See the page for Vault: https://www.hashicorp.com/vault-compliance
Or 1Password: https://support.1password.com/security-assessments/
As the comment from jbotz mentioned, exposing secrets in environment variables seems like a major issue and it would be one of the first points covered in such an audit.