Audit Concepts and Terminology (ISO 19011)
ISO 19011:2018 provides guidelines for auditing management systems, including ISO/IEC 27001 Information Security Management Systems (ISMS). It defines a shared vocabulary so that auditors, auditees and clients understand audit activities in the same way. An audit is a systematic, independent and do… ISO 19011:2018 provides guidelines for auditing management systems, including ISO/IEC 27001 Information Security Management Systems (ISMS). It defines a shared vocabulary so that auditors, auditees and clients understand audit activities in the same way. An audit is a systematic, independent and documented process for obtaining objective evidence and evaluating it objectively to determine the extent to which audit criteria are fulfilled. Audit criteria are the set of requirements used as a reference, such as ISO/IEC 27001 clauses, Annex A controls, policies, procedures, legal obligations and contractual requirements. Audit evidence consists of records, statements of fact or other verifiable information relevant to the criteria, gathered through interviews, observation and document review, often by sampling. Audit findings result from evaluating evidence against criteria and may show conformity, nonconformity or opportunities for improvement. A nonconformity is the non-fulfilment of a requirement, often graded by certification bodies as major or minor. The audit conclusion is the outcome of the audit after considering the objectives and all findings. Key planning terms include the audit programme, which covers arrangements for one or more audits over a specific period, and the audit plan, which describes the activities and logistics of a single audit. Audit scope defines the extent and boundaries, such as locations, processes and time period, while audit objectives state what the audit must accomplish. Roles include the audit client, who requests the audit; the auditee, the organization being audited; the audit team, led by an audit team leader; technical experts, who provide specific knowledge; guides; and observers. Audits are classified as first-party (internal), second-party (customers or suppliers) and third-party (independent certification or regulatory bodies). Combined audits cover multiple management systems, and joint audits involve multiple auditing organizations. ISO 19011 also sets out seven principles: integrity, fair presentation, due professional care, confidentiality, independence, an evidence-based approach and a risk-based approach. Together, these concepts help ensure that ISMS audits are consistent, reliable and valuable for decision-making.
Audit Concepts and Terminology (ISO 19011): A Complete Guide for ISO 27001 Lead Auditors
Introduction
ISO 19011:2018, Guidelines for auditing management systems, is the international reference for how management system audits should be planned, conducted and reported. For anyone preparing for the ISO 27001 Lead Auditor examination, its concepts and terminology form the vocabulary of the whole course. Almost every exam question, whether it is about scoping, evidence, findings or reporting, assumes you understand these terms precisely. This guide explains why the topic matters, what the key concepts are, how they fit together in practice, and how to answer exam questions on them with confidence.
Why Audit Concepts and Terminology Are Important
1. A common language. Auditors, auditees, certification bodies and top management must interpret terms like audit criteria, audit evidence and nonconformity in the same way. Misunderstanding a term can lead to an invalid finding or a disputed audit report.
2. Consistency and repeatability. When auditors use standardised definitions, two competent auditors examining the same evidence against the same criteria should reach similar conclusions. This is the basis of trust in certification.
3. Credibility of certification. Accreditation bodies expect certification audits to follow ISO 19011 guidance and ISO/IEC 17021-1 requirements. Correct use of terminology shows professional competence.
4. Exam success. Lead Auditor exams (PECB, IRCA/CQI, BSI, Exemplar Global and others) test both definitions and their application. Many wrong answers on these exams are designed to sound plausible. Typical traps swap audit evidence with audit findings, or audit programme with audit plan.
5. Foundation for later topics. Risk-based auditing, sampling, interviewing and report writing all build on these core concepts.
What It Is: Key Terms from ISO 19011 (Clause 3)
Audit: a systematic, independent and documented process for obtaining objective evidence and evaluating it objectively to determine the extent to which the audit criteria are fulfilled. Remember the three adjectives: systematic, independent, documented.
Combined audit: an audit carried out together at a single auditee on two or more management systems. An example is ISO 27001 with ISO 9001.
Joint audit: an audit carried out at a single auditee by two or more auditing organisations. Exams often test the difference between combined (multiple standards) and joint (multiple audit organisations).
Audit programme: arrangements for a set of one or more audits planned for a specific time frame and directed towards a specific purpose. An example is a three-year certification cycle.
Audit scope: the extent and boundaries of an audit. It typically covers locations, organisational units, activities, processes and the time period covered.
Audit plan: a description of the activities and arrangements for a single audit. It includes the schedule, auditors assigned and areas to be audited.
Audit criteria: the set of requirements used as a reference against which objective evidence is compared. Examples include ISO/IEC 27001 clauses, policies, procedures, legal and contractual requirements.
Objective evidence: data supporting the existence or verity of something. It can be obtained through observation, measurement, testing or other means.
Audit evidence: records, statements of fact or other information that are relevant to the audit criteria and verifiable.
Audit findings: the results of evaluating the collected audit evidence against the audit criteria. Findings can indicate conformity, nonconformity or opportunities for improvement, and can lead to recommendations or good practices.
Audit conclusion: the outcome of an audit, reached after considering the audit objectives and all audit findings.
Audit client: the organisation or person requesting an audit.
Auditee: the organisation, as a whole or parts of it, being audited.
Audit team: one or more persons conducting an audit, supported if needed by technical experts. One auditor is appointed as audit team leader.
Technical expert: a person who provides specific knowledge or expertise to the audit team. A technical expert does not act as an auditor.
Observer: an individual who accompanies the audit team but does not act as an auditor.
Guide: a person appointed by the auditee to assist the audit team.
Competence: the ability to apply knowledge and skills to achieve intended results.
Conformity: fulfilment of a requirement.
Nonconformity: non-fulfilment of a requirement.
Management system: a set of interrelated or interacting elements of an organisation to establish policies, objectives and processes to achieve those objectives.
Risk: the effect of uncertainty. In ISO 19011:2018 risk-based thinking applies to the audit programme and to the audit process itself.
Types of Audits
First-party audit: an internal audit conducted by, or on behalf of, the organisation itself.
Second-party audit: conducted by parties with an interest in the organisation, such as customers auditing suppliers.
Third-party audit: conducted by independent auditing organisations, such as certification bodies or regulators. ISO 19011 provides guidance across all types. Third-party certification audits additionally follow ISO/IEC 17021-1 and, for ISMS, ISO/IEC 27006.
The Seven Principles of Auditing (Clause 4)
1. Integrity: the foundation of professionalism. This means being honest, diligent, responsible and impartial.
2. Fair presentation: the obligation to report truthfully and accurately. Findings, conclusions and reports must reflect audit activities faithfully, including diverging opinions and obstacles encountered.
3. Due professional care: the application of diligence and judgement in auditing.
4. Confidentiality: the security of information. Auditors must not use audit information for personal gain or inappropriately.
5. Independence: the basis for impartiality and objectivity of audit conclusions. Auditors should not audit their own work.
6. Evidence-based approach: the rational method for reaching reliable and reproducible audit conclusions. Evidence should be verifiable and is normally based on samples.
7. Risk-based approach: an audit approach that considers risks and opportunities. It influences planning, conducting and reporting so that audits focus on matters significant to the audit client and to achieving the audit programme objectives.
A useful mnemonic is I-F-D-C-I-E-R: Integrity, Fair presentation, Due care, Confidentiality, Independence, Evidence, Risk.
Structure of ISO 19011:2018
Clause 4: Principles of auditing
Clause 5: Managing an audit programme (uses the Plan-Do-Check-Act cycle)
Clause 6: Conducting an audit, which runs as follows:
(a) initiating the audit
(b) preparing audit activities
(c) conducting audit activities
(d) preparing and distributing the report
(e) completing the audit
(f) conducting follow-up
Clause 7: Competence and evaluation of auditors
Annex A: Additional guidance, such as sampling, remote audits, auditing context, leadership and risks
How It Works: The Concepts in Action
Think of the terminology as a logical chain:
Audit programme (multi-audit arrangement) leads to audit objectives, scope and criteria defined for each audit. This leads to the audit plan for that audit. The auditor then collects objective evidence / audit evidence through interviews, observation and document review. The evidence is compared against the audit criteria to produce audit findings (conformity, nonconformity, opportunity for improvement). All findings, considered against the objectives, produce the audit conclusion, which is communicated in the audit report.
Practical ISO 27001 example:
A certification body runs a three-year audit programme for a cloud provider. For the surveillance audit, the audit criteria are ISO/IEC 27001:2022 clauses 4 to 10, the Statement of Applicability and the organisation's access control policy. The scope is the Dublin data centre and the operations team. The plan schedules an interview with the IT manager at 10:00. The auditor samples 25 leaver records and finds 3 accounts still active 30 days after departure. This is audit evidence. Compared with the criterion (Annex A control 5.18 Access rights and the internal policy requiring removal within 24 hours), it produces an audit finding: a nonconformity. After evaluating all findings, the team reaches an audit conclusion. For example, the ISMS is generally effective, but a minor nonconformity requires corrective action.
Key Distinctions Examiners Love
Audit programme versus audit plan: a programme covers many audits over time, while a plan covers one audit.
Audit evidence versus audit findings: evidence is the facts collected, while findings are the result of comparing evidence with criteria.
Audit findings versus audit conclusion: findings are individual results, while the conclusion is the overall outcome.
Audit client versus auditee: they may be the same organisation (as in certification) or different (as when a customer audits a supplier).
Technical expert versus observer versus guide: none of them act as auditors. Technical experts support the team, observers accompany it without participating, and guides are appointed by the auditee to help.
Combined versus joint audit: a combined audit covers several management systems, while a joint audit involves several auditing organisations.
Independence versus integrity: independence concerns freedom from bias and conflict of interest, while integrity concerns ethical behaviour and honesty.
Exam Tips: Answering Questions on Audit Concepts and Terminology (ISO 19011)
1. Memorise the exact definitions. Questions often quote a definition and ask you to identify the term, or vice versa. Pay attention to key words: systematic, independent, documented (audit); verifiable (audit evidence); evaluation against criteria (findings); outcome (conclusion).
2. Follow the logical chain. If unsure, ask: has the information been compared with criteria yet? If not, it is evidence. If yes, it is a finding. If it summarises all findings against the objectives, it is a conclusion.
3. Watch for scale words. Words like multiple audits, time frame, three-year cycle point to the audit programme. Words like schedule, single audit, daily agenda point to the audit plan.
4. Map scenarios to principles. In scenario questions, identify which principle is at stake:
(a) An auditor auditing their own department breaches independence.
(b) Omitting an unresolved diverging opinion from the report breaches fair presentation.
(c) Discussing client data with a competitor breaches confidentiality.
(d) Reaching a conclusion without sufficient samples breaches the evidence-based approach.
(e) Rushing an audit without proper judgement breaches due professional care.
(f) Ignoring high-risk areas during planning breaches the risk-based approach.
5. Know who does what. The audit programme manager manages the programme. The audit team leader manages the individual audit and the team. Technical experts never make audit judgements independently. Observers do not influence the audit. Guides do not audit.
6. Remember ISO 19011 is guidance. It uses should, not shall. It is not a certifiable standard. If an answer says an organisation can be certified to ISO 19011, it is wrong. Certification bodies are accredited against ISO/IEC 17021-1, and for ISMS also ISO/IEC 27006.
7. Distinguish audit types. A first-party audit is internal. A second-party audit is a customer or supplier audit. A third-party audit is certification or regulatory. A supplier audit by a customer is second-party, even if outsourced to a consultant acting on the customer's behalf.
8. Evidence must be verifiable. Hearsay, opinions and unverified statements are not reliable audit evidence. In answer options, prefer evidence that is objective, factual and traceable, such as records, logs, observed practices and corroborated interview statements.
9. Remember sampling. Audits are based on samples, so there is always uncertainty. The evidence-based approach accepts this. Answers claiming that audits examine 100 percent of records or provide absolute assurance are usually wrong.
10. Use elimination. Remove answers that confuse roles, mix up programme and plan, or confuse evidence and findings. Then choose the answer that best matches the ISO 19011 wording.
11. For essay or open questions (common in PECB exams), structure your answer around these points:
(a) Define the term using ISO 19011 language.
(b) Explain its role in the audit process.
(c) Give an ISO 27001-specific example.
(d) Link it to a relevant principle, such as evidence-based or risk-based.
12. Know the 2018 updates. ISO 19011:2018 added the risk-based approach as the seventh principle. It expanded guidance on managing audit programme risks, remote auditing and auditing context, leadership and commitment. It also aligned with the Harmonized Structure used by ISO 27001.
Sample Practice Questions
Q1: An auditor notes that the backup log shows no backups performed for 10 days. What is this?
Answer: audit evidence. It becomes a finding only when evaluated against the criterion, for example the backup policy requiring daily backups.
Q2: A certification body defines all audits for a client over a three-year cycle. What is this document or arrangement?
Answer: audit programme.
Q3: An internal auditor is asked to audit the change management process they designed. Which principle is threatened?
Answer: independence.
Q4: An ISO 27001 and ISO 22301 audit is carried out together by one certification body. Is this combined or joint?
Answer: combined. It covers two management systems with one auditing organisation.
Q5: Which statement best describes an audit conclusion?
Answer: the outcome of an audit after consideration of the audit objectives and all audit findings.
Summary
Audit concepts and terminology from ISO 19011 are the backbone of the ISO 27001 Lead Auditor role. Learn the definitions precisely. Understand the chain from programme to plan, evidence, findings and conclusion. Master the seven principles of auditing. Then apply these to realistic ISO 27001 scenarios. In the exam, read carefully, identify key words, map scenarios to principles and roles, and eliminate options that blur critical distinctions. Precise vocabulary and logical reasoning are key to scoring highly on this topic.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!