Free Tool

Audit readiness score.

Twelve questions. Zero mercy.

The twelve controls auditors sample most, weighted by how often each one stalls a real audit. Answer honestly — the tool runs entirely in your browser and stores nothing.

  1. Someone owns the compliance program by name, with real hours allocated.
  2. MFA is enforced (not just available) across production and your identity provider.
  3. The last two quarterly access reviews exist as recorded artifacts with decisions.
  4. Your policy set is written, tailored to how you operate, and executive-approved with dates.
  5. Evidence collects automatically from cloud, identity, and repos (not screenshots on demand).
  6. Offboarding provably revokes access — you could show a leaver’s revocation timestamps.
  7. A penetration test by an independent tester exists, dated within 12 months, with remediation.
  8. The incident response plan has been exercised — a real incident record or a tabletop on file.
  9. A vendor register exists with risk tiers and completed reviews for critical vendors.
  10. A risk assessment was completed within 12 months and lives in a maintained register.
  11. Endpoints are managed: disk encryption and screen lock enforced, coverage reportable.
  12. An auditor is selected (or shortlisted) and the audit date is on a calendar.
Frequently Asked
What does the score actually mean?

It weighs the twelve controls auditors sample most, by how often each one blocks or delays real audits. It is a readiness signal, not an audit — but teams that score above 80 here rarely get surprised in fieldwork, and teams below 50 always do.

Is my answer data stored anywhere?

No — the scorer runs entirely in your browser. Nothing you click leaves the page.

What should I do with a low score?

Work the highest-weight gaps first — ownership, MFA, and access reviews move both the score and real audit outcomes fastest. Or get the measured version: our readiness assessment produces a scored gap list and a dated plan in two weeks.