Corroboration and Evaluation of Evidence
In an ISO/IEC 27001 audit, corroboration and evaluation of evidence are central to the evidence-based approach described in ISO 19011 and ISO/IEC 27007. Audit evidence consists of records, statements of fact or other information that is relevant to the audit criteria and verifiable. A Lead Auditor … In an ISO/IEC 27001 audit, corroboration and evaluation of evidence are central to the evidence-based approach described in ISO 19011 and ISO/IEC 27007. Audit evidence consists of records, statements of fact or other information that is relevant to the audit criteria and verifiable. A Lead Auditor must make sure findings rest on reliable, objective evidence rather than assumptions or a single unverified claim. Corroboration means confirming information by checking it against independent sources or different audit methods. This is often called triangulation. An auditor normally combines three techniques: interviewing personnel, observing activities, and reviewing documents, records and technical configurations. For example, an IT manager may say that user access rights are reviewed quarterly, as Annex A control 5.18 expects. The auditor corroborates this by sampling review records, checking system logs for removed accounts, and perhaps confirming that a recent leaver's account was disabled promptly. Information from interviews alone is weaker evidence. When independent sources agree, confidence in the evidence rises. When they contradict each other, the auditor must investigate further before drawing a conclusion. Evaluation of evidence means comparing the collected, verified evidence against the audit criteria to produce audit findings. The criteria include the clauses of ISO/IEC 27001, the organization's ISMS policies and procedures, the Statement of Applicability, and legal or contractual requirements. The auditor judges whether the evidence is sufficient in quantity, often based on sampling, and appropriate in quality, meaning relevant and reliable. Findings are then classified as conformity, major nonconformity, minor nonconformity, or an opportunity for improvement. Key principles include objectivity, professional skepticism, traceability of evidence, and awareness of the uncertainty that sampling introduces. Nonconformities must be clearly stated, supported by verifiable evidence, and linked to the specific requirement that was not met. Done properly, corroboration and evaluation lead to credible, defensible audit conclusions. They also support fair certification decisions and give the auditee useful input for improving its information security management system.
Corroboration and Evaluation of Evidence in an ISO/IEC 27001 Audit: A Complete Guide for Lead Auditors
Introduction
Corroboration and evaluation of evidence sit at the heart of every ISO/IEC 27001 audit. An auditor's conclusions, whether a nonconformity, an observation or a statement of conformity, are only as strong as the evidence behind them. ISO 19011:2018 (Guidelines for auditing management systems) and ISO/IEC 27007 (Guidelines for ISMS auditing) both stress that audit findings must rest on verifiable, objective audit evidence. ISO/IEC 17021-1 sets requirements for certification bodies and also governs certification audits. This guide explains what corroboration and evaluation of evidence mean, why they matter, how they work in practice, and how to handle exam questions on the topic.
1. What Is It?
Audit evidence is defined in ISO 19011 as records, statements of fact or other information which are relevant to the audit criteria and verifiable. Audit evidence can be qualitative or quantitative.
Corroboration means confirming a piece of evidence with at least one other independent source. For example, an interviewee may say that access rights are reviewed quarterly. The auditor corroborates this by examining access review records and observing the system configuration.
Evaluation of evidence means comparing the collected and corroborated evidence against the audit criteria. These criteria include the ISO/IEC 27001 requirements, the Statement of Applicability, the organization's policies and procedures, and legal, regulatory or contractual obligations. The result of that comparison is the audit finding: a conformity, a nonconformity (major or minor), or an opportunity for improvement.
The logical flow defined by ISO 19011 is:
Sources of information → Collecting by appropriate sampling → Audit evidence → Evaluating against audit criteria → Audit findings → Review → Audit conclusions
2. Why Is It Important?
• Evidence-based approach: ISO 19011 lists the evidence-based approach as one of its seven principles of auditing. It is the rational method for reaching reliable and reproducible audit conclusions.
• Fair presentation: Findings and conclusions must truthfully and accurately reflect audit activities.
• Credibility of certification: Certification decisions rely on the audit report. Weak or uncorroborated evidence undermines the integrity of certification and the reputation of the certification body.
• Defensibility: Auditees can challenge nonconformities. Corroborated, documented evidence makes a finding defensible and helps avoid disputes.
• Avoiding bias: Corroboration protects against reliance on a single person's opinion, hearsay or the auditor's assumptions.
• Risk of sampling: Audits are based on samples, so there is always uncertainty. Corroboration and careful evaluation reduce the risk of wrong conclusions.
3. How It Works
3.1 Methods of collecting evidence
The three main techniques are:
• Interviews: statements from personnel. On their own these are the weakest evidence and usually need corroboration.
• Observation: watching activities, facilities and behaviours. Examples include clean desk practices, badge use and screen locking.
• Document and record review: policies, procedures, logs, risk assessments, the SoA, training records and incident reports.
Additional technical techniques include:
• Technical verification, such as reviewing firewall rules or system configurations.
• Re-performance, where the auditor repeats a check.
• Analysis of data and logs.
ISO/IEC 27007 also addresses remote and technical evidence gathering.
3.2 Triangulation
A common best practice is to triangulate: confirm the same fact through interview (what people say), documentation (what is written) and observation or records (what is actually done). When all three align, the evidence is strong. When they conflict, the auditor must investigate further.
3.3 Qualities of good evidence
Evidence should be:
• Relevant: related to the audit criteria and objective.
• Reliable: from a credible, independent source. Original records are better than copies, system-generated logs are better than manual ones, and evidence collected directly by the auditor is better than evidence reported second-hand.
• Sufficient: enough in quantity, meaning an adequate sample, to support the conclusion.
• Verifiable: another competent auditor could reach the same conclusion using the same evidence.
• Objective: factual, free of opinion and personal interpretation.
• Timely: covering the relevant audit period.
3.4 Hierarchy of reliability (general guidance)
Ranked from generally strongest to weakest:
1. Evidence obtained directly by the auditor through observation, technical testing or re-performance.
2. System-generated or third-party records.
3. Internal documents and records produced by the auditee.
4. Oral statements, especially uncorroborated statements from a single interviewee.
3.5 Sampling
ISO 19011 describes judgement-based sampling, which relies on the auditor's knowledge and experience, and statistical sampling, which uses random selection and supports statistical inference. The sample must be representative. Conclusions drawn from it carry inherent uncertainty, which should be communicated in the audit report where relevant.
3.6 Evaluating evidence and generating findings
• Compare the evidence against each relevant requirement.
• Decide whether it demonstrates conformity or nonconformity.
• For nonconformities, record three elements: the requirement (the criterion), the evidence (objective facts), and the statement of nonconformity (why the evidence fails the requirement).
• Grade the nonconformity:
- Major: the absence or total breakdown of a requirement, or a situation that raises significant doubt about the ISMS achieving its intended outcomes.
- Minor: an isolated or occasional lapse that does not compromise the system.
• Record conforming evidence as well. Good practice is to note strengths.
3.7 Handling conflicting or insufficient evidence
• If evidence conflicts, for example a procedure states one thing but practice differs, seek additional sources. Interview other staff, extend the sample or review more records.
• If evidence remains insufficient to support a nonconformity, do not raise one. You may record an observation or area for follow-up, or extend the audit trail if time allows.
• Evidence pointing to non-conformity outside the audit scope should be noted and communicated to the audit client or team leader as appropriate. It should not be ignored.
• Never base a finding on assumption, rumour or personal opinion.
3.8 Team review and conclusions
At the end of the audit, the audit team meets to:
• Review findings and confirm they are supported by evidence.
• Agree on the grading of nonconformities.
• Consider the uncertainty arising from sampling.
• Reach audit conclusions, such as whether to recommend certification.
Findings are then presented at the closing meeting. Divergent opinions between the team and the auditee should be discussed and, if possible, resolved. Unresolved disagreements are recorded.
3.9 Documentation
All evidence should be recorded with enough detail to allow traceability and later verification. Useful details include:
• Document references and version numbers.
• Record IDs, dates and sample sizes.
• Names or roles of interviewees.
• Locations and system names.
Working documents such as checklists and notes are retained in accordance with the certification body's procedures and confidentiality requirements.
4. Practical Example
Requirement: ISO/IEC 27001 Annex A 5.18 (Access rights, 2022 version) and the organization's access control policy, which requires quarterly user access reviews.
Interview: The IT manager states that reviews are done every quarter.
Document review: The policy confirms a quarterly frequency.
Records: Review records exist for Q1 and Q2, but none for Q3 or Q4 of the past year.
Technical verification: Three accounts of employees who left six months ago are still active in Active Directory.
Evaluation: The evidence is corroborated by records and technical verification and contradicts the interview statement. A nonconformity is justified. The grade, minor or major, depends on extent and impact. A systemic failure affecting multiple systems may be graded major.
5. Common Pitfalls
• Raising a nonconformity based solely on one interview.
• Accepting a documented procedure as proof that it is implemented.
• Confusing the existence of a policy with the effectiveness of a control.
• Writing findings with opinions such as 'the process seems weak' instead of facts.
• Failing to record evidence references.
• Extrapolating beyond the sample without justification.
• Treating auditee self-assessments as conclusive evidence.
Exam Tips: Answering Questions on Corroboration and Evaluation of Evidence
Tip 1: Know the definitions word for word. Be ready to define audit evidence, audit criteria, audit findings and audit conclusions as given in ISO 19011 and ISO 19011's terms.
Tip 2: Prefer answers that verify. In multiple-choice scenarios, the correct answer usually involves seeking additional, independent evidence before concluding. Be wary of options where the auditor immediately raises a nonconformity based on one statement, or accepts a claim without verification.
Tip 3: Spot the weakest evidence. If a question asks which evidence is least reliable, choose the uncorroborated verbal statement or hearsay. If asked for the most reliable, choose direct observation, technical verification or system-generated records.
Tip 4: Remember 'say, document, do'. Many scenario questions describe a gap between what people say, what documents state and what actually happens. The correct response is to identify the inconsistency and corroborate it, then raise a finding against the relevant clause, such as clause 7.5 for documented information or clause 8.1 for operational planning and control.
Tip 5: Write nonconformities in three parts. In essay or case-study exams, such as the PECB ISO/IEC 27001 Lead Auditor exam, structure each nonconformity as:
(1) the requirement, with clause or control reference;
(2) the objective evidence observed, with specific facts, dates and sample sizes;
(3) the reason it does not conform.
Then justify the grade, major or minor.
Tip 6: Justify major versus minor with evidence. Explain the extent (isolated or systemic), the impact on the ISMS's ability to achieve its outcomes, and whether the requirement is absent entirely.
Tip 7: Handle insufficient evidence correctly. If a case states that the auditor ran out of time or found only a hint of a problem, the right answer is usually not to raise a nonconformity. Instead, record it as an observation or area for further investigation in the next audit.
Tip 8: Mention sampling and uncertainty. When discussing conclusions, note that audits are sample-based and that there is inherent uncertainty. Show awareness of representative sampling, judgement-based or statistical.
Tip 9: Link to auditing principles. Name the evidence-based approach, fair presentation, due professional care, independence and integrity where relevant. Examiners reward linking actions to principles.
Tip 10: Avoid opinion and advice. Auditors report facts and must not provide consultancy. If an answer option has the auditor recommending a specific solution, it is usually wrong in a certification audit context.
Tip 11: Read case studies carefully for hidden evidence. Case-study questions often embed dates, version numbers or contradictory statements. Underline them and use them as your objective evidence.
Tip 12: Think about documented information versus implementation. A documented procedure proves design, not operation. Exams often test whether you will look for records demonstrating implementation and effectiveness.
Tip 13: Use correct terminology. Use the terms audit criteria, objective evidence, conformity, nonconformity, corroborate, verify, sample, and traceable. Precise language signals competence.
Summary
Corroboration ensures evidence is confirmed by multiple independent sources. Evaluation compares that evidence objectively against audit criteria to produce findings. Together they deliver reliable, reproducible and defensible audit conclusions, the foundation of a credible ISO/IEC 27001 certification. In the exam, always favour verification over assumption, structure findings clearly, and justify every conclusion with objective, traceable evidence.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!