The difference between an audit and an assessment essentially is the objective of each. An assessment analyzes the potential for things to happen in the future, while an audit reacts to how things were done in the past. One is no more or less important than the other, and people react to them very differently.
In an audit, there is a specific process or control “standard,” and an explanation of how activity should be performed to prove effective, essentially validating things are being done as they should be done. The primary objectives are to check whether described processes effectively conform to the stated standards, and whether the operators are following the described processes accurately.
In an assessment, there is no “standard;” they identify the current reality without the constraints of pre-defined problems. It accounts for emerging risks and reveals new insight. The primary objective is to provide direction for improvement efforts towards the goal of an ideal state within an organization’s risk tolerance.
For an organization that operates within the ISO 27000 framework, the specific purpose of assessment, whether for technical risks (specific vulnerabilities, etc.), process risks, or other risks, is to identify threats and vulnerabilities to an organization’s information and/or operations – that is, what can jeopardize the confidentiality, integrity and availability of that information, or what can threaten the continuity of operations. The internal audit on the other hand, is a listing of the controls and requirements, and then determining compliance within the whole scope of a control environment.
Assessment and audit have distinctly different purposes; an audit is to compare against a specific standard and find specific gaps, while assessments are about understanding the current state and the benefits and opportunities for improvement. Clarity in understanding the value of each is crucial to any organization risk management.