GOV-011 Compliance Monitoring and Internal Audit
Description
An audit plan defines the information security policies, controls and requirements checked in each cycle and the interval between cycles. An audit or compliance check report exists for each cycle the plan defines, stating its scope, the work performed and each finding with a severity and a named owner. Every report carries a management response. Findings are tracked in a register to a recorded closure date.
Rationale
A control that is never tested provides assurance only that somebody wrote it down. Internal verification finds the gap before an external audit, a regulator or an incident does. GOV-012 is the monitoring that runs between these cycles and GOV-020 is the independent assessment; the distinction that matters to an assessor is who performed the work and how far they sit from the function under review.
Applicability (9 profiles)
RTS 2024/1773 Art. 6(3), point (c), makes the provider's internal audit report one of the five assurance elements a financial entity may rely on. Art. 8(3), point (f), requires any report relied on to test the operational effectiveness of key controls rather than their design.
164.308(a)(8) makes a periodic technical and nontechnical evaluation against the requirements of the subpart a standard in its own right. The audit plan GOV-011 requires has to name Subpart C as a checked requirement set, not only the organisation's own policies.
Annex point 2.2.2 asks for something a cyclical audit does not provide: a standing compliance reporting system, appropriate to the entity structure, operating environment and threat landscape, capable of giving the management bodies an informed view of the current state of risk management. Point 2.2.3 adds significant incidents and significant changes as triggers for the monitoring.
Framework Mappings (20)
| A&A-03 | Risk Based Planning Assessment | full |
| A&A-05 | Audit Management Process | full |
| A&A-03 | Risk Based Planning Assessment | full |
| A&A-05 | Audit Management Process | full |
| DORA-RTS-2024/1773-Art.6.1 | Due diligence assessment of the prospective provider | informative |
| DORA-RTS-2024/1773-Art.6.3 | Assurance elements used in due diligence | informative |
| GDPR-Art.32.1 | Technical and Organisational Security Measures | partial |
| HIPAA-164.306.e | Maintenance | informative |
| HIPAA-164.308.a.1.ii.D | Information System Activity Review | informative |
| HIPAA-164.308.a.8 | Evaluation | full |
| 5.35 | Independent review of information security | full |
| 5.36 | Compliance with policies, rules and standards for information security | full |
| NIS2-Art.21.2.f | Assessment of the Effectiveness of Risk-Management Measures | informative |
| NIS2-Art.21.4 | Corrective Measures on Non-Compliance | informative |
| NIS2-CIR-2.2 | Compliance Monitoring | partial |
| NIS2-CIR-7 | Policies and Procedures to Assess the Effectiveness of Cybersecurity Risk-Management Measures | informative |
| CA-2 | Control Assessments | full |
| CA-7 | Continuous Monitoring | informative |
| CC4.1 | COSO Principle 16: Conducts Ongoing or Separate Evaluations | full |
| CC4.2 | COSO Principle 17: Evaluates and Communicates Deficiencies | partial |
Evidence (2)
Internal audit report documenting the scope, findings, and management responses for the most recent compliance and controls review.
Example: Internal Audit Report (PDF / Confluence), dated within the last 12 months, covering one or more security domains, listing findings by severity, and including a management response with agreed remediation actions and owners.
Test: Request the most recent internal audit report. Verify: (1) the report is dated within the defined audit interval, (2) scope is stated and covers information security controls, (3) findings are categorised by severity, (4) each finding has a management response with a named owner and target remediation date, (5) the audit was conducted by someone independent of the function being audited.
Audit finding remediation records showing corrective actions tracked to closure.
Example: Remediation tracker (Jira / ServiceNow / GRC platform) with tickets linked to audit findings, showing each finding's status (open/in-progress/closed), owner, and closure date or current target date.
Test: Request the remediation tracker for findings from the most recent audit. Verify: (1) all findings from the audit report appear in the tracker, (2) each has a named owner and target date, (3) closed findings have a documented closure date and verification step, (4) no findings are overdue without a documented extension and approver.
Questions (3)
Does your organisation conduct internal audits or compliance checks of information security controls at a defined interval?
An internal audit report should state scope, list findings by severity, include a management response with owners and target dates, and be produced by someone independent of the function audited.
How frequently does your organisation conduct information security internal audits?
Most frameworks expect at least annual internal audit activity. Findings should feed directly into the remediation tracker.
Which of the following does each internal audit or compliance check report carry?
Options run from the most commonly present to the least. A report with findings and no management response records an opinion rather than a commitment. Findings with no register behind them close by being forgotten.