The term is inherited from financial auditing, where client-prepared schedules have carried the “PBC” label for decades; security audit firms brought it along. You’ll meet the list at or just after the kickoff call, typically a few weeks ahead of fieldwork, as a shared spreadsheet or a queue in the firm’s portal. It lands in rounds: first documents and full populations — complete rosters of hires, production changes, and vendors for the period — then a follow-up round targeting the specific samples the auditor picks from them.
Every row names a thing to produce, the period it must cover, and — in a well-run response — an owner and a due date. That last part is where audits are won or lost: rows fan out across HR, engineering, and IT, and an auditor with nothing in hand has nothing to test, so a slow response stretches fieldwork week by week. The full treatment — an example list, the wave pattern, and a response playbook that spares your engineers — is on the auditor PBC list page; the one-paragraph version lives at PBC list in the glossary.
No — you’ll get one in ISO 27001, HITRUST, SOC 1, and financial-statement audits alike. Any engagement where an independent examiner tests your records starts with a version of it; the domains and sampling style shift by framework, the mechanics don’t.
One named coordinator — a compliance lead, or the managed provider in an operated program. Route everything through them: they parcel requests out to system owners, quality-check what comes back, and keep the auditor supplied without engineering calendars absorbing the churn.