Scope of the tax inspectorate audit: KVKK compliance (Article 32 - Security measures), data processing records (data controller registry), data breach notification procedure, staff training, incident response plan. Prep checklist: 1) Check if registered in the Data Controller Registry (VSS), 2) Data processing inventory (what type of data, for what purpose, retention period), 3) Security policy documentation (privacy notice, privacy policy, incident response plan), 4) IT controls (access logs, firewall rules, 2FA), 5) Staff training records (KVKK training, when it was done), 6) Data breach history (if any, how it was handled), 7) Backup procedures and tests (was a restore performed?). Questions the inspector might ask: 'Who has access to customer data', 'How is access revoked when an employee leaves', 'Who reports to whom in case of a data leak'. Vulnerability finding: If there's a breach, written 30-day remediation recommendation (administrative fine risk $500-5000). Penalty scope: Article 18 KVKK (5M-50M TL possible, but usually warning + recommendation). Periodicity: Can audit again within 5 years.