Audit checklists for the standards and regulations you’re audited against.

EU regulations and ISO standards, decomposed to the individual article, annex and clause and verified line by line. Accompanied by a free Compliance Matrix documenting the regulatory coverage for every checklist.

01 / Coverage

Paragraph-level verification

Each article, annex and clause reviewed individually and either mapped to one or more audit questions or recorded as informational. The signed Compliance Matrix accompanying every checklist documents this line by line.

02 / Authorship

Reviewed against a stated regulation version

Authored and reviewed by compliance management professionals with decades of regulatory experience. Each Compliance Matrix identifies the regulation version it was reviewed against.

03 / Deliverable

Five artefacts per Part

One canonical content set, five render targets for the Part you buy: Audit Checklist (PDF, MD), Audit Workbook (XLSX), Data Bank (CSV), Question Bank (XML). The Compliance Matrix ships separately with every Part as a downloadable verification document.

The auditchecklists.org catalog

23 available
Details for EU Whistleblowing Directive
EU Whistleblowing Directive

EU Whistleblowing Directive — Internal Reporting

Directive (EU) 2019/1937 audit checklist. Internal reporting channels, follow-up procedures, confidentiality, record-keeping and the prohibition of retaliation.

46 questions · v2019-10-23

€300 — includes 12 months of updates
Details for European Accessibility Act
European Accessibility Act

European Accessibility Act — Products & Services

Directive (EU) 2019/882 audit checklist. Economic-operator obligations — manufacturers, authorised representatives, importers, distributors and service providers — accessibility requirements (Annex I), conformity assessment, CE marking, the EU declaration of conformity and the disproportionate-burden assessment.

80 questions · v2019-04-17

€450 — includes 12 months of updates
Details for ISO 45001:2018
ISO 45001:2018

ISO 45001:2018 — Occupational Health & Safety Management Systems

ISO 45001:2018 audit checklist. Worker consultation and participation, hazard identification, OH&S risk and opportunity assessment, legal requirements, the hierarchy of controls, contractors and emergency preparedness, incident investigation, internal audit and management review — Clauses 4–10, full-split.

121 questions · v2018-03-12

€450 — includes 12 months of updates
Details for ISO 14001:2015
ISO 14001:2015

ISO 14001:2015 — Environmental Management Systems

ISO 14001:2015 audit checklist. Environmental aspects (life-cycle perspective), compliance obligations, environmental objectives, operational and emergency controls, evaluation of compliance, internal audit and management review — Clauses 4–10, full-split.

93 questions · v2015-09-15

€450 — includes 12 months of updates
Details for EU Data Act
EU Data Act

EU Data Act — Data Access, Sharing & Cloud Switching

Regulation (EU) 2023/2854 audit checklist. Entity obligations — data accessibility by design, data-holder access and sharing duties, third-party obligations, FRAND conditions and compensation, unfair contractual terms, B2G data sharing, switching between cloud/data-processing services, international transfer safeguards and smart-contract requirements.

94 questions · v2023-12-13

€450 — includes 12 months of updates
Details for CSDDD
CSDDD

Corporate Sustainability Due Diligence Directive (CSDDD)

Directive (EU) 2024/1760 audit checklist. The company due-diligence cycle — integrating due diligence into policy, identifying and prioritising adverse human-rights and environmental impacts, preventing and bringing them to an end, remediation, stakeholder engagement, complaints, monitoring, communicating and the Article 22 climate transition plan.

31 questions · v2024-06-13

€300 — includes 12 months of updates
Details for CSRD
CSRD

Corporate Sustainability Reporting Directive (CSRD)

Directive (EU) 2022/2464 audit checklist. The undertaking sustainability-reporting obligations — the dedicated sustainability statement, double materiality, business-model and transition-plan disclosures, targets, due diligence, value chain, ESRS conformity, digital tagging, publication and board responsibility.

25 questions · v2022-12-14

€300 — includes 12 months of updates
Details for ISO 37001:2016
ISO 37001:2016

ISO 37001:2016 — Anti-bribery Management Systems

ISO 37001:2016 audit checklist. Bribery risk assessment, anti-bribery policy and compliance function, employment due diligence, due diligence on transactions and business associates, financial and non-financial controls, gifts and hospitality, raising concerns and investigating bribery — Clauses 4–10, deep full-leaf split.

79 questions · v2016-10-15

€450 — includes 12 months of updates
Details for ISO 31000:2018
ISO 31000:2018

ISO 31000:2018 — Risk Management

ISO 31000:2018 audit checklist. The risk-management principles, framework (leadership, integration, design, implementation, evaluation, improvement) and process (communication, scope/context/criteria, risk assessment, treatment, monitoring, recording and reporting) — the foundation underpinning the risk clauses of ISO 27001, 37301, 45001 and 22301.

21 questions · v2018-02

€300 — includes 12 months of updates
Details for ISO 37301:2021
ISO 37301:2021

ISO 37301:2021 — Compliance Management Systems

ISO 37301:2021 audit checklist. Compliance obligations, compliance risk assessment, compliance culture and governance, the compliance function, controls, raising concerns, investigations, monitoring and management review — Clauses 4–10, full-split.

94 questions · v2021-04

€450 — includes 12 months of updates
Details for GDPR
GDPR

General Data Protection Regulation

GDPR audit checklist. Controller / processor obligations under Reg (EU) 2016/679.

381 questions · v2016-05-04

€600 — includes 12 months of updates
Details for NIS2
NIS2

Network & Information Security Directive (NIS2)

NIS2 audit checklist. Cybersecurity risk-management and reporting duties under Dir (EU) 2022/2555.

46 questions · v2022-12-14

€300 — includes 12 months of updates
Details for CRA
CRA

Cyber Resilience Act

CRA audit checklist. Cybersecurity requirements for products with digital elements under Reg (EU) 2024/2847.

153 questions · v2024-10-23

€600 — includes 12 months of updates
Details for NIS2 Impl.
NIS2 Impl.

NIS2 Implementing Regulation — Technical Measures

NIS2 implementing-act audit checklist. Technical and methodological requirements under Reg (EU) 2024/2690.

328 questions · v2024-10-17

€600 — includes 12 months of updates
Details for ISO/IEC 27001
ISO/IEC 27001

ISO/IEC 27001:2022 — ISMS

ISO/IEC 27001:2022 audit checklist. Information security management system clauses and Annex A controls.

219 questions · v2022-10-25

€600 — includes 12 months of updates
Details for ISO 9001
ISO 9001

ISO 9001:2015 — QMS

ISO 9001:2015 audit checklist. Quality management system requirements, clauses 4-10.

294 questions · v2015-09-15

€600 — includes 12 months of updates
Details for ISO/IEC 27002
ISO/IEC 27002

ISO/IEC 27002:2022 — Controls

ISO/IEC 27002:2022 audit checklist. Implementation guidance for the 93 ISO 27001 Annex A information security controls.

243 questions · v2022-02-15

€600 — includes 12 months of updates
Details for ISO/IEC 42001
ISO/IEC 42001

ISO/IEC 42001:2023 — AIMS

ISO/IEC 42001:2023 audit checklist. AI management system clauses, Annex A controls and informative annexes.

127 questions · v2023-12-18

€450 — includes 12 months of updates
Details for EU AI Act
EU AI Act

EU Artificial Intelligence Act

EU AI Act audit checklist. Provider and deployer obligations under Reg (EU) 2024/1689.

263 questions · v2024-07-12

€600 — includes 12 months of updates
Details for ISO 22301
ISO 22301

ISO 22301:2019 — BCMS

ISO 22301:2019 audit checklist. Business continuity management system requirements, clauses 4-10.

89 questions · v2019-10-31

€450 — includes 12 months of updates
Details for DORA
DORA

Digital Operational Resilience Act

DORA audit checklist. ICT risk-management, incident reporting and third-party duties under Reg (EU) 2022/2554.

237 questions · v2022-12-14

€600 — includes 12 months of updates
Details for DORA RTS
DORA RTS

DORA — Regulatory Technical Standards

DORA RTS audit checklist. The delegated technical standards elaborating DORA ICT risk-management and reporting.

480 questions · v2024

€600 — includes 12 months of updates

Questions answered

Short answers to what compliance managers ask before buying. For the full list including edge cases, see the complete FAQ.

Who wrote this checklist?

Authored and reviewed by compliance management professionals with decades of regulatory experience. Every Part is built question-by-question against the published regulation — every article, annex and clause — not extracted, not paraphrased, not generated wholesale. Every paragraph is signed off and recorded as covered, informational, or out of scope in the Compliance Matrix that ships with every Part as a downloadable verification document.

How do I know every paragraph of the regulation is covered?

Every Part ships with the Regulatory Compliance Matrix as a downloadable verification document. It lists every paragraph of the regulation as a row, with its coverage status (Covered / Informational / Out of scope) and the audit questions that map to it. You can verify the methodology paragraph-by-paragraph before paying. It's the auditor-of-the-auditor artefact.

What happens if the regulation is amended during my 12 months?

Every regulatory amendment within your 12-month update window is re-authored against the new version, re-rendered through the same pipeline, and emailed to you automatically. Our publish SLA is 30 days from the date the regulator publishes — non-delivery within that window counts as a defect under our refund policy.

Is this a subscription? Will my card be auto-debited?

No. It's a one-off purchase that includes 12 months of updates. Same procurement shape as buying a consultant cycle or a an annual standards subscription — single invoice, single approval line, no card-on-file. Thirty days before your update period ends we'll email you a one-click link to buy the next 12 months. You choose; nothing happens automatically. If you don't renew, you keep every artefact you've already downloaded — they're yours forever.