This research note discusses best practices for preparing for and managing an IT disaster recovery audit. Key findings include that audits are based on general control testing principles and require evidence of control execution, not just definition. A minimum requirement is a documented recovery plan, testing plan, and evidence of past tests. Recommendations include ensuring the audit scope is clear and that supporting evidence of past recovery plan exercises is provided if possible.