How do you know which controls are high risk before the auditor tells you?

Posted by Accurate-Yam5366@reddit | sysadmin | View on Reddit | 18 comments

CS here building a tool around audit prep. Trying to understand if this is a real problem before I invest more time in it.

From what I've read, most companies don't know which controls are high risk until the auditor tells them. Is that actually true or do compliance teams already have a way to prioritize before the audit starts?