Compliance
Advanced
50 min

Plan an Internal Audit

Pro

Scope, resource, schedule, and risk-based test plan for an annual internal audit cycle.

Company brief
WovenCart

Retail · Global

Description

D2C apparel brand with 400 employees, peak-season traffic concentrated in November-December.

Analyst task

Quantify the PCI scope question for the next QSA and write the internal page that walks finance through what is and is not in PCI scope at WovenCart.

Systems

  • Shopify Plus
  • AWS (ECS, RDS)
  • Marketing CDP
  • Warehouse management system

Regulatory exposure

  • PCI DSS
  • CCPA / state privacy laws
  • GDPR for EU customers

Top risks

  • Peak-season DDoS
  • Cardholder data leakage via marketing tooling
  • Phishing of finance team during peak
  • Open-source dependency compromise

Audit concerns

  • PCI scope clarity (Shopify handling vs in-scope systems)
  • Marketing CDP data flow documentation

Write your answer

Pro
Loading lab…