Due Professional Care and Confidentiality
In ISO/IEC 27001 Lead Auditor training, the fundamental audit principles come from ISO 19011, Guidelines for auditing management systems. Two of the seven principles are Due Professional Care and Confidentiality. Both shape how an auditor behaves and how trustworthy the audit results are. Due Prof… In ISO/IEC 27001 Lead Auditor training, the fundamental audit principles come from ISO 19011, Guidelines for auditing management systems. Two of the seven principles are Due Professional Care and Confidentiality. Both shape how an auditor behaves and how trustworthy the audit results are. Due Professional Care means auditors apply diligence and sound judgement throughout the audit. Their care should match the importance of the task and the confidence that clients and other interested parties place in them. In practice, this involves: - Planning the audit carefully. - Understanding the scope of the Information Security Management System (ISMS) and the organization's context. - Applying appropriate sampling techniques. - Gathering sufficient, objective evidence before reaching conclusions. - Recognizing the limits of their own competence and seeking technical experts when needed. - Maintaining current knowledge of ISO/IEC 27001, Annex A controls, and relevant legal requirements. A key part of this principle is professional judgement. Auditors must assess risks, evaluate the significance of findings, and avoid careless or superficial conclusions, recognizing that their reports may influence certification decisions and business operations. Confidentiality concerns the security of information. Auditors must handle sensitive information with discretion and protect it from unauthorized disclosure. During an ISMS audit, auditors often see highly sensitive material, such as: - Risk assessments and vulnerability reports. - Network architectures and security incident records. - Personal data and intellectual property. Auditors must not use audit information for personal gain or disclose it inappropriately, and they must not use it in ways that harm the auditee's legitimate interests. Good practice includes: - Signing non-disclosure agreements. - Securely storing and transmitting audit documents. - Limiting access to working papers. - Returning or destroying information according to agreed procedures. Auditors may disclose information only when the law requires it or when the auditee gives consent. Together, these principles build trust. Auditees become more willing to share information openly because they know it will be protected and evaluated competently. This openness improves the quality of audit evidence and helps ensure that audit conclusions are reliable, credible, and consistent with the ethical expectations of the auditing profession.
Due Professional Care and Confidentiality: A Complete ISO 27001 Lead Auditor Guide
Introduction
Due Professional Care and Confidentiality are two of the seven principles of auditing defined in ISO 19011:2018 – Guidelines for auditing management systems. ISO 27001 Lead Auditor courses and certification bodies build on ISO 19011 and ISO/IEC 17021-1, and the related audit guidance in ISO/IEC 27007. These two principles describe how an auditor must behave. Due professional care covers the care and judgement the auditor brings to the work. Confidentiality covers how the auditor protects the information obtained during the audit. Exam questions on these principles often appear as scenarios. You must recognise which principle is being applied or breached, and choose the most professional course of action.
The Seven Principles of Auditing (ISO 19011:2018, Clause 4)
1. Integrity: the foundation of professionalism.
2. Fair presentation: the obligation to report truthfully and accurately.
3. Due professional care: the application of diligence and judgement in auditing.
4. Confidentiality: the security of information.
5. Independence: the basis for the impartiality of the audit and objectivity of the audit conclusions.
6. Evidence-based approach: the rational method for reaching reliable and reproducible audit conclusions.
7. Risk-based approach: an audit approach that considers risks and opportunities.
Due professional care and confidentiality are numbers 3 and 4. Examiners often place them alongside the others as distractors, so you must be able to tell them apart.
PART 1: DUE PROFESSIONAL CARE
What It Is
ISO 19011 describes due professional care as the application of diligence and judgement in auditing. Auditors should exercise care in line with the importance of their task and the confidence placed in them by the audit client and other interested parties. A key factor is the ability to make reasoned judgements in all audit situations.
Put simply, the auditor must:
- Work carefully, thoroughly and competently.
- Apply professional scepticism, which means not accepting statements without verification.
- Use sound judgement when sampling, evaluating evidence and grading nonconformities.
- Plan and prepare adequately.
- Recognise the limits of their own competence and seek support (for example, a technical expert) where needed.
- Avoid negligence, shortcuts and superficial checks.
Why It Is Important
- Confidence and reliance: Certification decisions, regulators, customers and top management rely on audit conclusions. A careless audit can lead to an ISMS being certified when it is ineffective, which can expose the organisation and its stakeholders to information security risk.
- Credibility of certification: Accredited certification only has value if audits are performed with rigour.
- Legal and professional liability: Negligent audits can damage the certification body's reputation and lead to complaints, appeals or legal action.
- Accuracy of findings: Poor judgement can produce false nonconformities, which cause unfair burden, or missed nonconformities, which leave risk unaddressed.
How It Works in Practice
- Preparation: Reviewing documented information (the ISMS scope, Statement of Applicability, risk assessment and risk treatment plan) before the on-site audit.
- Competence: Understanding ISO/IEC 27001:2022 requirements and the Annex A controls (93 controls in 4 themes: organizational, people, physical, technological). Where the auditor lacks sector knowledge, a technical expert is used.
- Sampling: Choosing samples that are representative and adequate to support conclusions, and documenting the sampling approach.
- Verification: Cross-checking interview statements against records and observations. For example, if a manager says access reviews are performed quarterly, the auditor asks for the review records.
- Time management: Allocating enough time to the high-risk areas rather than rushing through them.
- Reasoned judgement: Grading a finding as a major or minor nonconformity, or an opportunity for improvement, based on objective evidence and its impact on the ISMS.
- Awareness of audit risk: Recognising that the audit may fail to detect issues, and planning to reduce that risk.
Examples of Breaches of Due Professional Care
- Signing off a control as effective after only an interview, without examining records.
- Auditing a highly technical cryptography process without the necessary knowledge or support.
- Skipping part of the audit plan because the auditee was busy, without recording or reporting the limitation.
- Raising a major nonconformity based on hearsay.
- Failing to follow up on an obvious red flag, such as an unlocked server room, because it was not on the checklist.
PART 2: CONFIDENTIALITY
What It Is
ISO 19011 describes confidentiality as the security of information. Auditors should exercise discretion in the use and protection of information acquired in the course of their duties. Audit information should not be used inappropriately for personal gain by the auditor or the audit client, or in a manner detrimental to the legitimate interests of the auditee. This includes the proper handling of sensitive or confidential information.
Why It Is Especially Important in ISO 27001 Audits
ISO 27001 auditors are exposed to some of the most sensitive information an organisation holds, including:
- Risk assessments that reveal vulnerabilities and threats.
- Network diagrams, security architecture and incident logs.
- Penetration test reports.
- Personal data (relevant to GDPR and other privacy laws).
- Commercial secrets and customer information.
If this information leaked, attackers could exploit the weaknesses identified. Confidentiality is therefore an ethical requirement, a contractual and legal obligation, and an information security issue in its own right. An auditor who mishandles information undermines the very thing being audited. Without trust in confidentiality, auditees would not be open with auditors, and the audit would lose its value.
How It Works in Practice
- Agreements: Auditors and certification bodies sign confidentiality or non-disclosure agreements. ISO/IEC 17021-1 requires certification bodies to have legally enforceable confidentiality arrangements.
- Handling evidence: Collect only what is necessary, and prefer viewing records on-site to taking copies. Some organisations may restrict access to certain information; ISO/IEC 27007 and 17021-1 recognise this, and the auditor must consider whether enough evidence is available.
- Secure storage and transmission: Encrypt laptops and files, avoid public Wi-Fi or unsecured email for audit data, and lock away paper notes.
- Discretion in conversation: Do not discuss findings in public places such as trains, restaurants or social media.
- No personal gain: Never use insider information, for example for share trading or for consulting opportunities.
- Disclosure only when authorised or required by law: Information is shared only with the audit client and authorised parties. If the law requires disclosure, the auditee is normally informed, unless that is prohibited.
- Retention and disposal: Keep audit records for the agreed period, then dispose of them securely.
- Photographs: Take them only with the auditee's permission.
Examples of Breaches of Confidentiality
- Telling one client about weaknesses found at a competitor.
- Posting on LinkedIn that you just audited Company X and found major security gaps.
- Leaving audit notes on a hotel desk or in an unattended car.
- Emailing the client's risk register to a personal account.
- Using knowledge of a client's upcoming merger to buy shares.
Relationship Between the Two Principles and Others
- Integrity vs Due Professional Care: Integrity is about honesty, ethics and diligence. Due professional care focuses on diligence, competence and judgement in performing the work.
- Confidentiality vs Integrity: Misusing information for personal gain breaches both, but the specific principle tested is usually confidentiality.
- Due Professional Care vs Evidence-Based Approach: Accepting statements without verification breaches due professional care. If the question focuses on reaching conclusions without verifiable evidence, the answer is the evidence-based approach.
- Due Professional Care vs Fair Presentation: Inaccurate reporting relates to fair presentation, while careless audit performance relates to due professional care.
Exam Tips: Answering Questions on Due Professional Care and Confidentiality
1. Learn the keywords.
- Due professional care: diligence, judgement, reasoned judgement, care, competence, thoroughness, importance of the task, confidence placed by the client.
- Confidentiality: security of information, discretion, protection, personal gain, detrimental to the auditee, sensitive information.
2. Identify the core behaviour in the scenario. Ask yourself what the auditor is doing wrong or right. If the issue is how well the work was done, the answer is due professional care. If it is what happened to the information, the answer is confidentiality.
3. Choose the most professional action. In situational questions, the best answer usually:
- Protects the auditee's information.
- Seeks verification before concluding.
- Escalates to the audit team leader or the certification body when unsure.
- Records audit limitations transparently.
- Avoids extreme actions, such as stopping the audit immediately, unless the situation truly requires them.
4. Watch for traps involving the law. Legal requirements can override confidentiality. However, the auditor should normally follow the defined procedure and inform the client where permitted, rather than disclosing on their own initiative.
5. Think like an ISMS auditor. For ISO 27001, confidentiality answers often involve information security controls such as encryption, need-to-know, secure disposal, and not removing documents from the site. Choose answers consistent with good information security practice.
6. Recognise competence limits. If an auditor is asked to audit an area outside their expertise, the due professional care answer is to involve a technical expert or inform the team leader. Bluffing through is never correct.
7. Restricted access scenarios. If the auditee refuses to show highly sensitive information, such as a classified incident report, the right approach is to look for alternative evidence, assess whether the restriction prevents a reliable conclusion, and record it. Demanding access aggressively, or ignoring the gap, is wrong.
8. Essay or case-study questions (PECB, IRCA/CQI and similar). Structure your answer as:
- Name the principle.
- Define it in ISO 19011 terms.
- Explain why it applies to the scenario.
- State the correct action.
- Mention the consequences of a breach (loss of trust, invalid audit, security risk).
9. Use the elimination technique. Remove options that describe other principles, such as independence (conflicts of interest) or fair presentation (reporting accuracy). Then pick the option that best matches diligence and judgement, or protection of information.
Sample Exam Questions
Q1. During a stage 2 audit, an auditor accepts the IT manager's statement that backups are tested monthly and records the control as conforming without reviewing any records. Which principle has been most clearly compromised?
A) Independence
B) Confidentiality
C) Due professional care
D) Fair presentation
Answer: C. The auditor failed to exercise diligence and professional scepticism. An evidence-based approach is also relevant, but the lack of care and verification points to due professional care as the best answer.
Q2. After auditing a bank, an auditor mentions the bank's firewall weaknesses during a conference presentation, without naming the bank. What is the best evaluation?
A) Acceptable because the bank was not named
B) A breach of confidentiality, because the information could still be detrimental to the auditee and was obtained during the audit
C) A breach of independence
D) Acceptable if the findings were already closed
Answer: B. Audit information must not be used outside the audit without authorisation. Contextual details can still identify the client.
Q3. An auditor is assigned to audit secure development controls but has no software development experience. What should the audit team leader do?
Answer: Apply due professional care by assigning a competent auditor or adding a technical expert, so that the audit is performed with appropriate competence and judgement.
Q4. The auditee asks the auditor not to take copies of its risk treatment plan. What should the auditor do?
Answer: Respect the request, review the document on-site, record relevant details in the audit notes without excessive sensitive data, and reference the document's identity and version. This is consistent with confidentiality.
Quick Revision Summary
- Due professional care means diligence plus reasoned judgement, in proportion to the importance of the task and the confidence placed in the auditor. It requires competence, preparation, scepticism, adequate sampling and verification.
- Confidentiality means the security of information. It requires discretion, no personal gain, no harm to the auditee, secure handling, NDAs, and disclosure only when authorised or legally required.
- Both principles are central to trust in the audit process. They are especially critical in ISO 27001, where the audit itself handles highly sensitive security information.
- In exams, identify whether the scenario concerns the quality of the work or the handling of information. Then choose the most professional, evidence-based and secure response.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!