What Is A Compliance Audit?

What Is A Compliance Audit?
Audit coming?
The documented procedures are the part an auditor can see. Start from the HR Compliance Policies and Procedures Manual for the employment side, or the Small Business Policies and Procedures Manual for a broader documented base.

The letter arrives, or the customer questionnaire does, and the word audit lands in your inbox. The first question is rarely how to pass. It is what is actually going to be asked for, and whether the records exist in a form somebody outside the business can read.

A compliance audit is narrower and more mechanical than most people expect. It checks one operation against one defined set of rules, and it runs almost entirely on documents. This article defines the term, separates it from the internal audit it gets confused with, and then does something the definition pages skip: it works through the exact evidence set an auditor asks for on a single real requirement, so you can see the shape of the request before it arrives.

What Is a Compliance Audit?

A compliance audit is a formal review that tests whether an organization is following a specific external rule, and it reaches that conclusion by examining documented evidence rather than by asking people what they do. The rule can be a federal regulation, a state filing requirement, a licence condition, an industry standard, or a clause in a customer contract. The audit does not judge whether your process is efficient or sensible. It judges whether it matches the requirement and whether you can prove it.

Three things define the scope of any compliance audit before it starts. First, the criteria: the exact rule being tested, usually cited down to a section number. Second, the period under review, which is almost always a defined stretch of past time rather than the state of the business today. Third, the population: the employees, transactions, sites or records the sample will be drawn from.

Which rules apply to you depends on what you sell, how you employ people, and where you operate. The Small Business Administration frames a business’s legal responsibilities as depending on its business and location, and splits them into internal requirements, ongoing state filing requirements, ongoing federal filing requirements, and licences, permits and recertification, as set out in its guidance on staying legally compliant. The Federal Trade Commission organizes its own business guidance the same practical way, by topic such as advertising and marketing, credit and finance, and privacy and security, and then again by industry.

That is the useful mental model. There is no single compliance audit. There is a compliance audit against a named requirement, and a business of any size is usually exposed to several of them at once.

Who Runs a Compliance Audit?

Four different parties commission compliance audits, and the difference matters because it changes what happens when something is wrong.

  • A regulator or agency. A government body tests you against a statute or regulation it enforces. The outcome can carry back pay, penalties or a corrective order.
  • An accredited certification body. A registrar audits a management system against a published standard and issues or withholds a certificate.
  • A customer or prime contractor. A buyer audits you against the terms of a contract or a supplier code before awarding or renewing work.
  • Your own organization. You commission the same test internally, before anybody else does, to find and close the gaps while they are still cheap.

The fourth case is the one you control, and it is why a documented internal audit checklist is worth building before an external party sets the agenda. The evidence an external auditor wants is the same evidence your own reviewer would look for. Only the consequences differ.

A compliance auditor’s role is narrow by design. They gather evidence against stated criteria, test a sample, and report findings. They are not there to redesign your process, and a good one will decline to. That independence is the point of the exercise.

Compliance Audit vs Internal Audit

These two terms overlap enough to cause real confusion, because an internal audit can be a compliance audit. The distinction is not who performs it. It is what the audit is measured against.

DimensionCompliance auditInternal audit
Measured againstAn external rule, standard or contract clauseYour own policies, controls and objectives
Question askedDoes this meet the requirement?Is this control working and is the risk covered?
Typical triggerA regulator, certification cycle, customer or licence renewalAn annual plan set by management or the board
ScopeNarrow, fixed by the cited criteriaBroad, set by risk and reset each cycle
Usual outputA conformity or nonconformity findingA recommendation to improve
Who sees itOften an outside partyUsually management only

The practical consequence is about tolerance. An internal audit can conclude that a control is weak but acceptable given the risk. A compliance audit has far less room for that judgment, because the requirement either was met during the period or it was not. If you want the mechanics of how evidence gets tested in either case, the walkthrough of internal audit testing covers sampling and test design in detail.

What an Auditor Actually Asks For: A Worked Evidence Set

Definitions of compliance audits are easy to find. What is harder to find is the document list. So here is one requirement, worked all the way down to the artefacts, using federal wage and hour recordkeeping as the example because almost every business with employees is exposed to it.

The requirement is 29 CFR Part 516, the recordkeeping regulations under the Fair Labor Standards Act. The Department of Labor summarises it in Fact Sheet 21, which states that every covered employer must keep certain records for each non-exempt worker, that the Act requires no particular form for the records, and that the records must be accurate.

Read that carefully, because it contains the whole logic of a compliance audit. No particular form is required. Specific content is required. That means an auditor cannot reject your filing system, but can absolutely conclude that a required data item is missing.

Here is the list of basic records the fact sheet says an employer must maintain, paired with the artefact that normally carries each one in a small business. Assemble this column by column and you have built the evidence pack before anybody asks for it.

Required data itemWhere the proof normally lives
Employee’s full name and social security numberSigned new hire form and payroll master record
Address, including zip codePayroll master record
Birth date, if younger than 19New hire file, age verification
Sex and occupationPayroll master record and job description
Time and day of week when the workweek beginsWritten pay policy and payroll system configuration
Hours worked each dayTimecards, clock export or signed schedule exception record
Total hours worked each workweekWeekly timesheet summary
Basis on which wages are paidOffer letter or pay rate change form
Regular hourly pay ratePayroll register
Total daily or weekly straight-time earningsPayroll register
Total overtime earnings for the workweekPayroll register
All additions to or deductions from wagesDeduction authorisations and payroll register
Total wages paid each pay periodPayroll register and general ledger posting
Date of payment and the pay period coveredPay stub and bank payment file
Payroll administrator pulling timecard and payroll folders from a filing cabinet to assemble an evidence pack for an audit

Two more details in the same fact sheet decide whether the pack survives contact with an auditor. The first is retention, and it is not a single period. Fact Sheet 21 states that each employer shall preserve for at least three years payroll records, collective bargaining agreements, and sales and purchase records, while the records on which wage computations are based, such as time cards, piece work tickets, wage rate tables, work and time schedules, and records of additions to or deductions from wages, should be retained for two years.

The second is access. The fact sheet is explicit that these records must be open for inspection by the Division’s representatives, who may ask the employer to make extensions, computations, or transcriptions. Records that exist but cannot be produced in a readable form during the visit are a practical failure even when the underlying data is complete.

That is the pattern. Take a named requirement, extract the specific items it demands, name the artefact that carries each item, confirm the retention period, and confirm somebody can retrieve it on request. Repeat for every requirement that applies to you and you have built a compliance evidence register. It is the single most useful thing an operations manager can produce before a first audit.

The Compliance Audit Process, Step by Step

Most compliance audits, whoever runs them, move through the same six stages.

Step 1: Scope and Criteria Are Fixed

The auditor states the rule being tested, the period under review and the sites or entities included. Ask for this in writing. An audit without a written scope tends to expand during fieldwork.

Step 2: The Document Request Arrives

You receive a list of records, usually with a deadline that is shorter than you would like. This is where a prepared evidence register converts weeks of scrambling into a morning of retrieval.

Step 3: Documents Are Reviewed Before Anyone Is Interviewed

The auditor reads your written policies and procedures first, to establish what you say you do. Gaps found here shape every question that follows.

Step 4: A Sample Is Tested

The auditor selects a sample of employees, transactions or records and traces each one to its supporting evidence. Findings come from the sample, not from an opinion about your systems.

Step 5: Findings Are Raised and You Respond

Each finding cites the requirement, the evidence examined and the gap. You get an opportunity to supply missing evidence or dispute the reading before the report is finalised. Use it, and supply documents rather than explanations.

Step 6: Corrective Action Is Agreed and Verified

You commit to a fix with an owner and a date, and the auditor verifies it, either at the next visit or through submitted evidence. A closed finding needs proof, not a promise.

Compliance Audit Examples by Requirement

The evidence-set pattern above works on any requirement. Three short examples show how differently the same pattern lands depending on the rule.

Wage and Hour Recordkeeping

Criteria are the FLSA recordkeeping regulations. Evidence is the payroll and timekeeping pack described above. The Wage and Hour Division publishes the supporting material itself, with tools, fact sheets, posters and other guidance organized by topic, including compliance toolkits by industry, so the criteria are not a secret you have to reverse engineer.

Workplace Injury and Illness Records

Criteria here come with a much longer clock. Under 29 CFR 1904.33, you must save the OSHA 300 Log, the privacy case list if one exists, the annual summary, and the OSHA 301 Incident Report forms for five years following the end of the calendar year the records cover. The same section requires you to update stored 300 Logs during that storage period when newly recordable cases are discovered or a classification changes, which is a maintenance obligation, not just a filing one.

Federal Award Spending

Some compliance audits are triggered by a number rather than by an event. Under 2 CFR 200.501, a non-federal entity that expends $1,000,000 or more in federal awards during its fiscal year must have a single or program-specific audit conducted for that year. Entities below the threshold are exempt from federal audit requirements for that year, but the same section states that their records must remain available for review or audit. Exempt from the audit is not the same as exempt from the records.

Notice what the three have in common. Each names a specific artefact, each attaches a retention period, and each assumes somebody can produce the record on request. That is the whole test.

Can You Fail a Compliance Audit?

Most compliance audits do not produce a pass or fail grade. They produce findings, and the findings are graded. A minor finding is a gap that does not defeat the purpose of the requirement and is normally closed with corrective action. A major or critical finding is a breakdown serious enough to block a certificate, a contract award, or a licence renewal until it is fixed.

Three failure modes account for most of the damage, and only one of them is about actually breaking the rule.

  1. The requirement was genuinely not met. Overtime was miscalculated, a licence lapsed, a required form was never filed. This is the real thing and it needs a real fix.
  2. The requirement was met but cannot be evidenced. The work happened, the record does not exist, was not retained for the required period, or cannot be retrieved. An auditor can only conclude from evidence.
  3. Practice has drifted from the written procedure. Your documented process says one thing and the sample shows another. This one is often found during the document review before any testing begins.

The second and third failure modes are documentation problems wearing a compliance costume, and they are the ones a business can eliminate in advance.

How To Prepare Before the Auditor Arrives

Preparation is not a special project. It is building, once, the evidence register the audit will ask you to produce anyway.

Compliance manager turning the pages of a binder of documented procedures beside a seated auditor taking notes on a legal pad
  • List the requirements that actually apply. Employment, tax, licensing, safety, privacy, industry rules, and every compliance clause sitting inside a live customer contract. Cite each one down to the section.
  • Name the artefact for every requirement. One row per required item, one named document per row, one named owner. Blank cells are your finding list, found early and for free.
  • Record the retention period beside each artefact. Retention differs by rule, from two years on the records that support wage calculations to five years on OSHA injury records. A single company-wide retention rule will be wrong in both directions.
  • Write the procedure down. A compliance audit reads your written process first. If it does not exist, the auditor has nothing to test practice against, and you have nothing to defend it with. The guide to workplace policies and procedures covers how to structure that documentation.
  • Test a sample yourself. Pick five employees or five transactions and trace them end to end. Whatever you find, the auditor would have found.
  • Fix the retrieval problem. If producing a record takes days, that is a finding in waiting. Centralised document control through management system software solves retrieval far more reliably than a shared drive does.

Do this once and the audit stops being an event you brace for. It becomes a request you already have an answer to.

Frequently Asked Questions

What is an example of a compliance audit?

A Wage and Hour Division review of your payroll and timekeeping records against the FLSA recordkeeping regulations is a common example. The auditor names the period, requests the payroll register and time records for a sample of non-exempt employees, and checks that each required data item is present, accurate and retained for the required period.

Can you fail a compliance audit?

Most compliance audits issue findings rather than a pass or fail grade. A minor finding is closed with corrective action. A major finding can block a certificate, a contract award or a licence renewal until it is resolved, and a regulatory audit can carry back pay or penalties on top.

What is the role of a compliance auditor?

The compliance auditor gathers evidence against stated criteria, tests a sample of records, and reports findings. The role is deliberately narrow. An auditor does not redesign your process or advise on how to run it, because doing so would compromise the independence that makes the opinion worth anything.

How is a compliance audit different from an internal audit?

The difference is the yardstick, not the auditor. A compliance audit measures you against an external rule, standard or contract clause and asks whether the requirement was met. An internal audit measures you against your own policies, controls and objectives and asks whether the control is working and the risk is covered. An internal team can perform either one.

How long should you keep records for a compliance audit?

Retention is set by each requirement, not by a general rule. Under the FLSA recordkeeping regulations, payroll records, collective bargaining agreements, and sales and purchase records are preserved for at least three years, while the records wage computations are based on are retained for two. OSHA injury and illness records run five years past the end of the calendar year they cover. Record the period next to each artefact rather than applying one company-wide default.

What should you do if you cannot find a requested record?

Say so promptly, explain what you do hold, and produce any secondary evidence that supports the same fact. Silence and reconstructed paperwork are far more damaging than an acknowledged gap. Then treat the missing record as a corrective action with an owner and a date, because the auditor will expect the retrieval problem fixed, not just the document found.

Make the Documentation Line the Easy One

A compliance audit is a documentation test with a regulator’s letterhead on it. The rule is published, the required items are enumerated, the retention periods are stated, and none of it is guesswork. What separates a difficult audit from a quiet one is whether somebody wrote the procedure down and whether the evidence can be produced on the day it is requested.

So build the evidence register before anybody asks for it, write the procedures that the register points to, and test a sample yourself. The audit then examines a system you already understand, rather than discovering one you have been running by memory.

HR Compliance Policies and Procedures Manual

Editable employment compliance policies and procedures covering the recordkeeping and documentation an employment audit asks to see.

Review the HR compliance manual
Small Business Policies and Procedures Manual

A broad documented base across accounting, HR, IT and operations, ready to edit into your own process language.

Review the business manual
How To Write a Policies and Procedures Manual

The writing guide for turning an evidence register into documented procedures an auditor can actually test against.

Review the writing guide
Discover Dash

Best Manual Deals