Communication During the Audit
Communication during the audit is a key activity in conducting an ISO/IEC 27001 audit. It follows the guidance in ISO 19011 and, for certification audits, the requirements of ISO/IEC 17021-1. Its purpose is to keep the audit on track, transparent and effective. The communication arrangements, inclu… Communication during the audit is a key activity in conducting an ISO/IEC 27001 audit. It follows the guidance in ISO 19011 and, for certification audits, the requirements of ISO/IEC 17021-1. Its purpose is to keep the audit on track, transparent and effective. The communication arrangements, including channels, contacts, language and reporting frequency, are usually confirmed during the opening meeting. There are three main lines of communication. First, within the audit team, members should meet regularly, often in daily briefings. They exchange information, assess progress, compare emerging findings, resolve conflicting evidence and reassign work if needed. This keeps the team's conclusions consistent and makes sure the full scope is covered. Second, with the auditee, the audit team leader should periodically report progress, significant findings and any concerns. This often happens at end-of-day meetings. It prevents surprises at the closing meeting and gives the auditee a chance to provide more evidence or clarify misunderstandings. Third, with the audit client, the client must be informed of progress and significant issues where appropriate, such as when the auditee and the client are different parties. Some situations need immediate escalation. Evidence of an immediate and significant risk should be reported without delay to the auditee and, if appropriate, the audit client. An example is an active security breach or a critical vulnerability exposing sensitive information. Concerns found outside the audit scope should be recorded and passed to the team leader, who decides whether to communicate them. If the available evidence shows that the audit objectives cannot be achieved, the team leader must report the reasons to the client and auditee. Possible causes include restricted access, unavailable personnel or missing documented information. The parties then agree on actions such as changing the audit plan, adjusting the objectives or scope, or ending the audit. Any change to scope must be reviewed and approved by the relevant parties. All communication must be professional, objective and confidential. Important communications should be documented. Guides and observers must not influence the audit.
Communication During the Audit: ISO/IEC 27001 Lead Auditor Guide
Introduction
Communication during the audit is a core part of conducting an ISO/IEC 27001 audit. It is guided by ISO 19011:2018 (clause 6.4.4, 'Communicating during the audit') and ISO/IEC 17021-1 for certification audits. For a Lead Auditor, it is not a soft skill added on top of the audit. It is the mechanism that keeps the audit on track, keeps the auditee informed, escalates risks and makes the findings credible and accepted.
Why It Is Important
An ISO/IEC 27001 audit examines an organization's Information Security Management System (ISMS). That system often covers sensitive information, critical processes and many stakeholders. Poor communication can cause misunderstandings, surprise findings, wasted time, damaged relationships and even audit failure. Good communication matters for these reasons:
- No surprises: The auditee learns about emerging nonconformities as they arise, not for the first time at the closing meeting.
- Team coordination: The audit team exchanges information, reassigns work and checks coverage of the audit plan.
- Timely escalation: Urgent or significant risks are raised promptly, such as an immediate threat to information security, safety or legal compliance.
- Audit objectives stay achievable: If evidence shows the objectives cannot be met, the audit client and auditee are told so a decision can be made.
- Better quality of findings: Ongoing dialogue lets the auditee clarify, provide more evidence or correct misunderstandings before findings are finalized.
- Professionalism and trust: This reflects the ISO 19011 principles of integrity, fair presentation and due professional care.
What It Is
Communication during the audit covers all formal and informal exchanges of information from the opening meeting to the closing meeting. It includes:
1. Internal team communication: Audit team members talk to each other regularly, and the audit team leader periodically brings them together.
2. Communication with the auditee: The team leader shares progress, concerns and emerging findings with the auditee's management or representative (guide or audit liaison).
3. Communication with the audit client: Issues beyond the audit scope, or problems in achieving objectives, are reported to the client. For certification audits, this may mean the certification body.
4. Escalation communication: Evidence suggesting an immediate and significant risk is reported without delay to the auditee and, as appropriate, the audit client.
How It Works
1. Arrangements set at the start
Communication arrangements are agreed during audit preparation and confirmed at the opening meeting. They cover:
- channels of communication
- who the contact persons are
- the frequency of progress briefings
- how urgent issues will be raised
- language
- confidentiality requirements
2. Audit team meetings
The team leader holds periodic meetings, often daily or at the end of each day. The team uses them to:
- exchange information
- assess audit progress against the plan
- reassign work among auditors if needed
- review emerging findings
- check consistency of judgment across the team
3. Progress reporting to the auditee
The team leader periodically tells the auditee, and the audit client where appropriate, about:
- audit progress
- any significant findings
- any concerns
Daily briefings or wrap-ups are common. Findings shared at this point are preliminary, not final.
4. Handling emerging issues
ISO 19011 describes several situations and how to handle them:
- Immediate and significant risk: Evidence collected suggests an immediate and significant risk, for example a severe security exposure. It should be reported without delay to the auditee and, as appropriate, the audit client.
- Concern outside the audit scope: This should be noted and reported to the team leader. Where appropriate, it is communicated to the audit client and auditee. The auditor should not expand the scope on their own authority.
- Objectives unattainable: Available evidence may show that audit objectives are unattainable, for example because records are unavailable or access is denied. The team leader reports the reasons to the audit client and auditee to decide on appropriate action. Options include reconfirming or modifying the audit plan, changing the objectives or scope, or terminating the audit.
- Changes to the audit plan or scope: Any need for change, as the audit progresses, should be reviewed and approved, as appropriate, by both the audit client and the auditee.
5. Role of guides and observers
Guides facilitate communication, establish contacts, arrange access and may witness the audit on behalf of the auditee. Guides and observers do not influence or interfere with the conduct of the audit. If they do, the team leader has the right to deny them certain participation.
6. Communication techniques during evidence gathering
Interviews are a key method of communication. Good practice includes:
- putting interviewees at ease and explaining the purpose
- interviewing people at the appropriate level and function
- using open questions, then closed questions to confirm
- listening actively
- avoiding leading questions
- summarizing and reviewing results with the interviewee
- thanking them
7. Confidentiality and ISMS sensitivity
ISO/IEC 27001 audits often involve sensitive information. Communication must respect agreed confidentiality arrangements, information classification and secure handling of evidence. For example, avoid emailing sensitive evidence over insecure channels.
8. Resolving disagreement
Diverging opinions on findings should be discussed and resolved before the closing meeting where possible. Unresolved diverging opinions should be recorded.
Example Scenario
On day two, an auditor discovers that a production database containing customer personal data is publicly accessible with default credentials. This is an immediate and significant risk. The auditor informs the team leader at once. The team leader then promptly notifies the auditee's top management or ISMS representative, and the audit client as appropriate. The team leader does not wait for the closing meeting. The auditor records the evidence objectively and does not attempt to fix the problem. Fixing it would compromise impartiality and amount to consultancy.
Exam Tips: Answering Questions on Communication During the Audit
1. Think 'no surprises at the closing meeting': Answers that hide findings until the end are usually wrong. Look for options where the team leader periodically informs the auditee of progress and concerns.
2. Immediate and significant risk means report without delay: If a scenario describes an urgent threat, the correct answer is prompt reporting to the auditee and, as appropriate, the audit client. It is not ignoring the issue, fixing it yourself or waiting for the report.
3. Outside scope means record and report, not investigate: Auditors must not unilaterally extend the scope. The correct action is to note the issue, inform the team leader and communicate it to the audit client and auditee as appropriate.
4. Objectives unattainable means the team leader informs the client and auditee: Expect answers about reporting the reasons and agreeing appropriate action. That action could be modifying the plan, changing scope or objectives, or terminating the audit.
5. Scope or plan changes need agreement: Changes should be reviewed and approved, as appropriate, by the audit client and the auditee. The audit team cannot decide alone.
6. Know who communicates: The audit team leader is responsible for formal communication with the auditee and audit client. Individual auditors report through the team leader.
7. Team meetings have a purpose: They are used to exchange information, assess progress and reassign work. Watch for distractor answers claiming team meetings are only social or optional.
8. Guides and observers do not interfere: If a question asks about an observer influencing interviews, the answer usually involves the team leader limiting or excluding them.
9. Stay impartial: Auditors communicate findings. They do not offer solutions or consultancy. Options where the auditor tells the auditee exactly how to fix a control are typically incorrect in certification contexts.
10. Confidentiality is critical in ISO 27001 audits: Prefer answers that protect sensitive information and follow agreed communication channels.
11. Scenario questions: Identify which situation applies: urgent risk, out-of-scope concern, objectives at risk, disagreement or scope change. Then apply the matching ISO 19011 response. Ask yourself: who must be informed, when, and by whom?
12. Essay or long-answer questions: Structure your answer in five parts:
(a) purpose of communication
(b) internal team communication
(c) communication with auditee and client
(d) escalation of significant issues
(e) documentation and confidentiality
Refer to ISO 19011 clause 6.4.4 to show standards knowledge.
13. Watch the wording: Words like 'immediately', 'without delay', 'periodically' and 'as appropriate' are often the key to the correct option. Absolute words such as 'never inform' or 'always stop the audit' are often distractors.
Summary
Communication during the audit keeps the audit transparent, coordinated and effective. The Lead Auditor sets the arrangements, holds regular team meetings and briefs the auditee and client on progress. They escalate urgent risks without delay, handle out-of-scope issues and unattainable objectives correctly, and agree any changes. Throughout, they maintain confidentiality and impartiality. In exams, link each scenario to the correct ISO 19011 response, and remember the guiding principle: timely, factual, impartial and confidential communication, with no surprises.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!