Irregularities and Illegal Acts Found During an Audit
In ISO/IEC 27001 auditing, irregularities are deviations from expected practice, such as falsified records, manipulated logs, missing evidence or unauthorized activities. They may result from error or from deliberate intent. Illegal acts are violations of laws or regulations, such as fraud, data pr… In ISO/IEC 27001 auditing, irregularities are deviations from expected practice, such as falsified records, manipulated logs, missing evidence or unauthorized activities. They may result from error or from deliberate intent. Illegal acts are violations of laws or regulations, such as fraud, data protection breaches, unlicensed software use, bribery or unauthorized surveillance. Under ISO 19011 and ISO/IEC 17021-1, auditors must handle these situations according to the principles of integrity, fair presentation, due professional care, confidentiality, independence and an evidence-based approach. An auditor is not a forensic investigator or law enforcement officer. The audit is not designed to detect every fraud or illegal act. However, auditors must apply professional skepticism. When they see warning signs, such as inconsistent records, reluctance to give access, altered documents or contradictory testimony, they should not ignore them. Auditors should first distinguish an honest mistake from a possible intentional act and gather objective, verifiable evidence. They should avoid accusations or legal judgments. In practice, an auditor who discovers a possible irregularity or illegal act should take the following steps: 1) Record the facts objectively and keep the evidence. 2) Promptly inform the audit team leader, who escalates the matter to the audit programme manager or certification body and, where appropriate, to the auditee's top management. 3) Stay within the audit scope rather than conducting a separate investigation. 4) Seek legal or compliance advice, especially where confidentiality obligations may conflict with legal duties to report certain crimes to authorities. If the issue relates to ISMS requirements, such as compliance with legal, statutory, regulatory and contractual obligations (Annex A control 5.31), it may be raised as a nonconformity. Serious issues may affect the validity of evidence, the confidence placed in the ISMS or the feasibility of continuing the audit. In such cases, the team leader may modify, suspend or terminate the audit after consulting the client and the certification body. Throughout the process, auditors must protect sensitive information, remain impartial, and ensure their conclusions are accurate, fair and defensible.
Irregularities and Illegal Acts Found During an Audit: ISO 27001 Lead Auditor Guide
Introduction
During an ISO/IEC 27001 audit, an auditor may come across things that go beyond ordinary nonconformities. Examples include evidence of fraud, data theft, bribery, falsified records, unlicensed software, privacy law violations, or deliberate concealment of security incidents. These are called irregularities and illegal acts. Knowing how to recognise and handle them is a core competence for a Lead Auditor. It is also a frequent topic in certification exams such as the PECB and CQI/IRCA ISO 27001 Lead Auditor exams.
Why It Is Important
1. Professional integrity and credibility: Certification bodies and auditors must stay impartial and trustworthy. Mishandling evidence of illegal activity can damage the credibility of the audit, the auditor and the certification body.
2. Legal exposure: An auditor who ignores, conceals or wrongly discloses illegal acts may face legal consequences. These can include breach of confidentiality, defamation, obstruction or failure to report where reporting is legally required.
3. Protection of the auditee and stakeholders: Illegal acts such as unauthorised disclosure of personal data can harm customers, employees and the public. Escalating them properly protects interested parties.
4. Validity of the ISMS: ISO 27001 requires organisations to identify legal, statutory, regulatory and contractual requirements (Clause 4.2 and Annex A control 5.31 in the 2022 version, A.18.1.1 in 2013). Systematic illegal acts may show that the ISMS is not effective and cannot support certification.
5. Auditor safety and ethics: Some situations involve risk to the auditor. Guidance exists so auditors do not act as investigators or put themselves in danger.
What It Is
Irregularities are intentional or unintentional deviations from expected, authorised or documented practices that may indicate wrongdoing. Examples are manipulated logs, backdated records, missing approvals or inconsistent evidence.
Illegal acts are actions that violate laws or regulations. Examples include:
- Fraud or embezzlement
- Software piracy or licence violations
- Breaches of data protection laws such as the GDPR
- Unauthorised surveillance of employees
- Bribery or corruption
- Deliberately concealing a reportable data breach
- Export control violations involving cryptography
Key distinctions:
- A nonconformity is the non-fulfilment of a requirement of the standard or the organisation's own ISMS.
- An irregularity or illegal act may also be a nonconformity, but it carries extra legal, ethical and reporting implications.
- The auditor is not a law enforcement officer, lawyer or forensic investigator. An ISMS audit is not designed to detect fraud. However, the auditor must apply professional skepticism and due professional care.
Relevant Principles and References
- ISO 19011:2018 principles of auditing: integrity, fair presentation, due professional care, confidentiality, independence, evidence-based approach and risk-based approach.
- ISO/IEC 17021-1: requirements for certification bodies on impartiality, confidentiality, and handling of information and complaints.
- ISO/IEC 27007: guidelines for auditing information security management systems.
- Codes of ethics from certification bodies and personnel certification bodies (e.g., PECB, IRCA).
- Audit contract and audit plan: they usually define confidentiality obligations and the reporting lines for sensitive matters.
How It Works: The Auditor's Response Process
Step 1: Recognise and stay objective. Notice the indicator, such as inconsistent records, evasive answers or evidence of unlicensed software. Do not jump to conclusions. Stay factual and impartial.
Step 2: Verify the evidence within the audit scope. Gather enough objective evidence by observation, document review and interviews to confirm what was seen. Do not go beyond the audit mandate. Do not start a forensic investigation, seize evidence, or access systems without authorisation.
Step 3: Document factually. Record what was observed: date, time, location, documents and persons present. Avoid accusations or legal conclusions. For example, write 'Licence records for 120 installations of software X could not be produced', not 'The company is committing piracy.'
Step 4: Escalate through the proper channel.
- An audit team member reports to the audit team leader.
- The audit team leader informs the audit programme manager or certification body management. Where appropriate, and according to the contract, the leader also informs the audit client and top management of the auditee.
- If senior management may be involved, escalate to the certification body. Seek guidance from its management or legal counsel rather than reporting to the people possibly implicated.
Step 5: Respect confidentiality. Do not disclose the matter to third parties such as police, regulators or media unless required by law. Disclosure should normally be decided by the certification body or the audit client, often with legal advice. Confidentiality is a core audit principle. The exception is a legal obligation to report, for example on money laundering, child exploitation or imminent danger to life, depending on jurisdiction.
Step 6: Assess the impact on the audit. The audit team leader decides, with the client and the certification body, whether to:
- Continue the audit
- Modify the audit objectives, scope or plan
- Suspend or terminate the audit (ISO 19011 allows this when objectives become unattainable or there is a risk to auditors)
Step 7: Report findings appropriately. If the issue relates to an ISMS requirement, raise a nonconformity. Examples include failure to identify legal requirements (Clause 4.2, control 5.31), failure to protect PII (control 5.34) or intellectual property (control 5.32), or failure to manage incidents (controls 5.24 to 5.28). Grade it as major or minor based on its effect on the ISMS. Sensitive details may go in a confidential section or a separate communication.
Step 8: Certification decision. The certification body may refuse, suspend or withdraw certification if the illegal acts show that the ISMS cannot meet its intended outcomes, including legal compliance.
Example Scenarios
1. An auditor discovers that the IT manager has been copying customer databases to a personal USB drive. Record the facts objectively, inform the audit team leader, and escalate to top management or the certification body as appropriate. Assess the impact on information security controls. Do not confront or accuse the individual.
2. The organisation has failed to notify a regulator of a significant personal data breach. This may be a nonconformity against legal requirements and incident management. Report it to the audit client and top management. The auditor does not normally notify the regulator directly unless required by law.
3. The auditee asks the auditor to ignore a finding in exchange for a gift. This is an attempted bribe. Refuse it, document it, and report it to the audit team leader and certification body immediately. It is an integrity and impartiality issue.
Exam Tips: Answering Questions on Irregularities and Illegal Acts Found During an Audit
1. Prefer escalation over unilateral action. The best answer usually involves informing the audit team leader (if you are a team member) or the certification body or audit client (if you are the leader). Avoid options where the auditor calls the police, contacts the media or confronts staff directly.
2. Remember the auditor is not an investigator. Reject answers suggesting the auditor should expand the investigation, collect forensic evidence or interrogate suspects. Gathering objective evidence within scope is fine.
3. Confidentiality is key, but not absolute. Choose answers that respect confidentiality unless the law requires disclosure. Watch for the phrase 'unless legally required'.
4. Stick to facts, not legal conclusions. Auditors report what they observed. They do not judge guilt. Answers using words like 'accuse', 'prosecute' or 'declare illegal' are usually wrong.
5. Link to ISO 27001 requirements. In scenario questions, identify the relevant clause or control: 4.2, 5.31 (legal requirements), 5.32 (intellectual property), 5.33 (protection of records), 5.34 (privacy and PII), 5.24 to 5.28 (incident management), and 6.4 (disciplinary process). Grade the nonconformity based on systemic impact.
6. Consider audit continuation. If the question asks what happens to the audit, remember the team leader may, after consulting the client and certification body, modify, suspend or terminate the audit if objectives cannot be met or auditors are at risk.
7. Handle top-management involvement carefully. If the people who would normally receive the report are implicated, the correct route is usually the certification body's management or legal function.
8. Integrity threats are always reported. Bribes, gifts, threats or pressure to change findings must be refused and reported. Impartiality is non-negotiable.
9. Watch for absolute words. Options with 'always', 'immediately inform authorities' or 'ignore because it is outside scope' are usually traps. Even out-of-scope illegal acts observed should be communicated appropriately. They are not ignored.
10. Use the ISO 19011 principles as a tiebreaker. When unsure, pick the answer that best shows integrity, fair presentation, due professional care, confidentiality and an evidence-based approach.
Quick Summary
- Recognise the issue and stay objective.
- Verify it within scope, without investigating.
- Document facts, not opinions.
- Escalate: team member, then team leader, then certification body or audit client.
- Keep it confidential unless the law requires disclosure.
- Assess the impact: continue, modify, suspend or terminate the audit.
- Raise a nonconformity against the relevant ISMS requirements.
- Let the certification body decide on certification consequences.
Mastering this topic shows that you understand the ethical and professional boundaries of the auditor's role. This is exactly what examiners want to see in a competent ISO 27001 Lead Auditor.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!