How to prepare a software change audit: a checklist

A practical checklist for a software change audit: what auditors sample, the evidence each change needs and how to answer in hours instead of weeks.

1 min read

What auditors sample

Change audits usually pick a sample of changes from a period and test each one against your change-management policy. The questions repeat, so the evidence can be prepared once and kept with every change.

The checklist for each change

  • The request and its business justification.
  • The requirement or story it implements.
  • The code: the branch, the pull request and its reviewer.
  • The test results and the environment where they ran.
  • The authorization: who, when and with which minutes.
  • The installation evidence in each environment.
  • The rollback plan, and what happened if it was used.
  • The complete history of state changes.

Check your policy against reality

  • Does the tool enforce the steps the policy describes?
  • Are the approvers the roles the policy names?
  • Is segregation of duties visible in the records?
  • Are emergency changes reviewed afterwards?

Answer in hours

When every change carries its evidence, the audit sample becomes a list of downloads. In DevGob that is one evidence package per change, hashed and signed, plus the audit log as CSV.

DevOps with governance, on one record

DevGob plans the work and governs every change on its way to production: backlog, sprints, committee authorizations, install evidence and an audit trail.