Compliance
IT Consulting

Compliance Audit Framework: Modules, Process & Template

Compliance Audit & Consulting Modular Framework

Quick answer: 
A compliance audit framework is a structured method for assessing an organization against the regulations and standards that apply to it — such as SOC 2, ISO 27001, GDPR, HIPAA, PCI DSS, NIS2, or DORA — and turning the findings into a prioritized remediation plan. Gart Solutions’ modular framework breaks the audit into 10 modules mapped to 5 pillars (Governance & Risk, Data Protection & Privacy, Security & Access Controls, Regulatory & Certification Readiness, Continuous Monitoring & Resilience), so you assess only what your target framework requires and get one unified report with a 30/60/90-day roadmap.

Most compliance audits fail in the same place: not at the auditor’s desk, but months earlier, when the scope was set. A team preparing for SOC 2 runs a generic checklist, misses that its EU customers pull GDPR and NIS2 into scope, and discovers the gap during an enterprise security review. A fintech assesses its access controls perfectly and never looks at vendor contracts, then learns DORA cares about both.

A good compliance audit framework fixes this by making scope explicit and modular. Below is the exact framework our team uses for compliance audit engagements — the modules, the pillars they map to, which modules each certification needs, who delivers what, and the structure of the final report. You can download the full framework as a spreadsheet and use it to scope your own audit, internally or with us.

What is a compliance audit framework?

A compliance audit framework is the blueprint for how an audit is run: which areas get assessed, what evidence is reviewed, how each area is scored, and how findings are reported. It is different from a regulation or standard. ISO 27001 tells you what controls an information security management system needs; a compliance audit framework tells you how to check whether your organization actually has them, where it doesn’t, and what to fix first.

In practice, the framework answers four questions every CTO, CISO, or compliance lead needs settled before an audit starts:

  1. What applies to us? Which regulations and certifications are mandatory, contractually required, or simply expected by customers in our industry and geographies.
  2. What do we assess? Which domains — governance, privacy, access, technical controls, vendors, resilience, evidence, training — are in scope for this audit.
  3. How do we score it? A consistent maturity scale so findings are comparable across modules and over time.
  4. What do we get at the end? A report with prioritized findings and a roadmap, not a pass/fail checklist.

The output of an audit run on this framework is what we call a Compliance Gap Assessment: an evidence-based, prioritized plan mapped to the actual controls of your target framework.

Why a modular compliance audit framework works better than a checklist

A single long checklist treats every company the same. A modular framework treats compliance as a set of building blocks that combine differently depending on your goal. That matters for three reasons.

Frameworks overlap heavily. SOC 2, ISO 27001, HIPAA, and PCI DSS share a large share of their underlying controls — typically 60–85% depending on the pair. Access management, encryption, logging, and incident response show up in almost all of them. Assessing those once, as modules, and mapping the evidence to every relevant framework avoids paying for the same work twice.

The cost of getting it wrong keeps rising. The global average cost of a data breach was $4.44 million in 2025, according to IBM’s Cost of a Data Breach Report. Regulatory clocks are tight too: GDPR requires notifying the supervisory authority within 72 hours of becoming aware of a personal data breach (Article 33, GDPR), and NIS2 adds a 24-hour early-warning requirement for essential and important entities. An audit that skips incident readiness misses one of the most heavily penalized areas.

Scope can grow without restarting. A company that starts with a SOC 2 readiness audit can add the Data Protection & Privacy module later for GDPR, rather than commissioning a second, disconnected audit. The modules and scoring stay the same, so results stay comparable.

The 5 pillars of the compliance audit framework

Every module maps to a primary and a secondary pillar. The pillars are the lens the final report uses to tell leadership where the organization is strong and where it is exposed.

The 10 modules of a compliance audit

Each module has a defined focus, a concrete client deliverable, and a typical effort estimate. The effort figures below are Gart engineering days for a mid-sized organization; they scale with the number of systems, entities, and jurisdictions in scope.

ModuleWhat it assessesDeliverableEffort (days)
1. Regulatory Scoping & Framework MappingWhich of ISO 27001, SOC 2, GDPR, NIS2, HIPAA/HITECH, PCI DSS, DORA, EU AI Act, and iGaming licensing (UKGC/MGA/Curaçao) apply; jurisdictional overlap and conflicts; certification vs. self-attestation.Regulatory applicability matrix with scope and priority ranking1.5
2. Governance, Risk & Policy ManagementRisk methodology and register, RACI, DPO/CISO mandate, completeness of InfoSec, Privacy, Acceptable Use, and Data Retention policies, board reporting cadence.Governance maturity report, policy gap list, risk register template2
3. Data Protection & PrivacyData mapping and RoPA, DPIAs/PIAs, consent and lawful basis, retention and deletion, cross-border transfers (SCCs, adequacy).Data flow map, privacy gap analysis, DPIA action plan1.5
4. Access Control & Identity ManagementIAM and least privilege, MFA coverage, privileged access, joiner/mover/leaver process, secrets and credential management.Access control assessment with prioritized hardening checklist1.5
5. Security Controls & Technical SafeguardsEncryption at rest and in transit, network segmentation, vulnerability and patch management, endpoint security, secure SDLC.Technical security posture report with remediation priorities1
6. Third-Party & Vendor Risk ManagementVendor due diligence, DPAs and subprocessor register, SOC 2/ISO report review cadence, concentration and fourth-party risk.Vendor risk register with tiering and reassessment schedule1.5
7. Business Continuity, Incident Response & DRIR plans and playbooks, breach-notification timelines (GDPR 72-hour, US state laws), BCP/DR plans, RTO/RPO, tabletop exercise cadence.Incident readiness report, notification-obligation matrix, DR gap analysis1.5
8. Audit Evidence, Monitoring & ReportingLogging and monitoring coverage for control evidence, internal control-testing cadence, KPI/KRI dashboards, audit trail retention.Evidence-readiness report with control-testing calendar1.5
9. Employee Awareness & TrainingOnboarding and annual training, phishing simulations, policy acknowledgment tracking, role-based training for engineering, finance, and support.Training maturity scorecard with improvement plan1
10. Certification & Attestation ReadinessControl-to-framework crosswalk (e.g., SOC 2 Trust Services Criteria, ISO 27001 Annex A), evidence readiness, mock-audit findings, auditor selection and timeline.Certification gap analysis, remediation roadmap, auditor-readiness checklist2
The 10 modules of a compliance audit

Where audits most often find problems

Across engagements, three modules surface the most critical findings. 

Access Control (Module 4) is first: stale accounts from incomplete offboarding, shared admin credentials, and MFA gaps on non-SSO tools. If that’s where you suspect trouble, our guide on running user access reviews without spreadsheets is a practical starting point. 

Audit Evidence (Module 8) is second: controls exist but nobody can prove they operated over the audit period — the most common reason behind a failed SOC 2 audit. 

Vendor Risk (Module 6) is third, especially for EU financial entities, where DORA turns ICT third-party oversight into a regulatory requirement; see our ICT third-party risk guide.

Download Compliance Audit & Consulting Modular Framework

Which modules do you need? Predefined compliance audit packages

Most organizations don’t need all ten modules. The framework includes eight predefined packages that bundle the right modules for a specific goal. The durations below are typical for the full package; your scope may be shorter or longer.

PackageGoalModulesTypical duration
GDPR & Data PrivacyAchieve and maintain GDPR / data-privacy readiness1, 3, 4, 7, 87.5 days
SOC 2 Readiness & CertificationPrepare for a SOC 2 Type I or Type II audit1, 2, 4, 5, 8, 109.5 days
ISO 27001 Certification ReadinessClose the gap to ISO 27001 certification1, 2, 4, 5, 6, 8, 1011 days
HIPAA / HITECHMeet healthcare data-protection requirements1, 3, 4, 5, 7, 88.5 days
PCI DSSSecure cardholder data and meet payment-industry requirements1, 4, 5, 7, 87 days
Vendor & Third-Party RiskReduce exposure from vendors and subprocessors1, 2, 6, 86.5 days
iGaming Regulatory ComplianceMeet UKGC / MGA / Curaçao licensing requirements1, 2, 3, 4, 5, 79 days
Enterprise Full Compliance Health CheckComprehensive evaluation across all compliance domains1–1015 days

Notice that Module 1 (Regulatory Scoping) appears in every package. That’s deliberate: every audit starts by confirming what actually applies. The ISO 27001 package is the only certification package that includes Vendor Risk by default, because ISO/IEC 27001:2022 Annex A — 93 controls in total — includes explicit supplier-relationship controls. The SOC 2 package leans on Module 10 to crosswalk your controls against the AICPA’s Trust Services Criteria. For framework-specific preparation, see our step-by-step guides to the SOC 2 audit, PCI DSS audit, and HIPAA audit.

Who does what: the three-party delivery model

Compliance sits at the intersection of law, engineering, and security testing, and no single firm is credible in all three. Every module and package in the framework names a primary owner and, where relevant, a supporting partner, so scope.

The lead shifts with the package. A GDPR or HIPAA engagement is legally led, with Gart handling technical data mapping and safeguards. SOC 2, ISO 27001, and PCI DSS are Gart-led, with the cybersecurity partner supplying penetration-test and technical evidence. The Enterprise Health Check engages all three in full.

How the compliance audit process works, step by step

Regardless of which package you choose, the audit follows the same sequence:

  1. Scoping call and regulatory mapping. Confirm business model, geographies, data types, and customer requirements; produce the applicability matrix and agree the modules.
  2. Evidence request. Policies, architecture diagrams, IAM exports, cloud configuration, vendor lists, IR and DR plans, training records.
  3. Stakeholder interviews. Engineering, security, legal, HR, and finance owners — controls on paper are checked against how work actually happens.
  4. Technical and legal analysis. Infrastructure and access review by Gart, contract and policy review by the legal partner, testing by the cybersecurity partner where in scope.
  5. Scoring. Each module receives a maturity score and a status of Strong, Needs Improvement, or High Risk.
  6. Report and roadmap walkthrough. Findings, prioritized remediation, and a 30/60/90-day plan, presented to technical and executive stakeholders.

Many teams pair the compliance audit with a broader IT audit when infrastructure cost, reliability, or architecture questions are also on the table.

How findings are scored

The Compliance Health Scorecard gives an overall audit score plus a maturity score for each assessed module. Every module lands in one of three statuses:

What’s in a compliance audit report

The deliverable is one cohesive report, not ten disconnected module write-ups. It is built for two audiences at once: leadership, who need the risk picture and investment priorities, and engineering and compliance owners, who need specific, evidenced actions.

Report sectionWhat it includes
Executive SummaryOverall compliance health, key risks, critical findings, top recommendations
Compliance Health ScorecardOverall score plus maturity score and status per module
Audit Scope, Objectives & MethodologyFrameworks, jurisdictions, systems covered; evidence reviewed, interviews, scoring approach
Regulatory Landscape & ApplicabilityWhich frameworks apply, why, and how they overlap or conflict
Compliance Maturity AssessmentStrengths, weaknesses, maturity level, and score for each module
Key Findings & RisksEach finding with severity, evidence, legal/business impact, recommended action
Domain reviewsGovernance & Risk, Data Protection & Privacy, Security & Access, Vendor Risk, Incident Readiness & BCP
Prioritized Remediation PlanActions grouped Critical / High / Medium / Low with expected impact
30/60/90-Day Compliance RoadmapWhat to address immediately, next, and later
Certification & Attestation Readiness SummaryGap-to-certification status, auditor readiness, recommended timeline
AppendixDetailed evidence, policy inventory, regulatory citations, scoring criteria

When do you need a compliance audit?

The framework lists twelve situations where a structured audit pays for itself. Each one points to a different question the audit is meant to answer.

TriggerWhat the audit helps identify
Preparing for SOC 2 or ISO 27001Control gaps, evidence readiness, audit-blocking issues
Entering a new regulated market or geographyWhich frameworks apply, jurisdictional conflicts, readiness gaps
Fundraising or investor due diligenceCompliance risks that could affect valuation or investor confidence
After a data breach or security incidentRoot cause, notification obligations, control failures
An enterprise customer’s security questionnaireWhether current controls satisfy customer and vendor requirements
Expanding into UKGC / MGA / Curaçao jurisdictionsLicensing-specific technical and governance requirements
Before an M&A transactionCompliance liabilities, undisclosed gaps, remediation cost exposure
New regulation (NIS2, DORA, EU AI Act)Gap between current posture and new requirements
Annual compliance or re-certification cycleDrift since the last audit and newly introduced gaps
Board or investor risk reviewBusiness-critical compliance risks and investment priorities
High vendor or third-party exposureVendor compliance gaps, contract gaps, concentration risk
New CISO or DPOAn independent baseline of current posture and priorities

If the trigger is NIS2 specifically, our NIS2 readiness guide covers the directive’s obligations in more depth.

Optional add-ons beyond the core audit

Some findings are best addressed with a focused sprint rather than a full remediation program. The framework offers seven add-ons: a Policy & Documentation Drafting Sprint, a DPIA workshop, an Incident Response Tabletop Exercise, an Employee Security & Compliance Training Program, a Vendor Risk Assessment Sprint, a Mock Audit / Pre-Certification Assessment, and a Compliance-as-a-Service retainer for continuous monitoring. The mock audit is the one we recommend most often before a first SOC 2 Type II or ISO 27001 Stage 2 audit — it is far cheaper to find an evidence gap in a rehearsal than in front of the certification body. Teams that want controls to stay audit-ready year-round usually combine the retainer with compliance automation tooling.

How to use the downloadable compliance audit template

The spreadsheet works whether you run the audit yourself or with an external team. Start with the Modules section and mark which of the ten apply, using the use-case table to sanity-check your reasoning. Then compare your selection with the closest predefined package — if you’ve picked modules 1, 2, 4, 5, 8, and 10, you’ve independently arrived at SOC 2 readiness. Use the effort column to estimate internal hours, and the report format section as the table of contents for your own findings document. If you get stuck on Module 1, that’s normal: regulatory applicability is the step where most internal audits go wrong, and it’s the one most worth an outside opinion.

Download Compliance Audit & Consulting Modular Framework

Know exactly where you stand — then fix it with the same team

Gart Solutions runs compliance audits on this framework for SaaS, fintech, healthcare, and iGaming companies across the EU and US. You get one Compliance Gap Assessment, and if the findings need engineering work, our Compliance Consulting team builds the controls directly in your infrastructure.

Compliance Audit
Modular, evidence-based assessment against SOC 2, ISO 27001, GDPR, HIPAA, PCI DSS, NIS2, DORA
Compliance Consulting
IAM, encryption, secrets, logging, and evidence automation, built in your cloud
Compliance-as-a-Service
Continuous monitoring so controls don’t drift between audits

You might also like

FAQ

arrow arrow

Thank you
for contacting us!

Please, check your email

arrow arrow

Thank you

You've been subscribed

We use cookies to enhance your browsing experience. By clicking "Accept," you consent to the use of cookies. To learn more, read our Privacy Policy