In a previous post, Advisera (Andrei) indicated that we are not required to send any of our completed documentation to our Supervisory Authority (I assume it’s only required in the event of a breach or complaint). If we’ve completed all our documentation and we feel that we have the proper processes and procedures in place who actually determines or how do we know if we’re GDPR-compliant?
How about a self assessment? You could use the "EU GDPR Readiness Assessment" and besides the answers also gather documentation to prove compliance. By the way, you should be able to answer Yes to all questions applicable to you. You could also engage a third party to perform an audit. The audit should focus both on processes and documents with a special focus on your Inventory of processing activities and DPIAs.
Also bear in mind that no body as of yet can certify that you are GDPR compliant. Certification bodies are yet to be established.