What's the first thing an auditor will actually ask to see?

We’re partway through and I want to prioritise. Of everything we’re producing, what does an auditor care about most, so I don’t polish the wrong thing?

Your risk assessment and the Statement of Applicability that comes off it. Get the risk picture right and most of the rest derives from it: the SoA, the treatment plan, the controls, most policies. It’s the single biggest thing an auditor works through: the risk assessment is the hub that roughly 80% of a review hangs off.

So the order that saves you time is: scope first (the boundary), then risk (what could go wrong, how badly, what you’ll do about it), then the SoA (each control marked applicable-or-not, with a reason), then the treatment plan. Policies and control evidence hang off that spine.

If you’re polishing individual policies before your risk assessment is solid, you’re polishing the wrong thing first.