Reading the documents before arriving
Preparation determines what you are able to see.
An auditor who reads the documented system beforehand arrives with specific questions. One who reads it on site spends the first day doing what could have been done at a desk and asks general questions that produce general answers.
The preparation that pays is identifying the joins: where a process hands to another function, where a requirement depends on somebody outside the organisation, and where the documentation is vague. Those are where evidence is thin.
Previous audit reports and the organisation's own internal audits are the highest-value reading available. Repeated findings across cycles say something the current cycle will not.
It is also worth looking at what the organisation publishes about itself, since claims made to customers and in tenders are commitments that the system has to support, and mismatches there are substantive.
Preparation should produce a written plan with the sample already outlined, because a sample chosen on site under time pressure will be the convenient one, and convenience is the enemy of a representative sample.
The other preparation worth doing is checking what has changed since the last audit. New sites, new products, a system migration or a change of management are where controls are least embedded, and an audit plan that samples evenly across a stable period and a period of upheaval has misallocated its effort.