Types of Audit Evidence
In ISO/IEC 27001 auditing, audit evidence is defined by ISO 19011 as records, statements of fact or other information that are relevant to the audit criteria and verifiable. Auditors compare this evidence against the audit criteria to produce audit findings, so it must be sufficient, appropriate an… In ISO/IEC 27001 auditing, audit evidence is defined by ISO 19011 as records, statements of fact or other information that are relevant to the audit criteria and verifiable. Auditors compare this evidence against the audit criteria to produce audit findings, so it must be sufficient, appropriate and objective. Evidence is usually gathered through sampling, using interviews, observation and document review. The PECB Lead Auditor approach groups evidence into seven types. Physical evidence is obtained through direct observation, such as seeing locked server rooms, badge readers, CCTV cameras or clean desks. It is highly reliable because the auditor witnesses it firsthand. Mathematical evidence results from calculations performed by the auditor, such as recalculating risk scores, checking the percentage of staff who completed awareness training, or verifying incident metrics. Confirmative evidence is obtained from independent or third parties, such as written confirmations from suppliers, cloud providers or external penetration testers, and helps corroborate the auditee's claims. Technical evidence comes from examining systems and technical controls, such as firewall rule sets, access control configurations, encryption settings, system logs and vulnerability scan results. Analytical evidence is produced by analyzing and comparing data, for example trend analysis of security incidents, reconciling user access lists with HR records, or comparing current results with previous periods to detect anomalies. Documentary evidence includes policies, procedures, the Statement of Applicability, risk treatment plans, records, contracts and meeting minutes. Auditors must verify that documents are approved, current and actually implemented. Verbal evidence is gathered through interviews with management and personnel. It is useful for understanding processes but is considered the least reliable on its own, so it should be corroborated by other evidence types. A competent auditor triangulates evidence from multiple sources, evaluates its reliability, independence and relevance, and records it properly in working papers. This ensures that audit conclusions are based on facts, consistent with the evidence-based approach principle of auditing, and reproducible by another auditor.
Types of Audit Evidence: A Complete Guide for ISO 27001 Lead Auditors
Introduction
Audit evidence is the foundation of every audit finding, conclusion and certification decision. In the context of ISO/IEC 27001 Lead Auditor training and exams, understanding the types of audit evidence is essential. It tells you how an auditor gathers proof, how strong that proof is, and whether it is sufficient to support a conformity or nonconformity statement. This guide explains why audit evidence matters, what it is, how it works in practice, and how to answer exam questions on the topic.
Why Types of Audit Evidence Are Important
1. Evidence-based approach: ISO 19011:2018 (Guidelines for auditing management systems) lists the evidence-based approach as one of the seven principles of auditing. It describes it as the rational method for reaching reliable and reproducible audit conclusions in a systematic audit process. Without evidence, an audit is only an opinion.
2. Credibility of findings: Every nonconformity raised must be traceable to objective evidence. Auditees, certification bodies and accreditation bodies can challenge findings that lack evidence.
3. Reproducibility: Another competent auditor reviewing the same evidence should reach the same conclusion. Verifiable evidence makes this possible.
4. Risk of wrong conclusions: Relying on weak evidence, such as hearsay or a single unverified statement, increases audit risk. That means certifying a non-conforming ISMS, or raising unjustified nonconformities.
5. Sampling decisions: Audits are performed on samples. The type and quality of evidence affects how much confidence the auditor can place in the sample.
6. Certification integrity: ISO/IEC 17021-1 and ISO/IEC 27006 require certification bodies to base certification decisions on sufficient and appropriate evidence.
What Audit Evidence Is
ISO 19011 and ISO 9000 define audit evidence as records, statements of fact or other information which are relevant to the audit criteria and verifiable.
Key elements of the definition:
- Relevant: It must relate to the audit criteria. These include ISO/IEC 27001 clauses, Annex A controls, the organization's own policies, and legal or contractual requirements.
- Verifiable: It must be possible to confirm it. Unverifiable information, such as rumours, assumptions or unconfirmed opinions, is not audit evidence.
- Qualitative or quantitative: Evidence may be descriptive or measurable.
Related terms you must distinguish:
- Audit criteria: The set of requirements used as a reference, against which evidence is compared.
- Objective evidence: Data supporting the existence or truth of something. It is obtained through observation, measurement, testing or other means.
- Audit findings: The results of evaluating the collected audit evidence against audit criteria. Findings can indicate conformity, nonconformity, or opportunities for improvement.
- Audit conclusion: The outcome of an audit, after considering the audit objectives and all audit findings.
The logical chain is: Audit Evidence + Audit Criteria → Audit Findings → Audit Conclusions.
The Main Types of Audit Evidence
Lead auditor courses (for example PECB, IRCA/CQI, BSI) commonly classify audit evidence into several types. The most widely taught classification includes the following.
1. Physical Evidence
Evidence obtained by direct observation or inspection of tangible things.
- Examples: locked server rooms, CCTV cameras installed, badge readers, fire suppression systems, clear desk compliance, shredders, labelled media, the visitor logbook being used at reception.
- Strength: Generally considered highly reliable, because the auditor sees it first-hand.
- Limitation: It shows the state at a point in time only. It does not prove the control operates consistently.
2. Documentary Evidence (Documents and Records)
Evidence obtained from documented information, whether paper or electronic.
- Documents describe what should happen. Examples: information security policy, Statement of Applicability (SoA), risk treatment plan, procedures, ISMS scope.
- Records prove what actually happened. Examples: access review logs, training records, incident reports, internal audit reports, management review minutes, backup logs, change tickets.
- Strength: Records are strong evidence of implementation and effectiveness, especially when generated by systems.
- Limitation: Documents alone prove intent, not implementation. Records may be incomplete or altered, so the auditor should verify authenticity.
3. Verbal / Testimonial Evidence (Interviews)
Evidence obtained from statements made by auditees during interviews.
- Examples: a system administrator explaining how user access is revoked; an employee describing how they would report a phishing email.
- Strength: Useful for understanding processes, awareness and culture. It also helps identify where to look for other evidence.
- Limitation: The weakest form on its own. Verbal statements should be corroborated by other evidence, such as records or observation. Statements from people with direct responsibility are more reliable than second-hand accounts.
4. Observational Evidence
Evidence obtained by watching activities and processes being performed. Some courses group this with physical evidence.
- Examples: observing a help desk employee verifying caller identity before a password reset; watching a visitor being escorted; observing a change advisory board meeting.
- Strength: Shows actual practice.
- Limitation: The observer effect: people may behave differently when watched.
5. Technical / Analytical Evidence (Testing, Re-performance, Analysis)
Evidence obtained by testing controls, re-performing activities, or analysing data.
- Examples: checking firewall rule sets; reviewing system configuration for password complexity; sampling terminated employees and confirming their accounts were disabled; analysing incident trends; reviewing vulnerability scan results.
- Strength: Very reliable, particularly when the auditor performs or witnesses the test.
- Limitation: Requires technical competence. It may need technical experts in the audit team.
6. Mathematical / Computational Evidence
Some syllabi list this as a separate type. It is evidence derived from calculations performed by the auditor.
- Examples: recalculating availability percentages; verifying that KPI figures in management review are computed correctly.
Summary of common classifications: Physical, Documentary, Verbal (Testimonial), Observational, Technical (Analytical), and Mathematical. In exams, the most frequently tested are physical, documentary, and verbal (interview) evidence. These correspond to the three classic methods of observation, document/record review, and interviews.
How Audit Evidence Works in Practice
Step 1 – Planning: The auditor reviews the ISMS documentation and risk profile. They identify which evidence will be needed for each clause and control, and prepare checklists or audit work documents.
Step 2 – Collecting information: ISO 19011 (Clause 6.4.7) describes collecting and verifying information by appropriate sampling. Methods include interviews, observation and review of documented information.
Step 3 – Verifying information: ISO 19011 states that only verifiable information can be audit evidence. The auditor corroborates information through triangulation. For example, the HR manager says leavers' access is removed within 24 hours (verbal). The auditor checks the joiner-mover-leaver procedure (document). They then sample leaver records against Active Directory disable dates (record/technical). Finally, they may observe the ticketing workflow (observation).
Step 4 – Recording: Evidence must be recorded precisely, so findings are traceable. Good notes capture document IDs and versions, record dates, names or roles of interviewees, sample sizes, locations and timestamps.
Step 5 – Evaluating against criteria: The evidence is compared with the audit criteria to generate findings: conformity, nonconformity (major or minor), or opportunity for improvement.
Step 6 – Reaching conclusions: The team reviews all findings to reach audit conclusions. These include the certification recommendation.
Qualities of Good Audit Evidence
Evidence should be:
- Sufficient: enough quantity, meaning an appropriate sample size and coverage.
- Appropriate: relevant to the criterion and reliable.
- Objective: factual, not opinion-based.
- Verifiable: can be confirmed.
- Reliable: from a trustworthy source.
Reliability hierarchy (general guidance):
- Evidence obtained directly by the auditor (observation, re-performance, testing) is more reliable than evidence obtained indirectly.
- Evidence from independent external sources is more reliable than internally generated evidence.
- Documentary or system-generated records are more reliable than verbal statements.
- Original documents are more reliable than copies.
- Evidence from systems with strong internal controls is more reliable than evidence from weakly controlled systems.
- Corroborated evidence from multiple sources is more reliable than a single source.
Sampling and Audit Evidence
Since audits cannot examine everything, auditors use sampling. ISO 19011 Annex A.6 describes two approaches:
- Judgement-based sampling: relies on the auditor's knowledge and experience.
- Statistical sampling: uses statistical methods to provide confidence levels.
Evidence based on a sample carries inherent uncertainty. The audit report should acknowledge this. Auditors also select samples to be representative, for example across time periods, sites, departments and risk levels.
Evidence for ISO 27001-Specific Requirements: Examples
- Clause 4.3 Scope: documented scope statement (documentary), plus interviews with top management (verbal).
- Clause 5.1 Leadership: management review minutes, resource approvals and policy sign-off (documentary), plus a top management interview (verbal).
- Clause 6.1.2 Risk assessment: risk methodology document, plus the risk register with dates and owners (records).
- Clause 7.2 Competence: training records and competence matrices (records).
- Clause 7.3 Awareness: interviews with staff on policy awareness (verbal), plus phishing simulation results (technical/records).
- Clause 9.2 Internal audit: audit programme, audit reports and corrective action records.
- Annex A 7.x Physical controls (ISO 27001:2022): on-site observation of secure areas (physical).
- Annex A 8.x Technological controls: system configuration reviews, logs and scan results (technical).
Common Pitfalls
- Accepting verbal assurances without verification.
- Treating a policy document as proof of implementation.
- Recording vague evidence, such as 'access control seems fine'.
- Using an unrepresentative sample.
- Including personal opinion or assumptions in findings.
- Failing to record the source and identifier of evidence.
Exam Tips: Answering Questions on Types of Audit Evidence
Tip 1 – Memorise the definition. Audit evidence is records, statements of fact or other information that are relevant to the audit criteria and verifiable. Many multiple-choice questions test the word verifiable. If an option includes unverifiable information, such as opinions, rumours or assumptions, it is not audit evidence.
Tip 2 – Know the chain. Evidence evaluated against criteria produces findings. Findings considered against audit objectives produce conclusions. Questions often try to confuse evidence with findings, or criteria with evidence.
Tip 3 – Classify scenario evidence correctly. When a question describes something, identify the type:
- Auditor saw the locked door: physical / observational.
- Auditor reviewed the access log: documentary (record).
- IT manager told the auditor backups run nightly: verbal / testimonial.
- Auditor checked firewall configuration: technical.
- Auditor recalculated the uptime percentage: mathematical / analytical.
Tip 4 – Know the reliability ranking. If asked which evidence is most reliable, choose evidence obtained directly by the auditor (observation, testing) or system-generated records. If asked which is least reliable, choose uncorroborated verbal statements, especially second-hand ones.
Tip 5 – Documents vs records. A policy or procedure shows the requirement is defined, not that it is implemented. To demonstrate implementation and effectiveness, the auditor needs records. Exam questions often ask what additional evidence is needed after reviewing a procedure. The answer is usually records, or observation of practice.
Tip 6 – Corroborate verbal evidence. In scenario questions where an auditee makes a claim, the correct auditor action is usually to seek corroborating evidence, such as requesting records or observing the activity. The wrong options are typically accepting the statement, or raising a nonconformity immediately.
Tip 7 – A nonconformity must be based on objective evidence. For essay or case-study exams (for example PECB), each nonconformity you write should include three parts:
(a) the requirement (clause or control);
(b) the evidence (what you saw, read or heard, with specifics);
(c) the statement of nonconformity (why the evidence fails to meet the requirement).
Be specific: 'Of 10 leavers sampled from January to March 2024, 3 still had active AD accounts on the audit date (records: HR leaver list v2, AD export dated 12/04/2024).'
Tip 8 – Absence of evidence. If no records exist to show a required activity was performed, that absence can itself support a nonconformity. Examples include no management review minutes, or no internal audit reports. Frame it as 'no evidence was available to demonstrate...'
Tip 9 – Link evidence to sampling. Remember that audit evidence is based on samples, which introduces uncertainty. Questions may ask why audit conclusions carry uncertainty. The answer is sampling and the limited time available.
Tip 10 – Remember the evidence-based approach principle. If a question asks which ISO 19011 principle relates to verifiable evidence and reliable, reproducible conclusions, the answer is the evidence-based approach. The other six principles are integrity, fair presentation, due professional care, confidentiality, independence and a risk-based approach.
Tip 11 – Watch for distractors. Typical wrong answers include:
- 'The auditor's personal experience is audit evidence.' This is false; experience informs judgement but is not evidence.
- 'Information from an anonymous source is sufficient evidence.' This is false unless verified.
- 'A documented procedure proves effective implementation.' This is false.
- 'Audit evidence must be quantitative.' This is false; it can be qualitative or quantitative.
Tip 12 – Use triangulation in case studies. When asked how you would audit a control, describe all three methods. Say whom you would interview, which documents and records you would review, and what you would observe or test. This shows a mature audit approach and scores highly with examiners.
Tip 13 – Respect confidentiality. Some evidence, such as personal data, classified information or security logs, may be restricted. The auditor may need to view it on site without taking copies. Exam questions may test whether an auditor should insist on removing sensitive evidence. Generally they should not; they should record references instead.
Quick Revision Summary
- Definition: relevant and verifiable records, statements of fact or other information.
- Main types: physical, documentary (documents and records), verbal/testimonial, observational, technical/analytical, mathematical.
- Collection methods: interviews, observation, review of documented information, and testing.
- Quality: sufficient, appropriate, objective, verifiable, reliable.
- Most reliable: direct auditor observation or testing, system records and external sources.
- Least reliable: uncorroborated verbal statements.
- Evidence plus criteria produces findings; findings plus objectives produce conclusions.
- Always corroborate, record specifics, and base every finding on objective evidence.
Mastering the types of audit evidence lets you plan effective audits, write defensible findings and confidently answer both multiple-choice and scenario-based questions in the ISO 27001 Lead Auditor exam.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!