Integrity and Fair Presentation
In the ISO/IEC 27001 Lead Auditor context, auditing is guided by the principles in ISO 19011:2018, Guidelines for auditing management systems. Integrity and Fair Presentation are two of its seven core principles, alongside Due Professional Care, Confidentiality, Independence, Evidence-Based Approac… In the ISO/IEC 27001 Lead Auditor context, auditing is guided by the principles in ISO 19011:2018, Guidelines for auditing management systems. Integrity and Fair Presentation are two of its seven core principles, alongside Due Professional Care, Confidentiality, Independence, Evidence-Based Approach and Risk-Based Approach. Together they make audit results trustworthy and useful. INTEGRITY is the foundation of professionalism. Auditors and audit programme managers should perform their work ethically, with honesty and responsibility. They should only undertake audit activities they are competent to perform, act impartially by remaining fair and unbiased in all dealings, and stay sensitive to any influences that could affect their judgement, such as pressure from auditees, commercial interests or personal relationships. For an ISMS auditor, integrity means not overlooking a missing risk assessment to please a client, not accepting inappropriate gifts, and not claiming expertise in areas like cloud security or cryptography without the needed competence. Integrity also means complying with applicable legal requirements and showing commitment to the organisation and audit programme. FAIR PRESENTATION is the obligation to report truthfully and accurately. Audit findings, audit conclusions and audit reports should truthfully and accurately reflect the audit activities. Significant obstacles encountered during the audit, such as restricted access to records or unavailable personnel, should be reported, as should unresolved, diverging opinions between the audit team and the auditee. Communication should be truthful, accurate, objective, timely, clear and complete. In practice, an ISO/IEC 27001 auditor must describe nonconformities against specific clauses or Annex A controls precisely, without exaggerating minor issues or downplaying major weaknesses, and should acknowledge positive practices as well as gaps. The relationship between the two principles is clear: integrity governs how the auditor behaves, while fair presentation governs how results are communicated. Without integrity, evidence may be biased; without fair presentation, even sound evidence may be misrepresented. Both are essential for certification bodies, auditees and interested parties to rely on audit outcomes when making decisions about information security.
Integrity and Fair Presentation: Core Audit Principles for the ISO 27001 Lead Auditor
Introduction
Integrity and Fair Presentation are the first two of the seven principles of auditing defined in ISO 19011:2018, Clause 4, the guidance standard for auditing management systems. The ISO/IEC 27001 Lead Auditor course and exam build on it. The seven principles are:
1. Integrity: the foundation of professionalism
2. Fair presentation: the obligation to report truthfully and accurately
3. Due professional care: the application of diligence and judgement in auditing
4. Confidentiality: security of information
5. Independence: the basis for the impartiality of the audit and objectivity of the audit conclusions
6. Evidence-based approach: the rational method for reaching reliable and reproducible audit conclusions
7. Risk-based approach: an audit approach that considers risks and opportunities
This guide explains what Integrity and Fair Presentation mean, why they matter, how they work in a real ISMS audit, and how to answer exam questions about them.
Why Integrity and Fair Presentation Are Important
An audit only has value if its users can trust it. Top management, certification bodies, accreditation bodies, customers and regulators all rely on the audit report to make decisions. Two examples:
- A certification decision is based on the auditor's report.
- A customer may accept a supplier because it holds ISO 27001 certification.
If an auditor is dishonest, works outside their competence, or gives in to pressure, the audit conclusions become unreliable. The same is true if the report hides problems or exaggerates findings. The consequences include:
- False assurance: an organisation appears secure when serious information security risks remain untreated.
- Unfair penalties: an organisation may receive nonconformities it does not deserve, harming its reputation and business.
- Loss of credibility: confidence in the auditor, the certification body and the ISO 27001 certification scheme is damaged.
- Legal and contractual risk: misleading reports can create liability for the auditor and the certification body.
Integrity is the personal and ethical foundation. Fair presentation is how that integrity shows up in the outputs of the audit. Together they make the audit trustworthy.
What Integrity Is
ISO 19011 describes integrity as the foundation of professionalism. Auditors, and the individuals managing an audit programme, should:
- Perform their work ethically, with honesty and responsibility.
- Only undertake audit activities if they are competent to do so.
- Perform their work in an impartial manner, remaining fair and unbiased in all their dealings.
- Be sensitive to any influences that may be exerted on their judgement while carrying out an audit.
Integrity in practice during an ISO 27001 audit
Honesty
- Do not falsify records or invent evidence.
- Do not claim to have sampled or verified something you did not.
Responsibility
- Follow the audit plan.
- Manage time properly.
- Do not skip clauses or Annex A controls in scope because you are short of time without disclosing it.
Competence
- Decline or seek support (for example, a technical expert) when an area is beyond your knowledge.
- An example is a highly specialised cryptographic implementation or an industrial control system environment.
Impartiality
- Treat all auditees equally.
- Avoid favouring departments, individuals or outcomes.
Resisting influence
- Recognise and reject gifts, hospitality, pressure from the auditee's management, or commercial pressure from your own organisation.
- Remember that a desire to be liked can also bias your findings.
What Fair Presentation Is
ISO 19011 describes fair presentation as the obligation to report truthfully and accurately. In detail:
- Audit findings, audit conclusions and audit reports should reflect truthfully and accurately the audit activities.
- Significant obstacles encountered during the audit should be reported.
- Unresolved diverging opinions between the audit team and the auditee should be reported.
- Communication should be truthful, accurate, objective, timely, clear and complete.
Fair presentation in practice
Truthful and accurate reporting
- A nonconformity statement should describe exactly what was observed, with the requirement and the evidence.
- For example: Clause 8.2 requires information security risk assessments at planned intervals. No risk assessment had been performed since March of the previous year, contrary to the documented 12-month interval in the risk methodology.
Objective
- Findings are based on evidence, not opinion, rumour or personal preference.
- Severity should be graded honestly. Do not upgrade a minor issue to a major one, or downgrade a major one to keep the client happy.
Complete
- Report both positive findings and nonconformities.
- Do not omit areas that were not audited. State them as limitations.
Reporting obstacles
- Examples include being denied access to a data centre or not being given key records.
- Other examples are a key interviewee being unavailable or time being cut short.
- These must be recorded because they affect the reliability of the audit conclusions.
Reporting diverging opinions
- If the auditee disagrees with a finding and the disagreement cannot be resolved at the closing meeting, it is noted in the report.
- The finding is not silently deleted or altered.
Timely and clear
- Reports are issued within agreed timeframes.
- They are written in language the intended recipients can understand.
How the Two Principles Work Together
Think of integrity as the auditor's character and conduct and fair presentation as the quality and honesty of the audit's outputs. An auditor with integrity will naturally present fairly. Fair presentation in turn demonstrates and protects that integrity.
They are applied across the whole audit lifecycle:
Audit programme and planning
- Assign competent auditors to each area.
- Declare conflicts of interest.
- Agree realistic audit time so the scope can be covered honestly.
Opening meeting
- Explain the audit process transparently, including how findings will be reported and how disagreements are handled.
Collecting evidence
- Sample fairly.
- Record evidence accurately.
- Remain neutral in interviews.
- Do not lead interviewees towards a desired answer.
Generating findings
- Compare evidence objectively against the audit criteria, such as ISO 27001 clauses 4 to 10, the Statement of Applicability, Annex A controls and internal policies.
Closing meeting
- Present findings exactly as recorded.
- Discuss disagreements.
- Note any that are unresolved.
Audit report
- Present a balanced, complete and accurate picture.
- Include scope, limitations, obstacles, unresolved diverging opinions and conclusions.
Relationship to Other Principles (Common Exam Trap)
Exam questions often test whether you can distinguish these principles from neighbouring ones:
- Integrity vs Independence
Independence concerns freedom from bias and conflict of interest arising from relationships and structure. Examples are not auditing your own work, or not auditing a client you consulted for. Integrity is broader and concerns ethical conduct: honesty, competence, impartiality and resisting influence. A gift offered to an auditor touches both, but resisting the influence is framed under integrity in ISO 19011.
- Fair presentation vs Evidence-based approach
The evidence-based approach concerns how conclusions are reached: verifiable evidence and appropriate sampling. Fair presentation concerns how results are communicated: truthfully, accurately and completely.
- Integrity vs Due professional care
Due professional care is about diligence and sound judgement in proportion to the importance of the task. Integrity is about ethics and honesty. Working outside one's competence is listed explicitly under integrity.
- Fair presentation vs Confidentiality
Fair presentation requires complete reporting to the intended recipients. Confidentiality restricts disclosure to unauthorised parties. They do not conflict.
Practical Scenarios
Scenario 1
The auditee's CEO hints that a large consulting contract may follow if the audit goes smoothly.
- Principle: Integrity, specifically being sensitive to influences.
- Correct action: Decline, remain impartial, and inform the audit programme manager or certification body.
Scenario 2
The IT manager refuses access to firewall configuration records, citing security sensitivity.
- Principle: Fair presentation, specifically reporting significant obstacles.
- Correct action: Try to resolve the issue. If it remains unresolved, record it in the report as a limitation on the audit conclusions.
Scenario 3
The auditee disagrees with a nonconformity on access review frequency (Annex A 5.18) and no agreement is reached at the closing meeting.
- Principle: Fair presentation, specifically reporting unresolved diverging opinions.
- Correct action: Record the finding and the auditee's differing view. Do not remove the finding to avoid conflict.
Scenario 4
An auditor is assigned to audit a cloud-native DevSecOps pipeline but has no knowledge of it.
- Principle: Integrity, specifically undertaking only audit activities within one's competence.
- Correct action: Inform the audit team leader or programme manager, and request a technical expert or reassignment.
Scenario 5
Due to time pressure, the team did not audit the remote site that was in scope.
- Principle: Fair presentation, specifically completeness and truthfulness.
- Correct action: Clearly state in the report that the site was not audited. Do not imply full coverage.
Exam Tips: Answering Questions on Integrity and Fair Presentation
1. Memorise the one-line definitions.
Integrity = the foundation of professionalism.
Fair presentation = the obligation to report truthfully and accurately.
Many multiple-choice questions simply match a principle to its definition.
2. Learn the key elements of each principle.
For integrity: honesty and responsibility, competence, impartiality, and sensitivity to influence.
For fair presentation: truthful and accurate findings, reporting obstacles, reporting unresolved diverging opinions, and communication that is truthful, accurate, objective, timely, clear and complete.
3. Look for keyword triggers.
The following words usually point to integrity:
- Gifts, bribes, pressure, ethics, honesty
- Working outside expertise
- Bias in conduct
The following words usually point to fair presentation:
- Report, obstacles, diverging opinions, disagreement
- Omitted findings, accuracy, completeness
4. Choose the answer that protects the reliability of the audit.
In scenario questions, the correct option is usually the one that is transparent and reports honestly. It also tends to escalate appropriately to the audit team leader or programme manager. Be wary of options that:
- Hide information
- Soften findings to please the client
- Delete disputed findings
- Ignore limitations
5. Never remove or alter a finding just because the auditee disagrees.
Try to resolve the disagreement with evidence. If it remains unresolved, record both positions. This is a favourite exam point.
6. Obstacles affect confidence in conclusions.
If a question describes denied access, missing records or unavailable personnel, the expected answer involves reporting it and considering its effect on the audit conclusions.
7. Competence is part of integrity.
Candidates often attribute competence issues to due professional care. ISO 19011 explicitly places undertaking activities only when competent under integrity.
8. Distinguish integrity from independence.
Choose independence if the issue is structural, such as auditing one's own work, a former employer or a past consulting client. Choose integrity if the issue is about ethical behaviour, honesty or resisting influence during the audit.
9. Balanced reporting is fair presentation.
A report that lists only nonconformities and ignores strengths, or exaggerates issues, is not fair. Objective reporting includes positive findings and accurate grading of nonconformities (major or minor).
10. For essay or scenario answers, use a clear structure.
- (a) Identify the principle involved.
- (b) Quote or paraphrase the ISO 19011 definition.
- (c) Explain the risk if it is violated.
- (d) State the correct auditor action.
- (e) Link it to the credibility of ISO 27001 certification.
11. Reference the right source.
The principles come from ISO 19011:2018, Clause 4. For third-party certification audits, also mention that ISO/IEC 17021-1 requires impartiality and that ISO/IEC 27006 applies to ISMS certification bodies. This shows depth.
12. Watch for absolute wording.
Options such as the auditor should never discuss findings with the auditee are usually wrong. Good options include:
- The auditor should discuss findings openly.
- Unresolved issues should be recorded.
Summary
Integrity means the auditor is honest, responsible, competent, impartial and resistant to undue influence. Fair presentation means the audit's findings, conclusions and reports are truthful, accurate, objective, timely, clear and complete. They must also disclose significant obstacles and unresolved diverging opinions.
Together these principles make an ISO 27001 audit trustworthy. In the exam, identify the principle from its keywords and recall the ISO 19011 wording. Then choose the action that keeps the audit honest, transparent and reliable.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!