Audit Test Plans
In an ISO/IEC 27001 audit, an audit test plan is a structured working document that the lead auditor and audit team prepare before on-site activities, usually for the Stage 2 audit. It defines exactly how each requirement of the standard and each applicable Annex A control will be checked. It turns… In an ISO/IEC 27001 audit, an audit test plan is a structured working document that the lead auditor and audit team prepare before on-site activities, usually for the Stage 2 audit. It defines exactly how each requirement of the standard and each applicable Annex A control will be checked. It turns the general audit plan, which covers scope, schedule, auditees, and logistics, into specific steps for collecting objective evidence. ISO/IEC 19011 calls these work documents, and the PECB Lead Auditor methodology treats them as essential preparation. A typical test plan includes several elements. It states the audit objective and audit criteria, such as clause 6.1.2 on risk assessment or control A.5.15 on access control. It sets out the audit procedures to be used: documented information review, interviews, observation, technical verification, analysis, and sampling. It describes the expected evidence, such as policies, records, logs, and configurations. It also identifies the sampling method and sample size, the responsible auditor, the auditee or process owner, and the time allocated. Space is left to record findings, evidence references, and conclusions of conformity or nonconformity. Auditors design tests based on risk, the Statement of Applicability, the results of the Stage 1 documentation review, and the organization's context. For example, to test user access reviews, the auditor may ask for the access management procedure, interview the IT manager, select a sample of review records from the past year, and check that revoked accounts were actually disabled in the system. Test plans bring consistency, traceability, and full coverage across the audit team. They help auditors manage time and avoid missing critical areas. They also support impartial, evidence-based conclusions. They should stay flexible, however, so that auditors can follow audit trails when new information or risks emerge. Completed test plans become part of the audit records and support the audit report and certification decision.
Audit Test Plans in ISO/IEC 27001 Audits: A Complete Guide for Lead Auditors
Introduction
In an ISO/IEC 27001 audit, the audit test plan is the practical bridge between the audit plan, which says what will be audited and when, and the fieldwork itself, which is how evidence is gathered. ISO 19011 and ISO/IEC 27007 guide auditors to prepare work documents such as checklists, audit test plans and sampling plans. These help them collect objective evidence efficiently and consistently. For anyone preparing for the ISO 27001 Lead Auditor exam, understanding audit test plans is essential. Questions often test whether you can choose the right audit procedure, sample size or evidence source for a given control.
Why Audit Test Plans Are Important
1. They ensure the audit is systematic and evidence-based. ISO 19011 lists the evidence-based approach as a principle of auditing. A test plan states in advance what evidence is needed to show that a requirement or control is fulfilled.
2. They provide adequate coverage of the scope. The plan maps the ISMS clauses (4 to 10) and the applicable Annex A controls from the Statement of Applicability (SoA) to specific tests. This prevents important areas from being missed.
3. They support a risk-based approach. Auditors can put more testing effort into high-risk processes, critical assets and controls with a history of nonconformities.
4. They make the best use of limited time. Audits run on tight schedules. A test plan helps the team divide work, avoid duplication and reach audit objectives within the agreed duration.
5. They provide consistency and traceability. When several auditors are involved, test plans keep the approach uniform. They also leave a record of what was tested, how, and with what results. This supports findings and the final audit conclusion.
6. They reduce audit risk. Audit risk is the risk of reaching a wrong conclusion. Defining test methods and sample sizes in advance lowers the chance of overlooking a nonconformity or reporting a false one.
What an Audit Test Plan Is
An audit test plan is a work document prepared by the audit team, usually during the preparation stage (stage 2 or surveillance audit preparation). It specifies, for each requirement or control, the following:
- Audit criteria: the clause of ISO/IEC 27001 or the Annex A control, plus internal policies and procedures, legal requirements and contractual obligations.
- Audit objective of the test: what the auditor wants to confirm, such as design adequacy, implementation or operating effectiveness.
- Audit procedures or techniques: how the evidence will be collected.
- Evidence sources: people to interview, documents and records to review, systems and locations to observe.
- Sampling approach: population, sample size and selection method.
- Responsible auditor and timing.
- Expected evidence and a place to record results: conforming, nonconforming or observation.
It differs from the audit plan. The audit plan is shared with the auditee and covers objectives, scope, criteria, schedule, team and logistics. The test plan is an internal working tool for the auditors that details the testing approach. It also goes beyond a simple checklist, because it defines the testing method and the evidence required, not just the questions to ask.
How Audit Test Plans Work
Step 1: Review the documented information. Using the stage 1 results, review the ISMS scope, information security policy, risk assessment, risk treatment plan, SoA and relevant procedures. Identify the key processes, risks and controls.
Step 2: Identify the audit criteria to test. List the mandatory requirements (clauses 4 to 10) and the Annex A controls declared applicable in the SoA. Also check the justification given for excluded controls.
Step 3: Prioritise using risk. Spend more effort on areas with high information security risk, recent changes, previous nonconformities, outsourced processes or complex technology.
Step 4: Select the audit procedures. ISO/IEC 27007 and the PECB methodology describe common procedures:
- Observation: watching activities as they happen, such as visitor sign-in or clean desk practice.
- Documentation review: examining policies, procedures and records, such as access review records or incident logs.
- Interview: questioning personnel to understand processes and awareness.
- Technical verification: examining system configurations, settings and logs, such as password policy settings or firewall rules.
- Analysis: evaluating data or trends, such as comparing the HR leavers list against active accounts.
- Re-performance or testing: repeating a control to confirm it works, such as attempting access with a disabled account in a controlled way.
Most tests combine several procedures (corroboration), because evidence from more than one source is more reliable than a single interview.
Step 5: Define sampling. Identify the population, such as all user accounts, all changes this year or all new starters. Then choose the method:
- Judgmental sampling: based on auditor knowledge and risk, for example selecting privileged accounts.
- Statistical sampling: random or systematic selection, which allows conclusions about the whole population.
Sample size depends on population size, risk, control frequency (daily, weekly, annual) and the confidence required. Larger populations and higher risks call for larger samples.
Step 6: Define the expected evidence and conformity criteria. State what conformity looks like. For example: every leaver's access must be revoked within 24 hours as required by the access control procedure.
Step 7: Assign responsibilities and schedule. Allocate tests to auditors and technical experts according to their competence, and align them with the audit plan.
Step 8: Execute, record and adapt. During fieldwork, auditors carry out the tests, record evidence (dates, record IDs, names or roles, system screenshots) and note results. The test plan is a living document. If evidence reveals new risks or the auditee's situation changes, the audit team leader can adjust tests, extend samples or follow audit trails.
Step 9: Evaluate results. Compare the evidence against the criteria to produce audit findings (conformity, nonconformity, opportunities for improvement). These feed into the audit conclusions.
Example Test Plan Entry
Criterion: Annex A 5.18 Access rights (ISO/IEC 27001:2022).
Objective: Verify that access rights are reviewed and revoked on termination.
Procedures: Review the access management procedure. Interview the IT administrator. Obtain the HR list of leavers for the last 6 months and compare it with the Active Directory accounts (analysis and technical verification). Review the quarterly access review records.
Sample: 15 leavers selected randomly from a population of 120, plus all leavers who held privileged access (judgmental).
Expected evidence: Accounts disabled on or before the termination date, and signed access reviews each quarter.
Result: To be recorded during the audit.
Common Pitfalls
- Relying only on interviews instead of verifying records and systems.
- Using samples too small to support a conclusion, or choosing samples suggested by the auditee (this compromises independence).
- Testing only design (that a policy exists) and not operating effectiveness (that it works over time).
- Ignoring the SoA and testing controls that are out of scope.
- Treating the plan as rigid and failing to follow audit trails when issues appear.
Exam Tips: Answering Questions on Audit Test Plans
1. Know the purpose. If asked why auditors use test plans, focus on collecting sufficient and appropriate objective evidence, ensuring coverage, applying a risk-based approach and supporting consistent, traceable conclusions.
2. Distinguish audit plan, test plan and checklist. The audit plan is communicated to the auditee and covers logistics and schedule. The test plan and checklist are internal work documents. Exam answers that confuse these are usually wrong.
3. Match the procedure to the control. Scenario questions often ask for the best way to verify a control. Technical controls (encryption, logging, configuration) are best verified by technical verification. Physical controls are best verified by observation. Records-based controls (training, access reviews) are best verified by documentation review. Awareness is best verified by interviewing staff. Choose the option that gives the most direct and reliable evidence.
4. Prefer corroborated evidence. If one answer relies only on interviews and another combines interviews with records or system verification, the combined approach is generally correct.
5. Remember sampling principles. The auditor selects the sample, not the auditee. Sample size rises with risk, population size and control frequency. Judgmental sampling relies on auditor expertise. Statistical sampling allows generalisation. Mention the risk that the sample is not representative.
6. Link to the SoA and risk assessment. Good test plans are based on the applicable controls in the SoA and on the organisation's risks. Answers that test excluded controls as implemented, or ignore risk, are weak.
7. Show flexibility. If a scenario describes unexpected evidence during the audit, the correct answer usually involves adjusting the test plan, such as extending the sample or following the audit trail, rather than ignoring the issue or stopping the audit.
8. Use precise terminology. Use terms such as audit criteria, objective evidence, audit procedure, population, sample, conformity, nonconformity, design effectiveness and operating effectiveness. Examiners reward accurate ISO 19011 and ISO/IEC 27007 language.
9. For essay or scenario answers, structure your response. Use this order: criterion, objective, procedure(s), evidence source, sample and justification, expected result. A short table-like structure in prose shows a methodical audit approach.
10. Justify your choices. Do not just state a sample size or technique. Explain why, for example: because privileged accounts represent higher risk, all were selected. Justification often earns most of the marks in open-ended Lead Auditor exam questions.
11. Watch for independence and objectivity. Options where the auditor accepts auditee-prepared summaries without verification, or lets the auditee choose samples, are typically incorrect.
12. Remember the time dimension. To test operating effectiveness, sample evidence across the audit period (for example, several months), not just a single date.
Summary
Audit test plans turn audit objectives into concrete, evidence-gathering actions. They define which criteria to test, which procedures to use, what to sample and what evidence shows conformity. Built on the SoA, the risk assessment and the auditor's professional judgement, they make ISO/IEC 27001 audits systematic, efficient and defensible. In the exam, show that you can select appropriate procedures, justify sampling, corroborate evidence and adapt the plan as the audit unfolds.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!