There’s no shame in admitting that audits are hard. For those of us in IT, hearing the word “audit” probably brings up a groundswell of negative connotations and the corresponding aggravation and headache: We know from having lived through it that tech-heavy regulatory audits — annual PCI assessments, HIPAA audits, ISO, etc. — cut directly into our staff’s ability to get their already-busy jobs done. Expect reduced productivity from employees, intrusive questions that take time to research and answer, and extra hours spent gathering evidence and reports.