Evidence-Based Approach
The evidence-based approach is one of the seven principles of auditing defined in ISO 19011, which underpins ISO/IEC 27001 Lead Auditor practice. It states that audit evidence is the rational method for reaching reliable and reproducible audit conclusions in a systematic audit process. An auditor m… The evidence-based approach is one of the seven principles of auditing defined in ISO 19011, which underpins ISO/IEC 27001 Lead Auditor practice. It states that audit evidence is the rational method for reaching reliable and reproducible audit conclusions in a systematic audit process. An auditor must never base findings on assumptions, opinions, hearsay, or personal impressions. Every conclusion about the conformity and effectiveness of an Information Security Management System (ISMS) must be traceable to verifiable information. Audit evidence consists of records, statements of fact, or other information that is relevant to the audit criteria and verifiable. These criteria include the requirements of ISO/IEC 27001 clauses 4 to 10, the Annex A controls, the organization's own policies and procedures, and applicable legal, regulatory and contractual requirements. Evidence is typically gathered through three main methods. The first is reviewing documented information, such as the Statement of Applicability, risk assessment and treatment reports, access logs and incident records. The second is interviewing personnel at various levels. The third is observing activities and processes as they occur. Strong evidence is objective, verifiable, relevant and sufficient. Auditors often triangulate, for example by corroborating an interview statement with a record or a direct observation, to increase confidence. Because audits are conducted within limited time and resources, the approach relies on appropriate sampling. The lead auditor must ensure that samples are representative, because the confidence placed in audit conclusions depends directly on the quality and quantity of the evidence examined. Auditors should also acknowledge the residual uncertainty that sampling introduces, since an audit cannot guarantee that every nonconformity has been detected. Collected evidence is evaluated against the audit criteria to produce audit findings, which may indicate conformity, nonconformity or opportunities for improvement. These findings then support the audit conclusions. Nonconformity statements must clearly reference the requirement, the evidence observed and the nature of the gap. Applying this principle ensures fairness, consistency and credibility. It allows different competent auditors to reach similar conclusions from the same evidence, and it enables auditees to accept the results and act on them with confidence.
Evidence-Based Approach: A Complete Guide for ISO 27001 Lead Auditors
Introduction
The Evidence-Based Approach is one of the seven principles of auditing defined in ISO 19011:2018 (Guidelines for auditing management systems), and it underpins every ISO/IEC 27001 Lead Auditor activity. It is the principle that turns an audit from a matter of opinion into a reliable, repeatable and defensible process. This guide explains why the principle matters, what it means, how it works in practice, and how to answer exam questions about it.
1. Why the Evidence-Based Approach Is Important
An ISMS certification audit gives assurance to top management, customers, regulators and certification bodies that an organisation manages information security effectively. That assurance is only worth something if the conclusions rest on facts. The Evidence-Based Approach matters because it:
• Ensures reliability: conclusions based on verifiable facts can be trusted by interested parties.
• Ensures reproducibility: another competent auditor examining the same evidence should reach similar conclusions.
• Protects objectivity: it reduces bias, assumptions and personal preference.
• Supports defensible nonconformities: every finding must trace back to objective evidence, so the auditee cannot reasonably dispute it.
• Enables fair certification decisions: certification bodies under ISO/IEC 17021-1 and ISO/IEC 27006 rely on documented evidence to grant, maintain or withdraw certification.
• Manages audit risk: because audits rely on sampling, a sound evidence-based approach keeps the risk of wrong conclusions acceptable.
2. What the Evidence-Based Approach Is
ISO 19011:2018 describes the principle as: "The rational method for reaching reliable and reproducible audit conclusions in a systematic audit process." It adds that audit evidence should be verifiable and should be based on samples of the information available, because an audit is conducted in a limited time with limited resources. Sampling should be used appropriately, since this is closely related to the confidence that can be placed in the audit conclusions.
The Seven Principles of Auditing (ISO 19011:2018)
1. Integrity: the foundation of professionalism
2. Fair presentation: the obligation to report truthfully and accurately
3. Due professional care: diligence and judgement in auditing
4. Confidentiality: security of information
5. Independence: the basis for impartiality and objective conclusions
6. Evidence-based approach: the rational method for reaching reliable and reproducible conclusions
7. Risk-based approach: an approach that considers risks and opportunities
Key Definitions (ISO 19011 / ISO 9000 terminology)
• Objective evidence: data supporting the existence or truth of something. It can be obtained through observation, measurement, test or other means.
• Audit evidence: records, statements of fact or other information that are relevant to the audit criteria and verifiable.
• Audit criteria: the set of requirements used as a reference against which objective evidence is compared. Examples are ISO/IEC 27001 clauses 4 to 10, Annex A controls, policies, procedures, legal and contractual requirements.
• Audit findings: the results of evaluating the collected audit evidence against the audit criteria. Findings may indicate conformity, nonconformity or opportunities for improvement.
• Audit conclusion: the outcome of the audit, after considering the audit objectives and all audit findings.
The Logical Chain
Audit criteria + Audit evidence → Audit findings → Audit conclusions
No conclusion may skip this chain. A finding without evidence is merely an opinion.
3. How the Evidence-Based Approach Works
3.1 Methods of Collecting Evidence
ISO 19011 (clause 6.4.7 and Annex A) describes several ways to gather evidence:
• Interviews: talking to personnel at all levels, such as asking a system administrator how user access reviews are performed.
• Observation: watching activities, such as seeing whether visitors are escorted and badges are worn.
• Document review: examining the Statement of Applicability, risk assessment methodology, information security policy and procedures.
• Record review: examining access review logs, incident records, training records, internal audit reports and management review minutes.
• Technical verification and testing: checking configurations, re-performing a control, or sampling backups and testing restore evidence.
3.2 Characteristics of Good Audit Evidence
• Verifiable: it can be confirmed by checking a record, a system or another source.
• Relevant: it relates directly to the audit criteria being assessed.
• Sufficient: there is enough of it to support the conclusion.
• Reliable: it comes from a credible source and is ideally corroborated.
• Objective: it is free from the auditor's personal opinion.
• Traceable: it is recorded precisely, with details such as document ID, version, date, person interviewed (by role), sample reference and location.
3.3 Hierarchy of Reliability (General Guidance)
• Evidence directly observed or verified by the auditor is generally stronger than verbal statements.
• Records and system-generated evidence are generally stronger than unsupported verbal claims.
• Evidence from independent sources is stronger than evidence from the auditee alone.
• Corroborated evidence, where several sources agree, is the strongest.
Important: interview statements ARE valid audit evidence, but where possible they should be verified or corroborated, especially before raising a nonconformity.
3.4 Sampling
Because auditors cannot check everything, ISO 19011 (Annex A.6) describes two types of sampling:
• Judgement-based sampling: relies on the auditor's knowledge, skills and experience, for example selecting high-risk systems or recent changes. Statistical conclusions cannot be drawn from it.
• Statistical sampling: uses a sampling design based on probability theory, for example random selection of 25 user accounts from 1,000. It allows confidence levels to be calculated.
Sampling introduces audit risk, meaning the sample may not represent the whole population. The audit report should acknowledge this uncertainty. Audit conclusions apply to what was sampled; certification is not a guarantee of 100% conformity.
3.5 Recording Evidence
Auditors use checklists, working papers and audit notes to capture evidence. A well-written nonconformity typically includes three parts:
• The requirement: the audit criterion, for example ISO/IEC 27001:2022 Clause 7.2 or Annex A 5.18.
• The evidence: what was found, for example "3 of 10 sampled leavers in Q2 still had active VPN accounts (records HR-L-045, HR-L-051, HR-L-063)."
• The statement of nonconformity: how the evidence fails to meet the requirement.
3.6 Practical ISMS Example
Criterion: ISO/IEC 27001 Clause 9.2 requires internal audits at planned intervals.
Auditee claim: "We audit every department annually."
Evidence-based action: request the internal audit programme, select a sample of departments, and review the audit reports, dates and auditor competence records.
Finding: the programme lists 8 departments, but no audit report exists for IT Operations or Facilities in the last 18 months.
Result: a nonconformity supported by objective, verifiable and traceable evidence.
3.7 What Is NOT Audit Evidence
• Rumours, hearsay or anonymous gossip that has not been verified
• The auditor's assumptions, feelings or past experience with other organisations
• Evidence that has no link to the audit criteria
• Information obtained outside the audit scope (unless the auditor reports it appropriately)
• Promises of future action, such as "we will implement it next month"
3.8 Relationship With Other Principles
• Fair presentation: findings must truthfully reflect the evidence.
• Due professional care: the auditor uses judgement when selecting and evaluating evidence.
• Independence: objective evidence supports impartial conclusions.
• Risk-based approach: it guides where to focus evidence collection and sampling.
• Confidentiality: evidence collected must be protected, particularly sensitive ISMS information.
4. Exam Tips: Answering Questions on Evidence-Based Approach
Tip 1: Memorise the definition. If asked to define the principle, use the ISO 19011 wording: "the rational method for reaching reliable and reproducible audit conclusions in a systematic audit process." Mention that evidence must be verifiable and is based on samples.
Tip 2: Use the keywords. Examiners look for the terms verifiable, objective evidence, reliable, reproducible, sampling, audit criteria, traceable, sufficient, relevant.
Tip 3: Distinguish the terms correctly. Know the difference between audit evidence (facts), audit criteria (requirements), audit findings (evidence compared to criteria) and audit conclusions (overall outcome). Multiple-choice questions often test this sequence.
Tip 4: Pick verification over acceptance. In scenario questions, when an auditee makes a verbal claim, the best answer is almost always to request objective evidence, such as records, documents, observation or sampling. The wrong answers usually involve accepting the claim, ignoring it, or immediately raising a nonconformity without evidence.
Tip 5: Never raise a nonconformity on opinion. If a scenario describes an auditor who "feels" or "assumes" something is wrong, that breaches the principle. The correct course is to gather and verify evidence first.
Tip 6: Know your sampling. Be ready to explain judgement-based versus statistical sampling, why sampling is necessary (limited time and resources), and that sampling creates audit risk and uncertainty.
Tip 7: Write findings in three parts. In essay or case-study exams, such as the PECB or IRCA/CQI ISO 27001 Lead Auditor exams, structure nonconformities as Requirement + Evidence + Statement. Be specific: quote the clause or Annex A control number, give quantities ("4 of 15 sampled"), dates and record IDs, and identify people by role, not by name.
Tip 8: Justify your answer with the principle. When asked "What should the auditor do?", name the principle explicitly. For example: "In line with the evidence-based approach of ISO 19011, the auditor should verify the statement by sampling access review records before reaching a conclusion."
Tip 9: Treat interview evidence as valid but corroborated. Do not choose answers claiming verbal evidence is worthless. It is valid evidence, but it should be corroborated where possible.
Tip 10: Watch for distractor words. Answers containing "assume", "believe", "likely", "probably", "based on previous experience" or "trust the manager" usually violate the evidence-based approach. Answers containing "verify", "sample", "review records", "observe" or "corroborate" usually align with it.
Tip 11: Link evidence to scope and criteria. Evidence must be relevant to the audit objectives, scope and criteria. If a scenario introduces information outside the scope, the best answer usually involves noting it and communicating it appropriately, not including it as a finding.
Tip 12: Remember reproducibility. A strong exam answer mentions that a different competent auditor, reviewing the same evidence, should reach a similar conclusion. This is the essence of the principle.
Sample Exam Question
During an audit, the IT Manager states that all servers are patched within 14 days, as required by the patch management procedure. What should the auditor do?
A) Accept the statement because the IT Manager is a senior employee
B) Raise a nonconformity because statements are not evidence
C) Select a sample of servers and review patch records and system reports to verify the statement
D) Record an opportunity for improvement
Correct answer: C. The evidence-based approach requires verifiable evidence obtained through appropriate sampling before a conclusion is reached.
Summary
The Evidence-Based Approach makes ISO 27001 audits credible. Auditors collect verifiable, relevant and sufficient objective evidence through interviews, observation, document and record review and technical testing, usually by sampling. They compare that evidence to the audit criteria to produce findings, and then reach reliable and reproducible conclusions. In the exam, always favour verification over assumption, cite the principle explicitly, and write findings that are traceable to specific evidence.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!