Support
No items found.

How to Talk to Auditors About Internal Controls, And Actually Get Credit for Your Work

August 5, 2026

Every year, utilities and critical infrastructure operators spend thousands of personnel-hours preparing for NERC CIP audits.  

They gather evidence, chase down asset data, reconstruct change logs, and brief internal teams on what auditors are likely to ask.  

And yet, a surprising number of organizations walk away from those audits having failed to communicate one of their most valuable assets: the quality of their internal controls program. 

At our recent User Conference, we hosted one of the most relevant and actionable sessions I have seen in years. A NERC CIP subject matter expert walked through what auditors are actually looking for when they evaluate internal controls. 

It wasn't only about if you have controls in place, but whether you can articulate them in auditor language, demonstrate they are working, and prove they are sustainable over time. 

If you run compliance operations at a utility and you have ever felt like auditors did not fully recognize the sophistication of your program, this is for you

Thank you to Chris Unton at Utilicast for sharing his years of expertise with our User Group audience. You can watch his presentation here:  

Executive Summary 

  • Clearly communicate your internal controls in auditor language by linking each control to a specific risk, regulatory requirement, and supporting evidence. 
  • Build your compliance program on complete OT asset visibility and layered controls to demonstrate that safeguards are operating effectively and consistently. 
  • Maintain a formal inventory of controls with documented ownership, evidence, and requirement mapping to simplify audits and strengthen compliance discussions. 
  • Automate asset discovery, change detection, and evidence collection to reduce audit preparation time while creating a more reliable, sustainable, and defensible controls program. 

Start With the Definition Auditors Actually Use 

Most compliance teams think of controls as only policies and procedures.  

Auditors think of them more broadly: a control is any method used to manage risk.  

That includes policies and procedures, and:  

  • organizational structures  
  • automated system behaviors 
  • and even the way you have structured your team's responsibilities. 

This distinction matters because organizations with strong compliance programs are often underselling themselves.  

They have real controls in place, such as automated asset monitoring, configuration change detection, access restriction workflows, but they are describing them to auditors in operational terms rather than control terms.  

The auditor is looking for evidence that a control exists, that it operates consistently, and that it achieves a specific objective. If you cannot frame your program that way, you are leaving credit on the table. 

Two Dimensions of an Effective Controls Program 

Unton, who boasts 25 years working in the electric utility industry, framed a mature controls program along two dimensions: risk assessment and compliance.  

These are not the same thing, though they overlap significantly. 

Risk assessment asks: What could go wrong, and how likely is it?  

Compliance asks: What does the standard require, and can we prove it?  

A strong internal controls program addresses both. This is not simply a checkbox exercise, and it is not just a theoretical risk model. It ties specific controls to specific risks, and it demonstrates that those controls are functioning as designed. 

One of the most valuable things you can do before an audit is map your existing controls to the specific NERC CIP requirements they address.  

CIP-015, for example, the new Internal Network Security Monitoring standard, requires operators to demonstrate real-time visibility into their networks. If your control is a passive traffic monitoring tool that only captures what traverses a mirror port, that may leave significant gaps.  

If your control actively communicates with assets at Level 1 of the Purdue model using native OT protocols, that is a fundamentally stronger control. This gives you the visibility and data required to back that up objectively.  

The Visibility Problem: When Operators Lack Alarms 

One of the starkest examples from the session involved operators who lacked alarm visibility across their environments. From an auditor's perspective, this is not just a gap in one control, it is evidence of a systemic visibility problem that puts the entire bulk electric system at risk. 

The session drew a direct line between asset visibility and control effectiveness.  

If you lack an accurate, current inventory of your OT assets, you cannot credibly claim that your controls are operating as designed.  

You are flying blind, and auditors know it. 

This is one reason that asset management is not just an operational function but also a foundational control in your OT environment.  

Everything downstream depends on broader functions, such as:

  • vulnerability prioritization  
  • configuration change management  
  • access control  
  • incident response.  

If your asset data is stale or incomplete, every control that relies on it is weakened. 

Layering Controls Is Strategy, Not Redundancy 

A concept that came up repeatedly in the session was the practice of deploying multiple controls to address the same risk at different points, or control layering. This is not an inefficiency.  

It is defense in depth, and auditors recognize it as a sign of program maturity. 

Consider how you might address the risk of unauthorized configuration changes. You could have a policy prohibiting unauthorized changes (administrative control), a workflow requiring change approvals (procedural control), a system that detects and alerts on configuration deviations (technical detective control), and a quarterly review process that validates the state of your environment (monitoring control).  

Each layer compensates for the weaknesses of the others. If the policy is ignored, the technical control catches it. If the technical control misses something, the quarterly review finds it. 

When you can walk an auditor through this layered structure, including naming the control, the risk it addresses, the mechanism by which it operates, and the evidence that it is functioning, you are speaking their language fluently. 

Build an Inventory of Controls, Not Just an Inventory of Assets 

One of the most actionable recommendations from the session: create and maintain a formal inventory of your internal controls, separate from your asset inventory. This document should capture:  

  • each control 
  • the risk it addresses  
  • the requirement it satisfies  
  • the evidence it generates 
  • and the owner responsible for it 

This goes beyond creating paperwork and is about making your program simple to understand to auditors who may only spend a few hours reviewing years of compliance work.  

If they can see at a glance that you have 47 controls mapped to specific CIP requirements, with owners and evidence sources documented for each, this specificity changes the character of the audit conversation.  

That shifts the audit from being examined to controlling the narrative and presenting. 

Automation Is the Difference Between a Defensible Program and a Paper One 

Manual compliance processes have a fundamental credibility problem: Auditors know that humans make mistakes, cut corners under pressure, and lose institutional knowledge when people leave.

A control that relies entirely on manual execution is inherently fragile. 

Automation changes that equation. When your asset inventory updates continuously from active device communication rather than periodic manual walkthroughs, auditors can see data timestamps and know the information is current.

When configuration change alerts fire automatically and generate logged evidence, there is no question of whether someone remembered to document the change. When compliance reports can be generated on demand with audit-ready formatting, the evidence chain is unambiguous.

We have seen utilities reclaim 80 to 85 percent of the time they previously spent on NERC CIP audit preparation simply by moving to automated data collection and reporting platforms. What used to take five hours now takes 45 minutes, highlighting efficiency gains and quality improvement.

Automated evidence is more consistent, more timestamped, and harder to dispute than manually assembled spreadsheets. 

The Sustainability Question Auditors Are Starting to Ask 

One of the more forward-looking points in the session addressed something auditors are increasingly probing: knowledge transfer. If your internal controls program depends on one or two key individuals who hold all the institutional knowledge, your program cannot be sustainable,and auditors are starting to flag that. 

Sustainability means your controls function even when your NERC CIP expert retires or moves to another organization. It means your processes are documented well enough that a new hire can follow them, and continue supporting them seamlessly.  

It also means your automated systems continue collecting data and generating alerts even when no one is actively monitoring them. This is where a well-implemented platform matters: the system carries institutional knowledge that does not walk out the door. 

What This Means for Your Next Audit 

The utilities that perform best in NERC CIP audits are not necessarily the ones with the most controls. They are the ones that can communicate their controls most clearly, by mapping each one to a requirement, a risk, an operating mechanism, and a body of evidence.  

They can demonstrate that their controls are not theoretical; they are running, logged, and tested. 

If you have been building your program the right way, with active asset monitoring, automated change detection, continuous vulnerability tracking, and audit-ready reporting, the question is whether your auditors can see it.  

Speaking their language, structuring your evidence the way they expect it, and engaging stakeholders across your organization before the audit begins are the factors that separate a passing audit from a strong one. 

Industrial Defender has been helping utilities build and demonstrate exactly this kind of program since 2006.  

If you are preparing for a NERC CIP audit or looking to strengthen your internal controls program before CIP-015 compliance deadlines arrive, we are glad to show you how our platform supports each layer of the control's framework described above.

AUTHOR

Alex Bagwell – Chief Revenue Officer, Industrial Defender