Audit Criteria
In ISO/IEC 27001 auditing, audit criteria are the set of requirements used as a reference against which objective evidence is compared. ISO 19011 and ISO/IEC 17021-1 define them this way. They are the benchmark that lets an auditor decide whether a finding is a conformity or a nonconformity. Withou… In ISO/IEC 27001 auditing, audit criteria are the set of requirements used as a reference against which objective evidence is compared. ISO 19011 and ISO/IEC 17021-1 define them this way. They are the benchmark that lets an auditor decide whether a finding is a conformity or a nonconformity. Without clearly defined criteria, findings would be subjective opinions rather than verifiable conclusions. When preparing an ISO/IEC 27001 audit, the Lead Auditor must identify, confirm and document the criteria together with the audit objectives and scope. These three elements form the foundation of the audit plan. Typical criteria include: the requirements of ISO/IEC 27001 clauses 4 to 10, covering context, leadership, planning, support, operation, performance evaluation and improvement; the Annex A controls that the organization has declared applicable in its Statement of Applicability; and the organization's own ISMS documentation, such as the information security policy, risk assessment methodology, risk treatment plan and operational procedures. Applicable legal, regulatory and contractual obligations also count, for example data protection laws or customer security requirements. During preparation, the Lead Auditor reviews documented information to confirm that the criteria are clear, current and accessible. The auditor also checks whether the scope and criteria are consistent, and whether the audit is feasible within the time and resources available. The criteria are communicated to and agreed with the auditee, often during the pre-audit contact and in the audit plan. They are then translated into working documents such as checklists and sampling plans that guide evidence collection. Each audit finding should reference the specific criterion involved, such as clause 6.1.2 or control 5.15, so that it is traceable and defensible. Criteria must remain stable throughout the audit, and any change requires agreement with the audit client. Properly defined criteria ensure objectivity, consistency and repeatability. They also ensure fair evaluation and support credible certification decisions.
Audit Criteria in ISO/IEC 27001 Audits: The Reference Point for Every Audit Finding
Introduction
Every audit needs a benchmark. Without one, an auditor would only be giving personal opinions. In ISO/IEC 27001 auditing, that benchmark is called the audit criteria. When you prepare an ISO/IEC 27001 audit, defining the audit criteria is one of the first and most important tasks. Audit objectives, scope, the audit plan, evidence collection, findings and conclusions all depend on it.
This guide covers four things:
• What audit criteria are.
• Why they matter.
• How they work across the audit process.
• How to answer exam questions on the topic, as tested in ISO/IEC 27001 Lead Auditor certifications such as PECB, IRCA/CQI and similar schemes.
1. What Are Audit Criteria?
ISO 19011:2018 (Guidelines for auditing management systems) defines audit criteria as:
"Set of requirements used as a reference against which objective evidence is compared."
The standard adds two notes:
• If the audit criteria are legal requirements (including statutory or regulatory requirements), the words "compliance" or "non-compliance" are often used in an audit finding.
• Requirements can include policies, procedures, work instructions, legal requirements and contractual obligations.
Put simply, audit criteria answer the question: "What are we checking the organization against?"
Typical audit criteria in an ISO/IEC 27001 audit
• ISO/IEC 27001:2022 requirements: the mandatory clauses 4 to 10, which cover:
- Context of the organization.
- Leadership.
- Planning, including information security risk assessment and treatment.
- Support.
- Operation.
- Performance evaluation.
- Improvement.
• Annex A controls: those determined as applicable in the organization's Statement of Applicability (SoA).
• The organization's own ISMS documentation: for example:
- Information security policy.
- Topic-specific policies.
- Risk assessment methodology.
- Risk treatment plan.
- Procedures and work instructions.
• Legal, statutory and regulatory requirements: for example data protection laws such as GDPR, sector regulations and telecommunications laws.
• Contractual requirements: for example security clauses in customer agreements and service level agreements.
• Other requirements the organization has committed to: for example industry codes, customer security requirements or group policies.
What is usually NOT an audit criterion
• ISO/IEC 27002 is a guidance standard. It uses "should", not "shall". In a certification audit you cannot raise a nonconformity simply because the organization did not follow an ISO/IEC 27002 recommendation. You can still use it to understand control intent or to make an opportunity for improvement.
• The auditor's personal preferences, experience or idea of best practice.
• Practices of other organizations, such as "Company X does it better".
2. Why Are Audit Criteria Important?
• Objectivity: Criteria turn an audit from opinion into a systematic, evidence-based comparison. This supports the ISO 19011 principles of evidence-based approach and fair presentation.
• Basis for findings: ISO 19011 defines audit findings as the "results of the evaluation of the collected audit evidence against audit criteria". No criteria means no findings.
• Defensible nonconformities: A nonconformity is the non-fulfilment of a requirement. Every nonconformity must trace back to a specific requirement in the criteria, such as a clause, control, policy statement or legal article. If the auditor cannot cite the requirement, the nonconformity is not valid.
• Consistency and repeatability: Different auditors using the same criteria should reach similar conclusions. This matters in certification audits and multi-site audits.
• Planning and resourcing: Criteria determine the competence the audit team needs, such as legal knowledge, cloud security or OT security. They also determine the audit duration and the documents to review.
• Clear expectations for the auditee: The auditee knows in advance what it will be assessed against. This reduces disputes during the closing meeting.
• Credibility of certification: In third-party audits under ISO/IEC 17021-1 and ISO/IEC 27006-1, clearly defined criteria give stakeholders confidence in the certificate.
3. How Audit Criteria Work in the Audit Process
3.1 Relationship with audit objectives and audit scope
Audit criteria, objectives and scope are three separate but connected elements, defined together:
• Audit objectives: why the audit is conducted. Example: to determine the conformity of the ISMS with ISO/IEC 27001 and its effectiveness in meeting its objectives.
• Audit scope: where and what is covered, i.e. the extent and boundaries. Examples: locations, departments, processes, activities and time period.
• Audit criteria: against what the evidence is compared.
A useful memory aid: Objectives = Why, Scope = Where/What/When, Criteria = Against what.
3.2 Defining audit criteria at the audit programme level
ISO 19011 clause 5.5.3 says the audit programme manager should determine the objectives, scope and criteria for each individual audit. This should be consistent with the overall audit programme objectives. Criteria should be agreed with the audit client and communicated to the auditee.
3.3 Feasibility of the audit
When starting an audit (ISO 19011 clause 6.2.3), the audit team leader checks whether the audit is feasible. One factor is whether there is sufficient and appropriate information for planning, including clarity of the audit criteria. If the criteria are unclear, contradictory or cannot be verified, the team leader should raise this with the audit client before continuing.
3.4 Including criteria in the audit plan
The audit plan should state the audit objectives, scope and criteria, along with any reference documents (ISO 19011 clause 6.3.2). The criteria are also confirmed at the opening meeting.
3.5 Document review (Stage 1 audit)
In a certification audit, the Stage 1 audit checks whether the organization's documented information addresses the requirements of ISO/IEC 27001. It also confirms the criteria that will apply in Stage 2. Typical activities:
• Reviewing the SoA to confirm which Annex A controls are applicable.
• Reviewing the justification for any excluded controls.
• Identifying the legal and contractual requirements the organization has listed.
3.6 Collecting evidence and generating findings (Stage 2 and surveillance audits)
The core audit logic is:
Audit evidence + Audit criteria → Audit findings → Audit conclusion
• Audit evidence: records, statements of fact or other information relevant to the audit criteria and verifiable.
• Audit findings: conformity, nonconformity or opportunity for improvement.
• Audit conclusion: the outcome of the audit, after considering the audit objectives and all audit findings.
Example
• Criterion: ISO/IEC 27001:2022 clause 9.2 requires the organization to conduct internal audits at planned intervals. Separately, the organization's Internal Audit Procedure states that all ISMS processes shall be audited at least once a year.
• Evidence: The audit programme and audit reports show that the HR security and supplier management processes have not been audited for 20 months.
• Finding: Nonconformity against clause 9.2 and the organization's Internal Audit Procedure.
3.7 Writing a nonconformity statement
A good nonconformity report has three elements:
• Requirement (criterion): what should be happening, with a specific reference.
• Evidence: what was observed, factual and verifiable.
• Statement of nonconformity: why the evidence does not meet the requirement.
If you cannot write the requirement part, you do not have a nonconformity.
3.8 Audit criteria in different audit types
• First-party (internal) audits: Criteria often include ISO/IEC 27001, internal policies and procedures, and management-defined objectives.
• Second-party (supplier) audits: Criteria often include contractual security clauses, customer security requirements and sometimes ISO/IEC 27001.
• Third-party (certification) audits: Criteria are mainly ISO/IEC 27001 requirements, plus the organization's documented ISMS and the legal, regulatory and contractual requirements it has identified. Certification bodies follow ISO/IEC 17021-1 and ISO/IEC 27006-1.
3.9 Special considerations for Annex A
• Clause 6.1.3 requires organizations to compare their necessary controls with Annex A and to produce an SoA with justification for inclusions and exclusions.
• An organization is not automatically nonconforming because it excluded an Annex A control.
• An exclusion becomes a nonconformity when it is not justified. Example: the risk assessment shows a risk that requires that control, but the control was excluded.
• Once a control is declared applicable and implemented, both the control and the organization's own description of its implementation become audit criteria.
4. Common Mistakes Related to Audit Criteria
• Confusing audit criteria with audit evidence. A policy document is a criterion when its requirements are the reference, and evidence when you check whether the policy exists and is approved.
• Treating ISO/IEC 27002 guidance as mandatory requirements in a certification audit.
• Raising nonconformities based on the auditor's opinion or on best practice.
• Confusing audit scope (boundaries) with audit criteria (requirements).
• Failing to confirm the criteria before the audit, which leads to disputes at the closing meeting.
• Ignoring legal and contractual requirements that the organization committed to under clause 4.2.
5. Exam Tips: Answering Questions on Audit Criteria
Tip 1: Memorize the definition word for word.
"Set of requirements used as a reference against which objective evidence is compared" (ISO 19011:2018, 3.7). Many multiple-choice distractors use the older wording ("policies, procedures or requirements") or confuse criteria with evidence or findings.
Tip 2: Know the chain: Criteria → Evidence → Findings → Conclusions.
Exams often test whether you can place each term correctly. Remember:
• Findings come from comparing evidence against criteria.
• Conclusions come from findings plus objectives.
Tip 3: Distinguish objectives, scope and criteria.
If a question asks which statement describes the audit criteria, look for the option that names requirements or reference documents, such as "ISO/IEC 27001:2022 and the organization's information security policy". Do not pick options describing locations, processes or time periods (scope) or purposes (objectives).
Tip 4: Check "shall" versus "should".
When a scenario describes an organization not following an ISO/IEC 27002 recommendation, the correct answer is usually not a nonconformity. It may be an opportunity for improvement, or an issue only if the organization's own policy or risk treatment requires it.
Tip 5: Always trace the requirement in scenario questions.
When asked whether a situation is a nonconformity, ask yourself: "Which requirement is not fulfilled?" Name the specific clause (e.g. 6.1.2, 7.2, 9.2), Annex A control (e.g. A.5.15 Access control, A.8.13 Information backup), policy or legal requirement. In essay-style exams, citing the exact criterion earns marks.
Tip 6: Remember the organization's own documentation is a criterion.
If the organization's procedure says "passwords shall be changed every 60 days" and evidence shows 120 days, that is a nonconformity against the organization's own requirement. This holds even though ISO/IEC 27001 does not prescribe a password change period.
Tip 7: Consider legal and contractual requirements.
Clause 4.2 requires the organization to determine the requirements of interested parties, including legal, regulatory and contractual ones. If a scenario mentions a data breach notification law or a customer contract clause, recognize it as a potential audit criterion.
Tip 8: Know who determines and agrees the criteria.
The audit programme manager determines the criteria for each audit, in consultation with the audit client. The audit team leader confirms the criteria and checks feasibility. If criteria are unclear, the auditor seeks clarification before the audit rather than inventing them.
Tip 9: Handle SoA and exclusion questions carefully.
An excluded Annex A control is a nonconformity only when the exclusion is unjustified or contradicts the risk assessment results. Look for scenario details that link a risk to an excluded control.
Tip 10: Use a structured answer in essay or open-ended questions.
A strong answer format is:
• (1) State the relevant audit criterion with its reference.
• (2) Describe the objective evidence.
• (3) Compare the evidence against the criterion.
• (4) State the finding: conformity, minor or major nonconformity, or opportunity for improvement.
• (5) Justify the grading where required.
This shows the examiner you understand that every finding depends on criteria.
Tip 11: Watch for traps involving auditor opinion.
Some answer options sound reasonable but rely on what the auditor thinks is good practice. Under the principles of integrity, fair presentation and evidence-based approach, the auditor must stick to the agreed criteria.
Tip 12: Link criteria to the audit plan and opening meeting.
If a question asks where the audit criteria are documented or confirmed, the answer is:
• The audit plan, which includes objectives, scope and criteria.
• Confirmation at the opening meeting.
• The audit report, which also states the criteria used.
6. Quick Revision Summary
• Definition: a set of requirements used as a reference against which objective evidence is compared (ISO 19011:2018).
• Typical sources:
- ISO/IEC 27001 clauses 4 to 10.
- Applicable Annex A controls per the SoA.
- ISMS policies and procedures.
- Legal, regulatory and contractual requirements.
• Not criteria for nonconformities: ISO/IEC 27002 guidance, auditor opinion, other organizations' practices.
• Purpose: objectivity, traceable findings, consistency, planning, credibility.
• Where they appear: audit programme, audit plan, opening meeting, audit report.
• Key logic: Evidence compared with Criteria gives Findings; Findings plus Objectives give Conclusions.
• Golden rule: no requirement, no nonconformity.
Master this concept and you will have a solid foundation for audit planning, evidence evaluation and nonconformity reporting, both in the exam and in real ISO/IEC 27001 audits.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!