Guides and Observers
In an ISO/IEC 27001 audit, guides and observers are people who accompany the audit team without being part of it. Their roles are addressed in ISO 19011:2018 (clause 6.4.7), which certification bodies apply alongside ISO/IEC 17021-1 and ISO/IEC 27006. A Lead Auditor must manage both roles so the au… In an ISO/IEC 27001 audit, guides and observers are people who accompany the audit team without being part of it. Their roles are addressed in ISO 19011:2018 (clause 6.4.7), which certification bodies apply alongside ISO/IEC 17021-1 and ISO/IEC 27006. A Lead Auditor must manage both roles so the audit stays objective, efficient and secure. Guides are usually appointed by the auditee to help the audit team. They act at the request of the audit team leader or the assigned auditor and do not evaluate evidence. Their typical duties are to: - arrange contacts and schedule interviews with process owners and control operators; - arrange access to specific sites, server rooms, secure areas or information systems; - make sure the team knows and follows site safety, security and confidentiality rules, which is especially important where classified information or restricted zones are involved; - witness the audit on behalf of the auditee; - clarify information or help collect it, for example by locating records, logs or documented procedures. Observers watch the audit but take no part in it. They may come from the auditee, the audit client, a regulator, an accreditation body assessing the certification body, or the certification body itself (such as trainee auditors or witness assessors). Their presence must be agreed in advance by the audit team leader and the auditee, and by the audit client where relevant. Observers must not influence or interfere with the audit. They are bound by the same health, safety, security and confidentiality arrangements as everyone else, and they may need to sign a non-disclosure agreement. The Lead Auditor keeps control throughout. If an observer or guide compromises impartiality or the auditee's information security, or disrupts interviews, the Lead Auditor may restrict or refuse their participation in particular activities. Both roles should be clarified at the opening meeting. Their presence should also be recorded, which supports transparency, confidence in the findings and the integrity of the certification process.
Guides and Observers in an ISO/IEC 27001 Audit: Complete Guide for Lead Auditor Exams
Introduction
When an ISO/IEC 27001 audit is carried out, the audit team is rarely the only group of people present. Two other roles often accompany the team during on-site (or remote) audit activities: guides and observers. ISO 19011:2018 (Guidelines for auditing management systems) and ISO/IEC 17021-1 (Requirements for bodies providing audit and certification of management systems) both define these roles. A Lead Auditor must understand them clearly, because they affect audit independence, objectivity, confidentiality, safety and the smooth running of the audit.
Why Guides and Observers Are Important
1. Protecting audit integrity: The audit conclusions must be based only on objective evidence gathered by the audit team. If guides or observers influence or interfere with the audit, the findings may be biased or invalid.
2. Efficiency and access: Guides help the audit team move through the auditee's premises, find the right people and reach the right information quickly. This is especially useful in large or secure facilities such as data centres.
3. Health, safety and security: In environments with physical security controls (ISO/IEC 27001 Annex A 7, Physical controls), visitors often must be escorted. Guides make sure auditors follow security and safety rules.
4. Transparency and oversight: Observers may come from accreditation bodies, regulators, the auditee's organisation or the certification body. Their presence supports oversight, witnessing and training.
5. Confidentiality: ISO/IEC 27001 audits involve sensitive information. Everyone present, including observers, must respect confidentiality arrangements.
6. Exam relevance: Lead Auditor exams (PECB, IRCA/CQI, BSI, Exemplar Global and others) regularly test the difference between guides and observers, who appoints them, what they may and may not do, and how the audit team leader handles problems involving them.
What Are Guides and Observers?
Guides
ISO 19011 defines a guide as a person appointed by the auditee to assist the audit team. Guides are normally employees of the auditee, such as the ISMS manager, an IT supervisor or a department head. They are not members of the audit team.
Typical responsibilities of guides (ISO 19011, clause 6.4.6):
- Establishing contacts and arranging timing for interviews
- Arranging visits to specific parts of the site or organisation
- Making sure the audit team knows and follows site safety and security rules and procedures, and that risks are addressed
- Witnessing the audit on behalf of the auditee when appropriate
- Providing clarification or helping collect information when requested by an auditor
Observers
ISO 19011 defines an observer as an individual who accompanies the audit team but does not act as an auditor. Observers are also not members of the audit team and do not influence or interfere with the conduct of the audit.
Examples of observers:
- Representatives of the accreditation body witnessing the certification body's auditors
- Regulators or other interested parties
- Members of the auditee's organisation (for example, staff being trained as internal auditors)
- Trainee auditors or consultants (subject to impartiality rules in ISO/IEC 17021-1)
- Representatives of a client organisation in second-party audits
Key Differences at a Glance
- Appointed by: Guides are appointed by the auditee. Observers' attendance must be agreed between the audit team leader (or audit client/certification body) and the auditee.
- Purpose: Guides assist the audit team. Observers watch the audit for their own purposes, such as witnessing, training or oversight.
- Role in audit: Neither is an audit team member, and neither collects evidence or reaches conclusions on the team's behalf. A guide may help gather information on request. An observer does not participate.
- Influence: Neither should influence or interfere with the audit.
- Who manages them: The audit team leader is ultimately responsible for managing the audit, including how guides and observers take part.
How It Works in Practice
1. Planning stage
- The audit plan should identify whether guides and observers will be present, including their names, roles and the reasons for their attendance where known.
- ISO 19011 (clause 6.3.2) states that the audit plan should cover the roles and responsibilities of the audit team members, as well as guides and observers.
- Observer attendance must be agreed in advance between the audit team leader/audit client and the auditee. The auditee can object to an observer, for example because of confidentiality or a conflict of interest.
- ISO/IEC 17021-1 (clause 9.2.3) requires the certification body to agree with the client the presence and justification of observers before the audit is carried out.
2. Opening meeting
- The audit team leader introduces all participants, including guides and observers, and confirms their roles.
- The leader explains that guides and observers must not interfere with the audit, and confirms confidentiality, safety and security arrangements.
3. During the audit
- Guides escort auditors, arrange interviews, explain site rules and help locate documents or records when asked.
- Auditors remain independent. They decide what to sample, whom to interview and what evidence to accept. A guide cannot direct the audit trail.
- Observers stay passive. They do not ask auditees questions, comment on findings or influence sampling.
- If a guide or observer interferes (for example, answering for interviewees, steering auditors away from areas, or pressuring the team), the audit team leader should address it politely but firmly. If the problem continues, the leader may ask them to leave the activity or report the matter to the audit client and auditee.
4. Special considerations for ISMS audits
- Secure areas such as server rooms and network operations centres usually require an escort. The guide makes sure access follows the auditee's physical and logical security controls.
- Auditors may need to view sensitive data. The guide may help confirm what can be viewed, copied or photographed, in line with the auditee's information classification rules.
- Observers must also respect non-disclosure agreements and information handling rules.
5. Remote audits
- In virtual audits, a guide may share screens, move cameras around the site, or connect auditors with personnel.
- Observers joining remotely must be identified and agreed, and recording of sessions must be agreed with the auditee.
6. Closing meeting and reporting
- Guides and observers may attend the closing meeting if appropriate and agreed.
- Observers do not contribute to the audit conclusions or nonconformities. The audit report may note who attended.
Common Scenarios and Correct Responses
- Scenario: A guide keeps answering on behalf of the interviewee.
Response: The auditor politely explains that the interviewee needs to answer directly, so the evidence reflects their own knowledge and practice. If this continues, the auditor raises it with the audit team leader, who may discuss it with the auditee's management.
- Scenario: An accreditation body assessor attends as an observer.
Response: This is a witness assessment of the certification body's audit team. The assessor observes and does not take part. Their presence should be agreed with the client in advance.
- Scenario: A guide stops the auditor from entering the data centre.
Response: The auditor finds out the reason (for example, safety, security or access rules). If entry is needed for the audit objectives, the team leader discusses alternatives with the auditee. If access is unjustifiably refused, this is a limitation of scope that is reported, and it may affect the audit conclusions.
- Scenario: An observer starts suggesting nonconformities.
Response: The audit team leader reminds the observer of their non-participating role. Only the audit team determines findings.
- Scenario: A consultant who helped implement the ISMS wants to observe.
Response: This is allowed only if agreed and if it does not compromise impartiality. The consultant must not influence the audit. Under ISO/IEC 17021-1, consultants must not act as audit team members.
Exam Tips: Answering Questions on Guides and Observers
1. Remember the core definitions. Guide = appointed by the auditee to assist the audit team. Observer = accompanies the audit team but does not audit. Neither one is part of the audit team.
2. Watch for the trap answer that guides or observers are team members. Any option saying a guide or observer can conduct interviews independently, write findings or decide audit conclusions is wrong.
3. Know who appoints whom. The auditee appoints guides. The audit client/certification body, the audit team leader and the auditee agree on observers. Technical experts and auditors in training, by contrast, are part of the audit team and are assigned by the audit programme manager/certification body.
4. Do not confuse observers with technical experts. A technical expert provides specific knowledge to the audit team, works under an auditor's direction and is a team member. An observer is not a team member.
5. Choose answers that protect independence and objectivity. When a scenario describes interference, the best answer is usually for the audit team leader to manage the situation tactfully: clarify roles, ask for non-interference, and escalate to the auditee/audit client if needed.
6. Prefer prior agreement. Questions often ask what must happen before observers attend. The answer is agreement with the auditee and inclusion in the audit plan, not a surprise arrival on the day.
7. Link to safety and security. If a question mentions secure areas or hazardous zones, remember that guides help auditors follow the auditee's safety and security rules.
8. Treat confidentiality as non-negotiable. Everyone present, guides and observers included, must respect the auditee's confidentiality and information security requirements. This is especially important in ISO/IEC 27001 audits.
9. Use reference clauses in essay answers. In written or scenario exams, cite ISO 19011:2018 clause 6.4.6 (roles and responsibilities of guides and observers) and clause 6.3.2 (audit plan). For certification audits, cite ISO/IEC 17021-1 clause 9.2.3 (observers, technical experts and guides). Citing standards shows depth.
10. Structure scenario answers. A strong answer follows this pattern: identify the role (guide or observer), state what the role may and may not do, explain the risk (bias, interference, confidentiality, safety), and describe the Lead Auditor's action (clarify, manage, document, escalate).
11. Keep the audit evidence clean. Information supplied by a guide should still be verified. Auditors should seek objective evidence from the responsible personnel and records, not rely only on the guide's statements.
12. Watch the wording. Phrases like should not influence or interfere, appointed by the auditee and not a member of the audit team are strong signs of a correct option.
Quick Revision Summary
- Guides: appointed by the auditee. They assist with contacts, access, safety, security and clarification, and may witness the audit for the auditee.
- Observers: accompany the team without auditing. Their attendance is agreed beforehand. They do not interfere.
- Neither is a member of the audit team. Both are subject to confidentiality and site rules.
- The audit team leader manages their participation and deals with any interference.
- Both should be included in the audit plan and introduced at the opening meeting.
If you master these points, you will be able to answer multiple-choice, scenario-based and essay questions on guides and observers with confidence in any ISO/IEC 27001 Lead Auditor examination.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!