A regulatory compliance audit — whether conducted by the ICO, EDPB, BaFin, a national NIS2 competent authority, or the ECB under DORA — is stressful if you are not prepared. Companies that have maintained their compliance documentation and processes throughout the year handle audits with significantly less disruption than those who scramble to produce records when an investigation begins.
Types of Regulatory Compliance Audits
Reactive investigation: Triggered by a complaint (data subject complaint to the ICO, customer complaint to a financial regulator), an incident (a reported breach), or a media report. The regulator investigates a specific concern.
Proactive sector sweep: The regulator decides to review compliance in a specific sector or for a specific type of practice (e.g., ICO cookie consent sector sweeps, ENISA NIS2 entity assessments, ECB DORA reviews of significant institutions).
Routine supervision: For regulated entities under ongoing supervision (banks under ECB oversight, fintech under EBA guidelines), periodic supervisory reviews of operational compliance are standard.
Enterprise customer audit: Not regulatory, but significant — enterprise customers who have contractual audit rights may conduct or commission security audits of vendors.
Each type requires similar documentation preparation but different levels of engagement.
What Regulators Look For
ICO (UK GDPR Investigations)
When the ICO investigates a data protection complaint or incident:
- Lawful basis for the processing complained about: Can you demonstrate the basis and document it?
- Privacy notice: Was it provided? Does it cover the processing? Was it current at the time?
- DSAR response: Was the request acknowledged within 30 days? Was a complete response provided?
- Breach notification: Was the breach assessed correctly? Was ICO notified within 72 hours if required?
- Security measures: Were appropriate technical and organisational measures in place?
- DPA with processors: Are signed DPAs in place with all vendors who process personal data?
NIS2 Competent Authority Reviews
National NIS2 competent authorities checking essential/important entity compliance:
- Registration: Is the entity registered?
- Governance: Is there a documented risk management framework? Board-level oversight?
- Security measures: Are Article 21 measures implemented? Evidence of access control, encryption, vulnerability management, BCP?
- Incident reporting: Has the entity reported significant incidents? Was reporting on time?
- Supply chain security: Is there a supplier assessment programme?
ECB/NCA DORA Reviews
For financial entities under DORA supervision:
- Register of Information: Is it complete? Has it been submitted?
- ICT risk management: Is the framework documented and operational?
- Third-party risk management: Critical ICT providers identified? Contracts containing Article 30 provisions?
- Incident management: Classification procedure in place? Evidence of proper incident reporting?
- Testing: Basic ICT testing programme in place? TLPT for significant entities?
Before an Audit: Preparation Checklist
Documentation Readiness
- All required policies exist and are current (within the last 12 months)
- All required registers and records are maintained (ROPA, vendor DPA log, AI system register, NIS2 Register of Information)
- All vendor DPAs are in place — complete list with signed DPAs
- Training records are maintained — date, topic, and completion by employee
- Incident records are maintained — all incidents documented with timeline, assessment, and resolution
Control Evidence
- Security controls are documented and can be demonstrated: MFA enabled, encryption confirmed, access control logs available
- Penetration test reports available (current — within 12 months)
- Vulnerability scan reports available
- BCP tested — test date and results documented
- Incident response procedure tested — tabletop exercise or full simulation
Response Readiness
- Designated contact for regulatory communications identified
- Legal counsel briefed and available to support if investigation begins
- Process for gathering documentation quickly in response to regulator requests
During an Audit: Conduct Principles
Respond promptly and completely. Regulators note delays and selective responses. Providing requested documents quickly and completely signals a cooperative posture that regulators reward.
Do not produce more than requested. Respond to the specific requests made. Do not volunteer information beyond what was asked.
Involve legal counsel. Regulatory investigations have legal dimensions. Have counsel review significant responses before they are sent.
Document the engagement. Keep records of all communications with the regulator — what was requested, what was provided, and when.
Do not destroy documents. Once an investigation is underway, document retention obligations are triggered. Destruction of relevant documents — even routine deletion — creates legal risk.
The Most Common Audit Finding: Gaps Between Policy and Practice
The most frequent finding in compliance audits is not the absence of policies — it is the gap between what the policies say and what actually happens.
Examples:
- Privacy notice says personal data is deleted after 12 months; actual deletion process does not exist
- DPA with a vendor says sub-processors are listed; the vendor's sub-processor list has not been updated in 24 months
- Information security policy requires annual penetration testing; no penetration test has been conducted
Prepare for an audit by verifying that your documented policies reflect operational reality — not aspirational standards. Where gaps exist between policy and practice, fix the practice or update the policy before an audit reveals it.