Security Standards

GSMA audit: what to expect on the day and how to prepare

A practical walkthrough of a GSMA SAS audit day — who attends, what auditors examine first, and the evidence gaps that most often become findings.

GSMA audit: what to expect on the day and how to prepare
10 September 2026 · 11 min read

What a GSMA audit is really testing

A GSMA SAS audit is not a generic ISO-style management system review. Auditors work from a published consolidated controls list and expect evidence that physical, personnel, production and logical controls operate as written — on the day and in the records.

Whether the engagement is SAS-UP (UICC / SIM / eSIM production) or SAS-SM (subscription management), the pattern is the same: walk the secure zones, interview operators and security staff, sample ceremony and logistics records, and test whether the layering of controls holds under real conditions.

What happens on audit day

Expect an opening meeting, a site and system orientation, then a mix of physical inspection, document sampling and interviews. Auditors often start where findings are historically common: zone boundaries, access control and anti-passback, CCTV coverage and retention, key or cryptographic ceremonies, and scrap or reject reconciliation.

You should have a named escort, a prepared evidence pack mapped to the checklist, and process owners who can demonstrate the control — not only point at a procedure. Closing meetings summarise findings; non-conformities need a clear corrective action path.

Evidence gaps that most often become findings

Procedures that do not match how operators actually work. Logs that are retained but never reviewed. Screening that covers employees but not contractors. Quantity variances in card or component flows without a documented investigation. Key ceremonies described in policy but thin in completed records.

Change is another trap: a new product line, courier, hosting environment or shift pattern that was never assessed against the SAS checklist. Maintain a change register with security impact assessments and renewals become reviews rather than rediscovery exercises.

How to prepare in the final eight weeks

Run an independent mock audit against the current GSMA requirements. Close critical gaps. Rehearse interviews with operators and security staff. Confirm CCTV retention, access reviews and ceremony logs are complete for the recent period auditors will sample.

AACL Global supports pre-audit readiness, mock audits and onsite or remote support during the formal GSMA audit for SAS-UP and SAS-SM programmes. If your audit date is fixed, start the final preparation window as early as you can.

To discuss this subject with our practitioners, write to info@aacl.co.ke.

WhatsAppSignalThreemaCall now