The Bavarian Data Protection Authority for the Private Sector (DPA) has published a questionnaire for the GDPR implementation (pdf) in companies. This questionnaire has already been published a while ago in German (pdf), but the DPA now translated this helpful set of questions into English.
Why is this of help to you? One has to know that the questionnaire is fictional and the DPA in fact sent it out to companies but did not except answers. The purpose of the questionnaire is to help companies and offer them the possibility to examine the status quo of the GDPR implementation by answering the questions.
However, this set of questions to some extent reveals the focus of a data protection authority when it comes to the question of GDPR compliance. Of course, these questions may in the end be altered and companies (especially in Bavaria) might be faced with other questions by the DPA. But companies should have a proper look at this catalogue, because in my opinion, these questions really form the very basis of topics companies must address in the time remaining till 25th May 2018.
The questions by the DPA concern (among other topics) overview of processing activities, the involvement of third parties and accountability and risk management.