Initial Contact with the Auditee
In ISO/IEC 27001 audit preparation, initial contact with the auditee is the first formal communication between the audit team leader and the organization being audited. It follows the acceptance of the audit mandate and is guided by ISO 19011 (clause 6.2.2) and ISO/IEC 17021-1 for certification aud… In ISO/IEC 27001 audit preparation, initial contact with the auditee is the first formal communication between the audit team leader and the organization being audited. It follows the acceptance of the audit mandate and is guided by ISO 19011 (clause 6.2.2) and ISO/IEC 17021-1 for certification audits. Its purpose is to establish a professional working relationship, confirm feasibility, and gather the information needed to plan an effective audit. The contact may be formal or informal, by phone, email, or meeting, and is usually made by the audit team leader. Key objectives include: confirming communication channels and identifying the auditee representative or guide; confirming the authority to conduct the audit; and communicating the audit objectives, scope, criteria, methods, duration, and audit team composition, including technical experts and observers. The auditor also requests access to relevant documented information for planning, such as the ISMS scope, information security policy, risk assessment and treatment methodology, and Statement of Applicability. The auditor determines applicable legal, regulatory, and contractual requirements, and identifies risks and opportunities related to the audit. Because ISO/IEC 27001 audits involve sensitive information, initial contact is critical for agreeing on confidentiality, the extent of disclosure, handling of classified or personal data, and any non-disclosure agreements. Practical arrangements are also made, including scheduling dates, site locations, multi-site sampling, remote audit technology, access permissions, security clearances, health and safety rules, and the need for interpreters. The auditee can raise objections to specific team members, which should be resolved before the audit proceeds. The auditor also identifies areas of particular interest or concern to the auditee, such as previous nonconformities. Successful initial contact sets clear expectations, reduces misunderstandings, demonstrates professionalism and impartiality, and supports a feasibility determination, ensuring the audit can achieve its objectives with sufficient information, cooperation, time, and resources.
Initial Contact with the Auditee: A Complete Guide for ISO/IEC 27001 Lead Auditors
Introduction
The initial contact with the auditee is the first formal step of an individual audit, after the audit programme manager has assigned the audit to an audit team leader. In the ISO/IEC 27001 Lead Auditor syllabus it falls under Preparing an ISO/IEC 27001 audit, as part of initiating the audit. It is based mainly on ISO 19011:2018, clause 6.2.2 (Establishing contact with the auditee). For certification audits, ISO/IEC 17021-1 and ISO/IEC 27006-1 add further requirements. This guide explains what the initial contact is, why it matters, how it works in practice and how to answer exam questions about it.
1. What Is the Initial Contact with the Auditee?
The initial contact is the first communication between the audit team leader (or the certification body) and the organization to be audited. Its purpose is to establish communication, confirm authority, exchange essential information and agree on the practical arrangements needed to plan and conduct the audit.
Key characteristics:
- Who: The audit team leader is responsible for making sure the contact happens. They may delegate the task to a team member, but they remain accountable. In third-party audits, the certification body's administration often makes the first contact during application review, and the audit team leader then follows up.
- When: After the audit has been assigned and before the audit plan is finalized. It comes before the feasibility determination, document review and Stage 1 activities.
- Form: It can be formal or informal, for example a phone call, video call, email or letter. Formal confirmation in writing is good practice.
- With whom: The auditee's representative, usually the ISMS manager, CISO or management representative, and sometimes the audit client if it is a different party.
2. Why Is It Important?
- It sets the tone of the audit. A professional first contact builds trust and cooperation, and it reduces the auditee's anxiety.
- It prevents surprises. Logistics, access rights, security rules and the availability of key people are clarified in advance.
- It confirms authority and legitimacy. The auditor confirms that the audit is authorized and that the auditee accepts it.
- It protects confidentiality. An ISMS audit involves highly sensitive information, such as risk assessments, vulnerability reports and network diagrams. Agreeing early on how this information will be handled is essential.
- It supports the feasibility determination. The information gathered shows whether there is enough information, enough cooperation, and enough time and resources to meet the audit objectives.
- It enables effective planning. The audit plan depends on accurate information about scope, sites, shifts, processes, risks and applicable legal requirements.
- It addresses team composition and impartiality. The auditee can raise valid objections to team members, for example a conflict of interest or a former employee, before the audit starts.
3. How It Works: Activities Covered (ISO 19011:2018, 6.2.2)
The audit team leader should make sure that contact with the auditee is used to:
1. Confirm communication channels with the auditee's representatives.
2. Confirm the authority to conduct the audit.
3. Provide relevant information on the audit objectives, scope, criteria, methods and team composition, including any technical experts.
4. Request access to relevant information for planning, including information on the risks and opportunities the organization has identified and how it addresses them.
5. Determine applicable statutory, regulatory and other requirements relevant to the auditee's activities, processes, products and services. Examples are GDPR and other data protection laws, sector regulations and contractual security obligations.
6. Confirm agreement on confidentiality, meaning the extent of disclosure and how confidential information will be treated.
7. Make arrangements for the audit, including the schedule.
8. Determine location-specific arrangements for access, health and safety, security, confidentiality and other matters. Examples are visitor badges, escort rules and restrictions on laptops or photography in data centres.
9. Agree on the attendance of observers and on the need for guides or interpreters.
10. Determine areas of interest, concern or risk for the auditee in relation to this specific audit.
11. Resolve issues about the composition of the audit team with the auditee or the audit client.
4. ISMS-Specific and Certification Considerations
- Confidential ISMS information: Before the certification audit, ISO/IEC 27006-1 requires the certification body to ask the client to report any ISMS-related information that cannot be made available for review because it is confidential or sensitive. Examples are records or details about the design and effectiveness of controls. The certification body then decides whether the audit can still be conducted adequately without that information.
- Scope and Statement of Applicability (SoA): The auditor confirms the ISMS scope, boundaries, interfaces, sites and the current SoA version.
- Remote auditing: If ICT tools are used, the auditor agrees on platforms, security of the connection, recording rules and how screens or documents will be shared.
- Audit type: The auditor clarifies whether this is an initial certification audit (Stage 1 and Stage 2), a surveillance audit, a recertification audit or a special audit. This affects the information requested.
- Multi-site organizations: The auditor collects the information needed for site sampling.
5. Link to Determining Audit Feasibility (ISO 19011, 6.2.3)
The information gathered during the initial contact feeds directly into the feasibility determination. The auditor checks for:
- sufficient and appropriate information for planning and conducting the audit;
- adequate cooperation from the auditee;
- adequate time and resources.
If the audit is not feasible, the auditor should propose an alternative to the audit client, in agreement with the auditee. Examples are postponing the audit, changing the scope or adding resources.
6. What the Initial Contact Is NOT
- It is not the opening meeting. The opening meeting happens at the start of on-site or remote audit activities.
- It is not the collection of audit evidence, and no findings or conclusions are drawn.
- It is not consulting. The auditor must not advise on how to implement controls, because this would threaten impartiality.
- It is not a negotiation of the audit criteria to suit the auditee. The criteria are defined by the audit programme and the audit client.
7. Practical Example
An audit team leader is assigned a Stage 1 audit of a cloud service provider. She calls the ISMS manager to introduce herself and the team. She confirms the scope (SaaS platform operations at two data centres) and the criteria (ISO/IEC 27001:2022). She requests the ISMS scope, policy, risk assessment summary and SoA. She asks about applicable regulations such as NIS2 and GDPR. She agrees that penetration test reports will only be viewed on site. She confirms that the data centre requires escorted access and ID in advance. She learns that a junior auditor on the team previously worked for a competitor, so she arranges a replacement. Finally, she proposes dates. She confirms all of this by email and then assesses feasibility.
Exam Tips: Answering Questions on Initial Contact with the Auditee
Tip 1: Know who is responsible. The audit team leader is responsible for making sure contact is established. If an option says the auditee initiates it, or that the top management of the auditee is responsible, it is usually wrong.
Tip 2: Know the timing. The initial contact comes before the feasibility determination and audit planning, and long before the opening meeting. Questions often test this sequence: assignment of the audit, initial contact, feasibility, document review or Stage 1, audit plan, Stage 2 or on-site activities, then the opening meeting.
Tip 3: Memorize the purposes. Use a memory aid such as C-A-I-R-L-C-S-L-O-R-T: Communication channels, Authority, Information on objectives and scope, Request for information (including risks), Legal requirements, Confidentiality, Schedule, Location arrangements, Observers and guides, Risks or concerns of the auditee, Team composition issues.
Tip 4: Spot the distractors. Wrong options often include actions such as:
- collecting audit evidence or interviewing staff;
- issuing nonconformities;
- recommending solutions;
- letting the auditee change the audit criteria.
None of these belong in the initial contact.
Tip 5: Formal or informal. If asked about the form of contact, the correct answer is that it can be formal or informal. However, confirmation in writing is good practice.
Tip 6: Handle confidentiality scenarios correctly. Suppose the auditee refuses to show a sensitive document. The correct approach is to agree in advance on how it will be handled, for example viewing it on site, viewing a redacted version or using an alternative source of evidence. The certification body then evaluates whether the audit can still achieve its objectives. Do not simply ignore the information, and do not automatically cancel the audit.
Tip 7: Handle objections to team members. If the auditee objects to an auditor, the team leader should resolve the issue with the auditee or the audit client. In certification, the auditee may object for valid reasons such as a conflict of interest. The certification body considers the objection, but it does not have to accept unjustified objections.
Tip 8: Link to feasibility. If a scenario describes a lack of cooperation, missing information or insufficient time, the expected answer refers to audit feasibility. The auditor should propose alternatives to the audit client in agreement with the auditee.
Tip 9: Use the scenario. In PECB scenario-based exams, base your answer on the facts in the case. Name the specific ISO 19011 activity that applies, and explain why it matters for an ISMS (confidentiality, security of locations, legal requirements).
Tip 10: Keep impartiality in mind. Any answer in which the auditor offers implementation help, discounts or advice during the initial contact breaches the impartiality principle and is wrong.
Sample Exam Questions
Q1: Who is responsible for ensuring that initial contact with the auditee is made?
A: The audit team leader.
Q2: The ISMS manager informs the team leader that visitors to the data centre must be escorted and must not bring cameras. Which initial contact activity does this relate to?
A: Determining location-specific arrangements for access, security and health and safety.
Q3: During the initial contact, the auditee asks the auditor to suggest how to fix gaps in its access control policy. What should the auditor do?
A: Politely decline. Providing advice would compromise impartiality. The auditor should keep the discussion to audit arrangements.
Q4: Which of the following is NOT a purpose of the initial contact: (a) confirming authority to conduct the audit, (b) agreeing on observers, (c) evaluating the effectiveness of controls, (d) determining applicable legal requirements?
A: (c). Evaluating effectiveness happens during the audit activities.
Summary
The initial contact with the auditee is a short but critical step. It establishes communication, confirms authority, shares the audit objectives, scope, criteria and team composition, and requests planning information. It also identifies legal requirements, settles confidentiality and logistics, and resolves team issues. In ISMS audits, the handling of sensitive information deserves special attention. In the exam, remember four things: the team leader is responsible, it happens before feasibility and planning, no evidence is collected, and impartiality and confidentiality must be preserved.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!