Risk-Based Approach to Auditing
In ISO/IEC 27001 Lead Auditor training, the risk-based approach is one of the seven principles of auditing defined in ISO 19011:2018. It means the auditor considers risks and opportunities when planning, conducting, and reporting an audit. Effort goes to the matters that are most significant to the… In ISO/IEC 27001 Lead Auditor training, the risk-based approach is one of the seven principles of auditing defined in ISO 19011:2018. It means the auditor considers risks and opportunities when planning, conducting, and reporting an audit. Effort goes to the matters that are most significant to the audit client and to achieving the audit objectives, rather than giving every area equal attention. The approach works at two levels. At the audit programme level, the person managing the programme identifies risks that could prevent the programme from meeting its objectives. Examples include insufficient resources, an audit team without enough information security competence, poor communication, limited access to auditee information, unrealistic schedules, and weak control of audit records. The programme manager then puts measures in place to address them, such as choosing qualified auditors, allowing enough audit time, and securing confidentiality agreements. At the individual audit level, the lead auditor applies risk-based thinking during preparation and on site. This involves reviewing the auditee's context, information security risk assessment, risk treatment plan, and Statement of Applicability. The auditor uses that information to decide which processes, locations, and Annex A controls deserve deeper examination. High-risk areas usually receive more audit time and larger samples. Examples include privileged access management, handling of sensitive data, supplier security, and incident management. Lower-risk areas may be sampled more lightly. This matters because audits are limited by time and resources and depend on sampling. A risk-based approach increases confidence that audit conclusions are reliable and that significant nonconformities are not missed. It also keeps the audit aligned with ISO/IEC 27001 itself, whose core requirement is that the organization manage information security risks systematically (Clause 6.1). A competent ISMS auditor therefore evaluates whether the organization's risk methodology is sound and consistently applied. The auditor also checks whether the controls selected actually address the identified risks. Finally, the auditor confirms whether risk owners have accepted residual risks. Throughout, the auditor stays alert to emerging risks that may justify adjusting the audit plan.
Risk-Based Approach to Auditing: A Complete Guide for ISO 27001 Lead Auditors
Introduction
The risk-based approach to auditing is one of the core concepts in the ISO 27001 Lead Auditor syllabus. It comes from ISO 19011:2018 (Guidelines for auditing management systems), where it is listed as the seventh principle of auditing. It also fits the risk-centred design of ISO/IEC 27001:2022. Every Lead Auditor needs to understand it, both to plan and run effective audits and to pass the certification exam.
What Is the Risk-Based Approach to Auditing?
ISO 19011:2018 describes it as an audit approach that considers risks and opportunities. That consideration should shape the planning, conducting and reporting of audits, so that audits focus on the matters that are significant for the audit client and for achieving the audit programme objectives.
In simple terms, auditors do not give equal time to everything. They direct their effort, sampling and attention to the areas where:
- failure would have the greatest impact,
- weaknesses are most likely, or
- important opportunities for improvement exist.
Two levels of risk are involved:
1. Risks related to the audit programme and the audit itself. These are the risks that the audit objectives will not be achieved. Examples include:
- an inadequate audit team,
- insufficient time,
- poor communication,
- lack of access to evidence,
- poor planning.
2. Risks related to the auditee's management system. These are the information security risks and the risks to the effectiveness of the ISMS. The auditor uses them to decide where to focus.
Why Is It Important?
Efficient use of limited resources: Audits are always constrained by time and budget, and an auditor cannot check every record, process or control. Focusing on high-risk areas means the time available produces the greatest assurance.
Alignment with ISO 27001 itself: ISO 27001 is built on risk management. Key clauses include:
- Clause 6.1 (actions to address risks and opportunities),
- 6.1.2 (risk assessment),
- 6.1.3 (risk treatment),
- 8.2 and 8.3 (performing risk assessment and treatment).
The Statement of Applicability (SoA) is derived from risk treatment decisions. It would be inconsistent to audit a risk-based standard without a risk-based mindset.
Better value for the auditee: Findings on significant risks are more meaningful to top management than minor administrative issues. They support real improvement in information security.
Higher audit confidence: By targeting areas where nonconformities are most likely or most damaging, the auditor reduces audit risk, meaning the risk of reaching an incorrect conclusion.
Required by accreditation rules: ISO/IEC 17021-1 and ISO/IEC 27006 require certification bodies to consider risk and complexity when determining:
- audit time,
- audit programme design,
- sampling,
- surveillance frequency.
How It Works in Practice
1. Audit programme level (ISO 19011 Clause 5)
The person managing the audit programme identifies and evaluates the risks and opportunities affecting the programme. ISO 19011 Clause 5.3 gives examples:
- Planning: failure to set relevant audit objectives or determine the extent, number, duration, locations and schedule of audits.
- Resources: insufficient time, equipment or training.
- Selection of the audit team: lack of the competence needed to conduct audits effectively.
- Communication: ineffective internal or external communication processes.
- Implementation: ineffective coordination of audits, or failure to consider information security and confidentiality.
- Control of documented information: ineffective determination of what is needed and how it is protected.
- Monitoring, reviewing and improving the programme: ineffective monitoring of programme outcomes.
- Availability and cooperation of the auditee and availability of evidence to be sampled.
Opportunities might include combining several audits in one visit, reducing travel, or matching auditor competence to audit needs.
2. Individual audit level: planning (ISO 19011 Clause 6.3)
When preparing the audit plan, the audit team leader takes a risk-based approach. The leader considers:
- the auditee's context,
- the nature and complexity of its activities,
- results of previous audits,
- known incidents,
- the risk assessment and risk treatment plan,
- the SoA and any exclusions.
The plan then gives more time and more experienced auditors to high-risk processes. Examples include access control for a cloud provider, or cryptography for a payment processor.
3. Document review
Reviewing the risk methodology, risk register and SoA early helps the auditor identify significant risks, critical assets and key controls to verify on site.
4. Sampling (ISO 19011 Annex A.6)
Sample sizes and selection are influenced by risk. Higher-risk areas justify larger samples or judgement-based selection, for example privileged user accounts rather than random accounts. Lower-risk areas may receive lighter sampling.
5. Conducting the audit
Auditors stay alert to emerging risks during interviews and observations. If new significant risks appear, the audit team leader may:
- adjust the audit plan,
- reallocate time,
- in serious cases, inform the audit client and auditee (ISO 19011 Clause 6.4.4).
6. Reporting
Findings are graded by significance, such as major nonconformity, minor nonconformity or opportunity for improvement. The impact of a nonconformity on the ISMS's ability to achieve its intended outcomes drives its classification and the urgency of correction.
7. Certification audit programme
Certification bodies use risk to define the three-year cycle, including surveillance focus and the number of sites sampled in multi-site organisations (ISO/IEC 27006). Past performance and incidents can increase or decrease audit effort.
Examples of Risk-Based Focus in an ISMS Audit
- A hospital: prioritise the confidentiality of patient records, access management and incident response.
- A software company: prioritise secure development, change management and supplier (cloud) security.
- A newly certified organisation with a history of incidents: give more time to incident management and corrective action effectiveness.
- Excluded Annex A controls: verify that the justification is consistent with the risk assessment.
Relationship to Other Audit Principles
The seven ISO 19011 principles are:
1. Integrity
2. Fair presentation
3. Due professional care
4. Confidentiality
5. Independence
6. Evidence-based approach
7. Risk-based approach
The risk-based approach works together with the evidence-based approach. Risk tells you where to look, and evidence tells you what you found. It also supports due professional care, because judging significance is part of professional judgement.
Common Misconceptions
- Wrong: A risk-based audit means auditing only high-risk areas. Correct: All clauses within scope (Clauses 4 to 10 for certification) must still be covered over the audit cycle. Risk determines depth, emphasis and sampling, not whether mandatory requirements are skipped.
- Wrong: The auditor performs the risk assessment for the auditee. Correct: The auditor evaluates the auditee's risk process and uses its outputs, but never takes over management's responsibility.
- Wrong: It only concerns information security risk. Correct: It also covers risks to the audit programme and audit process.
- Wrong: Risk-based means subjective. Correct: Conclusions must still be based on objective, verifiable audit evidence.
Exam Tips: Answering Questions on Risk-Based Approach to Auditing
1. Know the source and wording. Remember that it is the seventh principle in ISO 19011:2018 and was newly added in the 2018 edition. Remember the phrase: considers risks and opportunities, influencing planning, conducting and reporting.
2. Identify which risk the question means. Ask yourself whether it concerns risk to the audit programme or audit (resources, competence, time, access) or risk in the auditee's ISMS. Choose answers that match the correct level.
3. Prefer answers that allocate effort proportionately. In scenario questions, the best answer usually directs more time, sampling or competent auditors to high-impact areas. Look for this tied to the auditee's risk assessment, previous findings or incidents.
4. Reject options that skip mandatory requirements. Distractors often suggest ignoring low-risk clauses entirely or auditing only what management requests. Coverage of the scope and standard is still required.
5. Do not let the auditor become a consultant. Avoid answers where the auditor designs controls, rewrites the risk assessment or decides risk acceptance. The auditor assesses conformity and effectiveness.
6. Link to ISO 27001 clauses. Expect references to:
- Clause 6.1.2 (risk assessment),
- 6.1.3 (risk treatment and SoA),
- 8.2/8.3,
- 9.2 (internal audit), which requires the programme to consider the importance of processes and previous audit results, a risk-based concept.
7. Use risk to justify sampling choices. In essay or case-study answers, explain why you chose certain samples. For example: I selected privileged accounts and recent leavers because these represent the highest risk of unauthorised access.
8. Connect risk to nonconformity grading. When classifying findings, refer to the impact on the ISMS's ability to achieve intended results. A systemic failure, such as no risk assessment performed, indicates a major nonconformity.
9. Remember adaptability. If a scenario reveals a serious new risk during the audit, the correct response is often to adjust the plan and communicate with the audit client and auditee. Continuing blindly with the original plan is usually wrong.
10. Structure written answers clearly. A strong answer covers:
- Definition,
- Why it matters (efficiency, assurance, value),
- Application (planning, sampling, conducting, reporting),
- a practical example from the case study.
11. Watch for keywords. Words such as significant, priority, focus, proportionate, critical, previous results, incidents, complexity signal a risk-based answer.
Summary
The risk-based approach makes sure audits concentrate on what matters most to the organisation and to achieving audit objectives. It applies at both the programme and individual audit levels, shaping planning, team selection, sampling, execution and reporting. It never replaces objective evidence or full coverage of requirements. In the exam, show that you can use risk to prioritise intelligently while staying objective, independent and compliant with ISO 19011 and ISO 27001.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!