Skip to main content
Promotional banner for the pentest readiness checklist
What Do Auditors Actually Want to See in Your Compliance Program?Regulatory Obligations Management
6 min readFor Compliance Officers

What Do Auditors Actually Want to See in Your Compliance Program?

You've probably noticed your external auditors asking different questions lately. They're spending more time on your whistleblower hotline metrics. They want to know how many employees completed ethics training and what happened afterward. They're asking about investigation timelines and follow-up actions.

This isn't random curiosity. Paul Munter, the SEC's acting chief accountant, recently told audit firms they need to do better at identifying fraud risk. He specifically called out the need to assess whether companies have a genuine culture of ethics or just compliance theater. For you, that means audit season is about to get more substantive.

Here are the questions we're hearing from compliance officers who are preparing for these conversations.

Do auditors really care about my compliance program, or just financial controls?

They care about both, and increasingly they understand the two are connected.

Under [AS 2201](https://pcaobus.org/oversight/standards/auditing-standards/details/AS 2201), auditors must evaluate your entity-level controls as part of their assessment of internal control over financial reporting. Your control environment includes whether your organization demonstrates a commitment to integrity and ethical values. That's compliance program territory: your code of conduct, your whistleblower hotline, your anti-corruption training, your investigation processes.

But Munter's guidance went further. He warned auditors against simply confirming these controls exist. Every public company subject to the Sarbanes-Oxley Act has a code and a hotline. The question now is whether those controls actually work. Has your company just checked the box, or do you have evidence that employees trust the hotline enough to use it?

This shift matters because auditors are being told to look at your compliance program not as a separate compliance exercise, but as a critical component of your anti-fraud defenses.

What counts as "evidence" that my compliance program works?

Auditors want to see operational data, not policy documents.

Munter specifically mentioned employee surveys on corporate culture. If you're conducting regular culture assessments that measure trust, psychological safety, and willingness to report concerns, those results are evidence. If you're tracking whistleblower hotline metrics like report volume, time to resolution, substantiation rates, and retaliation complaints, that's evidence. If you're running periodic tests of your hotline, document those tests.

Other useful evidence includes:

  • Training completion rates broken down by department and role
  • Investigation closure reports showing root cause analysis
  • Disciplinary action logs demonstrating consistent enforcement
  • Exit interview data on whether departing employees felt comfortable raising concerns
  • Remediation tracking for control deficiencies identified through investigations

The pattern here is simple: show them what happens after you implement a control. Don't just prove you have a hotline. Show them how many calls you received, how you triaged them, how long investigations took, and what corrective actions followed.

How should I prepare for auditors to ask tougher questions?

Start by auditing your own compliance program before they do.

Review the COSO Internal Control-Integrated Framework principles related to control environment. Look at Principle 1 (demonstrates commitment to integrity and ethical values) and Principle 5 (holds individuals accountable). Ask yourself: if an auditor wanted to verify we're actually doing these things, what would I show them?

Then build a documentation habit. If you conduct an investigation, don't just close the case. Document the root cause, the corrective action, and the follow-up verification. If you deliver training, track not just completion but also assessment scores and post-training behavior changes. If you update a policy, note why you updated it and how you measured whether the change worked.

You should also coordinate with your internal audit team now. They're likely conducting their own fraud risk assessment. Make sure your investigation findings, disciplinary actions, and root cause analyses flow to them regularly. When external auditors review your fraud risk assessment process, they'll want to see that it's informed by actual incidents and investigations, not just theoretical scenarios.

What if I find gaps when I assess my own program?

Document them and show you're fixing them. Auditors understand that no control environment is perfect.

What concerns auditors (and regulators) is not finding a gap. It's finding a gap that management knew about but ignored, or finding the same gap year after year with no remediation plan. If your employee survey reveals that only 40% of staff trust the hotline, that's a problem worth addressing. But if you can show auditors that you identified the issue, implemented specific changes, and you're tracking whether trust scores improve, you've demonstrated something valuable: your compliance program has a feedback loop.

This aligns with both the U.S. Sentencing Guidelines and the Justice Department's guidance on effective compliance programs. Both frameworks emphasize periodic assessment and continuous improvement. Munter's statement is reinforcing that expectation from the audit side.

How does fraud investigation connect to all of this?

Your fraud investigations are data points in your company's fraud risk assessment.

When you investigate an incident of fraud, you should be asking: Why did this happen here? Was it a hiring problem? A control design flaw? A supervision gap? A culture issue in one department? That root cause analysis feeds into your enterprise fraud risk assessment, which auditors will review to evaluate your control environment.

For example, if you discover that employees in one region committed procurement fraud by splitting purchase orders to avoid approval thresholds, that's not just a disciplinary matter. It's evidence of a control weakness that should trigger a broader review of procurement controls and delegation of authority policies. If your investigation report includes that analysis and documents the remediation steps, you're giving auditors evidence that your anti-fraud efforts are dynamic, not static.

Make sure you have a clear process for escalating investigation findings to whoever owns fraud risk assessment at your company (often internal audit, enterprise risk, or the CFO's office). Auditors will want to see that connection.

Where should I focus if I'm short on time?

Prioritize evidence of effectiveness over policy documentation.

If you're preparing for an upcoming audit and you have limited bandwidth, focus on gathering operational metrics for your highest-risk areas. Can you show that your anti-corruption controls actually prevented or detected bribery attempts? Can you demonstrate that employees in high-risk roles completed targeted training and passed assessments? Can you prove your whistleblower hotline is accessible and that reports get investigated promptly?

Start with whatever controls are most material to your fraud risk profile. If you're in a highly regulated industry with significant third-party risk, focus on vendor due diligence and monitoring. If you have a distributed sales force with commission incentives, focus on revenue recognition controls and sales conduct monitoring.

Where to go for more

The SEC's Office of the Chief Accountant periodically issues statements on emerging audit issues. Munter's fraud risk statement is worth reading in full, along with AS 2201 for context on how auditors evaluate internal controls.

For compliance program assessment, review the Justice Department's "Evaluation of Corporate Compliance Programs" guidance and the U.S. Sentencing Guidelines Chapter 8. Both documents outline what effective compliance looks like from a regulatory perspective, and those same principles apply when auditors evaluate your control environment.

Finally, if your company uses the COSO Internal Control-Integrated Framework (and most public companies do), reread the sections on control environment and monitoring. The questions auditors will ask mirror the questions COSO says you should be asking yourself.

Promotional banner for the Penetration Report Template Kit

You Might Also Like