Blog

Articles on audit

What we publish on audit for CISOs, IT and compliance teams in LATAM.

Articles on what evidence an external or internal auditor expects from an awareness program: record format, review frequency and coverage by role under standards like PCI DSS 12.6 and ISO/IEC 27001. We cover the difference between showing that "a course was run" and showing that the program gets reviewed, measured and adjusted — which is what a compliance audit actually asks for today.

PCI DSS 12.6: what the auditor wants to see (and what an annual course doesn't prove)
PCI DSS, audit
Apr 2, 2026By Federico Hombre

PCI DSS 12.6: what the auditor wants to see (and what an annual course doesn't prove)

The requirement asks for a formal awareness program that includes phishing and social engineering. The evidence isn't a screenshot.

Read more

Want to see this in your organization?

Book a demo. We will look at how to measure human risk in your team and what to change first.

Book a demo