Audit Criteria, Findings and Conclusions
In ISO/IEC 27001 Lead Auditor practice, audit criteria, findings and conclusions form a logical chain defined in ISO 19011:2018 and applied in ISMS audits under ISO/IEC 27006. Audit criteria are the set of requirements used as a reference against which objective evidence is compared. In an ISMS aud… In ISO/IEC 27001 Lead Auditor practice, audit criteria, findings and conclusions form a logical chain defined in ISO 19011:2018 and applied in ISMS audits under ISO/IEC 27006. Audit criteria are the set of requirements used as a reference against which objective evidence is compared. In an ISMS audit, criteria typically include the clauses of ISO/IEC 27001 (4 to 10), the Annex A controls declared applicable in the Statement of Applicability, the organization's own information security policies and procedures, and applicable legal, regulatory and contractual obligations. Criteria must be clearly defined and agreed during audit planning, because without them the auditor has no objective basis for judgement. Audit evidence is verifiable information, such as records, statements of fact or observations, collected through interviews, document review and observation. It is gathered by sampling and must be relevant to the criteria. Audit findings are the results of evaluating the collected evidence against the audit criteria. Findings can indicate conformity or nonconformity. Nonconformities are usually graded as major, meaning an absence or total breakdown of a required process that raises significant doubt about the ISMS achieving its intended outcomes, or minor, meaning an isolated lapse that does not undermine the system. Findings may also identify opportunities for improvement or good practice. A well-written nonconformity states the requirement, the evidence and the gap, so the auditee can understand and address the root cause. Audit conclusions are the outcome of the audit, reached after the audit team considers the audit objectives and all audit findings together. Conclusions address matters such as the extent of conformity with the criteria, the effectiveness of the ISMS in meeting its objectives, and, in certification audits, a recommendation on whether to grant, maintain or withhold certification. Conclusions are agreed by the audit team, presented at the closing meeting and recorded in the audit report. In summary: criteria are the benchmark, evidence is what is found, findings compare the two, and conclusions are the overall judgement based on all findings and the audit objectives.
Audit Criteria, Findings and Conclusions: A Complete Guide for ISO 27001 Lead Auditors
Introduction
Audit criteria, audit evidence, audit findings and audit conclusions form the logical backbone of every management system audit. ISO 19011:2018 (Guidelines for auditing management systems) and ISO/IEC 17021-1 define these terms precisely. ISO/IEC 27007 applies them to Information Security Management Systems (ISMS). As an ISO 27001 Lead Auditor, you must understand each term and how they connect. Exam questions frequently test whether you can tell them apart and apply them in scenarios.
Why It Is Important
1. Objectivity and consistency: Audits must be evidence-based and repeatable. Clear criteria let two auditors examining the same evidence reach the same conclusion.
2. Credibility of certification: Certification decisions rely on documented findings traced back to criteria. Weak findings undermine the value of the certificate and expose the certification body to appeals and complaints.
3. Fairness to the auditee: An organisation can only be held to requirements it knows about. Defined criteria prevent auditors from judging against personal opinion.
4. Effective improvement: Well-written findings show exactly what is wrong and why. This helps the auditee perform root cause analysis and corrective action.
5. Professional practice: The principle of an evidence-based approach in ISO 19011 depends on this chain. Without it, an audit is just an opinion.
What They Are: Key Definitions (ISO 19011:2018, Clause 3)
Audit Criteria (3.7): The set of requirements used as a reference against which objective evidence is compared. Requirements may include:
- Standards such as ISO/IEC 27001:2022 clauses 4 to 10, and the Annex A controls applicable per the Statement of Applicability
- Policies, procedures and work instructions of the organisation
- Legal, statutory and regulatory requirements (e.g., GDPR, sector regulations)
- Contractual obligations and customer requirements
- Codes of conduct or other planned arrangements
Note: If the criteria are legal or regulatory, the finding is often described as compliance or noncompliance.
Objective Evidence / Audit Evidence (3.8, 3.9): Records, statements of fact or other information that are relevant to the audit criteria and verifiable. Audit evidence is gathered through interviews, observation and review of documents and records. Evidence must be verifiable. Hearsay or unconfirmed opinion is not sufficient on its own.
Audit Findings (3.10): The results of evaluating the collected audit evidence against audit criteria. Findings can indicate:
- Conformity: the requirement is fulfilled
- Nonconformity: non-fulfilment of a requirement. Certification bodies grade these as major or minor.
- Opportunity for improvement (OFI): conformity exists, but improvement is possible, if specified by the audit plan
- Good practice: noteworthy strengths may also be recorded
Important: a finding is NOT the evidence itself. It is the result of comparing evidence with criteria.
Audit Conclusion (3.11): The outcome of an audit, after considering the audit objectives and all audit findings. It is reached by the audit team collectively, usually before the closing meeting. It may address:
- The extent of conformity of the ISMS with the audit criteria
- The effectiveness of the ISMS in meeting its intended outcomes
- The suitability of the ISMS implementation, maintenance and improvement
- The achievement of audit objectives and coverage of the audit scope
- Recommendations, for example recommending certification, if the audit objectives specify this
How It Works: The Audit Logic Chain
Audit Criteria + Audit Evidence → Audit Findings → (considering audit objectives) → Audit Conclusion
Step 1: Define the criteria during planning. The audit programme manager and the lead auditor establish objectives, scope and criteria. These are documented in the audit plan and agreed with the client. For ISO 27001 certification, the criteria include ISO/IEC 27001:2022 and the organisation's own ISMS documentation, including the Statement of Applicability.
Step 2: Collect and verify evidence. Auditors sample information using interviews, observation and document review. Evidence relevant to the criteria and objectives is recorded, including sources, dates, references and interviewees' roles.
Step 3: Evaluate evidence against criteria to generate findings. Each finding should state:
(a) the requirement (criterion), e.g., ISO/IEC 27001:2022 clause 9.2 or Annex A control 5.15;
(b) the nonconformity statement, meaning what is wrong;
(c) the objective evidence supporting it.
Findings are reviewed with the auditee to acknowledge that the evidence is accurate. Divergent opinions should be resolved, or recorded if unresolved.
Step 4: Grade nonconformities.
- Major nonconformity: affects the capability of the ISMS to achieve its intended results. Examples include the absence or total breakdown of a required process (e.g., no internal audits conducted, no management review, no risk assessment), or a number of minor nonconformities in the same area indicating systemic failure. A major nonconformity typically prevents certification until it is corrected and verified.
- Minor nonconformity: does not affect the capability of the ISMS to achieve its intended results. Examples include an isolated lapse, such as one access review not being signed off.
- OFI: no requirement is breached, but there is a suggestion for improvement. Auditors must not provide consultancy or prescribe solutions.
Step 5: Prepare audit conclusions. The team meets before the closing meeting to:
- review findings against the audit objectives
- agree on conclusions, considering uncertainty inherent in sampling
- prepare recommendations if required
- discuss audit follow-up if included in the plan
Step 6: Present at the closing meeting and report. Findings and conclusions are presented in a way that ensures they are understood and acknowledged. The audit report then documents the criteria, findings and related evidence, and the conclusions.
Example of a Well-Written Nonconformity
Requirement: ISO/IEC 27001:2022 clause 9.2.2 requires the organisation to plan, establish, implement and maintain an audit programme.
Nonconformity: The organisation has not implemented its internal audit programme as planned.
Evidence: The 2024 internal audit programme (doc ISMS-AP-01 v2) scheduled audits of Annex A controls 8.13 (backup) and 5.24 (incident management) in Q2 and Q3. The ISMS Manager confirmed that neither audit had been carried out, and no audit reports were available.
Notice that the statement contains no opinion, blame or recommended solution.
Common Misconceptions
- "A finding is always negative." False. Findings can show conformity.
- "Auditor opinion counts as criteria." False. Criteria must be documented requirements.
- "Conclusion = list of nonconformities." False. A conclusion is an overall judgement against the audit objectives.
- "The lead auditor alone decides conclusions." The audit team agrees conclusions, under the lead auditor's leadership. For certification, the final certification decision is made by the certification body, not the audit team. The team only recommends.
- "Evidence is the finding." False. Evidence supports the finding.
Exam Tips: Answering Questions on Audit Criteria, Findings and Conclusions
1. Memorise the chain and its direction. Criteria are the yardstick and evidence is what you measure. Findings are the result of comparison, and conclusions are the overall outcome against objectives. Many multiple-choice distractors swap these terms. For example: "Audit criteria are the results of evaluating evidence" is wrong.
2. Spot keywords.
- "Reference against which evidence is compared" = criteria
- "Verifiable records, statements of fact" = evidence
- "Result of evaluation" = finding
- "Outcome of the audit, considering objectives and all findings" = conclusion
3. In scenario questions, always identify the requirement first. Ask yourself: "Which clause, control, policy or law is not fulfilled?" If you cannot cite a requirement, it is not a nonconformity. At most, it is an OFI or a matter for further investigation.
4. Grade carefully, major versus minor. Look for words like "no", "never", "not established" or "systematic". These suggest a major nonconformity, because the process is absent or has broken down. Words like "one instance", "isolated" or "one of 20 samples" suggest a minor nonconformity. Also ask whether the ISMS can still achieve its intended outcomes.
5. Write findings in three parts. In essay or written exams, structure each nonconformity as Requirement – Statement – Evidence. Make evidence specific and verifiable: give document IDs, dates, sample sizes and interviewee roles (not names, where appropriate). Avoid words like "poor", "bad" or "careless". Do not recommend solutions.
6. Distinguish clause requirements from Annex A controls. Annex A controls are criteria only when they are applicable in the Statement of Applicability. If a control is justifiably excluded, its absence is not a nonconformity. However, the exclusion's justification itself can be audited against clause 6.1.3.
7. Remember organisational criteria. If the organisation's own policy is stricter than ISO 27001, the auditee must still follow it. For example, a policy may require password changes every 60 days. Breaching your own documented procedure is a nonconformity against clause 7.5 or the related clause, or against the policy itself as criteria.
8. Know who does what at the end. The audit team prepares conclusions before the closing meeting. The lead auditor presents them. The certification body makes the certification decision. Questions that say "the lead auditor grants certification" are wrong.
9. Handle disagreement correctly. If the auditee disputes a finding, the auditor should try to resolve it by re-examining evidence. If it remains unresolved, both opinions are recorded in the report. The auditor does not simply drop the finding to avoid conflict, nor does the auditor argue indefinitely.
10. Recognise the sampling limitation. Conclusions are based on samples, so there is inherent uncertainty. Expect questions on why conclusions should include a disclaimer, or a statement on the representativeness of sampling.
11. Eliminate consultancy answers. In multiple-choice options, reject choices where the auditor designs the corrective action, implements a fix, or advises on a specific tool. Auditors report findings. Auditees determine corrections and corrective actions under ISO 27001 clause 10.2.
12. Practise with mini-scenarios. For each scenario, ask:
(a) What are the criteria?
(b) What is the evidence, and is it verified?
(c) Is it conformity, nonconformity or OFI?
(d) If nonconformity, is it major or minor, and why?
(e) How does it affect the overall conclusion and recommendation?
Quick Summary
- Criteria = requirements (what should be)
- Evidence = verifiable facts (what is)
- Finding = comparison result (the gap or the match)
- Conclusion = overall outcome against audit objectives (so what?)
Master this chain and you will answer the majority of related exam questions confidently and correctly.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!