Pabau Engage inbox

Pabau Engage is here: every patient conversation in one inbox.

Learn more
Book a demo Book a demo
☰
Compliance and security

LSA audit checklist

Avatar photo Maja Popovska
Last Updated: October 7, 2026

An LSA audit checklist is a structured list of the controls, records, and corrective actions your organization must evidence during a compliance audit. “LSA audit” has no single official definition. The term is used loosely for a local or internal compliance audit, and your funder or regulator sets its scope.

The checklist walks your team through five areas: Scope, internal controls, documentation, risk, and corrective action. Run it before an external audit to find weak controls early, or use it on its own as an internal governance review. This guide covers what goes in it, how to run it, and when a different audit applies instead.

Found our content helpful?

Download your free LSA audit checklist

A fill-in compliance audit checklist with sections for audit scope, internal controls, documentation evidence, and risk evaluation. It closes with a corrective action plan that records owners and completion dates for each finding.

Download template
Key takeaways

Key takeaways

An LSA audit checklist is a compliance documentation framework that organizations use to verify adherence to regulatory standards, internal control requirements, and audit procedures.

The checklist covers five core audit areas: Compliance requirements, internal controls review, documentation evidence, risk assessment, and corrective action planning.

There is no defined LSA audit standard, so set the checklist’s scope from your funder’s or regulator’s requirements. Single Audits, LPAs, and ISO audits each differ in scope and required evidence.

Using a structured checklist reduces compliance risk, keeps you audit-ready, and gives auditors clear evidence that your governance and controls work.

What is an LSA audit checklist?

An LSA audit checklist guides your organization through a structured review of its governance, internal controls, and adherence to applicable regulations. “LSA audit” is used loosely for a local or internal compliance audit, with no standard regime behind the name. Your funder or regulator sets the scope, and the checklist adapts to it.

Some institutions use the same initials for a narrower review. Florida International University, for example, runs a required Laboratory Self Audit (LSA) for its academic and research labs. If that is the review you face, follow your institution’s own form.

For a general compliance audit, the checklist breaks the process into five actionable sections:

  • Define the compliance standard or regulation being audited.
  • Document the evidence gathered.
  • Assess how well internal controls work.
  • Identify risks or deficiencies.
  • Plan corrective actions.

Working through the same sections every time keeps each audit consistent, and every finding arrives with supporting evidence.

Who needs to complete an LSA audit?

Organizations subject to federal funding, grant oversight, or regulatory compliance may need an LSA or equivalent compliance audit. This typically includes healthcare practices, educational institutions, and nonprofits receiving federal funds. It also covers organizations subject to the Single Audit Act (31 U.S.C. 7501) and 2 CFR Part 200 Subpart F.

Even when no audit is mandated, an internal review against a structured checklist tells leadership whether governance frameworks work as intended. It also shows whether your risk controls hold up under testing.

Five areas the checklist covers

A complete LSA audit checklist addresses five core compliance areas.

  • Regulatory compliance scope: Which standards, regulations, or funding conditions apply to your organization, and for which fiscal period?
  • Internal controls assessment: Are internal control procedures in place, documented, and operating effectively to prevent or detect noncompliance?
  • Documentation and evidence gathering: What records, ledgers, policies, and procedural documentation must be assembled to support compliance claims?
  • Risk identification and evaluation: Have areas of noncompliance, weak controls, or operational risks been identified and assessed for materiality?
  • Corrective action planning: For each finding, has management documented a remediation plan, assigned ownership, and set a completion timeline?

How to run the audit in five steps

Follow these five operational steps to put the checklist to work in your organization.

  1. Define the audit scope and regulatory context. Identify which compliance standard, funding stream, or regulatory body triggers the audit requirement. Document the fiscal year, the funds or operations under review, and the applicable regulations. Examples include 2 CFR Part 200, Generally Accepted Government Auditing Standards (GAGAS), or funder-specific conditions. This clarity keeps your checklist focused on the right areas.
  2. Assign an audit lead and data collectors. Designate a compliance officer or audit lead to coordinate the audit. Assign team members to gather documentation from each functional area (finance, HR, clinical operations, IT security). Make clear who owns evidence collection for each checklist section.
  3. Gather internal controls documentation. List each control or process the checklist covers, such as approval workflows, segregation of duties, and access controls. For each one, collect the policy document, procedure manual, training records, and sample transactions showing the control in operation. This step typically takes two to four weeks.
  4. Conduct the internal controls review and risk assessment. Interview key staff, observe processes in action, and test sample transactions to verify controls work as documented. Record every deviation or weakness you find. Rate each finding for severity and materiality using your organization’s risk assessment framework.
  5. Prepare a corrective action plan for findings. For each deficiency, write a remediation plan that names the root cause and describes the corrective action. Assign an owner and set a realistic completion date. Document how you will verify the corrective action worked.

Documentation and evidence required

Before the audit begins, gather evidence in three categories: Policy documents, operational records, and transaction samples.

  • Governance policies (code of conduct, delegation of authority, conflict-of-interest disclosure)
  • Internal control procedures (approval workflows, vendor management, data security protocols)
  • Compliance certifications and training records (staff attestations, regulatory training completion)
  • Financial records and transaction samples (invoices, journal entries, approval documentation)
  • Audit work papers and prior-year audit findings with corrective action responses

If clinical documentation falls inside your audit scope, sample patient records as well. Our medical chart audit guide explains how to pick and score that sample.

Internal controls review

An internal controls review examines whether preventive and detective controls are designed and operating effectively. Every control needs three elements: A documented policy, evidence that staff understand and follow it, and examples of the control working as intended.

Common control review areas include the following:

  • Segregation of duties: No single person both approves and executes a transaction.
  • Approval thresholds: Transactions above a set dollar amount require multi-level sign-off.
  • Access controls: IT systems restrict access based on role and need.

Public companies test these same controls under federal securities law. Our Sarbanes-Oxley compliance checklist shows how that more formal review is organized.

How to handle audit findings and corrective actions

When an audit identifies a deficiency, document it clearly and respond promptly.

  1. Classify the finding. Rate severity as critical (immediate risk to compliance or finances), significant (a moderate control weakness needing timely remediation), or minor (low risk). Typically, only critical and significant findings need a formal corrective action plan.
  2. Analyze the root cause. Determine whether the deficiency stems from a missing policy, inadequate training, poor IT system design, or staff not following procedure. The root cause drives the corrective action.
  3. Design the corrective action. Outline the specific steps to fix the deficiency, who will own implementation, and when it will be complete. Examples include revising a procedure, retraining staff, implementing system controls, or adjusting approvals and segregation of duties.
  4. Set follow-up verification. Plan when and how you will confirm the corrective action worked. For example, re-test transactions 30 days after implementation, or retest controls after a quarter.
  5. Close the finding. Once evidence shows the corrective action is working, mark the finding as closed and document the closure evidence in the audit file.

LSA audit checklist vs other audit checklists

LSA audit checklists differ from Single Audits, LPA (Layered Process Audit) checklists, and ISO audit frameworks in scope, regulatory trigger, and evidence requirements.

Audit Type Regulatory Trigger Focus Typical Frequency
LSA audit checklist Local or internal compliance review, with scope set by your funder or regulator (no defined LSA standard) Internal controls and regulatory adherence Annual or as required by funder
Single Audit (2 CFR 200) Federal funds expended at or above the threshold (currently $1,000,000) Compliance with federal spending rules and grant requirements Annual, externally conducted
LPA (Layered Process Audit) Internal operational improvement initiative Production process compliance and continuous improvement Monthly or quarterly, internally conducted
ISO audit checklist ISO certification pursuit or maintenance Quality management system design and implementation Annual, third-party auditor

Use an LSA audit checklist when your organization faces local compliance requirements or internal governance reviews. If federal funding triggers the audit, you will need a Single Audit instead, which follows GAGAS and 2 CFR Part 200. For ongoing operational process audits, an LPA checklist may fit better than a formal compliance audit. The decision runs in a fixed order, shown below.

Decision diagram: spent 1,000,000 dollars or more in federal awards this fiscal year leads to a Single Audit, annual and external; pursuing ISO certification leads to an ISO audit, annual and third-party; checking one repeating process leads to an LPA checklist, monthly or quarterly; a funder, regulator or board wanting evidence of controls leads to an LSA audit checklist, annual or as the funder requires
Check the Single Audit threshold first, because crossing it decides your audit type. Threshold from 2 CFR 200.501, frequencies from the table above.

Best practices for managing the audit file

A well-run audit needs planning. Start the checklist six to eight weeks before the audit date to leave time for evidence gathering, staff interviews, and corrective action planning.

Store your checklist and supporting evidence in one central location, such as a shared drive, audit management software, or a compliance system. That way, audit leads can access it and auditors can review it during fieldwork. Assign clear ownership for each section, set deadlines for evidence submission, and track completion status weekly.

Document every finding with specific evidence (copies of policies, transaction samples, email exchanges, meeting notes) rather than generic statements. This shows auditors that you have investigated thoroughly and gives management usable data for corrective action. Practices that hold patient data should also run a HIPAA risk assessment alongside the audit, since it tests the security controls in more depth.

Tailoring the template to your organization

After downloading the template, follow these steps to tailor it to your organization.

  1. Review the template sections and identify which apply to your regulatory context. Remove or modify sections that do not apply.
  2. Add organization-specific details: The fiscal year under audit, applicable funding sources, and the name of the compliance standard. Examples include OMB Uniform Guidance, state grant requirements, or the HIPAA Privacy Rule.
  3. Assign each section to the responsible department (finance, HR, IT, clinical operations) and set submission deadlines for evidence.
  4. Customize the internal control descriptions to match your organization’s procedures. Use language from your policy manuals, not generic audit language.
  5. After the audit, preserve the checklist and work papers in your audit file. They become the baseline for next year’s audit and evidence that you maintain internal governance controls.

Check how long your funder or regulator expects you to keep the file before you archive it. If it holds patient records, medical record retention periods apply as well.

How Pabau keeps audit evidence ready for review

Without a shared system, building an audit file is slow manual work. Someone exports reports, digs signed consent forms out of shared drives, and asks staff to confirm who approved what. That collection work can swallow most of the six-to-eight-week run-up.

Pabau, the practice management platform we build, keeps that evidence where the work already happens. Patients sign consent and intake forms digitally, and the forms are stored on their record. Treatment notes are time-stamped, and role-based permissions control which staff can view or change each record.

When an auditor asks for access controls or a sample of signed consents, you pull them from one system instead of five. Our compliance software for practices page shows how permissions and time-stamped documentation work together.

Keep audit evidence organized with Pabau

Pabau stores signed forms, time-stamped treatment notes, and role-based staff permissions in one system. When the auditor asks, the evidence is already dated and in one place.

Pabau clinic management dashboard

Conclusion

Run the checklist before anyone asks for it. A team that treats it as an internal review six to eight weeks out finds weak controls while there is still time to fix them. The alternative is reading about them in the auditor’s findings.

The trade-off is effort up front. Evidence gathering alone takes two to four weeks, so give every section an owner on day one. And if your federal spending crosses the Single Audit threshold, treat this checklist as preparation for that audit, not a substitute for it.

Book a demo to see how Pabau keeps signed forms, treatment notes, and staff permissions ready for your next audit.

Continue your research

Continue your research

Auditing internal controls at a public company? Sarbanes-Oxley compliance checklist walks through the control areas a SOX review tests.

Working on a defense contract? CMMC compliance checklist covers the cybersecurity controls that certification requires.

Need a written privacy policy for your audit file? HIPAA compliance policy template gives you a starting document to adapt.

Auditing clinical records too? Medical chart audit explains how to sample and score patient charts.

Testing your data security controls? HIPAA risk assessment shows how to find and rate risks to patient data.

Frequently asked questions

What is the difference between an LSA audit and a Single Audit?

A Single Audit (2 CFR Part 200 Subpart F) is a federal compliance audit. It is required when an organization spends federal funds at or above the threshold, currently $1,000,000 a year. An LSA audit checklist is a broader compliance tool for local, state, or internal governance reviews, with no defined LSA standard behind it. Single Audits are externally conducted. LSA checklists can be internal or external, depending on the funder.

How often should we run an LSA audit?

Frequency depends on your funding source and regulatory requirements. If you spend federal funds at or above the Single Audit threshold, annual audits are mandatory. For internal governance reviews or compliance with grant requirements, annual or biennial audits are common. Check your funder’s audit requirements.

Can we use an LSA audit checklist without hiring an external auditor?

Yes. An LSA audit checklist can be used for internal compliance reviews. However, if federal funds or a specific funder require an external audit, you must engage a qualified auditor. Internal reviews complement formal audits by identifying issues before external fieldwork begins.

What should we do if we find deficiencies during the audit?

Document the deficiency clearly, identify its root cause, and develop a corrective action plan assigning responsibility and a completion date. Re-test the corrective action to confirm it is effective. Include the finding and management’s response in the audit report for transparency to the funder or audit committee.

Does the downloadable template meet federal audit standards?

The template is a starting point for internal compliance reviews. If you must undergo a federal Single Audit, the external auditor follows GAGAS (Generally Accepted Government Auditing Standards) and designs their own audit procedures. Use the template as a foundation, and adapt it to your auditor’s requirements and your funder’s compliance obligations.

Found our content helpful?
×