[{"data":1,"prerenderedAt":317},["ShallowReactive",2],{"blog-list-en":3},[4,92,180],{"id":5,"title":6,"body":7,"date":81,"description":82,"extension":83,"locale":84,"meta":85,"navigation":86,"path":87,"seo":88,"slug":89,"stem":90,"__hash__":91},"blog\u002Fblog\u002Fen\u002Fcomo-preparar-uma-auditoria.md","How to prepare for a compliance audit",{"type":8,"value":9,"toc":72},"minimark",[10,14,18,23,26,30,33,37,40,44,57,61,64],[11,12,6],"h1",{"id":13},"how-to-prepare-for-a-compliance-audit",[15,16,17],"p",{},"An audit is only stressful when preparation is left to the end. With a continuous process, audit day becomes a formality.",[19,20,22],"h2",{"id":21},"_1-define-the-scope","1. Define the scope",[15,24,25],{},"Confirm which frameworks and controls are being audited, which systems and processes are in scope, and which period is covered (relevant for operating-effectiveness audits).",[19,27,29],{"id":28},"_2-collect-evidence-continuously","2. Collect evidence continuously",[15,31,32],{},"The most common mistake is trying to gather evidence the week before. Evidence should be captured as the work happens: logs, approval records, meeting minutes, configurations.",[19,34,36],{"id":35},"_3-run-a-gap-analysis","3. Run a gap analysis",[15,38,39],{},"Before the auditor arrives, walk every control and answer: does evidence exist? Is it current? Does it cover the whole period? Where there are gaps, open corrective actions with an owner and a due date.",[19,41,43],{"id":42},"_4-on-audit-day","4. On audit day",[45,46,47,51,54],"ul",{},[48,49,50],"li",{},"Have a single point of contact.",[48,52,53],{},"Present evidence organized by control, not by system.",[48,55,56],{},"Document every auditor request and its response.",[19,58,60],{"id":59},"stay-ready-dont-chase","Stay ready, don't chase",[15,62,63],{},"Norma turns audit prep into a permanent state rather than a sprint. Every control is already linked to its evidence and open actions.",[15,65,66,71],{},[67,68,70],"a",{"href":69},"\u002Fen\u002Fservices\u002F","Learn about Smart Audits",".",{"title":73,"searchDepth":74,"depth":74,"links":75},"",2,[76,77,78,79,80],{"id":21,"depth":74,"text":22},{"id":28,"depth":74,"text":29},{"id":35,"depth":74,"text":36},{"id":42,"depth":74,"text":43},{"id":59,"depth":74,"text":60},"2026-03-05","A practical checklist for stress-free compliance audit prep: scope, evidence collection, gap management, and audit day.","md","en",{},true,"\u002Fblog\u002Fen\u002Fcomo-preparar-uma-auditoria",{"title":6,"description":82},"como-preparar-uma-auditoria","blog\u002Fen\u002Fcomo-preparar-uma-auditoria","-YNQKfJArlUN3a4DZRi_81rAd0oX-SsgcuE9mwxTOyQ",{"id":93,"title":94,"body":95,"date":172,"description":173,"extension":83,"locale":84,"meta":174,"navigation":86,"path":175,"seo":176,"slug":177,"stem":178,"__hash__":179},"blog\u002Fblog\u002Fen\u002Fo-que-e-gestao-de-risco-grc.md","What is GRC risk management?",{"type":8,"value":96,"toc":167},[97,100,108,112,132,135,139,142,149,153,156],[11,98,94],{"id":99},"what-is-grc-risk-management",[15,101,102,103,107],{},"GRC stands for ",[104,105,106],"strong",{},"Governance, Risk & Compliance",". It is an integrated model for aligning an organization's strategy with its risk management and its obligations.",[19,109,111],{"id":110},"the-three-disciplines","The three disciplines",[45,113,114,120,126],{},[48,115,116,119],{},[104,117,118],{},"Governance"," — how the organization is directed and controlled: policies, roles, and accountability.",[48,121,122,125],{},[104,123,124],{},"Risk"," — identifying, assessing, and treating threats to business objectives.",[48,127,128,131],{},[104,129,130],{},"Compliance"," — meeting applicable laws, regulations, and standards.",[15,133,134],{},"Handled in silos, these three functions duplicate effort and lose context. Integrated, they share the same data: a risk links to the control that mitigates it, which in turn links to the evidence proving the control works.",[19,136,138],{"id":137},"why-integrate","Why integrate",[15,140,141],{},"When risk lives in one spreadsheet, compliance in another, and policies in a third place, no one has the full picture. An audit becomes a treasure hunt.",[15,143,144,145,148],{},"An integrated GRC model links ",[104,146,147],{},"standards → controls → risks → assets → processes → policies → evidence",". Change one control and everything depending on it updates automatically.",[19,150,152],{"id":151},"how-norma-helps","How Norma helps",[15,154,155],{},"Norma is built around this linked model. Instead of reconciling spreadsheets, you stay audit-ready by default.",[15,157,158,162,163,71],{},[67,159,161],{"href":160},"\u002Fen\u002Fproducts\u002F","See Norma's products"," or ",[67,164,166],{"href":165},"\u002Fen\u002Fcontact\u002F","get in touch",{"title":73,"searchDepth":74,"depth":74,"links":168},[169,170,171],{"id":110,"depth":74,"text":111},{"id":137,"depth":74,"text":138},{"id":151,"depth":74,"text":152},"2026-02-10","An introductory guide to Governance, Risk & Compliance (GRC): what it means, why integrating the three disciplines matters, and how a single platform cuts manual work.",{},"\u002Fblog\u002Fen\u002Fo-que-e-gestao-de-risco-grc",{"title":94,"description":173},"o-que-e-gestao-de-risco-grc","blog\u002Fen\u002Fo-que-e-gestao-de-risco-grc","ptwAXy34igypHsfa9BdJCyZEvvGU1R6DMCuNQwsfsTk",{"id":181,"title":182,"body":183,"date":309,"description":310,"extension":83,"locale":84,"meta":311,"navigation":86,"path":312,"seo":313,"slug":314,"stem":315,"__hash__":316},"blog\u002Fblog\u002Fen\u002Fiso-27001-vs-soc-2.md","ISO 27001 vs SOC 2: which should you choose?",{"type":8,"value":184,"toc":303},[185,188,191,195,202,206,213,227,231,287,290,294,297],[11,186,182],{"id":187},"iso-27001-vs-soc-2-which-should-you-choose",[15,189,190],{},"ISO 27001 and SOC 2 are the two information-security frameworks customers and partners ask for most. They are not competitors — they solve different problems.",[19,192,194],{"id":193},"what-iso-27001-is","What ISO 27001 is",[15,196,197,198,201],{},"ISO 27001 is an international standard for an ",[104,199,200],{},"Information Security Management System (ISMS)",". It certifies that an organization runs a continuous process of risk assessment and control implementation. The certificate is issued by an accredited body and is valid for three years, with annual surveillance audits.",[19,203,205],{"id":204},"what-soc-2-is","What SOC 2 is",[15,207,208,209,212],{},"SOC 2 is an ",[104,210,211],{},"audit report"," based on the Trust Services Criteria (security, availability, processing integrity, confidentiality, and privacy). It comes in two flavors:",[45,214,215,221],{},[48,216,217,220],{},[104,218,219],{},"Type I"," — evaluates control design at a point in time.",[48,222,223,226],{},[104,224,225],{},"Type II"," — evaluates operating effectiveness over a period (typically 3 to 12 months).",[19,228,230],{"id":229},"when-to-choose-each","When to choose each",[232,233,234,250],"table",{},[235,236,237],"thead",{},[238,239,240,244,247],"tr",{},[241,242,243],"th",{},"Criterion",[241,245,246],{},"ISO 27001",[241,248,249],{},"SOC 2",[251,252,253,265,276],"tbody",{},[238,254,255,259,262],{},[256,257,258],"td",{},"Market",[256,260,261],{},"International \u002F Europe",[256,263,264],{},"Mostly US",[238,266,267,270,273],{},[256,268,269],{},"Output",[256,271,272],{},"Certificate",[256,274,275],{},"Attestation report",[238,277,278,281,284],{},[256,279,280],{},"Focus",[256,282,283],{},"Management system",[256,285,286],{},"Operational controls",[15,288,289],{},"Many organizations end up needing both. The good news: the controls overlap heavily.",[19,291,293],{"id":292},"mapping-controls-across-frameworks","Mapping controls across frameworks",[15,295,296],{},"This is where most teams lose time — maintaining parallel spreadsheets. Norma maps a single set of controls against multiple frameworks at once, so one piece of evidence satisfies both ISO 27001 and SOC 2 requirements simultaneously.",[15,298,299,300,71],{},"Want to see how? ",[67,301,302],{"href":165},"Talk to our team",{"title":73,"searchDepth":74,"depth":74,"links":304},[305,306,307,308],{"id":193,"depth":74,"text":194},{"id":204,"depth":74,"text":205},{"id":229,"depth":74,"text":230},{"id":292,"depth":74,"text":293},"2026-01-15","A practical comparison of ISO 27001 and SOC 2 — what each framework covers, when each makes sense, and how to map controls across both.",{},"\u002Fblog\u002Fen\u002Fiso-27001-vs-soc-2",{"title":182,"description":310},"iso-27001-vs-soc-2","blog\u002Fen\u002Fiso-27001-vs-soc-2","VER1jX7ZyyuqYlsh21kD1zpKVRB_NtQ7Swke3J0z1S4",1785141782662]