Audit Plan Preparation
Audit plan preparation is a critical step in preparing an ISO/IEC 27001 audit. It turns the audit program into a practical, time-bound roadmap for a specific audit. Guided by ISO 19011 and, for certification audits, ISO/IEC 27006, the audit team leader develops the plan after reviewing the auditee'… Audit plan preparation is a critical step in preparing an ISO/IEC 27001 audit. It turns the audit program into a practical, time-bound roadmap for a specific audit. Guided by ISO 19011 and, for certification audits, ISO/IEC 27006, the audit team leader develops the plan after reviewing the auditee's documented information. This information typically includes the ISMS scope, information security policy, risk assessment and treatment methodology, Statement of Applicability (SoA), and results from previous audits or the Stage 1 review. A well-structured audit plan typically defines: (1) audit objectives, such as determining ISMS conformity with ISO/IEC 27001 requirements and evaluating its effectiveness; (2) audit scope, including organizational units, processes, physical locations, and the Annex A controls covered; (3) audit criteria, such as ISO/IEC 27001 clauses, legal and contractual requirements, and internal policies; (4) dates, times, and duration of activities, including opening and closing meetings; (5) audit methods, such as interviews, observation, document review, technical verification, and sampling techniques; (6) roles and responsibilities of team members, technical experts, and guides; (7) the resources needed; and (8) arrangements for confidentiality, reporting, and follow-up. The plan should be risk-based. Audit time and focus should go to the areas with the greatest information security risks, significant changes, critical processes, or past nonconformities. Lead auditors should also consider remote auditing, multi-site sampling, and the availability of key personnel. The plan is shared with the auditee in advance so that it can raise any objections and prepare resources. Any disputes are resolved before the audit begins. The plan must also remain flexible, allowing adjustments as audit evidence emerges during fieldwork. Finally, the team leader uses the plan to assign tasks and prepare work documents such as checklists and sampling plans. Effective audit plan preparation ensures that the audit is efficient, objective, and consistent, and that it delivers reliable conclusions about the organization's ISMS.
Audit Plan Preparation in ISO/IEC 27001 Lead Auditing: A Complete Guide with Exam Tips
Introduction
Audit plan preparation is one of the most important activities in the Preparing an ISO/IEC 27001 Audit phase of the lead auditor body of knowledge. Before any opening meeting is held or any evidence is collected, the audit team leader must produce a clear, realistic and agreed audit plan. This guide explains what the audit plan is, why it matters, how it is prepared according to ISO 19011 and ISO/IEC 17021-1 (with ISO/IEC 27006 for ISMS certification), and how to answer exam questions on the topic.
1. What Is an Audit Plan?
An audit plan is a description of the activities and arrangements for an audit (ISO 19011, clause 3.6). It is different from the audit programme.
• Audit programme: a set of one or more audits planned for a specific time frame and directed towards a specific purpose. An example is the three-year certification cycle (Stage 1, Stage 2, surveillance audits and recertification).
• Audit plan: the detailed plan for a single audit, prepared by the audit team leader.
The audit plan turns the audit programme's requirements into a practical schedule. It tells the auditee and the audit team what will be audited, when, where, how and by whom.
2. Why Is Audit Plan Preparation Important?
• Ensures the audit objectives are achieved. It aligns activities with the audit objectives, scope and criteria.
• Provides coverage of the ISMS. It covers clauses 4 to 10 of ISO/IEC 27001 and the relevant Annex A controls, based on the Statement of Applicability (SoA).
• Supports a risk-based approach. ISO 19011 Principle (f) and clause 5.3 require planning to consider risks and opportunities. These include risks to achieving the audit objectives as well as the auditee's information security risks.
• Enables efficient use of resources. It allocates auditors, technical experts, guides and time effectively.
• Facilitates communication and agreement. The plan is presented to the auditee so they can make personnel, facilities and records available. It also lets them raise objections before the audit starts.
• Demonstrates professionalism and impartiality. A well-structured plan shows a systematic, evidence-based approach and reduces surprises or conflicts.
• Provides a basis for managing change. When circumstances change, the plan is the reference point for agreed revisions.
3. Inputs to the Audit Plan
The audit team leader uses information from several sources:
• The audit programme and the documented information from the person managing the audit programme.
• Audit objectives, scope and criteria.
• Results of the Stage 1 audit (for certification), including the ISMS documentation review and readiness assessment.
• The auditee's context: size, complexity, number of sites, processes, technologies, outsourced processes, legal and regulatory requirements.
• The Statement of Applicability, the risk assessment and the risk treatment plan.
• Previous audit results, nonconformities and corrective actions.
• Audit time calculation according to ISO/IEC 27006 (number of effective personnel plus complexity factors).
• Language, cultural and logistical considerations.
• Information security and confidentiality requirements, such as access restrictions and NDAs.
4. Content of the Audit Plan (ISO 19011 clause 6.3.2.2)
The level of detail depends on the scope and complexity of the audit. A typical plan includes:
• Audit objectives.
• Audit scope: organizational and functional units, processes, physical locations and boundaries.
• Audit criteria and any reference documented information, such as ISO/IEC 27001:2022, the SoA, policies, and legal or contractual requirements.
• Locations, dates, expected time and duration of audit activities, including meetings with management.
• Audit methods, including sampling and the extent of remote auditing.
• Roles and responsibilities of audit team members, guides and observers.
• Allocation of resources, considering risks and opportunities.
Where appropriate, the plan may also include:
• The auditee's representative.
• The working and reporting language.
• Topics of the audit report.
• Logistics and communication arrangements, such as travel and facilities.
• Specific measures to address risks to achieving audit objectives.
• Confidentiality and information security matters.
• Follow-up actions from a previous audit.
• Coordination with other planned activities, as in combined or integrated audits.
5. How Audit Plan Preparation Works: Step by Step
Step 1: Review the audit programme and documented information. Confirm objectives, scope, criteria, duration and team composition.
Step 2: Establish initial contact with the auditee. Confirm communication channels, authority to conduct the audit, access arrangements, health and safety, and security requirements.
Step 3: Determine feasibility of the audit. Check that there is sufficient and appropriate information, adequate cooperation and sufficient time and resources. If the audit is not feasible, propose an alternative to the audit client.
Step 4: Perform a risk-based analysis. Identify risks to the audit, such as unavailable personnel, restricted access to confidential systems, multi-site complexity or remote work. Also consider the auditee's significant information security risks and focus effort on them.
Step 5: Define audit methods and sampling. Decide on interviews, observation and document review, and on on-site versus remote auditing. Define sampling for multi-site organizations according to ISO/IEC 27006.
Step 6: Assign audit work. The audit team leader allocates responsibility for specific processes, functions, sites or controls. Assignments consider competence, independence (auditors must not audit their own work), and the effective use of technical experts and auditors-in-training.
Step 7: Prepare the schedule. Sequence activities logically: opening meeting, process audits, daily team meetings, closing meeting. Top management interviews are often placed early. Allow time for reviewing evidence and preparing findings.
Step 8: Communicate and agree the plan. Present the plan to the auditee, and to the audit client if different, before the on-site activities. Any objections should be resolved between the team leader, the auditee and the audit client.
Step 9: Prepare work documents. Prepare checklists, sampling plans, audit questionnaires and forms for recording evidence and findings. Work documents should not restrict the extent of audit activities, which can change as information is collected.
Step 10: Review and revise as necessary. The plan is flexible. Changes may be needed during the audit, and these should be agreed with the auditee.
6. Special Considerations for ISO/IEC 27001 Audits
• Stage 1 informs Stage 2 planning. Findings from Stage 1, such as documentation gaps or areas of concern, must be reflected in the Stage 2 plan.
• Confidential and sensitive information. Some records, such as security logs or penetration test results, may not be made available. The plan should address this, and the certification body must decide whether the ISMS can be adequately audited without them (ISO/IEC 27006).
• Annex A controls. The plan should show which controls in the SoA will be sampled and verified.
• Technology-intensive environments. Cloud, data centres and outsourced services may require technical experts or remote auditing techniques.
• Multi-site organizations. Sampling must be justified, and the central function must always be audited.
• Audit time. This is determined according to ISO/IEC 27006 tables and adjusted for complexity factors.
7. Roles in Audit Plan Preparation
• Audit team leader: responsible for preparing the audit plan and assigning work.
• Audit programme manager: provides the inputs (objectives, scope, criteria, team).
• Audit team members: prepare work documents for their assigned areas.
• Auditee: reviews the plan, provides feedback and ensures availability.
• Audit client: may need to approve the plan or resolve disputes.
8. Common Pitfalls to Avoid
• Confusing the audit plan with the audit programme.
• Creating an overly rigid plan that cannot accommodate findings.
• Ignoring Stage 1 results or previous nonconformities.
• Assigning auditors to areas where they lack competence or have conflicts of interest.
• Failing to schedule time for the team to review findings.
• Not communicating the plan to the auditee in advance.
• Using checklists as a substitute for professional judgement.
Exam Tips: Answering Questions on Audit Plan Preparation
Tip 1: Know who does what. The audit team leader prepares the audit plan. The person managing the audit programme establishes the programme. Many exam distractors swap these roles.
Tip 2: Distinguish plan from programme. If the question refers to a single audit (dates, sites, auditor assignments), the answer concerns the audit plan. If it refers to multiple audits over time or a certification cycle, it concerns the audit programme.
Tip 3: Remember the core contents. Memorize the mandatory elements: objectives, scope, criteria, locations, dates, duration, methods (including sampling), roles and responsibilities, and resource allocation. Questions often ask which item is NOT typically part of the plan. Examples include detailed audit findings and conclusions, which come later.
Tip 4: Emphasize the risk-based approach. When asked how to prioritize audit activities, choose answers that focus on significant information security risks, Stage 1 concerns, previous nonconformities and critical processes.
Tip 5: The plan must be communicated and agreed. If a scenario describes the auditee objecting to the plan, the correct action is to resolve it among the team leader, auditee and audit client before proceeding. The team leader should not ignore the objection or unilaterally cancel the audit.
Tip 6: Flexibility is key. The plan can be revised during the audit, but changes must be agreed with the auditee and, where appropriate, the audit client. Avoid answers that say the plan is fixed and cannot change.
Tip 7: Scenario-based questions. Read the scenario carefully for clues such as multi-site operations, confidential information restrictions, remote work, or Stage 1 findings. The best answer usually adapts the plan to these specific conditions rather than offering a generic response.
Tip 8: Work documents support, not restrict. Checklists help the auditor but should never limit the investigation. Answers suggesting auditors must strictly follow a checklist are usually wrong.
Tip 9: Competence and impartiality in assignments. When asked about allocating work, choose answers that match auditor competence to the area and avoid conflicts of interest. Technical experts operate under the direction of an auditor and do not act as auditors independently.
Tip 10: Structure essay or open-ended answers. For written answers, follow this structure: define the audit plan (ISO 19011), explain its purpose, list key contents, describe the preparation steps, mention risk-based considerations and ISMS-specific aspects (SoA, Annex A, confidentiality), and conclude with communication and agreement. Use the terminology from the standards.
Tip 11: Watch for timing. The plan is prepared after the feasibility determination and document review (Stage 1 for certification), and before the on-site activities and opening meeting. Questions may test the correct sequence of audit activities.
Tip 12: Eliminate extreme answers. Options using words like always, never or only are often wrong in audit planning questions, because ISO 19011 emphasizes appropriateness to scope and complexity.
Summary
Audit plan preparation translates the audit programme into a practical, risk-based and agreed set of activities for a specific ISO/IEC 27001 audit. It ensures objectives are met, resources are used efficiently, and the auditee is prepared. For the exam, master the definition, contents, responsibilities, sequence and flexibility of the audit plan. Always apply a risk-based, scenario-specific approach when selecting answers.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!