Auditee
Definition
The organization or organizational unit being audited. In planning, the auditee provides key inputs: system inventory, risk register, previous audit findings, control documentation, and access to personnel for interviews.
- Provides
- System inventory, risk register, prior findings
- Also provides
- Access to personnel for interviews
- Role in scoping
- Supplies inputs the auditor uses to set scope
Common questions
Can the auditee refuse an auditor's request for records that fall within agreed scope?+
Refusing access to in-scope records or personnel is itself typically recorded as a limitation or finding, since it prevents the auditor from forming a conclusion on that area.
Why does the auditee supply the risk register rather than the auditor building one independently?+
The auditee holds the operational knowledge of its own processes and prior control weaknesses, so its risk register grounds the audit in real known exposures rather than assumptions made from outside.
Related terms
- Audit Criteria
- The standards, policies, or requirements against which audit evidence is compared. Common criteria include ISO/IEC 27001, NIST SP 800-53, PCI-DSS, and the...
- Audit Objectives
- The questions the audit is designed to answer, stated in terms of control criteria. For example: do access management controls satisfy the...
- Audit Plan
- The document that translates scope and objectives into a structured programme of fieldwork: what will be tested, how, by whom, on what...
- Audit Scope
- The documented boundaries of an audit: which systems, processes, organizational units, locations, and time periods are included. Scope is agreed between auditor...
- Scope Creep
- The unintended expansion of a penetration test beyond the agreed boundaries, either because testers follow a vulnerability chain into an out-of-scope system...