreams, one question: will you pass?

An external audit fails on specifics: a control that is not mapped, evidence that does not exist, a policy nobody has signed, a staff answer that contradicts the document. The assessment works through each failure mode before the auditor gets the chance to.

Control mapping against the target framework

Every control in the framework you are facing (ISO 27001 Annex A, SOC 2 Trust Services Criteria, DPDP Act obligations, or the customer questionnaire itself) mapped to what your organization actually does today. Each control gets a status: implemented, partial, missing, or not applicable with a documented justification. The output is a control-by-control register, not a maturity score that hides the detail.

Evidence inventory: what you have vs what they will ask for

Auditors do not accept "we do that". They ask for the access review record, the tested restore log, the signed policy acknowledgement, the change ticket with approval. We build the evidence request list your auditor is likely to issue, then check each item: does it exist, does it cover the audit period, is it in a form an auditor will accept. Missing evidence is flagged early because some of it takes months to accumulate.

Policy and documentation gaps

The document set the framework expects: information security policy, access control, incident response, business continuity, vendor management, data protection and retention. We check what exists, what is missing, what is stale, and where the document says one thing while your team demonstrably does another. That last category is the one that widens audits, so it gets fixed first.

Technical control gaps

The technical controls the framework requires, verified rather than assumed: MFA coverage, access provisioning and deprovisioning, logging and log retention, backup and tested restores, endpoint protection, patching cadence, encryption at rest and in transit. Where a control is absent or partial, it goes into the gap register with effort and dependency noted so remediation can be sequenced realistically.

Interview preparation for your staff

Auditors interview control owners, and the answer either matches the documentation or it opens a line of enquiry. We rehearse each control owner: how the control works, how they know it operated, what they would say about an exception. One hour per owner changes fieldwork more than most technical remediation, and it is the part almost every first-time auditee skips.

Remediation plan sequenced by your audit timeline

Not a generic to-do list. Every gap gets an owner, an effort estimate, and a date worked backwards from the audit. Items that need elapsed time (evidence accumulation, a quarter of access reviews, three months of operating logs) start immediately. Items fixable in a week are scheduled where they fit. You always know what must be done by when, and what happens if it slips.

Framework selection guidance

Many organizations start this engagement unsure whether they need ISO 27001, SOC 2, or just a solid answer to a customer questionnaire. We map who is asking (an enterprise customer, an export market, an RBI or SEBI-regulated client, an internal board mandate) to the framework that actually satisfies them, so you do not spend a year certifying against the wrong standard.

Ongoing compliance calendar

Passing once is not the goal; staying auditable is. The assessment closes with a compliance calendar: which reviews recur quarterly, which evidence must be generated continuously, when surveillance audits and re-attestations fall due, and who owns each entry. It turns audit readiness from an annual scramble into a routine your team runs without us.

Deliverables

Four documents you walk away with.

Everything is written, owned, and dated. Nothing is delivered as a verbal debrief or a slide deck that evaporates. These four artifacts are the engagement.

Gap register

Every control in the target framework with a status, a severity, and a finding. The register is the single source of truth for what stands between you and a pass.

  • Control-by-control mapping to the target framework
  • Status per control: implemented, partial, missing, not applicable
  • Severity ranked by audit impact, not just technical risk
  • Written findings an auditor could read without translation

Evidence checklist

The evidence request list your auditor is likely to issue, with a status per item: exists, exists but insufficient, missing. Ordered by how long each item takes to produce.

  • Likely evidence requests mapped per control
  • What you hold today vs what must be generated
  • Period-coverage flags: evidence that must start accumulating now
  • Format notes: what auditors accept and what they reject

Remediation roadmap

The gap register turned into a plan: every item with a named owner, an effort estimate, and a date worked backwards from your audit or certification target.

  • Owners and dates per remediation item
  • Time-dependent items front-loaded (logs, reviews, operating evidence)
  • Dependencies mapped so nothing blocks silently
  • A realistic call on whether the audit date is achievable

Mock-audit findings

A rehearsal of the real thing: evidence requested with deadlines, control owners interviewed, documents sampled. The findings read like an auditor wrote them, because that is the point.

  • Evidence requests issued with two-day deadlines, as an auditor would
  • Control-owner interviews with question-by-question notes
  • Findings classified the way your auditor will classify them
  • A readiness verdict: proceed, proceed with conditions, or defer
Why GR IT for readiness

Four reasons the dry run works.

Readiness work is easy to do badly: a checklist interview, a reassuring score, a certificate-shaped surprise six months later. Here is what we do differently.

We request evidence, not assurances

We do not ask whether you perform access reviews. We ask for the last review record with a two-day deadline, exactly as the auditor will. The difference between those two questions is the entire value of the engagement.

Frameworks we have taken clients through

ISO 27001, SOC 2, CERT-In, and sector frameworks for RBI and SEBI-regulated environments. We prepare you for certifying bodies and CPA firms we have actually sat across the table from.

Independent of the certifier

We are not the certification body and we do not resell one. Our only incentive is that you pass on the first attempt, because a deferred certification is a failed engagement for us too.

Sequenced to your date, honestly

If the audit date is not achievable, the assessment says so in week one, with the evidence for why and the earliest date that is. An honest "not yet" is cheaper than a failed Stage 2 audit.

Who books this

Six situations where the dry run changes the outcome.

The common thread: somebody external is going to assess you, the date is real or imminent, and failing has a business cost. Scope varies; the discipline does not.

SaaS startup asked for SOC 2 by a customer

An enterprise prospect makes SOC 2 a condition of the contract. We map the Trust Services Criteria to what you run today, tell you honestly whether Type 1 satisfies the contract or Type 2 is required, and sequence the observation window so the deal timeline and the attestation timeline actually meet.

Manufacturer pursuing ISO 27001 for exports

Export customers and international tenders increasingly require ISO 27001. We scope the ISMS realistically (plant, office, OT boundaries), build the Annex A gap register, and prepare the documentation and operating evidence a certification body will sample at Stage 1 and Stage 2.

BFSI vendor facing an RBI-regulated client review

Banks and NBFCs push their regulatory obligations down their vendor chain: RBI cyber security framework expectations, outsourcing due diligence, SEBI CSCRF for market intermediaries. We translate the client's questionnaire into a control map and prepare the evidence pack their risk team expects to see.

Company preparing for DPDP enforcement

The DPDP Act 2023 applies whether or not anyone has audited you yet. We assess your consent flows, data inventory, retention practices, breach notification readiness, and processor contracts against the Act's obligations, so a regulator inquiry or a customer's DPDP clause finds a prepared organization.

Losing deals to security questionnaires

Every enterprise deal now arrives with a 200-question security review, and slow or weak answers stall pipelines. We build a reusable evidence library and a standard answer set mapped to the common questionnaire formats, so responses take days instead of weeks and stop costing you deals.

Enterprise vendor onboarding, Indian and global

Onboarding into a large Indian group or a global customer's vendor program means due diligence against their framework, on their timeline. We run the readiness pass against their specific checklist, close the gaps that block onboarding, and prepare your team for the assessor call.

Frameworks

ISO 27001, SOC 2, DPDP, or the questionnaire: which do you actually need first?

Most organizations do not need every framework. They need the one that satisfies whoever is asking. This is how the four most common targets in India compare, and how we advise sequencing them.
Feature
ISO 27001
Certification
SOC 2
Attestation (Type 1 / 2)
DPDP Act 2023
Legal obligation
Customer questionnaires
Deal requirement
Who is asking for it
Enterprise buyers, export markets, tenders, regulated clientsSaaS customers, mostly US and global enterpriseThe law: applies to processing digital personal data in IndiaAny enterprise customer during vendor onboarding
What you receive at the end
A certificate from an accredited certification bodyA CPA firm attestation reportNo certificate exists; you evidence compliance when reviewedA passed review and an unblocked deal
Realistic first-time timeline
6-12 months including operating evidenceType 1 in months; Type 2 adds a 3-12 month observation windowOngoing; enforcement readiness is achievable in weeks to monthsDays to weeks with the right evidence on hand
Renewal cycle
Three-year cycle with annual surveillance auditsAnnual re-attestationContinuous obligationPer customer, often annually
Best first move when
Multiple customers or tenders name it, or exports demand itOne or more SaaS customers explicitly require a SOC 2 reportYou process personal data at scale (that is most businesses)One live deal is blocked and the timeline is short
Typical trap
Certifying an artificially narrow scope customers then rejectBuying a Type 1 when the customer contract demands Type 2Treating it as an IT project when it is a data-governance oneAnswering aspirationally and being caught at renewal
How it runs

Six steps, 1-3 weeks, remote-first.

Document review plus workshops, run remotely with your team wherever in India they sit. On-site days are available where physical controls are in scope. Duration depends on the framework: a questionnaire readiness pass is fast, a full ISO 27001 or SOC 2 gap assessment takes the full three weeks.
  1. 1

    Kickoff and scoping

    Day 1

    Confirm the target framework, the audit or review date, the scope (entities, systems, locations, data), and who owns which control area. You get the document request list the same day so collection starts immediately.

  2. 2

    Document review

    Days 2-5

    Policies, procedures, prior audit reports, existing certificates, contracts with security clauses, and the customer questionnaire if there is one. Reviewed against the framework before any workshop, so workshop time is spent on questions documents cannot answer.

  3. 3

    Workshops and evidence testing

    Days 4-8

    Structured sessions with control owners across identity, infrastructure, operations, HR, and data protection. In parallel we issue evidence requests with deadlines and assess what arrives: does it exist, does it cover the period, would an auditor accept it.

  4. 4

    Gap register delivered

    Week 2

    The control-by-control register with severity and findings, plus the evidence checklist. Walked through live with your team so every finding is understood and nothing lands as a surprise in a PDF.

  5. 5

    Remediation plan

    Week 2-3

    The register becomes a roadmap: owners, effort, dates worked backwards from the audit. Time-dependent items (operating evidence, review cycles, log retention) are flagged to start now. We state plainly whether the target date is achievable.

  6. 6

    Mock audit (optional, recommended)

    Week 3 or pre-audit

    A rehearsal under audit conditions: evidence requests with deadlines, control-owner interviews, document sampling. Best run either at the end of the assessment or two to four weeks before the real audit, after remediation has landed.

Straight answers

The questions that decide whether to book this.

Test yourself first

Twelve evidence requests to make of your own team this week.

Ask for these with a two-working-day deadline, exactly as an auditor would. The ones that arrive late, incomplete, or as an undated screenshot are your gap register, free of charge.

Access and identity

  • The last access review, with outcomes per item
    Not a statement that it happened.
  • Access removal records for three recent leavers
    With dates and approvals.
  • The current privileged account list
    Including service accounts, with approvals.
  • MFA coverage report against the full user list
    Coverage needs a denominator.

Operations

  • Three changes with approval and testing evidence
    Chosen by you, not by the team.
  • The last tested restore record
    Date, scope, outcome. A schedule is not a test.
  • Patch status against the asset inventory
    Unknown assets are findings too.
  • Log retention configuration vs the audit period
    Ninety days of logs cannot evidence a year.

Governance

  • The policy set with review dates and sign-offs
    Check the dates before the auditor does.
  • Consent and data-inventory records for personal data
    The DPDP Act baseline.
  • Vendor due-diligence records for two critical suppliers
    Your customers will ask about your vendors.
  • The incident register, including minor incidents
    An empty register reads as "not operating".
Next step

Find out where you stand before the auditor does.

Tell us which framework or customer review you are facing and the date you are working to. We reply within 4 business hours with a scoped plan for a 1-3 week readiness assessment. No obligation, no retainer.