Recommendation for Certification
In the ISO/IEC 27001 Lead Auditor framework, the recommendation for certification is one of the final steps when closing an audit. Once the Stage 2 audit is complete, the audit team leader reviews all audit evidence, findings, and conclusions. Based on this review, the team decides whether the audi… In the ISO/IEC 27001 Lead Auditor framework, the recommendation for certification is one of the final steps when closing an audit. Once the Stage 2 audit is complete, the audit team leader reviews all audit evidence, findings, and conclusions. Based on this review, the team decides whether the auditee's Information Security Management System (ISMS) conforms to ISO/IEC 27001 requirements and is effectively implemented. The recommendation is then formally submitted to the certification body. The recommendation is not the certification decision itself. Under ISO/IEC 17021-1 and ISO/IEC 27006, the final decision must be made by a person or committee within the certification body who did not take part in the audit. This separation preserves impartiality. The auditor's role is to provide a well-founded, evidence-based recommendation, and the certification body grants, refuses, maintains, or withdraws certification. Typically, the audit team leader can choose one of three recommendations. The first is unconditional certification, used when no nonconformities, or only observations, were found. The second is conditional certification. For minor nonconformities, this usually depends on the certification body accepting the auditee's corrective action plan. For major nonconformities, it depends on verification that corrections and corrective actions are effective within a defined period, often through a follow-up audit or document review. The third is a recommendation against certification. This is used when serious or numerous major nonconformities show the ISMS is not effective, or when key elements are missing, such as risk assessment, the Statement of Applicability, internal audit, or management review. The recommendation must be supported by objective evidence and clearly recorded in the audit report. During the closing meeting, the audit team leader presents the findings and the recommendation to the auditee's management. The leader must also explain that the recommendation still has to be confirmed by the certification body. Similar recommendations are made after surveillance and recertification audits. In those cases, the auditor recommends whether certification should be maintained, renewed, suspended, or withdrawn.
Recommendation for Certification: Closing an ISO/IEC 27001 Audit
Introduction
The recommendation for certification is the final professional judgment the audit team leader makes at the end of an ISO/IEC 27001 initial certification audit (and, in adapted form, at recertification). It turns everything gathered during Stage 1 and Stage 2 into one clear statement to the certification body: should this organization's Information Security Management System (ISMS) be certified, certified only after certain conditions are met, or not certified at all? For the ISO/IEC 27001 Lead Auditor exam, you must understand what the recommendation is, who makes it, what it is based on, and how it differs from the certification decision.
1. What Is the Recommendation for Certification?
The recommendation is the audit team's formal conclusion, documented in the audit report and usually announced at the closing meeting. It states whether the audit team believes the ISMS conforms to ISO/IEC 27001 and is effectively implemented.
Key characteristics:
- It is made by the audit team leader, on behalf of the audit team.
- It is a recommendation, not a decision. The decision to grant, refuse, maintain, extend, reduce, suspend or withdraw certification belongs to the certification body.
- It must rest on objective audit evidence and the audit conclusions, not on the auditor's personal preference, the auditee's pressure or commercial considerations.
- It is governed mainly by ISO/IEC 17021-1 (requirements for bodies providing audit and certification of management systems) and ISO/IEC 27006 (additional requirements for ISMS certification bodies). ISO 19011 supplies general auditing guidance.
2. Why Is It Important?
- It links the audit to certification: The certification body relies on the audit team's recommendation and report to make an informed, defensible decision.
- It protects the credibility of certification: Accredited certification is valuable only if certificates go to organizations that genuinely meet ISO/IEC 27001. A weak or biased recommendation damages trust in the whole scheme.
- It supports impartiality: Separating the recommendation (by the auditors) from the decision (by independent persons) is a core impartiality safeguard. The people who carried out the audit should not be the ones who make the certification decision.
- It gives the auditee clarity: The organization learns where it stands, what it must correct and what happens next.
- It records accountability: A documented, evidence-based recommendation provides a clear audit trail for accreditation bodies and for appeals or complaints.
3. How It Works: The Process Step by Step
Step 1: Complete the audit and review the findings
Before the closing meeting, the audit team meets privately. It reviews all audit findings and any other relevant information collected against the audit objectives. It agrees the audit conclusions, taking into account the uncertainty inherent in the audit process, such as sampling. It also classifies nonconformities as major or minor.
- Major nonconformity: A nonconformity that affects the capability of the ISMS to achieve its intended results. Examples include the total absence of an ISMS requirement, such as no risk assessment or no internal audit, or a systemic failure, or significant doubt that effective process control is in place.
- Minor nonconformity: A nonconformity that does not affect the capability of the ISMS to achieve its intended results, such as an isolated lapse.
- Opportunities for improvement / observations: These are not nonconformities and do not prevent a positive recommendation.
Step 2: Determine the recommendation
Based on the evidence, the audit team leader typically chooses one of three outcomes:
a) Recommend certification (unconditional): No nonconformities, or only minor nonconformities. For minor nonconformities, the auditee submits a correction and corrective action plan, which the certification body reviews and accepts. Implementation is usually verified at the next surveillance audit.
b) Recommend certification subject to conditions (conditional recommendation): One or more major nonconformities exist, but the ISMS is otherwise largely in place. Certification cannot be granted until the correction and corrective actions for each major nonconformity have been reviewed, accepted and verified as effective. Verification may be through a document review or a follow-up (special) audit on site. Under ISO/IEC 17021-1, if the certification body cannot verify the corrections and corrective actions for a major nonconformity within 6 months after the last day of Stage 2, it must conduct another Stage 2 before recommending certification.
c) Do not recommend certification: The ISMS is not sufficiently implemented or effective. Typical causes are numerous or systemic major nonconformities, a missing management review or internal audit cycle, or a scope that cannot be confirmed. The organization will usually need to fix its ISMS and undergo a new Stage 2, or even a new Stage 1.
Step 3: Present the recommendation at the closing meeting
The audit team leader presents the audit findings and conclusions, including the recommendation. They make clear that the final decision rests with the certification body. The closing meeting should also cover:
- The nonconformities and their classification.
- The time frame for the auditee to submit correction and corrective action plans.
- The consequences of not addressing nonconformities.
- The post-audit activities, such as follow-up and surveillance.
- The complaint and appeal processes.
- Any diverging opinions, which should be discussed and, if possible, resolved. Unresolved diverging opinions must be recorded.
Step 4: Document the recommendation in the audit report
The audit report should include:
- The audit objectives, scope and criteria.
- The audit findings and evidence.
- The nonconformities.
- The conclusions on ISMS conformity and effectiveness.
- The recommendation, including any conditions.
- Any unresolved issues.
For ISMS audits, ISO/IEC 27006 also expects the report to address the following:
- The organization's risk assessment and risk treatment.
- The Statement of Applicability.
- The effectiveness of the ISMS in meeting information security objectives.
Step 5: The certification decision by the certification body
Independent, competent persons who did not take part in the audit review the information package. This package includes:
- The audit report.
- Comments on nonconformities.
- Corrections and corrective actions taken by the client.
- Confirmation that the audit objectives were achieved.
- The recommendation.
These persons may accept the recommendation, or they may request more information or decide differently if the evidence does not support it. Only then is the certificate issued. Initial certificates are typically valid for three years, with surveillance audits in years one and two.
4. Recommendation vs. Certification Decision: Key Distinctions
- Who: The audit team leader recommends; the certification body decides.
- Basis: The recommendation is based on the audit evidence and conclusions. The decision is based on a review of the full audit record, including the recommendation and the corrective actions.
- Timing: The recommendation is made at the end of the audit, at the closing meeting and in the report. The decision comes afterwards.
- Authority: An auditor must never promise or grant a certificate, or state that the organization is certified, at the closing meeting.
5. Recommendations in Other Audit Types
- Surveillance audits: The recommendation concerns continuing (maintaining) certification. It may also concern suspension if serious issues arise.
- Recertification audits: The recommendation concerns renewal. Major nonconformities must be corrected and verified before the certificate expires.
- Scope extension or reduction: The recommendation concerns changing the certified scope.
6. Common Pitfalls for Auditors
- Recommending certification despite unresolved major nonconformities.
- Downgrading a major nonconformity to a minor one to please the client. This is an impartiality violation.
- Telling the auditee they are certified.
- Basing the recommendation on opinion rather than verifiable evidence.
- Failing to record unresolved diverging opinions.
- Ignoring missing mandatory elements that make the system incomplete, such as the following:
- The risk assessment.
- The Statement of Applicability.
- The internal audit.
- The management review.
Exam Tips: Answering Questions on Recommendation for Certification
Tip 1: Always separate recommendation from decision. If an option says the audit team leader grants or issues the certificate, it is wrong. The auditor recommends; the certification body decides. The decision-makers must be independent of the audit team.
Tip 2: Classify nonconformities first, then choose the outcome. In scenario questions, identify each finding and decide whether it is major, minor or an opportunity for improvement. Then apply this logic:
- Only minors or none: recommend certification, with an accepted action plan for any minors.
- One or more majors: recommendation is conditional on verified correction and corrective action.
- Pervasive or systemic failure: do not recommend.
Tip 3: Know what makes a nonconformity major. Typical major nonconformities include:
- No risk assessment or risk treatment.
- No Statement of Applicability.
- No internal audit or management review performed before Stage 2.
- Repeated failures of the same control across sites.
- Evidence that a requirement is systematically not met.
A single missed signature or one outdated document is usually minor.
Tip 4: Remember the 6-month rule. If corrections and corrective actions for major nonconformities cannot be verified within 6 months of the last day of Stage 2, another Stage 2 audit is required before certification can be recommended.
Tip 5: Justify with evidence. In essay or scenario answers, explicitly link your recommendation to specific audit evidence and ISO/IEC 27001 clauses or Annex A controls. For example: Clause 9.2 internal audit not performed, so this is a major nonconformity and the recommendation is conditional. Examiners reward reasoning, not just the conclusion.
Tip 6: Mention the closing meeting and report. When asked how the recommendation is communicated, cite the closing meeting and the audit report. Note that the team leader explains that the final decision lies with the certification body, sets timelines for action plans, and records any unresolved diverging opinions.
Tip 7: Watch for impartiality traps. Scenarios may show the auditee pressuring the auditor, offering inducements, or arguing that a deadline such as a contract tender requires the certificate. The correct answer always keeps the recommendation evidence-based and unchanged by such pressure.
Tip 8: Do not confuse opportunities for improvement with nonconformities. Observations and opportunities for improvement never block a positive recommendation, and they do not require a formal corrective action plan.
Tip 9: Use the correct terminology. Use terms such as these:
- Recommend for certification.
- Recommend subject to verification of corrective actions.
- Not recommended.
- Certification decision.
- Correction vs. corrective action. A correction eliminates the detected nonconformity; a corrective action eliminates its cause.
Tip 10: Structure scenario answers clearly. A strong answer format is:
(1) Summarize the key findings.
(2) Classify each finding with justification.
(3) State the recommendation.
(4) State the conditions and timelines.
(5) Note that the certification body makes the final decision.
Sample Exam Scenario
During Stage 2, the audit team finds that the organization has not conducted a management review. Two employees also had not completed security awareness training. What should the audit team leader recommend?
Model answer:
- The missing management review (clause 9.3) is a major nonconformity. It is a complete absence of a mandatory ISMS requirement and affects the system's ability to achieve its intended results.
- The training gap for two employees is a minor nonconformity (clause 7.2/7.3, Annex A people controls). It is an isolated lapse.
- The audit team leader should therefore recommend certification only after the correction and corrective action for the major nonconformity have been verified. This must happen within 6 months of the end of Stage 2, or a new Stage 2 is needed.
- For the minor nonconformity, the auditee should submit an action plan, which will be verified at surveillance.
- The team leader communicates this at the closing meeting and records it in the audit report. They make clear that the final certification decision rests with the certification body.
Summary
The recommendation for certification is the audit team leader's evidence-based conclusion on whether an ISMS deserves certification. It can be unconditional, conditional or negative, and it is driven mainly by the presence and severity of nonconformities. It is communicated at the closing meeting and in the audit report, then reviewed by an independent decision-maker in the certification body. For the exam, the essentials are:
- Separate the recommendation from the decision.
- Classify nonconformities correctly.
- Apply the major nonconformity verification rules.
- Justify every recommendation with objective evidence.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!