Audit Follow-Up and Verification of Corrective Actions
Audit follow-up and verification of corrective actions is the final stage of the audit process, described in ISO 19011 clause 6.6. It ensures that identified nonconformities are actually resolved, not merely documented. Under ISO/IEC 27001 clause 10.2, the auditee organization must react to each no… Audit follow-up and verification of corrective actions is the final stage of the audit process, described in ISO 19011 clause 6.6. It ensures that identified nonconformities are actually resolved, not merely documented. Under ISO/IEC 27001 clause 10.2, the auditee organization must react to each nonconformity by controlling and correcting it and dealing with its consequences. It must then evaluate the need to eliminate root causes, implement corrective actions, review their effectiveness and update the ISMS where necessary. The auditor does not prescribe solutions, which preserves independence and objectivity. After the closing meeting, the auditee typically submits a corrective action plan within an agreed timeframe. A robust plan distinguishes correction, which is the immediate fix of the symptom, from corrective action, which eliminates the root cause. It should include root cause analysis using techniques such as the five whys or fishbone diagrams, together with assigned responsibilities, resources and target dates. The Lead Auditor or audit team first evaluates the plan for adequacy, then verifies its implementation and effectiveness. The verification method depends on the severity of the finding. Minor nonconformities may be verified through documentary evidence, such as updated procedures, training records or system logs, or at the next scheduled audit. Major nonconformities usually require an on-site or remote follow-up audit before certification can be granted or maintained, in line with ISO/IEC 27006 requirements for certification bodies. Effectiveness is confirmed when evidence shows that the issue has not recurred and the related control operates as intended. From an audit programme management perspective, the programme manager tracks the status of all findings, monitors deadlines and escalates overdue actions. Trends in recurring nonconformities are used to adjust audit scope, frequency and risk focus. Results feed into management review under clause 9.3 and drive continual improvement under clause 10.1. A finding is formally closed only when objective evidence demonstrates both implementation and effectiveness. This completes the audit cycle and strengthens the organization's information security posture.
Audit Follow-Up and Verification of Corrective Actions (ISO/IEC 27001 Lead Auditor)
Introduction
Audit follow-up and verification of corrective actions is the final, and often underestimated, phase of the audit lifecycle in an ISO/IEC 27001 audit program. An audit that identifies nonconformities but never confirms whether they were resolved adds little value. This guide explains why follow-up matters, what it involves, how it works in practice under ISO 19011 and ISO/IEC 17021-1 (and ISO/IEC 27006 for certification of ISMS), and how to answer exam questions on the topic.
1. Why Audit Follow-Up Is Important
• Closes the improvement loop: ISO/IEC 27001 is built on the Plan-Do-Check-Act (PDCA) cycle. Auditing is the 'Check' step. Corrective action and its verification are the 'Act' step. Without follow-up, the cycle is broken.
• Supports Clause 10.1 (Nonconformity and corrective action) of ISO/IEC 27001:2022: the organization must react to nonconformities, evaluate the need to eliminate their causes, implement actions, review their effectiveness, and keep documented information as evidence. The auditor checks that this happened.
• Protects certification integrity: certification bodies cannot grant or maintain certification while major nonconformities remain open. Verification gives confidence to stakeholders that the certificate is meaningful.
• Reduces information security risk: nonconformities often reflect weak controls such as access management, backups or supplier security. Leaving them unresolved leaves real exposure.
• Feeds the audit program: results of follow-up inform risk-based planning of future audits, as required by ISO 19011 Clause 5.
• Demonstrates auditor competence and objectivity: a lead auditor must show that conclusions are based on objective evidence, not on promises made by the auditee.
2. What It Is
Audit follow-up is the set of activities conducted after the audit report is issued. These activities confirm that the auditee has addressed audit findings, typically nonconformities, through correction and corrective action.
Key definitions (ISO/IEC 27000 and ISO 9000 vocabulary):
• Nonconformity: non-fulfilment of a requirement.
• Correction: action to eliminate a detected nonconformity (fixing the immediate problem). Example: revoking access for a user who left the company.
• Corrective action: action to eliminate the cause of a nonconformity and to prevent recurrence. Example: redesigning the leaver process so HR automatically notifies IT.
• Root cause analysis: systematic identification of the underlying reason for the nonconformity, using tools such as 5 Whys, Ishikawa diagrams or fault tree analysis.
• Effectiveness: the extent to which planned activities are realized and planned results achieved. In other words, did the action actually prevent recurrence?
Important principle: ISO 19011 Clause 6.7 states that the audit conclusions may indicate the need for corrections, corrective actions or opportunities for improvement. Such actions are usually decided and undertaken by the auditee within an agreed timeframe. They are not considered part of the audit. The auditee keeps the person managing the audit program and/or the audit team informed of the status of these actions. The completion and effectiveness of the actions should be verified, and this verification may be part of a subsequent audit.
3. How It Works: The Follow-Up Process
Step 1: Reporting the findings
• Nonconformities are graded, typically as major or minor in certification audits.
• A major nonconformity is the absence of, or total breakdown of, a system or requirement. It can also be a situation that raises significant doubt about the ISMS achieving its intended outcomes, or several minor nonconformities on the same requirement that together show a systemic failure.
• A minor nonconformity is an isolated lapse that does not affect the capability of the ISMS to achieve its intended results.
• Opportunities for improvement (OFIs) or observations are noted but do not require formal corrective action.
Step 2: Auditee prepares an action plan
• The auditee analyses the extent and root cause of each nonconformity.
• The auditee then submits a corrective action plan containing the correction, the root cause, the corrective action, responsibilities and target dates.
• In certification audits, the certification body defines timeframes. Typical practice is that the action plan is submitted within around 30 days. Majors are usually expected to be corrected and verified within about 90 days, or before the certification decision.
Step 3: Auditor reviews and accepts the plan
• The auditor evaluates whether the root cause analysis is credible.
• The auditor checks whether the proposed actions address the cause, not just the symptom, and whether the timescales are realistic.
• The auditor does not prescribe the solution. Advising on specific solutions would compromise independence and could be treated as consultancy.
Step 4: Verification of implementation and effectiveness
Verification can be performed in several ways, depending on the significance of the nonconformity:
• Documentary review (off-site / desk review): commonly used for minor nonconformities. Evidence might include updated procedures, training records, screenshots or logs.
• Follow-up audit (on-site or remote): commonly required for major nonconformities, where implementation must be observed in practice.
• Verification at the next scheduled audit: often used for minor nonconformities, where the plan was accepted and implementation is checked at the next surveillance audit.
The auditor verifies two things:
• Implementation: was the action actually carried out as planned?
• Effectiveness: has the action eliminated the cause, so that the nonconformity does not recur? Evidence of effectiveness often needs records over a period of time, for example several months of access reviews.
Step 5: Closing or escalating
• If the evidence is satisfactory, the nonconformity is closed and the closure is recorded.
• If it is not satisfactory, the nonconformity remains open. Possible consequences include:
• a further follow-up;
• escalation of a minor to a major nonconformity if it is not addressed or has recurred;
• in certification contexts, delay of initial certification, suspension, scope reduction or withdrawal of certification.
Step 6: Feedback into the audit program
• The audit program manager reviews follow-up outcomes as part of monitoring and reviewing the audit program (ISO 19011 Clauses 5.6 and 5.7).
• Recurring issues or ineffective actions may lead to increased audit frequency, a larger sample size or focus areas in future audits.
4. Roles and Responsibilities
• Auditee: owns the nonconformity. The auditee performs root cause analysis, plans and implements the correction and corrective action, and evaluates effectiveness internally.
• Audit team / lead auditor: reviews the action plan, verifies the evidence, and decides whether the nonconformity can be closed. The audit team stays objective and does not design solutions.
• Audit program manager: ensures follow-up is scheduled and tracked, keeps records, and uses results to improve the program.
• Certification body decision-maker: in third-party audits, considers the status of corrective actions before granting, maintaining or renewing certification.
5. First, Second and Third-Party Context
• Internal audits (first-party): follow-up is required under ISO/IEC 27001 Clause 9.2 and Clause 10.1. Management review (Clause 9.3) considers the status of actions from previous reviews and the nonconformities and corrective actions.
• Supplier audits (second-party): follow-up is driven by contractual requirements.
• Certification audits (third-party):
• For Stage 2 major nonconformities, ISO/IEC 17021-1 requires the certification body to review and accept corrections and corrective actions before certification is granted.
• For minor nonconformities, the certification body requires the client to submit a plan and reviews it. Implementation may be verified at the next audit.
6. Records and Documented Information
The following should be retained as documented information:
• Nonconformity reports
• Root cause analyses
• Action plans
• Verification evidence
• Closure statements
Two requirements drive this:
• ISO/IEC 27001 Clause 10.1 requires documented information on the nature of nonconformities, the actions taken, and the results of corrective action.
• ISO 19011 requires that audit program records demonstrate follow-up.
7. Common Pitfalls Auditors Must Avoid
• Accepting a correction (a fix) as if it were a corrective action (cause removal).
• Accepting 'retraining the staff' or 'human error' as a root cause without deeper analysis.
• Closing nonconformities based on verbal assurances without objective evidence.
• Writing the corrective action for the auditee, which compromises independence.
• Verifying implementation but not effectiveness.
• Failing to check whether similar nonconformities exist elsewhere (extent of the problem).
Exam Tips: Answering Questions on Audit Follow-Up and Verification of Corrective Actions
Tip 1: Know who does what.
The auditee decides on and implements actions. The auditor verifies them. If an answer option has the auditor designing or implementing the corrective action, it is almost always wrong.
Tip 2: Distinguish correction from corrective action.
Exam scenarios often describe an immediate fix and ask whether the nonconformity can be closed. A correction alone is insufficient if the root cause has not been addressed.
Tip 3: Remember that follow-up is not part of the audit itself.
ISO 19011 states that actions are not considered part of the audit. Verification may, however, be part of a subsequent audit. Questions may test this subtle point.
Tip 4: Match the verification method to severity.
• Major nonconformities generally require stronger verification, such as on-site or follow-up audits, before certification can be granted or continued.
• Minor nonconformities typically require an accepted action plan, with verification at the next audit or via document review.
Tip 5: Always look for objective evidence.
The correct answer usually involves reviewing records, observing practice, sampling or interviewing. Accepting a statement, an email promise or management assurance is usually wrong.
Tip 6: Implementation versus effectiveness.
If a question asks what the auditor should verify, the best answer includes both. Remember that effectiveness may need evidence over time.
Tip 7: Know the consequences of unresolved nonconformities.
Possible consequences include:
• escalation from minor to major;
• delayed certification;
• suspension or withdrawal of certification;
• increased audit frequency in the audit program.
Tip 8: Link to ISO/IEC 27001 clauses.
Clause 10.1 covers nonconformity and corrective action. Clause 9.2 covers internal audit. Clause 9.3 covers management review, which includes follow-up of previous actions and nonconformities. Scenario questions often expect you to cite or recognise these.
Tip 9: Watch for independence traps.
The auditor may explain the requirement or clarify the finding. The auditor must not recommend a specific product, procedure or consultancy service. This is particularly important for certification body auditors under ISO/IEC 17021-1.
Tip 10: Use structured answers in essay or scenario questions.
A strong answer:
• identifies the finding and its grade;
• states the auditee's responsibility (correction, root cause, corrective action, timeframe);
• describes the auditor's review of the plan;
• specifies the verification method and evidence;
• explains how closure is recorded;
• notes how results feed back into the audit program.
Tip 11: Be alert to recurrence.
If a scenario shows that a previously closed nonconformity has reappeared, the correct interpretation is usually that the earlier corrective action was ineffective. This often justifies raising a new nonconformity against Clause 10.1 as well.
Tip 12: Avoid absolutes unless the standard states them.
Specific timeframes, such as 30 or 90 days, are certification body practices, not ISO/IEC 27001 requirements. In the exam, prefer answers stating 'within an agreed timeframe' or 'as defined by the audit program or certification body rules'.
Summary
Audit follow-up turns audit findings into real improvement. The auditee owns the problem and the solution. The auditor objectively verifies that actions were implemented and are effective, using evidence proportionate to the severity of the finding. The audit program manager tracks outcomes and adjusts future audits accordingly. Mastering these distinctions will help you answer exam questions confidently and perform as a competent ISO/IEC 27001 Lead Auditor.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!