Issue clear PBC and information requests that state the item, period, population, required fields and format, track owner and status, and check completeness against the source system.
Start an audit with clear expectations: prepare scope and information requests, confirm roles and escalation points in the meeting, and document agreed dates, owners and scope changes afterwards.
Test whether your evidence is relevant, reliable and sufficient — right period and population, credible sources, corroborated high-risk evidence, resolved conflicts and conclusions that do not exceed the evidence.
Start with the audit question, not the software: define and validate the data, design risk-based tests, investigate exceptions in context and save logic for reuse or monitoring.