Evaluating Action Plans
In the ISO/IEC 27001 Lead Auditor context, evaluating action plans is a key activity in closing an audit. After the closing meeting, the auditee must respond to each nonconformity raised during the audit by submitting an action plan within an agreed timeframe, often 30 to 90 days depending on the c… In the ISO/IEC 27001 Lead Auditor context, evaluating action plans is a key activity in closing an audit. After the closing meeting, the auditee must respond to each nonconformity raised during the audit by submitting an action plan within an agreed timeframe, often 30 to 90 days depending on the certification body's rules and the severity of the finding. The lead auditor's role is to determine whether each plan is acceptable before the certification decision is made or the audit is formally closed. A complete action plan typically includes the correction, which is the immediate action to eliminate the detected nonconformity. It should also include a root cause analysis explaining why the nonconformity occurred, using techniques such as the 5 Whys or fishbone diagrams. It should describe the corrective action intended to prevent recurrence, in line with clause 10.2 of ISO/IEC 27001. Finally, it should name responsible persons, set realistic deadlines, identify required resources, and state how effectiveness will be verified. The auditor evaluates whether the root cause is credible and actually addresses the underlying problem rather than the symptom. The auditor also checks whether the proposed actions are proportionate, feasible and likely to be effective, and whether the extent of the problem has been considered across other processes or locations. Timelines must be reasonable for the risk involved. If a plan is inadequate, the auditor returns it with clear reasons and requests a revision. To preserve impartiality, as required by ISO/IEC 17021-1 and ISO/IEC 27006, the auditor must not prescribe or design solutions, because that would amount to consultancy. The type of nonconformity affects follow-up. Major nonconformities usually require evidence of implementation, sometimes through a follow-up audit, before certification can be granted. Minor nonconformities may be accepted on the basis of the plan, with implementation verified at the next surveillance audit. The evaluation results are documented and support the final audit conclusion and certification recommendation.
Evaluating Action Plans in ISO/IEC 27001 Lead Auditing: A Complete Guide to Closing an Audit
Introduction
Evaluating action plans is one of the final responsibilities of an ISO/IEC 27001 Lead Auditor when closing an audit. After nonconformities have been identified and communicated at the closing meeting, the auditee must propose how it will address them. The audit team, led by the Lead Auditor, then judges whether those proposals are adequate. Evaluating action plans links audit findings to real improvement of the Information Security Management System (ISMS), so certification bodies, accreditation bodies and exam boards (such as PECB) treat it as a core competency.
Why Evaluating Action Plans Is Important
1. It makes sure nonconformities are actually resolved. An audit that identifies problems but never checks whether they are fixed adds little value. Evaluating the action plan confirms the organization has a credible path to conformity.
2. It supports the certification decision. In third-party certification, a major nonconformity usually prevents a certification recommendation. The certification body must first accept the corrections and corrective actions, and often verify them. For minor nonconformities, an accepted action plan is typically enough to proceed, with implementation verified at the next surveillance audit.
3. It upholds ISO/IEC 27001 clause 10.2 (Nonconformity and corrective action). The standard requires the organization to react to nonconformities, evaluate the need to eliminate their causes, implement the needed actions, review effectiveness and keep documented information. The auditor's evaluation checks that this process is applied correctly.
4. It protects the credibility of certification. Under ISO/IEC 17021-1 and ISO/IEC 27006, certification bodies must review and accept corrections and corrective actions. Weak evaluation undermines trust in the certificate.
5. It drives continual improvement. When action plans target root causes rather than symptoms, the ISMS becomes more robust and recurrence is prevented.
What Evaluating Action Plans Means
An action plan is a document prepared by the auditee, not the auditor, in response to each nonconformity. It typically contains:
- The nonconformity reference and description
- Correction: immediate action to eliminate the detected nonconformity (fixing the symptom), e.g., revoking the access rights of a terminated employee.
- Root cause analysis: identification of why the nonconformity occurred, using methods such as the 5 Whys, Ishikawa (fishbone) diagrams or fault tree analysis.
- Corrective action: action to eliminate the cause of the nonconformity and prevent recurrence, e.g., integrating HR termination workflows with the identity management system.
- Responsibilities: who will carry out each action.
- Timelines: target completion dates.
- Resources needed.
- Method for verifying effectiveness: how the organization will confirm the action worked.
Evaluating the action plan means the auditor reviews this document and decides whether it is acceptable, i.e., likely to eliminate the nonconformity and its causes within a reasonable timeframe.
Key Distinctions to Remember
- Correction vs. corrective action: Correction fixes the immediate problem. Corrective action removes the cause to prevent recurrence. A good plan normally contains both.
- Corrective vs. preventive action: ISO/IEC 27001:2013 and 2022 no longer have a separate clause on preventive action. Prevention is addressed through risk-based thinking (clause 6.1). Corrective action addresses nonconformities that have already occurred.
- Auditor role vs. consultant role: The auditor evaluates. The auditor does not design or recommend specific solutions, because doing so would compromise impartiality and independence.
How It Works: The Process Step by Step
Step 1: Nonconformities are communicated. At the closing meeting, the audit team presents findings, classified as major or minor, and explains the deadline for submitting action plans. A common practice is to require plans within a defined period, such as 30 days, though this varies by certification body.
Step 2: The auditee performs root cause analysis and drafts the plan. The organization investigates each nonconformity and proposes corrections and corrective actions.
Step 3: The auditor reviews the plan against acceptance criteria. The Lead Auditor checks whether:
- The root cause has been correctly identified, not just the symptom restated.
- The correction addresses the immediate issue.
- The corrective action logically eliminates the identified root cause.
- The scope is adequate: has the organization checked whether similar issues exist elsewhere (extent of the problem)?
- Responsibilities are clearly assigned.
- Deadlines are realistic and proportionate to the severity. Major nonconformities usually require faster resolution.
- Resources are available.
- A method to verify effectiveness is defined.
- The actions do not introduce new risks or nonconformities.
Step 4: Decision. The auditor either accepts the plan, or rejects it and asks for revision, explaining which criteria are not met. The auditor should explain the deficiency (for example, "the root cause analysis only restates the finding") without prescribing the exact solution.
Step 5: Verification. Depending on the nonconformity:
- Major nonconformities: Usually require verification of implementation and effectiveness before certification is granted. This may be done through documentary evidence or a follow-up (special) audit on-site.
- Minor nonconformities: An accepted action plan is usually sufficient to proceed. Implementation and effectiveness are verified during the next surveillance audit.
Step 6: Documentation and audit follow-up. The evaluation results are recorded, and the nonconformities are closed when verification is satisfactory. Under ISO 19011, audit follow-up is not formally part of the audit itself unless specified, but it is a key activity in certification audits.
Common Weaknesses Auditors Look For
- The root cause is stated as "human error" with no deeper analysis. Ask: why was the error possible? Was training, process design or oversight lacking?
- The corrective action is "retrain the employee" when the issue is systemic.
- Only a correction is provided, with no corrective action.
- Vague timelines such as "ASAP" or "in due course".
- No owner assigned.
- No effectiveness check planned.
- The action addresses a single instance without checking for similar occurrences in other departments or systems.
- Actions are disproportionate or unrealistic, for example replacing an entire system for a minor documentation gap.
Example
Nonconformity: Three of ten sampled user accounts belonging to former employees were still active (Annex A control on access rights / user access management).
Weak action plan: "Accounts disabled. Will be more careful in the future." This has a correction but no root cause, no corrective action, no owner and no timeline.
Strong action plan: Correction: all three accounts disabled immediately, and a full review of all accounts completed against the HR leaver list within 5 days. Root cause: no formal link between the HR offboarding process and IT access revocation, and no periodic access review performed. Corrective action: implement an automated HR-to-IAM deprovisioning workflow and introduce quarterly access reviews owned by system owners. Owner: IT Security Manager. Deadline: 60 days. Effectiveness check: internal audit samples leavers after two quarters.
The auditor would accept the strong plan.
Exam Tips: Answering Questions on Evaluating Action Plans
1. Know who does what. The auditee develops and implements the action plan. The auditor evaluates and accepts or rejects it. Any answer choice in which the auditor writes, designs or recommends specific corrective actions is almost always wrong. Impartiality is the key principle.
2. Distinguish correction from corrective action. Many questions test this. Correction = fix the symptom now. Corrective action = eliminate the root cause to prevent recurrence. If a scenario plan only fixes the symptom, it is incomplete.
3. Look for root cause analysis. An acceptable plan must show genuine root cause analysis. If the "root cause" just restates the nonconformity, or blames human error without investigation, the correct answer is usually to reject or ask for revision.
4. Apply the acceptance checklist. In scenario questions, check the plan for: root cause, correction, corrective action, responsible person, realistic deadline, resources and an effectiveness check. Identify which element is missing. That is often the answer.
5. Remember major vs. minor treatment. Major nonconformity: corrections and corrective actions must normally be accepted and verified (possibly by a follow-up audit) before a certification recommendation. Minor nonconformity: an accepted plan is enough to recommend certification, with verification at the next surveillance audit.
6. Link to clause 10.2. When justifying an answer, reference ISO/IEC 27001 clause 10.2: react, evaluate the need for action on causes, implement, review effectiveness, update the ISMS if needed, and retain documented information.
7. Watch for proportionality. Actions should be appropriate to the effects of the nonconformity, as clause 10.2 states. A plan that is excessive or far too weak may be unacceptable.
8. Consider the extent of the problem. Strong answers note whether the organization checked if the same issue exists elsewhere. Good auditors look for this.
9. For essay or open questions, structure your answer. (a) State what you would review, (b) assess each element against the criteria, (c) give a clear decision (accept or reject), (d) justify it with evidence and references to the standard, and (e) describe follow-up or verification. Use auditor language: "based on the evidence provided", "the root cause analysis is insufficient because...".
10. Avoid traps. Common distractors include: the auditor closes the nonconformity as soon as the plan is received (wrong, since implementation and effectiveness still need verification for closure); the auditor downgrades a major to a minor because a good plan was submitted (wrong, since classification is based on the finding, not the response); and the auditor fixes the problem on-site (wrong, since it violates independence).
11. Time-related reasoning. If a scenario mentions unrealistic deadlines, such as implementing a complex technical change in two days, or excessively long ones for a serious issue, note it as grounds for requesting revision.
12. Effectiveness is not the same as implementation. Implementation means the action was done. Effectiveness means it achieved the intended result and the nonconformity did not recur. Exam questions often test whether you know verification must cover effectiveness.
Summary
Evaluating action plans is how the Lead Auditor makes sure audit findings lead to real, lasting improvement. The auditee owns the plan. The auditor objectively judges whether it contains a sound root cause analysis, appropriate corrections and corrective actions, clear ownership, realistic timelines and a way to verify effectiveness. In the exam, stay impartial, apply the acceptance criteria systematically, distinguish correction from corrective action, and remember the different treatment of major and minor nonconformities. Mastering these points will let you answer both multiple-choice and scenario-based questions with confidence.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!