Does the control operate as required?
An audit examines criteria and evidence. For example, an assessor may reconcile selected leaver records with account-disablement timestamps, or inspect whether a cloud audit trail is configured. The conclusion is bounded by the records, settings and period assessed.
Can an attacker cross the boundary?
A penetration test can attempt to exploit weaknesses under agreed rules. Exploitation evidence may demonstrate consequences that a configuration review cannot. It also needs its own authorisation, safety conditions, target inventory and technical expertise.
Combine them deliberately
A control review may reveal a question worth validating technically. A pentest may reveal a recurring weakness whose process cause needs audit work. Keep the objectives, procedures and evidence distinct in the statement of work, even when the reports inform each other.
Choose the relevant starting point
Read the related pentest procurement guide or prepare your audit requirements here.
Build your audit scoping brief, or send your requirements with an NDA or RFP. High-level context is sufficient for the first conversation.

