Determining the Type and Amount of Evidence
In ISO/IEC 27001 auditing, guided by ISO 19011 and ISO/IEC 27006, determining the type and amount of evidence is a professional judgment the auditor makes to ensure conclusions are reliable, objective and defensible. Audit evidence consists of records, statements of fact or other information that a… In ISO/IEC 27001 auditing, guided by ISO 19011 and ISO/IEC 27006, determining the type and amount of evidence is a professional judgment the auditor makes to ensure conclusions are reliable, objective and defensible. Audit evidence consists of records, statements of fact or other information that are relevant to the audit criteria and verifiable. Its quality is judged on two dimensions: appropriateness (relevance and reliability) and sufficiency (quantity). Types of evidence include: documented information such as the ISMS scope, information security policy, risk assessment, Statement of Applicability and procedures; records such as access reviews, incident logs, training records and management review minutes; interviews with top management, process owners and staff; direct observation of activities and physical controls; technical verification such as checking system configurations, firewall rules or backup restorations; and analytical evidence such as trends in metrics and KPIs. Reliability generally increases when evidence is obtained directly by the auditor, comes from independent sources, is documented rather than oral, and is corroborated. Interview statements should therefore be confirmed through records or observation, a practice often called triangulation. The amount of evidence depends on several factors: the audit objectives, scope and criteria; the risk and criticality of processes and controls; the size and complexity of the organization; the maturity and effectiveness of the ISMS; results of previous audits and known nonconformities; and available time and resources. Because auditors cannot examine everything, they use sampling. Judgment-based sampling relies on auditor expertise to focus on high-risk areas, while statistical sampling provides quantifiable confidence. Samples should be representative across time periods, locations and personnel. Auditors should gather enough evidence to support each finding and conclusion, recognizing that audit evidence is based on samples and carries inherent uncertainty. If evidence is insufficient, contradictory or unavailable, the auditor should extend sampling, seek alternative sources, or report the limitation. Planning evidence collection through audit plans and checklists helps achieve efficient, consistent and risk-based evaluation of ISMS conformity and effectiveness.
Determining the Type and Amount of Evidence: ISO 27001 Lead Auditor Guide
Determining the Type and Amount of Evidence
This topic sits within the fundamental audit concepts and principles of the ISO/IEC 27001 Lead Auditor syllabus. It covers two questions: what kind of evidence you need, and how much is enough to support reliable conclusions. The guide is built around ISO 19011 (Guidelines for auditing management systems) and ISO/IEC 27007 (Guidelines for ISMS auditing). It also draws on the evidence-based approach, which is one of the core auditing principles.
1. Why It Is Important
Audit conclusions are only as credible as the evidence behind them. ISO 19011 lists an evidence-based approach as an auditing principle. It describes this as the rational method for reaching reliable and reproducible audit conclusions in a systematic audit process. Getting the type and amount of evidence right matters for several reasons:
• Reliability of conclusions: Too little evidence, or evidence of the wrong kind, can lead to false conclusions. You might wrongly declare conformity, or raise a nonconformity that does not exist.
• Defensibility: Findings must be verifiable. If the auditee challenges a nonconformity, the auditor must show objective evidence that clearly supports it.
• Efficiency: Audits are limited in time and resources. Collecting too much evidence wastes effort. Collecting too little exposes the audit to risk.
• Managing audit risk: Audits rely on sampling, so there is always a risk that the evidence is not fully representative. Choosing appropriate evidence types and sample sizes lowers this risk to an acceptable level.
• Certification integrity: In third-party audits, accreditation bodies expect certification decisions to rest on sufficient and appropriate evidence. ISO/IEC 17021-1 and ISO/IEC 27006 set requirements for this.
2. What It Is
Audit evidence (ISO 19011 / ISO 9000) is defined as records, statements of fact or other information that are relevant to the audit criteria and verifiable.
Objective evidence is data supporting the existence or truth of something. It can be obtained through observation, measurement, testing or other means.
Determining the type of evidence means choosing which sources and methods will best show whether the audit criteria are fulfilled. Determining the amount of evidence means deciding how many samples, interviews and records are needed for a confident conclusion.
Main types of audit evidence
• Documentary evidence: Policies, procedures, the Statement of Applicability (SoA), risk assessment and risk treatment plans, records, logs, reports, meeting minutes and contracts.
• Records/technical evidence: System configurations, access control lists, firewall rules, SIEM logs, backup logs, vulnerability scan results and patch reports.
• Testimonial evidence (interviews): Statements from personnel at different levels. These are useful but generally considered weaker unless corroborated.
• Observational evidence: Directly watching activities, such as visitors signing in, clear desk practices, badge use, server room access and the handling of media.
• Re-performance/testing evidence: The auditor repeats a control or watches it being performed. Examples include requesting a user access review, checking that a terminated user's account is disabled, or testing a restore.
• Analytical evidence: Comparing trends, metrics and KPIs, such as incident trends or the percentage of systems patched within SLA.
Qualities of good evidence
• Sufficient: Enough in quantity to support the conclusion.
• Appropriate: Relevant to the audit criteria and reliable.
• Verifiable: Another auditor could obtain the same evidence and reach the same conclusion.
• Objective: Factual, not opinion or hearsay.
General reliability hierarchy (rule of thumb)
Evidence obtained directly by the auditor through observation or re-performance is usually more reliable than evidence provided by the auditee. Evidence from independent external sources is usually more reliable than internally generated evidence. Documented evidence is more reliable than oral statements. Original records are more reliable than copies. Evidence that is corroborated (triangulated) across several sources is the strongest of all.
3. How It Works
Step 1: Understand the audit objectives, scope and criteria
The criteria include ISO/IEC 27001 clauses 4 to 10, Annex A controls applicable per the SoA, the organization's own policies, and legal or contractual requirements. Together they define what must be demonstrated. Each requirement suggests a natural evidence type:
• Clause 6.1.2 (risk assessment) points to the documented methodology and risk register.
• Clause 9.2 (internal audit) points to the audit programme, reports and corrective actions.
• Control A.5.18 (access rights) points to access review records, plus testing a sample of joiners, movers and leavers.
Step 2: Consider risk (risk-based auditing)
ISO 19011 promotes a risk-based approach. Higher-risk processes or controls deserve more evidence and larger samples. These include critical assets, areas with prior nonconformities, recent major changes, complex processes and outsourced processes. Lower-risk areas may need less evidence. Relevant factors include:
• The significance of the process to information security objectives
• Results of previous audits
• Maturity of the ISMS
• Complexity and number of sites
• Changes to the organization, technology or threat landscape
• Incidents and complaints
Step 3: Choose audit methods and evidence sources
ISO 19011 Annex A describes audit methods along two dimensions:
• Extent of involvement: Human interaction (interviews, observation) versus no human interaction (document review, record sampling).
• Location: On-site versus remote.
A mix of methods gives corroboration. For example, a procedure says leavers' access is removed within 24 hours. The auditor reviews the procedure (documentary). They interview HR and IT (testimonial). They sample leavers from the HR system and check their account status in Active Directory (technical/re-performance). Finally, they compare timestamps (analytical).
Step 4: Determine the amount of evidence (sampling)
An auditor rarely examines 100% of a population, so sampling is used. ISO 19011 (Annex A.6) describes two approaches:
• Judgement-based sampling: Relies on the auditor's knowledge, skills and experience. It is common in management system audits. It allows focus on high-risk items, but it cannot give statistically valid conclusions about the whole population.
• Statistical sampling: Uses random selection and probability theory to give a measurable confidence level. It is used when large populations need quantifiable conclusions.
Factors that affect sample size:
• Size and homogeneity of the population
• Risk and criticality
• Required confidence level
• Effectiveness of the auditee's own controls and monitoring
• Frequency of the control (daily, weekly, monthly, annual)
• Results of initial samples. If an exception is found, the auditor may expand the sample to see whether it is isolated or systemic.
• Audit time available
A common practical guide relates sample size to control frequency:
• Annual control: 1 instance
• Quarterly: 2
• Monthly: 2 to 5
• Weekly: 5 to 15
• Daily: 20 to 40
• Many times per day: 25 to 60
These figures are indicative only. Exams focus on the principle that sample size rises with frequency, population and risk.
Step 5: Plan the evidence collection
Plan it in the audit plan and record it in work documents (checklists, sampling plans, evidence logs). ISO/IEC 27007 also covers using information and communication technology for remote audits, and access to sensitive information.
Step 6: Collect, verify and record
Only verifiable information is accepted as audit evidence. Record specific details so the finding is traceable, for example: Sample of 15 leavers between Jan and Jun; 3 accounts still active more than 30 days after departure; IDs X, Y, Z. Information that cannot be verified should not form a finding. It may be noted as an area to follow up.
Step 7: Evaluate sufficiency and adjust
Ask whether the evidence is enough to reach a conclusion against each criterion. If it is not, collect more: expand the sample, use another method, or corroborate an interview with records. If the evidence cannot be obtained, report this as an obstacle or limitation. Examples include confidential data the auditee will not disclose, or systems that are unavailable.
Step 8: Handle evidence limitations and confidentiality
Some ISMS evidence is highly sensitive, such as vulnerability reports, encryption keys and personal data. ISO/IEC 27007 and ISO/IEC 27006 recognize that some records may not be made available. The auditor should agree alternatives in advance, such as viewing on-site without taking copies, or redacted versions. The auditor must still judge whether the remaining evidence is sufficient. If not, this is reported as a limitation that may affect confidence in the audit conclusions.
Uncertainty
ISO 19011 notes that audit evidence is based on samples, so there is an element of uncertainty in auditing. People acting on the conclusions should be aware of this. Proper evidence selection reduces uncertainty but never eliminates it.
4. Practical ISMS Examples
• Clause 5.2 Information security policy: Review the approved policy (documentary). Check how it is communicated, for example on the intranet or through training records. Interview staff on their awareness (testimonial). Corroborating several sources gives a sufficient amount.
• Clause 7.2 Competence: Sample personnel in key ISMS roles, such as the CISO, system administrators and incident handlers. Review their training records and certificates, and compare these with role requirements.
• A.8.13 Information backup: Review the backup policy. Sample backup logs across the period. Request or observe evidence of restore tests. A restore test is re-performance, the strongest evidence that backups actually work.
• A.7.2 Physical entry: Observe entry controls and review visitor logs for a sample of days. Check access card reports for the server room against the list of authorized persons.
• Clause 9.3 Management review: Review the minutes and confirm that all required inputs and outputs are covered. Check that actions were followed up. This is usually a low-frequency activity, so all instances in the period may be reviewed.
5. Common Pitfalls
• Relying only on interviews without corroboration
• Checking that a document exists without checking that it is implemented (records) and effective (outcomes)
• Using the auditee's hand-picked samples instead of the auditor selecting them
• Using too small a sample for a high-frequency, high-risk control
• Failing to expand the sample when an exception appears
• Recording vague evidence that cannot be traced or verified
• Raising a nonconformity based on hearsay or assumption
6. Exam Tips: Answering Questions on Determining the Type and Amount of Evidence
Tip 1: Anchor answers in the evidence-based approach. When a question asks how an auditor reaches a reliable conclusion, the answer usually involves objective, verifiable evidence obtained through appropriate sampling. Opinions or assumptions are never the answer.
Tip 2: Learn the definitions word for word. Audit evidence means records, statements of fact or other information, relevant to the audit criteria and verifiable. Only verifiable information is accepted as evidence. Questions often hinge on the word verifiable.
Tip 3: Prefer corroboration. In scenario questions, the best answer typically triangulates documents, interviews and observation or records. If an option says accept the manager's statement, it is usually wrong unless verification follows.
Tip 4: Remember the reliability ranking. Direct observation and re-performance beat auditee-supplied information. Independent external evidence beats internal. Written beats oral. Original beats copy. Choose the option giving the most reliable evidence for the criterion in question.
Tip 5: Link amount to risk. If a question asks how to decide sample size, look for factors such as risk, criticality, population size, control frequency, required confidence and previous audit results. Higher risk means more evidence.
Tip 6: Know judgement-based versus statistical sampling. Judgement-based sampling depends on auditor expertise, is common in ISMS audits, and cannot support statistically valid conclusions. Statistical sampling uses random selection and gives measurable confidence. Exams often ask which is appropriate or what its limitation is.
Tip 7: Expand the sample when exceptions appear. If a scenario describes finding one deviation, the best next step is usually to extend the sample. This shows whether the problem is isolated or systemic before you grade the nonconformity. Jumping straight to a major nonconformity is not the best step.
Tip 8: The auditor selects the samples. Any option where the auditee chooses which records to show the auditor is a red flag for bias.
Tip 9: Distinguish design from implementation and effectiveness. A documented procedure shows design. Records show implementation. Outcomes, metrics and test results show effectiveness. If a question asks for evidence of effectiveness, documents alone are insufficient.
Tip 10: Handle confidential evidence correctly. If the auditee refuses access to sensitive information, the correct response is usually one of these:
• Seek alternative evidence, such as on-site viewing or redacted copies.
• Assess whether the remaining evidence is sufficient.
• If it is not, report the limitation to the audit client or in the report.
Do not ignore the gap or invent conclusions.
Tip 11: Acknowledge uncertainty. Because audits are sample-based, no audit gives absolute assurance. Options claiming an audit proves full conformity are typically wrong.
Tip 12: For essay or scenario questions, use a structure.
(1) State the audit criterion, citing the clause or control.
(2) Name the evidence types you would seek and why.
(3) Describe the sampling approach, size and selection.
(4) Explain how you would corroborate.
(5) State how you would evaluate sufficiency, and what you would do if an exception or limitation arose.
(6) Note how you would record the evidence traceably.
Tip 13: Watch for distractors. Wrong options often include:
• Relying on a single source
• Accepting verbal assurances
• Sampling 100% when unnecessary
• Sampling only the most recent period
• Letting time pressure justify inadequate evidence
• Writing findings based on suspicion
Tip 14: Spread samples across time, locations and personnel. Good sampling covers the whole audit period, multiple sites and shifts, and different roles or systems. This avoids a biased picture. Options showing representative spread are usually correct.
7. Quick Summary
Determining the type and amount of evidence means choosing appropriate, verifiable evidence sources and gathering enough of them to reach reliable, reproducible conclusions against the audit criteria. Use a mix of documents, records, interviews, observation and re-performance, and corroborate across sources. Scale the amount to risk, population, control frequency and required confidence, using judgement-based or statistical sampling. Expand samples when exceptions arise. Report limitations openly. Remember that audit conclusions always carry some uncertainty because they are based on samples.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!