Preparing Audit Conclusions
In the ISO/IEC 27001 Lead Auditor framework, preparing audit conclusions is a key activity in the closing phase. The audit team turns the evidence and findings gathered during the audit into an overall judgment about the auditee's Information Security Management System (ISMS). Following ISO 19011 a… In the ISO/IEC 27001 Lead Auditor framework, preparing audit conclusions is a key activity in the closing phase. The audit team turns the evidence and findings gathered during the audit into an overall judgment about the auditee's Information Security Management System (ISMS). Following ISO 19011 and ISO/IEC 17021-1, the conclusions must be objective, evidence-based and tied directly to the audit objectives, scope and criteria. Before the closing meeting, the audit team leader holds a team meeting to review all findings. The team checks each nonconformity, observation and opportunity for improvement against its supporting evidence to confirm accuracy, traceability and correct classification, such as major or minor nonconformity. The team also considers the uncertainty that comes with audit sampling and resolves any disagreements among members to reach consensus. The conclusions typically address several areas: 1. The degree to which the ISMS conforms to ISO/IEC 27001 requirements, including the clauses and Annex A controls as justified in the Statement of Applicability. 2. The effective implementation, maintenance and continual improvement of the ISMS. 3. The capability of management review and internal audit to keep the system suitable, adequate and effective. 4. Whether the audit objectives were achieved and the scope fully covered. The team then prepares recommendations. In certification audits, this means recommending one of three outcomes: granting or maintaining certification, granting it conditionally once corrective actions for nonconformities are accepted, or not recommending certification. Final certification decisions remain with the certification body, not the auditors. If the audit plan requires it, the team may also note follow-up activities. The lead auditor should present the conclusions clearly and neutrally. Unresolved diverging opinions between the audit team and the auditee should be discussed and, if possible, settled, or otherwise recorded. Well-prepared conclusions form the basis of the closing meeting and the audit report. They give stakeholders a credible, impartial view of how well the organization manages information security risks.
Preparing Audit Conclusions in ISO/IEC 27001 Lead Auditing: A Complete Guide
Introduction
Preparing audit conclusions is one of the final and most important activities a Lead Auditor carries out before the closing meeting of an ISO/IEC 27001 audit. It is the point where all the evidence, findings and observations gathered during the audit are brought together. From them, the audit team forms an overall, objective judgement about the Information Security Management System (ISMS) against the audit objectives and audit criteria. This guide explains what audit conclusions are, why they matter, how they are prepared in line with ISO 19011 and ISO/IEC 17021-1, and how to answer exam questions on the topic.
What Are Audit Conclusions?
ISO 19011:2018 defines an audit conclusion as the outcome of an audit, after consideration of the audit objectives and all audit findings.
It helps to see where conclusions sit in the chain of audit outputs:
1. Audit criteria: the requirements used as a reference, such as ISO/IEC 27001 clauses, Annex A controls, the organisation's policies, and legal and contractual requirements.
2. Audit evidence: records, statements of fact or other information that is relevant to the criteria and verifiable.
3. Audit findings: the results of evaluating the evidence against the criteria. Findings may show conformity, nonconformity (major or minor), opportunities for improvement or good practice.
4. Audit conclusions: the overall outcome reached by considering all findings in light of the audit objectives.
In short: evidence leads to findings, and findings combined with the objectives lead to conclusions. A conclusion is not a single finding. It is a holistic judgement about the ISMS as a whole within the audit scope.
Why Preparing Audit Conclusions Is Important
1. It fulfils the audit objectives. Every audit has defined objectives. Examples include determining conformity with ISO/IEC 27001, evaluating whether the ISMS is effective at meeting its intended outcomes, or deciding whether certification can be recommended. Conclusions directly answer these objectives.
2. It supports certification decisions. In third-party audits, the audit team's conclusion and recommendation feed into the certification body's decision process. Under ISO/IEC 17021-1, that decision is made by persons not involved in the audit. A well-reasoned conclusion makes the decision defensible.
3. It ensures objectivity and consistency. A structured team discussion reduces individual bias. It also ensures that all findings are weighed consistently and that conclusions rest on evidence, not opinion.
4. It reflects the evidence-based approach. ISO 19011 lists an evidence-based approach as a core principle of auditing. Conclusions must be traceable back to verifiable evidence.
5. It adds value for the auditee. Clear conclusions help top management understand how capable and mature their ISMS is, where the risks lie and where improvement is needed.
6. It underpins the closing meeting and the audit report. The closing meeting and the final report communicate the conclusions. Poorly prepared conclusions lead to disputes, confusion and loss of credibility.
How Preparing Audit Conclusions Works
ISO 19011:2018 (clause 6.4.9) describes preparing audit conclusions as a team activity carried out before the closing meeting. It typically involves the following steps.
Step 1: The audit team meets privately
The audit team leader convenes the team, including any technical experts, without the auditee present. Observers and guides do not take part in forming conclusions. The aim is to review and reach agreement on the audit outcomes.
Step 2: Review the audit findings against the audit objectives
The team reviews all findings and any other appropriate information collected during the audit. For ISO/IEC 27001 this includes:
- the mandatory ISMS requirements in Clauses 4 to 10
- the Statement of Applicability (SoA) and the justification for including or excluding Annex A controls
- the results of risk assessment and risk treatment
- internal audit and management review outputs
- the performance evaluation and improvement processes
Step 3: Consider the uncertainty inherent in the audit process
Audits are based on sampling, so there is always some uncertainty. The team should recognise this when reaching conclusions. It should also state in the report that the evidence was based on a sample of the available information.
Step 4: Agree on the audit conclusions
The team aims to reach consensus on:
- the extent of conformity with the audit criteria and how robust the ISMS is
- how effectively the ISMS is implemented, maintained and improved
- whether the ISMS is capable of achieving its intended outcomes, such as protecting confidentiality, integrity and availability
- how well the audit objectives have been met
- whether the audit scope was adequately covered
- any similar findings across different areas that point to systemic trends
Step 5: Grade and confirm nonconformities
Findings are confirmed and classified:
- A major nonconformity affects the ability of the ISMS to achieve its intended results. Examples are the total absence of a required process such as risk assessment, or a systemic failure.
- A minor nonconformity does not affect the ability of the ISMS to achieve its intended results. It is typically an isolated lapse.
The team checks that each nonconformity is supported by objective evidence and clearly linked to a specific requirement.
Step 6: Prepare recommendations (if specified in the audit objectives)
In certification audits, the team decides on a recommendation. Possible recommendations are:
- grant, maintain or renew certification
- grant certification conditionally, subject to acceptance of correction and corrective action plans for minor nonconformities
- withhold certification until major nonconformities have been corrected and verified, possibly through a special or follow-up audit
- in the case of surveillance, suspend or withdraw certification
Recommendations for improvement, if included, must be impartial. For third-party auditors they must not amount to consultancy. Auditors must not propose specific solutions.
Step 7: Discuss audit follow-up (if applicable)
The team identifies whether follow-up is needed. This could be verifying corrective actions remotely, reviewing evidence of correction, or planning a follow-up visit.
Step 8: Prepare for the closing meeting
The team leader organises the conclusions so they can be presented clearly. This includes confirming the wording of nonconformities, preparing a summary of strengths and weaknesses, and anticipating possible disagreements from the auditee.
Key Inputs and Outputs
Inputs: the audit plan and objectives, the audit criteria, audit evidence, the findings log, auditor notes, previous audit results, the SoA and risk treatment plan, and the results of document review.
Outputs: agreed audit conclusions, classified nonconformities, a certification recommendation where applicable, follow-up requirements, and the basis for the closing meeting presentation and audit report.
Common Characteristics of Good Audit Conclusions
- Evidence-based: traceable to verifiable audit evidence.
- Objective and impartial: free from personal bias or pressure from the auditee.
- Balanced: they recognise both strengths and weaknesses.
- Aligned with objectives: they answer the specific objectives in the audit plan.
- Clear and concise: understandable by top management.
- Consensus-based: agreed by the audit team, with the team leader responsible for the final decision.
Handling Disagreement
Within the audit team: Differences of opinion should be discussed and resolved using evidence. The audit team leader is ultimately responsible for the conclusions.
With the auditee: Diverging opinions about findings or conclusions should be discussed and, where possible, resolved during the closing meeting. Under ISO 19011, if they cannot be resolved, they should be recorded. In certification, unresolved disputes may be referred to the certification body's appeals or complaints process.
Practical Example
During a stage 2 certification audit of a cloud services provider, the team identified the following:
- one minor nonconformity in access review records, where two quarterly reviews were missed
- one minor nonconformity in supplier security monitoring
- strong evidence of an effective risk assessment process
- a well-maintained SoA
- a functioning management review
In the private team meeting, the team concluded that the ISMS conforms to ISO/IEC 27001 except for the two minor nonconformities. They also concluded that the ISMS is effectively implemented and capable of achieving its intended outcomes. The team recommended certification, subject to acceptance of corrective action plans within the defined timeframe.
If instead the organisation had never performed an internal audit (Clause 9.2), the team would raise a major nonconformity. It would then recommend that certification be withheld until the nonconformity was corrected and verified.
Relationship to Other Closing Activities
- Preparing audit conclusions comes first. It is a private team activity.
- The closing meeting follows. Here the conclusions and findings are presented to the auditee.
- Preparing and distributing the audit report comes next. The report formally documents the conclusions.
- Audit follow-up covers verification of corrections and corrective actions.
Exams often test whether you know this sequence.
Exam Tips: Answering Questions on Preparing Audit Conclusions
1. Know the definitions precisely. Be able to tell audit evidence, audit findings and audit conclusions apart. A frequent trick question presents a single nonconformity as a conclusion. Remember that conclusions consider all findings and the audit objectives.
2. Remember who prepares conclusions and when. The audit team prepares them, led by the audit team leader, before the closing meeting and without the auditee. Observers, guides and auditee representatives do not take part.
3. Link conclusions to the audit objectives. In scenario questions, always ask yourself what the objectives of the audit were. If the objective was certification, the conclusion should include a certification recommendation.
4. Recognise sampling and uncertainty. Conclusions should acknowledge that audits are based on samples. If an answer option suggests conclusions guarantee full conformity, it is likely wrong.
5. Distinguish major from minor nonconformities. Scenario questions often ask you to classify a finding. Ask whether it affects the ability of the ISMS to achieve its intended results, or whether it is systemic or a total absence of a requirement. If so, it is major. Isolated lapses are minor.
6. Know the certification decision boundary. The audit team recommends; the certification body decides. An answer stating that the lead auditor grants certification is incorrect under ISO/IEC 17021-1.
7. Avoid consultancy. In essay or scenario answers, never propose specific technical solutions for nonconformities as a third-party auditor. You can state that corrective action is required, but the auditee determines how.
8. Use structured answers in essay questions. A strong answer typically:
(a) defines audit conclusions
(b) states that the team meets privately before the closing meeting
(c) lists the activities: reviewing findings against objectives, considering uncertainty, reaching consensus, classifying nonconformities, preparing recommendations and identifying follow-up
(d) links the conclusions to the specific scenario, for example by recommending certification with conditions
(e) justifies the answer with evidence from the case
9. Reference the standards correctly. Cite ISO 19011:2018 clause 6.4.9 for preparing audit conclusions, and ISO/IEC 17021-1 for certification audit requirements. Use ISO/IEC 27001 clause numbers when classifying nonconformities, for example 6.1.2 for risk assessment, 9.2 for internal audit and 9.3 for management review.
10. Watch for keywords in multiple-choice questions. Words like all findings, audit objectives, audit team, consensus and before the closing meeting usually point to correct answers. Words like auditee agrees, single finding, lead auditor certifies or after the report usually point to distractors.
11. Address disagreements correctly. If a question asks what to do when the auditee disagrees with a conclusion, the correct approach is to discuss it with evidence and attempt to resolve it. If it cannot be resolved, record the divergent opinion. Never simply remove a valid finding because of auditee pressure.
12. Balance the conclusion. High-scoring answers mention both positive aspects (strengths, effective controls) and negative aspects (nonconformities, risks). This shows a holistic, fair judgement.
Summary
Preparing audit conclusions is the critical step that turns raw audit findings into a meaningful, objective judgement about an organisation's ISMS. It is carried out privately by the audit team before the closing meeting. It considers all findings against the audit objectives, acknowledges sampling uncertainty, classifies nonconformities and, where required, produces a certification recommendation. In the exam, focus on precise definitions, roles, sequence, nonconformity classification, the limits of auditor authority, and structured, evidence-based reasoning.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!