Free Tool
Audit readiness score.
Twelve questions. Zero mercy.The twelve controls auditors sample most, weighted by how often each one stalls a real audit. Answer honestly — the tool runs entirely in your browser and stores nothing.
- Someone owns the compliance program by name, with real hours allocated.
- MFA is enforced (not just available) across production and your identity provider.
- The last two quarterly access reviews exist as recorded artifacts with decisions.
- Your policy set is written, tailored to how you operate, and executive-approved with dates.
- Evidence collects automatically from cloud, identity, and repos (not screenshots on demand).
- Offboarding provably revokes access — you could show a leaver’s revocation timestamps.
- A penetration test by an independent tester exists, dated within 12 months, with remediation.
- The incident response plan has been exercised — a real incident record or a tabletop on file.
- A vendor register exists with risk tiers and completed reviews for critical vendors.
- A risk assessment was completed within 12 months and lives in a maintained register.
- Endpoints are managed: disk encryption and screen lock enforced, coverage reportable.
- An auditor is selected (or shortlisted) and the audit date is on a calendar.
Frequently Asked
What does the score actually mean?
It weighs the twelve controls auditors sample most, by how often each one blocks or delays real audits. It is a readiness signal, not an audit — but teams that score above 80 here rarely get surprised in fieldwork, and teams below 50 always do.
Is my answer data stored anywhere?
No — the scorer runs entirely in your browser. Nothing you click leaves the page.
What should I do with a low score?
Work the highest-weight gaps first — ownership, MFA, and access reviews move both the score and real audit outcomes fastest. Or get the measured version: our readiness assessment produces a scored gap list and a dated plan in two weeks.