Audit Working Papers
Audit working papers are the documents an ISO/IEC 27001 auditor prepares and uses to plan, conduct, record and support the outcome of an Information Security Management System (ISMS) audit. ISO 19011 guidance recognises them as essential tools for consistency, traceability and objectivity. During a… Audit working papers are the documents an ISO/IEC 27001 auditor prepares and uses to plan, conduct, record and support the outcome of an Information Security Management System (ISMS) audit. ISO 19011 guidance recognises them as essential tools for consistency, traceability and objectivity. During audit preparation, the lead auditor and the audit team build working papers from the audit objectives, scope and criteria. These criteria include ISO/IEC 27001 clauses 4 to 10, the Annex A controls, the Statement of Applicability, the risk assessment and treatment results, and the organisation's own policies. Typical working papers include the audit plan, checklists or audit protocols, sampling plans, interview question sets, evidence-recording forms, attendance lists for opening and closing meetings, and forms for nonconformity reports and observations. Checklists help auditors cover the required clauses and controls systematically, but they should not restrict professional judgement. Auditors should follow audit trails wherever the evidence leads. During the audit, working papers capture objective evidence. This includes who was interviewed, which records, logs, configurations or procedures were examined, sample sizes, dates, locations and observations of practice. Notes should be factual, specific and verifiable, for example by citing document identifiers, version numbers or ticket references. This allows findings to be traced back to evidence and audit criteria. Good working papers support the evaluation of conformity, the grading of nonconformities as major or minor, team reviews, and preparation of the audit report and conclusions. They also enable continuity between Stage 1 and Stage 2 audits and later surveillance audits. Because working papers often contain sensitive information about vulnerabilities, assets and security incidents, auditors must protect their confidentiality, integrity and availability. They must be handled under the certification body's procedures and the agreed retention requirements, and they must not be disclosed without authorisation. In summary, audit working papers turn an audit from opinion into evidence-based, defensible and repeatable assurance.
Audit Working Papers in ISO/IEC 27001 Lead Auditor: A Complete Guide
Introduction
In an ISO/IEC 27001 audit, audit working papers are the documents an auditor uses to plan, carry out, record and support the audit. They are the paper trail that turns observation into evidence and evidence into conclusions. For the ISO/IEC 27001 Lead Auditor exam (PECB, IRCA/CQI, Exemplar Global and others), you need to know what they are, why they matter, how they are prepared and protected, and how to apply that knowledge to scenario questions.
1. What Are Audit Working Papers?
Audit working papers are all the documents and records an auditor creates, collects or uses while preparing for and conducting an audit. ISO 19011:2018 (Guidelines for auditing management systems), clause 6.3.4, calls the related activity preparing documented information for the audit. ISO/IEC 27007 adds guidance specific to auditing an ISMS.
Typical working papers include:
- Audit checklists: questions or prompts built from ISO/IEC 27001 clauses 4 to 10, Annex A controls, and the auditee's own policies and procedures.
- Audit plan and audit programme extracts.
- Sampling plans: what was sampled, how, and why.
- Evidence records: interview notes, observations, copies or references of documents and records reviewed (for example, access review logs, risk registers, Statement of Applicability, incident records, training records).
- Forms for recording findings: conformities, nonconformities (major and minor), opportunities for improvement and observations.
- Meeting records: opening and closing meeting attendance lists and notes.
- Audit trails: cross-references from each finding to its evidence and to the audit criteria.
- Stage 1 review notes and documentation review reports in certification audits.
- Communications with the auditee and the audit team during the audit.
Working papers can be paper-based or electronic (tablets, audit software, spreadsheets). The format matters less than whether they are complete, accurate, traceable and protected.
2. Why Are Audit Working Papers Important?
a) Evidence-based approach: ISO 19011 lists the evidence-based approach as a principle of auditing. Conclusions must rest on verifiable audit evidence. Working papers are where that evidence is recorded.
b) Traceability and defensibility: Every nonconformity must be traceable to objective evidence and to a specific requirement. If an auditee disputes a finding, the working papers show what was seen, where, when and from whom.
c) Structure and consistency: Checklists and plans help the auditor:
- cover the full audit scope;
- manage time effectively;
- keep coverage consistent across auditors and audit days;
- avoid forgetting key ISMS requirements, such as risk assessment (6.1.2), risk treatment (6.1.3), the SoA, internal audit (9.2) and management review (9.3).
d) Memory aid and continuity: Audits run over several days, sites and team members. Working papers keep information intact. They also support later surveillance and recertification audits, and the audit team leader's preparation of the report.
e) Report preparation: The audit report draws directly on the working papers. Good papers produce accurate, timely reports.
f) Accreditation and quality review: Certification bodies are accredited under ISO/IEC 17021-1 and, for ISMS, ISO/IEC 27006. They must keep records that show audits were done competently. Accreditation bodies and internal technical reviewers examine working papers when making certification decisions.
g) Professional and legal protection: In a complaint, appeal or legal dispute, working papers are the record of the auditor's due professional care.
3. How Audit Working Papers Work: The Lifecycle
Step 1: Preparation (before the audit)
- Review the auditee's documented information: ISMS scope, policy, risk methodology, SoA and risk treatment plan.
- Prepare checklists linked to the audit criteria and objectives.
- Decide sampling methods: judgmental (based on risk and auditor knowledge) or statistical.
- Assign working documents to audit team members according to their roles.
- Consider risk: concentrate on areas with higher information security risk or past nonconformities.
ISO 19011 notes that working documents should not restrict audit activities. They can change as information collected during the audit points to new lines of enquiry. A checklist is a guide, not a straitjacket.
Step 2: Use during the audit
- Record objective evidence at the time it is found: who was interviewed (role, not always name), what document or record was examined (title, version, date, reference number), and what was observed.
- Note both conformities and nonconformities. Positive evidence matters too.
- Use cross-references, for example: Finding NC-03, Clause 8.1 / Annex A 5.18, evidence: access review for Q2 not performed, sampled 5 of 20 systems.
- Follow audit trails, horizontal (across departments) and vertical (from policy to procedure to record).
- Hold daily audit team meetings to share findings and update working papers.
Step 3: Analysis and conclusions
- Evaluate the evidence against the criteria to produce audit findings.
- Grade findings (major or minor nonconformity, OFI) according to the certification body's or programme's rules.
- Write nonconformity statements with three parts: the requirement, the evidence, and the nonconformity, meaning why the evidence fails the requirement.
Step 4: Reporting and retention
- The audit team leader compiles the report from the working papers.
- Working papers are retained, controlled and protected according to the audit programme, contracts, legal and regulatory requirements, and certification body procedures.
- When retention ends, they are disposed of securely.
4. Protection and Confidentiality of Working Papers
This matters especially in ISO/IEC 27001 audits, because auditors may handle sensitive information such as network diagrams, vulnerability reports, risk registers and incident records.
- Confidentiality is an ISO 19011 principle. Auditors must protect information obtained during the audit.
- Working papers containing confidential or sensitive information must be safeguarded: encrypted laptops, locked storage, controlled access.
- Auditors should not take copies of highly sensitive documents unless necessary and agreed with the auditee. A reference is often enough, for example: Firewall rule review dated 12/03 sighted, ID FW-REV-07.
- Some information may be classified or restricted. The auditee may allow viewing only on site.
- Personal data in working papers must be handled in line with privacy laws such as the GDPR.
- Working papers generally belong to the audit organisation (the certification body or internal audit function), not the auditee. They are not usually handed to the auditee, although the audit report is.
5. Characteristics of Good Working Papers
- Complete: cover the scope and criteria planned.
- Accurate: record facts precisely, without opinion or speculation.
- Legible and clear: another competent auditor can understand them.
- Traceable: evidence is linked to requirements and findings.
- Objective: verifiable facts, not hearsay. If information comes from an interview, it is verified where possible.
- Timely: written during or immediately after the activity.
- Secure: protected for confidentiality and integrity.
- Retained: kept for the defined retention period.
6. Checklists: Benefits and Limitations
Benefits: structure, coverage, consistency, time management, memory aid, evidence of planning, and help for less experienced auditors.
Limitations: they can make the audit mechanical or tick-box, discourage auditors from following leads, miss context-specific risks, and become outdated if not tailored.
Best practice: tailor checklists to the auditee's context, risks and processes, use open questions, and stay flexible.
7. Typical Exam Question Types
- Definitions: which of the following is NOT a working paper?
- Purpose: what is the main purpose of audit working papers?
- Confidentiality scenarios: an auditor leaves working papers in a hotel lobby, or a client asks for a copy of the auditor's notes. What should happen?
- Checklist use: the auditor finds an issue not on the checklist. What should they do?
- Evidence recording: which note is the best record of objective evidence?
- Nonconformity writing: write a nonconformity statement from scenario evidence.
- Retention and ownership: who owns the working papers, and how long are they retained?
- Essay questions (PECB): describe how you would prepare working documents for a Stage 2 audit of a given organisation.
Exam Tips: Answering Questions on Audit Working Papers
Tip 1: Anchor answers in ISO 19011 and ISO/IEC 17021-1. Use the right vocabulary: audit evidence, audit criteria, audit findings, objective evidence, traceability, confidentiality, evidence-based approach. Examiners reward correct terms.
Tip 2: Remember that working documents must not restrict the audit. If a question asks what an auditor should do when evidence points beyond the checklist, the answer is almost always to follow the audit trail within the audit scope, record it, and inform the audit team leader if it affects the plan.
Tip 3: Confidentiality wins in scenario questions. If an option involves sharing working papers with third parties, leaving them unprotected, or photographing sensitive client data without permission, it is almost certainly wrong. Choose the option that protects the information and respects the auditee's security rules.
Tip 4: Know who owns what. The audit report goes to the audit client and, usually, the auditee. The working papers stay with the audit organisation. If the auditee asks for the auditor's notes, the correct response is usually a polite refusal, pointing them to the audit report.
Tip 5: Recognise good objective evidence. When choosing the best recorded evidence, pick the most specific, factual and verifiable entry. For example: Reviewed access rights list for HR system dated 05/04/2024; 3 of 15 sampled users were leavers with active accounts. Avoid vague answers such as access control seems weak.
Tip 6: Write nonconformities in three parts. In essay or case-study questions, structure findings as:
(1) Requirement: ISO/IEC 27001 clause or Annex A control, or the organisation's own procedure.
(2) Evidence: what was seen, with references and sample sizes.
(3) Statement of nonconformity: how the evidence fails the requirement.
Do not include root causes or recommendations of specific solutions, because auditors should not act as consultants.
Tip 7: Tailor, do not copy. When asked to prepare a checklist or working document for a scenario, show that you have used the organisation's context: its sector, critical assets, SoA exclusions, outsourced processes and past findings. Generic clause lists score lower.
Tip 8: Link working papers to sampling. Say what you would sample, how many, and why. For example: select 10 changes from the change log across the last 6 months to verify A.8.32 change management. This shows practical competence.
Tip 9: Include positive findings. Working papers should record conformity as well. Questions sometimes test whether auditors record only problems. They should not.
Tip 10: Watch for distractors. Common wrong options include:
- working papers must be handed to the auditee at the closing meeting;
- checklists must be followed strictly without deviation;
- working papers can be destroyed immediately after the report is issued;
- auditors may keep client documents for future reference or training.
Tip 11: For essay questions, use a clear structure.
- Define audit working papers.
- State their purpose and importance.
- Describe their preparation, use, and retention and protection.
- Apply all of this to the scenario.
- Conclude with how they support reliable audit conclusions.
Tip 12: Remember the ISMS twist. In an ISO/IEC 27001 audit, the auditor must also follow the auditee's information security rules. Examples include clean desk policies, restricted photography in data centres, not plugging USB devices into client systems, and following classification labels. Mentioning this shows ISMS-specific awareness.
8. Quick Revision Summary
- What: documents prepared, collected and used to plan, perform and record the audit.
- Why: evidence-based conclusions, traceability, consistency, reporting, accreditation and professional protection.
- How: prepared from the audit criteria and risks, used flexibly on site, cross-referenced to findings, protected, retained and securely disposed of.
- Key standards: ISO 19011 (6.3.4 and 6.4), ISO/IEC 17021-1, ISO/IEC 27006, ISO/IEC 27007.
- Key exam principles: do not restrict the audit, protect confidentiality, record objective evidence, the audit organisation owns the papers, and write findings in three parts.
Conclusion
Audit working papers turn an audit from a conversation into an evidence-based, defensible evaluation of an ISMS. A Lead Auditor who prepares tailored, flexible working documents, records evidence precisely and protects that information will produce credible audit conclusions. Show that understanding in the exam, with correct terminology and attention to confidentiality, and you will be well prepared for any question on this topic.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!