Audit Feasibility
In ISO/IEC 27001 auditing, audit feasibility is the assessment made before the audit to confirm whether it can realistically meet its objectives. ISO 19011:2018 (clause 6.2.3) states that feasibility should be determined to give reasonable confidence that the audit objectives can be achieved. The a… In ISO/IEC 27001 auditing, audit feasibility is the assessment made before the audit to confirm whether it can realistically meet its objectives. ISO 19011:2018 (clause 6.2.3) states that feasibility should be determined to give reasonable confidence that the audit objectives can be achieved. The audit team leader carries out this assessment while preparing the audit, after the objectives, scope and criteria have been defined and initial contact with the auditee has been made. The assessment considers three main factors. First, there must be sufficient and appropriate information for planning and conducting the audit, such as the ISMS scope, the information security policy, the risk assessment and treatment results, the Statement of Applicability and records of internal audits and management reviews. Second, the auditee must cooperate adequately by granting access to sites, personnel, systems and evidence. Third, there must be adequate time and resources, including competent auditors and technical experts, travel arrangements and, for remote audits, reliable information and communication technology. For information security audits, ISO/IEC 27007 also highlights some specific concerns. The auditee may restrict access to confidential or classified information, which could limit the evidence available. Legal and regulatory constraints, safety and security rules on site, language barriers and complex or outsourced processes can also affect the audit. In certification audits, the auditor must also check that the ISMS has been operating long enough to produce objective evidence of its effectiveness. If the audit is found not to be feasible, the team leader should propose alternatives to the audit client after consulting the auditee. Options include changing the scope or objectives, rescheduling, adding resources or experts, or postponing the audit until the ISMS is mature enough. The reasons for the decision should be documented. When feasibility is confirmed, the auditor can proceed with the document review, the audit plan and the assignment of work to the audit team. A feasibility check reduces the risk of inconclusive results, wasted effort and disputes with the auditee, and it supports an audit that is credible, efficient and evidence-based.
Audit Feasibility in ISO/IEC 27001 Audits: A Complete Guide for Lead Auditors
Introduction
Before an ISO/IEC 27001 audit is planned in detail, the audit team leader (and, for certification, the certification body) must first answer one basic question: can this audit actually achieve its objectives? This is audit feasibility. It is one of the first activities in the preparation phase. It is described in ISO 19011:2018, clause 6.2.3 (Determining the feasibility of the audit) and is reinforced for certification audits by ISO/IEC 17021-1 (application review) and ISO/IEC 27006-1.
1. What Is Audit Feasibility?
Audit feasibility is the process of checking whether there is reasonable confidence that the audit objectives can be achieved before committing to the audit. According to ISO 19011, the feasibility determination should consider the availability of:
• Sufficient and appropriate information for planning and conducting the audit.
• Adequate cooperation from the auditee.
• Adequate time and resources for conducting the audit.
Feasibility follows establishing initial contact with the auditee (clause 6.2.2). It comes before preparing the audit plan, assigning work to the team, and reviewing documented information in detail.
2. Why Is Audit Feasibility Important?
• Protects audit credibility: An audit that cannot gather enough objective evidence produces unreliable conclusions. In a certification context, this could lead to wrongly granting or refusing certification.
• Prevents wasted effort and cost: Problems such as unavailable personnel, a missing Statement of Applicability, or restricted site access are found early, not on audit day.
• Supports the principle of evidence-based approach: Conclusions must rest on verifiable evidence. If evidence cannot be accessed, the audit cannot be valid.
• Manages risk to the audit programme: ISO 19011 takes a risk-based approach. Feasibility is a key point where audit risks are identified and treated.
• Addresses confidentiality issues specific to ISMS audits: Information security audits often involve sensitive data. The auditee may refuse access to some records, so feasibility must confirm that the ISMS can still be adequately audited.
• Maintains impartiality and professionalism: Accepting an audit that cannot be properly performed is a poor professional practice. It may also breach accreditation requirements.
3. How Audit Feasibility Works
Step 1: Gather initial information
Through initial contact (and, for certification, the application form), the auditor obtains:
• The ISMS scope, sites, number of employees and shifts.
• Processes, activities and technologies, including cloud services and outsourced processes.
• Legal, regulatory and contractual requirements.
• Key documented information, such as the ISMS scope statement, risk assessment, risk treatment plan and Statement of Applicability.
• Contact persons, languages used, and any special conditions such as security clearances, health and safety rules, or restricted areas.
Step 2: Assess information availability
• Is the documented information available in time and in sufficient detail?
• Under ISO/IEC 27006-1, the certification body asks the client to report any ISMS-related information that cannot be made available for review because it is confidential or sensitive. Examples include records, control effectiveness information and incident reports.
• The certification body then determines whether the ISMS can be adequately audited in the absence of that information. If not, the audit cannot proceed until suitable access arrangements are agreed. Possible arrangements include on-site viewing only, redacted records, or access through a cleared auditor.
Step 3: Assess auditee cooperation
• Will top management and process owners be available?
• Will the auditee grant access to sites, systems, records and people?
• Is the management system mature enough to be audited? For example, have internal audit and management review been performed before a Stage 2 audit?
Step 4: Assess time and resources
• Is the audit duration sufficient? For certification, duration is calculated using the IAF MD 5 and ISO/IEC 27006-1 rules on effective employees and complexity factors.
• Are competent auditors available, with the right technical knowledge (for example cloud, OT or cryptography), language skills, and freedom from conflicts of interest?
• Are technical experts, interpreters or guides needed?
• Are tools for remote auditing available and secure?
Step 5: Consider other factors affecting feasibility
• Travel restrictions, safety and security risks at sites, political instability, pandemics.
• Legal restrictions on data access or data transfer across borders.
• Multi-site sampling constraints.
• Timing issues, such as audits during peak business periods or system migrations.
Step 6: Decide and act
Possible outcomes include:
• Feasible: Proceed to audit planning.
• Feasible with adjustments: For example, extend the duration, add a technical expert, use remote techniques, change the dates, or agree special access arrangements for confidential information.
• Not feasible: ISO 19011 states that when the audit is not feasible, an alternative should be proposed to the audit client, in agreement with the auditee. Alternatives include postponing, changing the objectives or scope, or changing the audit method. In certification, the body may decline the application or delay the Stage 1 or Stage 2 audit.
Step 7: Keep monitoring
Feasibility is not a one-time check. If conditions change during preparation or the audit itself, the audit team leader re-evaluates feasibility. Examples include key personnel becoming unavailable, evidence being withheld, or a major incident occurring. The team leader then reports obstacles to the audit client and, where appropriate, to the person managing the audit programme. This ties to ISO 19011 clause 6.4.4, which covers communicating evidence of risk and problems during the audit.
4. Who Is Responsible?
• Audit programme manager or certification body: Performs the overall feasibility check during application review and audit programme establishment.
• Audit team leader: Confirms feasibility for the specific audit during preparation and communicates issues.
• Audit client and auditee: Provide information and cooperation. They are informed of, and agree to, any alternatives.
5. Practical Examples
• A bank refuses to show its risk assessment details to external auditors. The certification body must decide whether alternative evidence or on-site viewing is enough. If it is not, the audit is not feasible as proposed.
• An organization requests a Stage 2 audit but has not yet completed an internal audit or management review. The audit is not feasible at this time, so it should be postponed.
• A data center site requires security clearance that no assigned auditor holds. Possible solutions are assigning a cleared auditor, using a technical expert, or changing the dates.
• The audit duration calculated for 800 employees and three sites cannot be met with the client's requested two days. The duration must be adjusted, or the audit is not feasible.
6. Common Misconceptions
• Feasibility is not the same as the Stage 1 audit. Stage 1 evaluates the readiness of the ISMS. Feasibility comes earlier and decides whether the audit can be conducted at all.
• Feasibility is not about whether the auditee will pass. It is about whether the auditor can collect enough evidence to reach a valid conclusion.
• An infeasible audit is not simply cancelled without discussion. Alternatives should be proposed to the audit client in consultation with the auditee.
Exam Tips: Answering Questions on Audit Feasibility
• Memorize the three ISO 19011 feasibility factors: sufficient and appropriate information, adequate cooperation from the auditee, and adequate time and resources. Many questions are built directly around these.
• Know the sequence: initial contact, then feasibility, then audit planning. If a question asks what to do before preparing the audit plan, feasibility is usually the answer.
• Know the response when an audit is not feasible: propose an alternative to the audit client in agreement with the auditee. Do not proceed anyway, and do not cancel unilaterally.
• Watch for confidentiality scenarios: If the auditee withholds sensitive ISMS information, the correct answer usually involves determining whether the ISMS can be adequately audited without it (ISO/IEC 27006-1). Possible arrangements include on-site review, redaction, or a postponement.
• Distinguish feasibility from readiness: Questions about whether the ISMS is ready for Stage 2 relate to the Stage 1 audit. Questions about whether the audit can be conducted at all relate to feasibility.
• In scenario questions, justify with evidence: In essay-style exams (for example PECB), identify the specific obstacle, link it to the relevant feasibility factor, cite the standard (ISO 19011 6.2.3 or ISO/IEC 27006-1), and propose a practical solution. Example solutions are adding a technical expert, extending the duration, using remote audit methods, or rescheduling.
• Remember that feasibility is ongoing: If a scenario describes obstacles arising during the audit, the team leader should reassess feasibility and report to the audit client and the audit programme manager.
• Eliminate extreme answers: Options such as issuing a nonconformity because the auditee refused information before the audit, or certifying anyway, are usually wrong. Prefer answers showing communication, risk assessment and agreed alternatives.
• Use the right terminology: reasonable confidence, audit objectives, audit client, auditee, audit programme, objective evidence. Precise wording earns marks.
• Link feasibility to risk-based thinking: Explaining that feasibility is a way to address risks to achieving the audit objectives shows deeper understanding.
Summary
Audit feasibility is the early checkpoint that ensures an ISO/IEC 27001 audit can deliver valid, evidence-based conclusions. It examines information availability, auditee cooperation, and time and resources. It also addresses ISMS-specific issues such as confidential information and the technical competence of auditors. When obstacles exist, alternatives are agreed with the audit client and auditee. Mastering this concept helps you plan real audits professionally and answer exam questions with confidence.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!