Findings aren’t a failure. They’re what an audit system exists to catch, and in a maturing control environment, some will surface, that’s the system doing its job, not failing at it. What actually matters isn’t the number on the final report. It’s whether you have a management system that catches gaps, tracks them, and closes them before they become a pattern.
That said, I’ve walked two certifications with zero findings audit, ISO 27001, ISO 27701, and PCI-DSS simultaneously at TikTok Shop, and ISO 27001:2022 recertification at SPayLater. Neither happened by accident, and neither happened because the underlying controls were flawless. They happened because the management system behind them was doing exactly what it’s supposed to do, consistently, long before the auditor showed up. Zero findings audit, when it happens, is what a well-run system produces. It’s not the goal in itself, it’s a signal that the goal, a genuinely functioning control environment, is being met.
That distinction matters because it changes where you spend your effort. Writing the policy is the easy 20%. Making sure the policy is actually followed, evidenced, and defensible eleven months after you wrote it is the hard 80%, and it’s the part that determines the audit outcome.
The framework is not the control
Frameworks like ISO 27001, ISO 27701, or a regulator’s data protection and cybersecurity checklist give you a list of what needs to exist. They don’t tell you who owns it, how often it needs refreshing, or what proof an auditor will accept. Treating the framework document as the finish line is the single most common reason findings appear. The control existed on paper in January. Nobody checked it in September. The audit comes in October.
Operationalizing a framework means converting each control from a static requirement into a recurring operational task with an owner, a cadence, and a defined document of proof. That conversion work is IT GRC’s actual job. The framework tells you what. Your job is to build the machine that keeps it true.
Build one master tracker, and make it do two jobs
A single master tracker, mapped control by control from the framework, is the backbone of any zero findings audit process. It needs to do two things that are easy to conflate but aren’t the same thing:
Test of design confirms the control, as written, is capable of achieving its objective. This is largely a one-time or infrequent exercise, revisited when the process or system changes.
Test of implementation confirms the control is actually operating, on the evidence available right now, not on the assumption that it’s still running the way it was designed.
Separating these two columns in the tracker matters because auditors separate them too. A control can pass design and fail implementation, or vice versa, and conflating them in your own tracking is how gaps get missed internally before they get found externally. Each row should carry: control reference, owner, evidence type required, last refresh date, and next due date. If a row doesn’t have all five, it isn’t ready for audit, it’s ready for a finding.
Quarterly check-ins are the mechanism, not the paperwork
A tracker that isn’t refreshed is just a more organized version of the problem. The fix is a quarterly check-in with each control owner, not to ask “are you compliant”, but to physically pull the latest evidence, timestamp it, and confirm it still reflects reality.
This cadence does two things at once. It catches drift early, when it’s a conversation, rather than late, when it’s a finding. And it builds a paper trail showing the organization actively monitors its own controls between audits, which is itself something auditors look for. A control checked once a year and rediscovered in a panic the week before the audit reads very differently to an assessor than one with four dated, evidenced check-ins on record.
Periodic controls, access reviews, log reviews, vendor reassessments, backup restoration tests, need their own calendar with reminders, separate from the general quarterly cycle. These are the controls most likely to lapse quietly because they have no natural trigger. Nobody notices a quarterly access review didn’t happen until someone asks for it. A calendar with automated reminders removes reliance on memory, which isn’t a control.
Sponsorship has to be visible, not just present
None of the tracking mechanics work without genuine top-down sponsorship, and this is where a lot of GRC functions undersell their own leverage. A signature on a policy doesn’t move anyone. What moves people is a department head hearing, from their own chain of command, that control ownership is part of the job, not an add-on IT GRC nags them about.
The voice has to come from the top for one practical reason: department heads respond to their own chain of command, not to a compliance function with no line authority. When the CEO or board states that control effectiveness is a business priority, that statement does the organizational work IT GRC can’t do alone.
But sponsorship from the top, delivered unchanged, doesn’t land. “Maintain ISO 27701 compliance” means nothing to a customer service lead. This is where IT GRC actually earns its place: translating a top-down mandate into what it concretely means for each department, and more importantly, why it benefits them specifically, not just the organization abstractly. Access reviews prevent an ex-employee from causing a breach that lands on that department’s leader personally. Evidence logs mean an audit takes hours instead of weeks of scrambling.
Done well, this shifts compliance from being imposed to being understood. People maintain controls because they see the downside they’re avoiding and the upside they’re getting, not because a policy document told them to. That shift is what actually sustains a zero findings posture year over year, because coerced compliance decays the moment attention moves elsewhere, and understood compliance doesn’t.
The pattern behind every zero findings audit
A tracker that separates design from implementation. A cadence that forces evidence refresh before it goes stale. A calendar that doesn’t rely on anyone remembering. Sponsorship that makes the mandate real without making it feel forced. Take any one of these away and the others compensate for a while, then stop compensating right around audit season.
That’s the pattern I’ve built every zero findings result on so far, and it hasn’t failed me yet.
About Me
William Chandra is an IT GRC and data protection professional with years across Big 4 assurance, hypergrowth e-commerce, and OJK-licensed financial services. He holds CISA, CISM, CRISC, and ISO 27001:2022 Lead Auditor certifications and serves on the executive team of ISACA Indonesia’s Certification Office.
Connect with me on Linkedin or read more about IT GRC here.
