An auditor is an independent examiner who assesses whether a company's processes, systems and controls meet the requirements of a specific standard (such as ISO 27001 or SOC 2).
The auditor is the central figure in every certification process. A distinction is made between internal auditors (who examine their own company) and external auditors (who work for certification bodies or audit firms).
A good auditor does not look for mistakes in order to punish someone, but to confirm the effectiveness of the management system. For GRC teams, the "audit experience" is crucial: when an auditor sees a complete history (audit trail) of your assets in Kopexa and finds evidence immediately, that builds trust. A well prepared system massively shortens the time the auditor has to spend on site, which in turn lowers audit costs.