Audit Interviews
In an ISO/IEC 27001 audit, interviews are one of the main ways a Lead Auditor gathers objective evidence, alongside document review and observation. ISO 19011 guidance treats interviews as a way to confirm that the Information Security Management System (ISMS) is understood, implemented, and effect… In an ISO/IEC 27001 audit, interviews are one of the main ways a Lead Auditor gathers objective evidence, alongside document review and observation. ISO 19011 guidance treats interviews as a way to confirm that the Information Security Management System (ISMS) is understood, implemented, and effective in daily operations, not just documented. The aim is to check that clauses 4 to 10 and the selected Annex A controls are actually practised by people at all levels. Preparation is essential. The auditor reviews the Statement of Applicability, risk assessment, risk treatment plan, and previous audit results. This helps identify whom to interview, such as top management, the ISMS manager, risk owners, IT administrators, HR staff, and ordinary end users. The audit plan schedules interviews during normal working hours and, where possible, at the interviewee's workplace. When conducting the interview, the auditor should put the interviewee at ease, introduce themselves, and explain the purpose and scope. The auditor relies mainly on open questions such as 'How do you...?', 'Show me...', and 'What happens when...?'. Closed questions are used to confirm facts, while leading questions are avoided. Active listening, neutral body language, and patience encourage honest answers. The auditor asks people to describe their actual work, for example how they report a security incident, grant access rights, or handle backups, rather than reciting policy. Evidence obtained through interviews must be verified. Statements are cross-checked against records, system configurations, logs, and direct observation, a practice known as triangulation. The auditor takes clear notes that capture names or roles, dates, and specific facts. These notes support traceable findings. At the end of the interview, the auditor summarises key points, clarifies any misunderstandings, and thanks the interviewee. Possible nonconformities are noted for later confirmation rather than argued on the spot. Throughout the process, auditors stay impartial, respect cultural differences and confidentiality, and adapt their techniques for remote audits. This keeps the conclusions fair, evidence-based, and reliable.
Audit Interviews in ISO/IEC 27001 Lead Auditor: A Complete Guide to Conducting Effective Interviews and Answering Exam Questions
Introduction
Audit interviews are among the most important evidence-gathering techniques an ISO/IEC 27001 auditor uses. An Information Security Management System (ISMS) is built from documents, technical controls and records, but it is run by people. Interviews let the auditor confirm whether those people understand, apply and maintain the ISMS in daily work. This guide explains what audit interviews are, why they matter, how to conduct them well, and how to answer exam questions on the topic, based on ISO 19011 (Guidelines for auditing management systems) and ISO/IEC 27007 (Guidelines for ISMS auditing).
What Are Audit Interviews?
An audit interview is a structured conversation between an auditor and an auditee. Its purpose is to collect information that, once verified, becomes audit evidence. ISO 19011 lists interviewing as one of the main methods of collecting information, alongside:
- observing activities
- reviewing documented information
- sampling
Interviews can take place:
- on-site (face to face), or
- remotely (video conference, telephone or other ICT tools).
They can involve individuals or small groups, and they cover all levels of the organization, including:
- top management
- process owners
- risk owners
- system administrators
- HR staff
- general employees
- contractors, where relevant
An interview is not an interrogation. It is a professional, respectful exchange in which the auditor seeks facts about how processes and controls actually operate. These facts are then compared against the audit criteria: ISO/IEC 27001 requirements, Annex A controls, the organization's policies and procedures, legal requirements, and contractual obligations.
Why Are Audit Interviews Important?
1. They verify implementation, not just documentation. A policy may look perfect on paper. Only by talking to staff can an auditor confirm that it is understood and followed. Example: an access control policy may require quarterly access reviews. Asking the system administrator how those reviews are performed shows whether the requirement is met in practice.
2. They assess awareness and competence. Clause 7.2 (Competence) and Clause 7.3 (Awareness) require that people know the information security policy, their contribution to ISMS effectiveness, and the consequences of nonconformity. Interviews are the main way to test this.
3. They reveal the context and intent behind processes. Interviews with top management show leadership commitment (Clause 5). They also show how organizational context, interested parties and risk appetite (Clauses 4 and 6) shape the ISMS.
4. They guide where to look next. What an auditee says helps the auditor decide which records to sample, what to observe and which follow-up questions to ask.
5. They help triangulate evidence. Interview statements are corroborated with documents and observation. This builds a reliable, objective picture of conformity.
6. They build rapport and understanding. Well-handled interviews reduce auditee anxiety and encourage openness. This improves the quality of the audit and the acceptance of its findings.
How Audit Interviews Work: The Process
1. Preparation
- Review the audit plan, scope, objectives and criteria.
- Identify who should be interviewed, based on roles and responsibilities (for example, the RACI matrix or organization chart).
- Prepare work documents such as checklists, question lists or audit trails. These support the auditor but should not restrict the conversation.
- Schedule interviews during normal working hours and at the auditee's workplace where possible, so that it causes minimal disruption.
- Consider confidentiality, language, cultural factors and any accessibility needs.
2. Opening the Interview (ISO 19011 guidance)
- Interview people at appropriate levels and functions, who perform the activities or tasks within the audit scope.
- Put the interviewee at ease.
- Explain the reason for the interview and any note-taking.
- Start by asking the person to describe their work.
- Avoid leading questions that suggest the answer.
- Ask in advance whether the auditee is willing to have the interview recorded. Recording requires their consent.
3. Conducting the Interview
Use a mix of question types:
- Open questions (who, what, where, when, why, how; or 'show me', 'tell me', 'explain') gather broad information. Example: 'How do you handle a reported security incident?'
- Closed questions (yes/no) confirm specific facts. Example: 'Was this backup tested last month?'
- Probing or follow-up questions dig deeper. Example: 'What happens if the approver is unavailable?'
- Clarifying or summarizing questions confirm understanding. Example: 'So, if I understand correctly, you review logs weekly?'
Avoid:
- Leading questions, such as 'You always encrypt laptops, don't you?'
- Multiple questions at once
- Hypothetical questions that produce opinions rather than facts
- Aggressive or accusatory language
Active listening is key. Let the auditee talk, show attentiveness, do not interrupt unnecessarily, and watch for non-verbal cues. Ask to be shown evidence ('Can you show me the last access review?'). This turns an interview into a combined interview, observation and document-review technique.
4. Recording Information
Record:
- the interviewee's name and role (or another identifier, if anonymity is agreed)
- the date and location
- the key statements made
- any references to records seen
Notes should be factual, objective and traceable. Interview statements alone are generally not sufficient objective evidence. Where possible, they should be verified by other means, such as documents, records or observation.
5. Closing the Interview
- Summarize the key points and review them with the interviewee.
- Thank the person for their time and cooperation.
- Explain what happens next. Do not announce nonconformities to individual staff during routine interviews. Findings are communicated through the proper channels, such as team discussions with the guide or auditee representative and the closing meeting.
6. Verifying and Evaluating
- Information from interviews must be verified before it is accepted as audit evidence.
- Unverifiable information is treated with caution. Use professional judgement about the degree of reliance placed on it.
- Evidence is compared against the audit criteria to generate audit findings.
Special Considerations in ISMS Interviews
- Confidentiality: Auditors may hear sensitive information, such as vulnerabilities or incident details. It must be protected according to the audit programme and confidentiality agreements.
- Technical depth: Interviews with IT staff may need a technical expert on the audit team. The lead auditor remains responsible for the audit.
- Remote interviews: Confirm the identity of participants. Ensure secure communication channels and stable connectivity. Agree in advance on screen sharing for evidence.
- Guides and observers: Guides facilitate the audit but should not answer on behalf of the interviewee. Observers should not influence or interfere with the interview.
- Sampling people: Select interviewees from different shifts, locations and functions to get a representative view.
- Difficult auditees: Stay calm, professional and objective. Clarify the purpose, redirect the conversation, and escalate to the lead auditor or audit client only when needed.
- Top management interviews: Focus on ISMS policy, objectives, resources, management review, roles, risk acceptance and continual improvement.
Typical Interview Targets and Topics
- Top management: leadership commitment, policy, ISMS objectives, resources, management review outputs.
- ISMS manager: scope, risk assessment methodology, Statement of Applicability, internal audits, corrective actions.
- Risk owners: approval of risk treatment plans and acceptance of residual risks.
- HR: screening, terms of employment, awareness training, disciplinary process, termination responsibilities.
- IT and operations: access control, backups, logging, change management, vulnerability management, incident handling.
- General staff: policy awareness, reporting of security events, clear desk, password practices.
- Suppliers and facilities: physical security, supplier agreements and monitoring.
Exam Tips: Answering Questions on Audit Interviews
Tip 1: Know the ISO 19011 guidance on interviewing. Exam questions often test the recommended practices:
- interview people at appropriate levels
- conduct the interview during normal working hours and at the normal workplace where practical
- put the interviewee at ease
- explain the purpose
- avoid leading questions
- summarize and review results
- thank the interviewee
Any answer option that contradicts these practices is usually wrong.
Tip 2: Prefer open questions for gathering information. If asked which question is best for understanding a process, choose the open, non-leading one. 'How do you manage user access when an employee leaves?' is better than 'You remove access immediately, right?'
Tip 3: Interviews alone are not enough. If a question asks whether an auditee's verbal statement is sufficient to conclude conformity, the answer is usually no. The auditor should verify it through records or observation. Look for options that mention verification, corroboration or sampling.
Tip 4: Stay objective and evidence-based. Correct answers reflect ISO 19011 principles:
- integrity
- fair presentation
- due professional care
- confidentiality
- independence
- an evidence-based approach
- a risk-based approach
Reject options where the auditor gives advice or consultancy, makes assumptions, or reaches conclusions without evidence.
Tip 5: Handle scenario-based questions methodically. In scenarios (for example, an employee cannot explain the incident reporting process), ask yourself:
- What criterion applies? Here, Clause 7.3 and Annex A control 6.8 (Information security event reporting).
- Is the evidence sufficient? Should more people be sampled?
- What is the appropriate finding?
A single unaware employee may warrant further sampling before you decide whether the issue is isolated or systemic.
Tip 6: Recognize the role of guides and observers. If a guide keeps answering for the interviewee, the correct response is to politely ask that the interviewee answer directly. Escalate if the problem persists.
Tip 7: Remember confidentiality and consent. Recording requires consent. Sensitive information must be protected. Personal opinions should not be attributed to individuals in the report without justification.
Tip 8: Don't communicate nonconformities prematurely. Auditors do not argue with or criticize auditees during interviews. Findings are discussed with the auditee representative and presented at the closing meeting.
Tip 9: Choose the right interviewee. Questions may ask who should be interviewed about a topic:
- risk acceptance: risk owners
- ISMS policy and resources: top management
- backups: the IT operator
The best answer targets the person who actually performs or is accountable for the activity.
Tip 10: Watch for keywords in answer options. Phrases such as 'verify', 'sample', 'open question', 'put at ease', 'objective evidence' and 'summarize' signal good practice. Phrases such as 'assume', 'advise', 'accept the statement', 'leading question' and 'interrupt' usually indicate wrong answers.
Tip 11: For essay or long-answer exams, structure your response as follows:
(a) the purpose of the interview
(b) preparation
(c) conduct, including question types and active listening
(d) recording
(e) verification of information
(f) closing
Link your points to ISO 19011 and to the relevant ISO/IEC 27001 clauses or Annex A controls. Give concrete sample questions to show practical understanding.
Sample Exam-Style Question and Answer
Question: During an audit, the auditor asks a network administrator, 'You review firewall logs every day, correct?' The administrator says yes. The auditor records this as conformity. What is wrong with this approach?
Answer: The auditor asked a leading, closed question that suggested the expected answer. The auditor also accepted a verbal statement without verification. Better practice is to ask an open question, such as 'How are firewall logs monitored and reviewed?', and then request evidence, such as log review records or monitoring tool outputs. Only verified information should be treated as audit evidence when determining conformity with Annex A control 8.15 (Logging) and 8.16 (Monitoring activities).
Key Takeaways
- Audit interviews are a core evidence-gathering method under ISO 19011 and ISO/IEC 27007.
- They reveal how the ISMS actually works and test awareness, competence and leadership commitment.
- Effective interviews are well prepared, use open and non-leading questions, rely on active listening, and are respectful and confidential.
- Interview information must be recorded accurately and verified before it is used as audit evidence.
- In exams, choose answers that reflect objectivity, verification, appropriate interviewee selection, and ISO 19011 good practice.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!