Winging It · Implausible Deniability

There is a particular kind of energy that descends on an organisation approximately seven days before an external auditor arrives. It is not panic, exactly. Panic implies surprise. This is something closer to the energy of a family whose estranged aunt has announced she's coming for Christmas. Everyone knew it was possible. Nobody prepared. And now someone is frantically vacuuming under the sofa cushions while someone else hides the bottles.

I first experienced this phenomenon around 2018, where I watched a grown man, a senior infrastructure engineer with two decades of experience, and a pension to protect, spend an entire Tuesday afternoon updating screenshots in a document that nobody had opened since the previous audit. He was replacing screenshots from Windows 7 with screenshots from Windows 10. The systems hadn't changed. The controls hadn't changed. The only thing that had changed was the rounded corners on the dialogue boxes, and he was terrified the auditor would notice.

I didn't say anything. I was too busy updating my own screenshots.

Audit prep week, despite the name, is spent preparing the appearance of having been prepared all along. Actual preparation would involve maintaining your controls continuously, updating your documentation as things change, and treating your evidence repository as a living system rather than a graveyard you visit once a year with fresh flowers.

I have never met a single organisation that does this. I have met several that claim to, and I have nodded politely, which is a skill I've honed to near-Olympic standard.

What actually happens is this. On a Monday morning, someone in GRC sends a calendar invite titled something like "ISO 27001 Surveillance Audit — Evidence Collection Coordination." It is sent to approximately forty people across the business. Thirty-six of them will ignore it. Three will forward it to someone else with the message "Is this yours?" One person, always the same person, always slightly too junior for the responsibility they're carrying, will open a spreadsheet.

The spreadsheet is the real star of audit prep week. It has tabs. So many tabs. One per control domain, plus a tracker, plus a tab called "Notes" that contains a single cell reading "Check with Dave re: firewall rules" from eighteen months ago. Dave left in March.

By Wednesday, the spreadsheet has become a shared Google Sheet with fourteen people editing simultaneously, and if you've never watched a compliance team try to collaboratively manage evidence in a live spreadsheet, I can only describe it as watching fourteen people try to parallel park the same car. Someone has reformatted column D. Someone else has added conditional formatting that turns everything red, which would be useful if it meant something, but it doesn't. It is simply red. A colleague of mine once described this phase as "the fog of compliance" and I've never heard anything more accurate in my life.

The evidence itself is a study in archaeological fiction. Screen captures taken that morning of configurations that have existed for two years, carefully dated to look routine rather than frantic. Policy documents opened for the first time since they were approved, their "Last Reviewed" dates quietly nudged forward. Access review spreadsheets that were supposed to be quarterly but are, upon close inspection, four copies of the same review with different dates in the header.

I have done this. I am not observing from a position of moral superiority. I have personally changed a "Last Reviewed" date on a document I was reviewing for the first time, while telling myself that the act of reviewing it now was, technically, a review, and therefore the date was accurate. The human capacity for self-justification during audit prep week is extraordinary.

Then there's the access logs. Someone in IT will be asked to pull access logs for a critical system. They will discover that the logging was turned off in September because it was "filling up the disk." This will be fixed quietly, the logs will start again from Wednesday afternoon, and everyone will hope the auditor doesn't ask for anything before Wednesday afternoon.

They always ask for something before Wednesday afternoon.

By Thursday, the energy shifts. The panic has resolved into a kind of grim acceptance. The evidence is what it is. The spreadsheet has forty-seven tabs and three unresolved comments. Someone has uploaded a PDF to the evidence folder that is just a blank page, and nobody knows who or why, but there isn't time to investigate. The CISO does a "dry run" walkthrough with the team, which is billed as a rehearsal and runs as a group therapy session where everyone takes turns explaining why their particular gap isn't a gap if you look at it from the right angle.

There is always one control that everyone knows is going to be a finding. It was a finding last year. It was a finding the year before. It has a remediation plan that says "Q2" without specifying which Q2, or indeed which year. The plan is to acknowledge it early, look appropriately contrite, and point to the remediation plan as evidence of "ongoing improvement." The auditor will note it. Everyone will agree it needs to be fixed. It will be a finding again next year. This is the circle of compliance life, and I find it strangely comforting in its predictability.

Friday is quiet. The calm before. People go home early. Someone sends a message in the team chat that says "We're in good shape" and everyone knows it means "We've done what we can and the rest is in God's hands."

The auditor arrives on Monday. They are perfectly pleasant. They accept the tea. They accept most of the evidence. They ask to see the access review and someone pulls it up with the quiet confidence of a man who definitely didn't create it on Thursday. Nobody blinks. The auditor doesn't blink. It is a masterclass in mutual restraint. Because, and this is the part that nobody talks about, the auditor also knows. They know the screenshots were taken last week. They know the policy was reviewed for the first time on Tuesday. They know the access review is the same one with different dates. Auditing is a system that works because both sides have agreed to maintain a very specific fiction, and as long as the fiction is maintained with sufficient effort, everyone gets to go home.

The audit concludes. There are three minor non-conformities, one of which is the same one from last year, and one of which nobody fully understands but everyone agrees to remediate by Q3, which is auditor for "see you next year." The report arrives in a PDF. Someone files it in a folder that seven people have access to and nobody will open until next November. The spreadsheet is abandoned. The logging fills up the disk again.

And in approximately eleven months, someone in GRC will send a calendar invite, and the whole thing will begin again.

I sometimes wonder what would happen if we all just kept the evidence up to date throughout the year. Maintained the documentation. Reviewed the access quarterly, and meant it. Treated the controls as living things rather than exam answers.

I asked an auditor once, off the record, over a coffee, whether any of this worked. Whether the annual performance, the scramble, the fiction, achieved anything meaningful.

She thought about it for a long time. Then she said, "It gets people to look at their controls at least once a year. That's more than they'd do otherwise."

Which is the most depressing endorsement of anything I've ever heard.

— Chris