What is included in a tech audit?
The proposal fixes the decision, risk hypothesis, scope, exclusions, criteria, evidence request, access, interviews, conflicts, finding fields, decision forum, and closure path. Specialist security, legal, certification, or remediation work is listed separately.
How long does a tech audit take?
The schedule follows the systems, environments, access, interviews, sampling, specialist tests, evidence quality, draft challenge, and decision date. The proposal records those dependencies and the treatment of late or unavailable evidence.
How do you judge whether the audit worked?
The audit succeeds when the agreed evidence supports a decision, material uncertainty is visible, each accepted action has an accountable person, and closure requires a defined test, artefact, approval, transfer, or measured result.
Who should be involved from our side?
The decision owner, people who control the relevant systems and evidence, affected operators, and any required security, finance, procurement, legal, or transaction specialists. Conflicts and access constraints are recorded before review.