GRC Lab

GRC Lab

Home
Notes
Chat
Courses
Archive
About

What to Do When Auditors Ask for a Document That Isn't Required?

An auditor asks for a piece of paper, and your heart sinks. But what if they're wrong?
READ THE LATEST
Most Popular
View all
Why your SoA is NOT compliant!
Oct 30 • Aron Lange
The New "Big Three": How ISO 27701:2025 Completes the Modern Governance Playbook
Oct 16 • Aron Lange
The Missing Link in your Documentation
Oct 24 • Aron Lange
CMMC is Here - What's Next?
Oct 7 • Aron Lange

Recent posts

View all
Why your SoA is NOT compliant!
As an auditor, I see the same mistake all the time. Here’s what the standard actually requires.
Oct 30 • 
Aron Lange
The Missing Link in your Documentation
Discover the difference between processes and procedures.
Oct 24 • 
Aron Lange
The New "Big Three": How ISO 27701:2025 Completes the Modern Governance Playbook
ISO/IEC 27701 was finally released!
Oct 16 • 
Aron Lange
CMMC is Here - What's Next?
A guest article by Jacob Hill.
Oct 7 • 
Aron Lange
Farewell RMF, Hello CSRMC!
Today the U.S. Department of War (DoW) surprised us all.
Sep 25 • 
Aron Lange
Requirements vs. Controls
Discover the critical difference between requirements and controls in GRC, and learn how to avoid costly audit mistakes that could impact your…
Sep 21 • 
Aron Lange
Recommendations
Luiza's Newsletter
Luiza's Newsletter
Luiza Jarovsky, PhD
The Security Industry
The Security Industry
Richard Stiennon
Resilient Cyber
Resilient Cyber
Chris Hughes
Venture in Security
Venture in Security
Ross Haleliuk
© 2025 Aron Lange
Privacy ∙ Terms ∙ Collection notice
Start your SubstackGet the app
Substack is the home for great culture