May 24, 2026

The 15-Year Audit Odyssey (2009–2024)

What 15 years of PwC, EY, KPMG and ENI SOX audits taught me about IT governance.

The Beginning: No CISO, No Team, No Framework

In 2009, I was responsible for IT security at an energy retail company with no formal security program. No CISO. No security team. No ISO 27001. No documented policies.

And then the auditors arrived.

The first audit was a learning experience I would not wish on any IT manager unprepared for it. Evidence requests for controls that didn't exist. Questions about processes that had never been documented. Findings that required immediate remediation under time pressure.

What I learned from that first audit shaped everything that followed.

The Evidence Problem

Auditors don't evaluate what you do. They evaluate what you can prove you did.

This distinction seems obvious in retrospect. At the time, it was a revelation. We had good security practices in many areas — but we couldn't demonstrate them. Undocumented controls are, from an audit perspective, non-existent controls.

The response: I built an evidence architecture. Monthly evidence collection routines. Standardized formats. Named owners for every control. A repository designed for retrieval under time pressure.

The result: evidence retrieval time dropped from days to under 2 hours. Over 15 years of audits, this single change eliminated more audit risk than any security tool we deployed.

The SOX Years

As an Eni Group subsidiary, we were subject to SOX IT General Controls. This added a layer of rigor that many companies avoid: financial IT controls, segregation of duties, change management controls, access management — all under scrutiny by Big 4 auditors who had seen every variation of control failure.

SOX audit preparation became a year-round activity, not a annual sprint. Monthly control testing. Quarterly evidence review. Continuous monitoring of privileged access.

The discipline required for SOX compliance created a security culture that benefited every other area of IT governance.

The ISO 27001 Journey

We achieved ISO 27001 certification with a solo implementation — no external consultants, no dedicated security team. The certification process took 18 months of parallel work alongside normal IT operations.

What made it achievable: a systematic approach to the gap assessment, prioritization of controls by risk impact, and — critically — management commitment that translated into resource allocation when needed.

The certification was not the goal. The goal was the control framework that certification validated. The certificate expires. The controls — if embedded in operations — don't.

The Rotating Auditor Problem

Over 15 years, auditors rotate. The PwC team that assessed us in 2012 had different interpretations than the EY team in 2017 or the KPMG team in 2021. The same control can be assessed differently by different firms, different teams, and different individuals within the same firm.

The response: build controls robust enough to satisfy any reasonable interpretation, and document the rationale for every control design decision. When an auditor challenges a control approach, the answer should not be "that's how we've always done it" but "here's the risk we're managing and here's why this control design addresses it."

Zero Critical Findings: What It Actually Means

Fifteen years of audits. Zero major findings. Zero regulatory fines.

This is not a claim of perfection. Every audit finds something. The question is the severity classification. Minor findings — process improvements, documentation gaps, control enhancements — are expected and healthy. They indicate an audit that's working.

Major findings indicate control failures that create material risk. Avoiding them over 15 years required: consistent investment in control infrastructure, year-round monitoring rather than annual preparation, and a culture where audit readiness was an operational state, not an event.

What I Would Tell My 2009 Self

Build the evidence architecture first. Before frameworks, before certifications, before tools — build the system that proves what you do. Everything else builds on that foundation.

Document not just what you do, but why. Auditors respect controls they understand. Controls that exist for clear, articulable reasons survive scrutiny. Controls that "have always been done this way" don't.

Treat audit findings as gifts. Every finding is a free gap assessment from people whose job is to find problems. The organizations that treat findings defensively miss the opportunity. The organizations that treat them as intelligence gain competitive advantage.