What the audit has to clarify
The audit should map not only the application itself, but also environment, release path, access, data, integrations, and the knowledge concentration around the system.
- access to repositories, hosting, and third parties
- critical workflows and operational risk
- release process, monitoring, and rollback options
- state of documentation, knowledge, and ownership