After enough assessments you stop being surprised. The controls that sink a first attempt are almost never the sophisticated ones — they are the housekeeping items that nobody owns.
1. Asset inventory that reflects reality
If your inventory is a spreadsheet last touched nine months ago, everything downstream is unverifiable. Start here, automate discovery, and accept that the first accurate count will be uncomfortable.
2. Log retention you can actually produce
Logging is usually enabled. Retention at the required window, in a form you can search under time pressure, usually is not.
3. Joiner-mover-leaver
The leaver half is the one that fails. Ask how long a departed employee's access persists — then verify it against the last three departures rather than the policy document.
4. Privileged access
Shared admin credentials remain the most common single finding. Vault them, and make check-out an event that gets logged.
5. Third-party risk
Your assessors will ask which suppliers touch your data. If the answer takes a week to assemble, that is itself the finding.
6. Backup restoration testing
Backups almost always run. Restores are almost never tested. Schedule a real restore quarterly and keep the evidence.
7. Change management
Emergency changes are legitimate; undocumented ones are not. A lightweight record beats a heavyweight process nobody follows.
8. Awareness that is measured
Completion rates are not outcomes. Run a phishing simulation, publish the click rate, and track it over time.
None of this is exotic. That is exactly why it gets skipped.