Drafting Audit Findings
In an ISO/IEC 27001 audit, drafting audit findings is the step where the auditor turns collected evidence into clear, defensible statements about how well the information security management system (ISMS) conforms to the audit criteria. Following ISO 19011 and ISO/IEC 27007 guidance, findings resul… In an ISO/IEC 27001 audit, drafting audit findings is the step where the auditor turns collected evidence into clear, defensible statements about how well the information security management system (ISMS) conforms to the audit criteria. Following ISO 19011 and ISO/IEC 27007 guidance, findings result from evaluating objective evidence against criteria such as ISO/IEC 27001 clauses 4 to 10, applicable Annex A controls, the Statement of Applicability, the organization's own policies, and legal or contractual obligations. Findings fall into three main types. A conformity confirms that a requirement is met. A nonconformity is the non-fulfilment of a requirement. It is usually graded as major when it represents a systemic breakdown, a missing required process, or a failure that undermines the ISMS's ability to achieve its intended outcomes. It is graded as minor when it is an isolated lapse that does not compromise the system overall. An opportunity for improvement highlights a potential weakness or a better practice without being a breach. A well-drafted nonconformity normally has three parts. The first is the requirement, which cites the exact clause or control. The second is the objective evidence, which records what was seen, heard, or reviewed, including document references, records, dates, locations, and the roles of interviewees. The third is the statement of nonconformity, which explains concisely how the evidence fails to meet the requirement. Findings must be factual, verifiable, traceable, and impartial. They should be written in neutral language that avoids blame, opinion, or assumptions, and they should not prescribe solutions, because corrective action is the auditee's responsibility. Auditors should check that the sampled evidence is sufficient, and the audit team should review findings together to ensure consistency and correct grading and to remove duplicates. Draft findings should be discussed with the auditee during the audit or at the closing meeting so that facts can be confirmed and misunderstandings resolved. Clear, accurate findings support credible audit conclusions, enable effective root cause analysis and corrective action, and form the foundation of the audit report and the certification decision.
Drafting Audit Findings in an ISO/IEC 27001 Audit: A Complete Guide for Lead Auditors
Introduction
Drafting audit findings is one of the most critical skills an ISO/IEC 27001 Lead Auditor must master. Audit findings are the formal written result of evaluating collected audit evidence against audit criteria. They form the backbone of the audit report, drive the auditee's corrective actions, and ultimately influence the certification decision. A poorly written finding can be disputed, misunderstood or rejected. A well-drafted finding is clear, objective, traceable and actionable.
Why Drafting Audit Findings Is Important
1. Foundation of the certification decision: The certification body's decision to grant, maintain, suspend or withdraw certification is largely based on the findings documented by the audit team.
2. Drives continual improvement: Findings trigger corrective actions under clause 10.2 (Nonconformity and corrective action) of ISO/IEC 27001, helping the organization improve its Information Security Management System (ISMS).
3. Legal and contractual defensibility: Findings may be reviewed by the certification body, accreditation bodies and the auditee. They must be backed by verifiable evidence so they can withstand challenge.
4. Credibility of the auditor and certification body: Vague, subjective or unsupported findings damage trust and may lead to appeals or complaints.
5. Communication tool: Findings tell top management exactly where the ISMS fails to meet requirements. This allows informed decisions on resources and risk.
6. Compliance with ISO 19011 and ISO/IEC 17021-1: These standards require findings to be based on objective evidence and to be clearly reported.
What Audit Findings Are
According to ISO 19011, an audit finding is the result of the evaluation of collected audit evidence against audit criteria. Findings can indicate either conformity or nonconformity. They can also identify opportunities for improvement or record good practices, where the audit plan allows.
Key related terms:
- Audit criteria: The set of requirements used as a reference. Examples include ISO/IEC 27001 clauses 4 to 10, Annex A controls, the organization's own policies and procedures, and legal, regulatory and contractual requirements.
- Audit evidence: Records, statements of fact or other information that are relevant to the audit criteria and verifiable. Evidence comes from interviews, observation and document or record review.
- Audit conclusion: The outcome of the audit after considering the audit objectives and all audit findings.
Types of Findings
1. Major nonconformity: Affects the capability of the management system to achieve its intended results. Typical cases:
- the absence or total breakdown of a required process (for example, no risk assessment performed at all, or no internal audits conducted);
- a number of minor nonconformities related to the same requirement that together indicate a systemic failure;
- a situation that raises significant doubt about effective process control.
A major nonconformity normally prevents certification until it is corrected and verified.
2. Minor nonconformity: Does not affect the capability of the management system to achieve its intended results. It is usually an isolated lapse, for example one access review not performed in one quarter while all others were.
3. Opportunity for improvement (OFI): Not a nonconformity. It is an observation where the requirement is met, but the auditor sees potential to improve effectiveness or efficiency. In certification audits, OFIs must not be phrased as specific consulting solutions.
4. Positive finding / good practice: A record of notable strengths.
5. Observation (in some schemes): A potential risk of future nonconformity that does not currently breach a requirement.
How Drafting Audit Findings Works
Step 1: Collect and verify evidence
During the audit, evidence is gathered through sampling, interviews, observation and document review. Only verifiable information can be audit evidence. Hearsay or unverified statements should be corroborated before being used.
Step 2: Compare evidence to audit criteria
The auditor determines whether the evidence shows the requirement is fulfilled. If the requirement is not fulfilled, a potential nonconformity exists.
Step 3: Determine the type and grade
Consider these questions:
- Is the breach isolated or systemic?
- Does it affect the ISMS's ability to achieve its intended outcomes?
- Is a required process missing entirely?
Step 4: Write the nonconformity statement
A well-structured nonconformity typically contains three elements, sometimes called the ACE or RES model.
- Requirement (criteria): State precisely which requirement is not fulfilled, for example 'ISO/IEC 27001:2022 clause 9.2.2 requires the organization to plan, establish, implement and maintain an audit programme' or 'Annex A control 5.18 Access rights'. Quote or paraphrase the requirement accurately.
- Evidence (objective evidence): Describe what was seen, heard or reviewed. Include traceable details such as document references, dates, record IDs, locations, sample sizes and the roles of interviewees. Name roles rather than individuals, to keep the report impersonal and non-blaming.
- Statement of nonconformity: A concise statement of what is lacking, such as 'The organization has not ensured that access rights are reviewed at planned intervals.'
Example of a well-drafted nonconformity:
Requirement: ISO/IEC 27001:2022 Annex A 5.18 and the organization's Access Control Policy (ACP-002, v3.1, section 4.2) require user access rights to be reviewed every quarter.
Evidence: A sample of 4 quarterly access review records for the ERP system (Q1 to Q4 2023) was requested. Records were available for Q1 and Q2 only. The IT Security Manager confirmed that Q3 and Q4 reviews were not performed due to staff shortages.
Nonconformity: Quarterly user access reviews for the ERP system were not carried out as required for two of the four sampled quarters.
Grade: Minor (an isolated lapse in one system, while the process exists and was previously implemented).
Step 5: Review findings with the audit team
Before the closing meeting, the audit team meets to review all findings and agree on grading. They ensure consistency and confirm that each finding is supported by evidence.
Step 6: Communicate and acknowledge
Findings should be communicated to the auditee during the audit, where possible, so there are no surprises at the closing meeting. The auditee may be asked to acknowledge the findings. Acknowledgement means agreement with the facts, not necessarily with the grading. Diverging opinions should be discussed and resolved. If they remain unresolved, they are recorded in the report.
Step 7: Include in the audit report
Findings are documented in the audit report along with the audit conclusions. The auditee then submits a corrective action plan. For a major nonconformity, the certification body typically requires correction and verification within a defined period, often a maximum of 6 months under ISO/IEC 17021-1 practice. Verification may be on-site or document-based.
Characteristics of Good Audit Findings
- Factual and objective: Based on evidence, not opinion or assumption.
- Clear and concise: Easy to understand by someone not present at the audit.
- Traceable: Includes references to records, documents, dates and locations, so the finding can be verified later.
- Linked to a requirement: Every nonconformity must cite a specific criterion. If you cannot cite a requirement, it is not a nonconformity.
- Non-prescriptive: Describes the problem, not the solution. Auditors must not suggest how to fix it, because that would compromise impartiality (consultancy).
- Impersonal: Refers to roles, not names, and avoids blame.
- Appropriately graded: Major or minor based on impact and extent, not on the auditor's personal feelings.
- Written in neutral language: Avoid words like 'always', 'never', 'poor', 'terrible' or 'careless'.
Common Mistakes When Drafting Findings
- Writing a finding without a clear requirement reference.
- Using vague evidence such as 'several records were missing' instead of 'records for 3 of 10 sampled employees were missing'.
- Recommending corrective actions inside the finding.
- Grading based on severity of language rather than on systemic impact.
- Combining unrelated issues into one finding.
- Raising nonconformities against 'best practice' that is not part of the audit criteria.
- Including personal names or emotive language.
- Raising a nonconformity for an Annex A control that was justifiably excluded in the Statement of Applicability. Note, however, that an unjustified exclusion may itself be a nonconformity against clause 6.1.3.
Relationship with Corrective Action
The auditee is responsible for four things:
- performing a correction (immediate fix);
- conducting root cause analysis;
- implementing corrective action to prevent recurrence;
- evaluating the effectiveness of that action.
The auditor reviews the action plan and verifies implementation. A clearly drafted finding makes root cause analysis much easier for the auditee.
Exam Tips: Answering Questions on Drafting Audit Findings
1. Know the definitions precisely. Exams frequently test the ISO 19011 definitions of audit finding, audit evidence, audit criteria and audit conclusion. Remember that a finding equals evidence evaluated against criteria. Also remember that findings can be positive (conformity), not only negative.
2. Major versus minor: focus on impact and extent. In scenario questions, ask yourself these questions:
- Is a required process completely missing?
- Is the failure systemic, occurring across multiple samples or locations?
- Does it put the ISMS's intended results at risk?
If yes, choose major. If it is a single, isolated lapse in an otherwise functioning process, choose minor. Remember that a cluster of minors on the same requirement can be escalated to a major.
3. Every nonconformity needs a requirement. If a scenario describes something the auditor dislikes but no requirement is breached, the correct answer is usually an opportunity for improvement, not a nonconformity.
4. Do not prescribe solutions. Answers that include phrases like 'the auditor should recommend implementing tool X' are typically wrong in certification audit contexts. The auditor identifies the problem. The auditee determines the solution.
5. Look for objective, verifiable evidence. When asked to choose or write the best finding, select the option with specific, traceable evidence: dates, document IDs, sample sizes and roles. Reject options that are vague, emotional or based on assumptions.
6. Structure your written answers. For essay or case-study exams (for example, PECB ISO/IEC 27001 Lead Auditor), use a clear structure:
- Requirement / Clause: cite the exact clause or Annex A control.
- Evidence: what was observed, with specifics.
- Nonconformity statement: what is not fulfilled.
- Grade with justification: major or minor, and why.
Examiners award marks for each element, so omitting the justification loses points.
7. Use the correct clause numbers. Be familiar with ISO/IEC 27001:2022 clauses 4 to 10 and the 93 Annex A controls grouped into 4 themes:
- Organizational (5.1 to 5.37)
- People (6.1 to 6.8)
- Physical (7.1 to 7.14)
- Technological (8.1 to 8.34)
Common exam references include:
- 6.1.2 Risk assessment
- 6.1.3 Risk treatment and Statement of Applicability
- 7.2 Competence
- 7.5 Documented information
- 9.2 Internal audit
- 9.3 Management review
- 10.2 Nonconformity and corrective action
8. Watch for the Statement of Applicability trap. If a control is excluded with a valid justification, do not raise a nonconformity for not implementing it. If it is excluded without justification, or is needed based on the risk assessment, the nonconformity relates to clause 6.1.3.
9. Distinguish correction, corrective action and root cause. Questions may ask who does what. The auditee performs correction, root cause analysis and corrective action. The auditor evaluates and verifies.
10. Recognize the role of the audit team meeting. Findings are reviewed and agreed by the audit team before the closing meeting. The audit team leader has the final say in case of disagreement within the team.
11. Handling disagreement with the auditee. If the auditee disputes a finding, the auditor should re-examine the evidence and try to resolve the disagreement. If it remains unresolved, both positions are recorded in the report. The auditor should not simply drop a valid finding under pressure. Impartiality and integrity are key principles.
12. Read scenarios carefully for sampling details. Phrases like '1 out of 50 records' suggest minor. Phrases like 'none of the departments' or 'no evidence that the process exists' suggest major.
13. Eliminate wrong answers using principles. Apply the ISO 19011 principles to rule out options:
- integrity
- fair presentation
- due professional care
- confidentiality
- independence
- evidence-based approach
- risk-based approach
Any answer that violates these, such as basing a finding on rumor, is likely incorrect.
14. Manage your time in written exams. Draft findings concisely. Two to four sentences per element is usually sufficient. Clarity matters more than length.
Summary
Drafting audit findings converts raw audit evidence into meaningful, defensible conclusions about an ISMS. A good finding:
- cites the requirement;
- presents specific objective evidence;
- states the nonconformity clearly;
- is graded correctly based on its impact on the ISMS.
Mastering this skill is essential both for real-world auditing and for passing the ISO/IEC 27001 Lead Auditor examination. Think like an auditor: be factual, be fair, be specific, and never prescribe the fix.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!