Audit Observations and Opportunities for Improvement
In an ISO/IEC 27001 audit, audit findings result from evaluating collected audit evidence against audit criteria such as the standard's requirements, Annex A controls, the organization's policies, and legal obligations. Findings fall into three groups: conformities, nonconformities, and the less fo… In an ISO/IEC 27001 audit, audit findings result from evaluating collected audit evidence against audit criteria such as the standard's requirements, Annex A controls, the organization's policies, and legal obligations. Findings fall into three groups: conformities, nonconformities, and the less formal categories of observations and opportunities for improvement (OFIs). ISO 19011 provides the guidance, and certification bodies apply them under ISO/IEC 27006. An audit observation is a finding that does not yet constitute a nonconformity but shows a potential weakness or risk that could lead to one. For example, an auditor may find that access reviews are performed but documented inconsistently, or that a risk treatment plan is complete but its owners are not clearly assigned. Observations are based on objective evidence. They highlight areas where the information security management system (ISMS) is vulnerable, and they often receive extra attention in later surveillance audits. The organization is not formally required to respond, but ignoring an observation may allow it to escalate into a minor or major nonconformity. An opportunity for improvement is a suggestion about where effectiveness, efficiency, or maturity could be enhanced, even though requirements are being met. Examples include automating log monitoring, improving the clarity of security metrics for management review, or integrating incident lessons learned more systematically. OFIs support clause 10.1 of ISO/IEC 27001, which requires continual improvement. The Lead Auditor must handle both carefully. Auditors must remain impartial and must not provide consultancy. They may identify what could be improved, but they should not prescribe specific solutions or recommend products or vendors. Findings must be clearly worded, traceable to evidence and criteria, and presented at the closing meeting. They are then recorded in the audit report and clearly distinguished from nonconformities, which require corrective action. Used well, observations and OFIs add value to the audit, help the auditee strengthen its ISMS proactively, and reinforce a culture of continual improvement.
Audit Observations and Opportunities for Improvement in ISO/IEC 27001 Audits: A Complete Guide for Lead Auditors
Introduction
Every ISO/IEC 27001 audit produces audit findings. Many candidates think only of nonconformities, but a complete audit also records observations (sometimes called areas of concern) and opportunities for improvement (OFIs). These softer findings show the auditee where its Information Security Management System (ISMS) could weaken over time. Lead Auditor exams test them often because they require judgement: you must decide whether the evidence shows a requirement that is not met, a risk that has not yet become a failure, or simply a chance to do better. This guide covers why these findings matter, what they are, how they are identified, worded and reported, and how to answer exam questions on them.
1. Why Audit Observations and OFIs Are Important
a) They add value beyond pass or fail. A certification audit decides whether the ISMS conforms. Observations and OFIs help the organization strengthen its ISMS before weaknesses turn into nonconformities or security incidents.
b) They support continual improvement. Clause 10.1 of ISO/IEC 27001 requires the organization to continually improve the suitability, adequacy and effectiveness of the ISMS. OFIs from internal and external audits are a direct input to that process and to management review (Clause 9.3).
c) They give early warning. An observation flags a trend or a situation that could lead to a nonconformity, such as backups that succeed but whose restores are rarely tested. The auditee can act before the issue becomes a finding at the next audit.
d) They protect auditor credibility and impartiality. Grading a weakness correctly is a core auditor skill. Raising a nonconformity without evidence of an unmet requirement is unfair. Ignoring a real risk is negligent. Observations and OFIs give the auditor a proportionate way to report concerns.
e) They are tested in exams. Lead Auditor exams (PECB, IRCA/CQI, BSI, Exemplar Global and others) present scenarios and ask you to classify a finding, word it correctly, or identify inappropriate auditor behaviour, such as giving consultancy advice.
2. What They Are: Key Definitions
Audit finding (ISO 19011:2018, 3.10): the results of the evaluation of the collected audit evidence against audit criteria. ISO 19011 notes that audit findings indicate conformity or nonconformity. They can also lead to the identification of risks, opportunities for improvement, or the recording of good practices.
Audit criteria: the set of requirements used as a reference. Examples are ISO/IEC 27001 clauses 4 to 10, the applicable Annex A controls in the Statement of Applicability, the organization's own policies and procedures, and legal, regulatory and contractual requirements.
Nonconformity: non-fulfilment of a requirement. It is usually graded as:
• Major: absence of, or total breakdown of, a requirement, or a situation that raises significant doubt about the ISMS achieving its intended results.
• Minor: an isolated lapse that does not undermine the system's ability to achieve its intended results.
Observation (area of concern): a finding where no requirement is currently breached, but the evidence suggests a potential weakness, risk or trend. If it is not addressed, it could lead to a nonconformity. Many certification bodies use this category, though the exact term varies (observation, area of concern, comment, note).
Opportunity for improvement (OFI): a finding where the requirement is met, but the auditor sees a way to make the process more effective, efficient or mature. OFIs are improvement-oriented rather than risk-oriented.
Good practice / positive finding: a noteworthy strength recorded to recognise effective implementation.
Key distinction:
• Nonconformity: a requirement is NOT met. Objective evidence proves it. Correction and corrective action are required.
• Observation: the requirement is met today, but there is a risk it may not be met in future. No formal corrective action is required, but the auditee should consider it.
• OFI: the requirement is met, and it could be done better. Action is optional and at the auditee's discretion.
3. How It Works: The Process
Step 1: Collect objective evidence. Evidence comes from interviews, observation of activities and review of documented information (records, logs, policies, configurations). Sampling applies. Under ISO 19011 principles, findings must be based on verifiable evidence, not opinion or hearsay.
Step 2: Evaluate the evidence against the audit criteria. For each item, ask: What does the requirement say? What did I find? Is there a gap?
Step 3: Classify the finding. A practical decision path:
1. Is there a specific requirement (standard, SoA, policy, law, contract) that is not fulfilled, with objective evidence? If yes, it is a nonconformity. Then grade it as major or minor.
2. If no, is there a credible risk or emerging trend that could lead to non-fulfilment? If yes, it is an observation.
3. If no, could the process be made more effective, efficient or mature? If yes, it is an OFI.
4. If the area is notably strong, record a good practice.
Step 4: Word the finding correctly. A well-written observation or OFI:
• is factual and refers to the evidence seen (what, where, when, sample);
• links to the relevant clause or control where possible;
• explains the potential risk or benefit;
• does not prescribe a specific solution. External auditors must stay impartial and must not act as consultants (ISO/IEC 17021-1 and ISO/IEC 27006-1).
Good example (observation): 'Access reviews for the finance application were completed quarterly as required by the Access Control Policy. However, two of the last four reviews were completed more than 20 days late. If this trend continues, the defined review frequency (A.5.18) may not be met.'
Good example (OFI): 'The supplier security assessment process meets the requirements of A.5.19 to A.5.21. There is an opportunity to improve efficiency by considering a risk-based tiering of suppliers so that assessment effort is proportionate to supplier criticality.'
Poor example (consultancy): 'The organization should buy tool X to automate access reviews.' This recommends a specific solution and compromises impartiality.
Step 5: Communicate the findings. Share findings progressively during the audit and confirm them with the auditee to avoid surprises. The audit team reviews and agrees findings before the closing meeting. At the closing meeting the lead auditor presents nonconformities, observations and OFIs, and explains that observations and OFIs do not require formal corrective action plans. Any diverging opinions should be discussed and, if unresolved, recorded (ISO 19011, 6.4.10).
Step 6: Report. The audit report lists observations and OFIs separately from nonconformities, with enough detail for the auditee to understand them.
Step 7: Follow up. The auditee decides whether and how to act on observations and OFIs. Good practice is to feed them into the continual improvement process and management review. At the next surveillance or recertification audit, the auditor often checks what was done. An ignored observation whose risk has materialised may then be raised as a nonconformity.
4. Observations and OFIs in Internal vs External Audits
• Internal audits (Clause 9.2): internal auditors usually have more freedom to suggest improvements, as long as they stay objective and do not audit their own work. OFIs from internal audits are a major input to improvement.
• Certification (third-party) audits: auditors may point out where improvement is possible but must not offer specific solutions or consultancy. Observations and OFIs do not affect the certification decision. Nonconformities do.
• Second-party audits (supplier audits): conventions depend on the contract, but the same classification logic usually applies.
5. Common Scenarios and Correct Classifications
• No documented risk assessment exists. Major nonconformity (Clause 6.1.2 and 8.2). This is not an observation.
• One of 25 sampled employees has not completed annual awareness training, which the policy requires. Minor nonconformity (Clause 7.3 / A.6.3), as an isolated lapse against a stated requirement.
• All training is complete, but completion rates are falling each quarter and are close to the deadline. Observation, because of the risk trend.
• Incident logs are maintained correctly in spreadsheets; a more structured system could allow trend analysis. OFI.
• The auditor personally thinks the password length should be 16 characters, but the policy says 12 and is followed. No nonconformity. At most an OFI, and only if it is supported by the organization's own risk assessment context. Personal preference is not an audit criterion.
• Excellent, well-tested business continuity exercises with documented lessons learned. Good practice / positive finding.
6. Exam Tips: Answering Questions on Audit Observations and Opportunities for Improvement
Tip 1: Look for the requirement first. Before choosing an answer, ask: 'Is there a requirement, and is it unmet?' If the scenario shows a clear breach of a 'shall' in the standard, the SoA, a policy or a law, the answer is a nonconformity, not an observation. Examiners often disguise a nonconformity as a 'minor issue' to tempt you to choose observation.
Tip 2: Trigger words matter. Phrases such as 'could lead to', 'trend', 'at risk of', 'currently meets but' suggest an observation. Phrases such as 'could be more efficient', 'could be enhanced', 'better practice' suggest an OFI. Phrases such as 'not performed', 'no evidence', 'contrary to the procedure' suggest a nonconformity.
Tip 3: Never choose an answer where the external auditor prescribes a solution. Options such as 'recommend a specific product', 'write the procedure for them' or 'design the control' break impartiality. The correct option usually describes the weakness and leaves the solution to the auditee.
Tip 4: Remember who decides action. The auditee decides whether to act on observations and OFIs. Formal corrective action plans are required only for nonconformities. Answers stating that an OFI 'must be closed before certification' are wrong.
Tip 5: Know the ISO 19011 definition. Audit findings indicate conformity or nonconformity and can lead to identification of risks, opportunities for improvement or recording of good practices. Questions may quote this definition directly.
Tip 6: Evidence over opinion. Every finding, including an observation or OFI, must be based on objective evidence. If a scenario says the auditor 'felt' or 'heard from a colleague', the finding is not valid until it is verified.
Tip 7: Do not overgrade or undergrade. In essay or scenario questions, justify your classification. State the evidence, the criterion, the gap (or absence of a gap), and the risk. Then explain why it is a major NC, minor NC, observation or OFI. Marks are usually given for the reasoning, not only the label.
Tip 8: Write findings in the right structure. If asked to draft an observation or OFI, include:
(1) the context or requirement reference;
(2) the objective evidence seen;
(3) the potential risk or improvement benefit;
(4) neutral, non-prescriptive wording.
Keep it concise, factual and traceable.
Tip 9: Link to follow-up. Mention that observations should be reviewed at the next audit and that unresolved risks may become nonconformities. This shows understanding of the audit programme cycle.
Tip 10: Connect to ISMS clauses. Show how OFIs feed Clause 9.3 (management review inputs include audit results and opportunities for continual improvement) and Clause 10.1 (continual improvement). This shows system-level thinking that examiners reward.
Tip 11: Watch for the 'good practice' option. Some questions ask what should be done with a strong finding. Recording good practice is valid and encouraged under ISO 19011.
Tip 12: Manage time on scenario questions. Underline evidence statements in the scenario. Map each one to a clause or control. Classify it, then write. Avoid listing every possible finding. Focus on those the question asks for.
7. Quick Revision Summary
• An audit finding is the result of evaluating evidence against criteria.
• A nonconformity means a requirement is not met; corrective action is mandatory.
• An observation means the requirement is met but at risk; consideration is advised.
• An OFI means the requirement is met but could be better; action is optional.
• External auditors must remain impartial: identify, do not prescribe.
• All findings require objective evidence and clear, factual wording.
• Observations and OFIs feed management review and continual improvement and are followed up at later audits.
Final thought: A competent Lead Auditor knows that certification is not the only value of an audit. Classifying, wording and reporting observations and opportunities for improvement accurately helps organizations build a stronger ISMS. Showing that judgement in the exam is a reliable way to earn top marks.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!