I'm an engineer in Poland with no compliance background, so if you did an audit for your app in the past (SOC 2/ISO 27001/HIPAA/PCI etc.):
1. What did you produce (Screenshots? SQL query? CSV?)
2. Who did it in your company? How long did it take? Is it a recurring task?
3. Did you build anything in-house for it? Are you still maintaining it?
If you used a tool for that then I'd appreciate if you tell me which one.