Multi-Site Audits and Site Sampling
Multi-site audits apply when an organization runs a single Information Security Management System (ISMS) across several locations, such as headquarters, branches, data centres or remote offices. When planning the audit, the Lead Auditor must decide whether sampling is allowed or whether every site … Multi-site audits apply when an organization runs a single Information Security Management System (ISMS) across several locations, such as headquarters, branches, data centres or remote offices. When planning the audit, the Lead Auditor must decide whether sampling is allowed or whether every site has to be visited. The main references are IAF MD 1 (certification of multiple sites based on sampling) and ISO/IEC 27006-1, which adds ISMS-specific requirements for certification bodies. Sampling is only allowed if certain conditions are met. All sites must operate under one ISMS that is centrally administered and covered by a common management review. Internal audits must have covered every site. A central function must have the authority to require corrective action at any site. The sites should also carry out similar activities with comparable information security risks. If sites differ significantly in processes, risk or technology, they may need separate or full coverage. IAF MD 1 bases the minimum sample size on the square root of the number of sites. It uses roughly √x for initial audits, 0.6√x for surveillance and 0.8√x for recertification, always rounded up. The sample is then adjusted for risk factors, including: - the complexity and size of each site - internal audit results and complaints - legal and regulatory differences - geographic, cultural and language differences - recent changes and the criticality of the information assets involved Part of the sample is selected on a risk basis and part at random. The central function is audited at every audit. Across the certification cycle, the audit programme must cover all ISMS clauses and all applicable Annex A controls. A nonconformity found at one site is treated as potentially affecting every site. The organization must investigate how widespread it is and apply corrective action across the whole network. Certification cannot proceed until this is done, and problem sites cannot simply be removed from scope to avoid findings. When preparing the audit, the Lead Auditor documents the sampling rationale in the audit plan. The plan should allocate auditor competence, language skills and time, and consider remote auditing techniques under IAF MD 4 where appropriate.
Multi-Site Audits and Site Sampling in ISO/IEC 27001 Certification Audits
Introduction
Many organizations that seek ISO/IEC 27001 certification do not run their Information Security Management System (ISMS) from a single building. They may have a head office, regional branches, data centers, call centers, warehouses, development hubs or cloud operations spread across cities and countries. Auditing every location in full at every audit would often be impractical and costly. Multi-site auditing and site sampling is the set of rules that lets a certification body audit a representative selection of sites and still give justified confidence that the whole ISMS conforms to ISO/IEC 27001. For a Lead Auditor, it is a core part of preparing an audit: it shapes the audit programme, the audit plan, the audit time, the team and the conclusions you can draw.
1. Why Multi-Site Audits and Site Sampling Are Important
Efficiency without losing confidence: Sampling reduces audit time and cost when sites perform similar activities under one ISMS, while still giving reasonable assurance across the whole scope.
Credibility of certification: A certificate that lists many sites must be backed by evidence. Poor sampling, such as only visiting the best-run sites, undermines trust in certification. The rules protect the integrity of accredited certification.
Risk-based coverage: Information security risks differ between sites (for example, a data center versus a sales office). Sampling must reflect these risks, so high-risk sites receive attention.
Detecting systemic weaknesses: Multi-site audits test whether the central function really controls the ISMS. A nonconformity at one site may reveal a weakness that affects all sites.
Compliance for certification bodies: Certification bodies accredited to ISO/IEC 17021-1 must follow ISO/IEC 27006-1 (requirements for bodies certifying ISMS) and IAF MD 1 (the IAF mandatory document on the audit and certification of multi-site organizations). Lead Auditors must apply these rules correctly.
2. What It Is: Key Concepts and Definitions
Multi-site organization: An organization with an identified central function (often called the central office or head office) at which certain ISMS activities are planned, controlled and managed, and a network of sites at which those activities are fully or partially carried out.
Central function: The location or part of the organization responsible for the management system. It typically controls policy, risk assessment methodology, the Statement of Applicability, document control, internal audit, management review, corrective action and the analysis of data. It is always audited, not sampled.
Site: A permanent or temporary location where work or a service is performed. Virtual sites (for example, staff working remotely, or a cloud-based operation where work is performed online) may also be considered sites.
Temporary site: A location set up for a limited time, such as a project office or an installation site at a client's premises.
Site sampling: Selecting a subset of sites for on-site or remote audit, with the results used to draw a conclusion about the whole multi-site ISMS.
Multi-site certification: One certificate, issued to the organization with its central function, with the sites in scope listed on the certificate or in an appendix.
3. Eligibility Conditions for Site Sampling
Sampling is a privilege, not a right. Before sampling, the certification body must confirm the organization meets the eligibility criteria, mainly drawn from IAF MD 1 and ISO/IEC 27006-1:
a) One ISMS: All sites operate under a single, centrally controlled and administered ISMS with the same policies and procedures.
b) Central control and authority: The central function has the organizational authority to define, establish and maintain the ISMS and to require sites to implement corrective actions.
c) Central internal audit and management review: All sites are subject to the organization's internal audit programme and are covered by management review. Under ISO/IEC 27006-1, every site should be internally audited, normally within the certification cycle, before or during the certification audit.
d) Central data collection and analysis: The central function can collect and analyse data from all sites, including complaints, incidents, corrective actions, changes and internal audit results.
e) Similar activities and risks: Sites in the same sample group should carry out substantially similar activities with comparable processes, risks and controls. Where sites differ significantly, they are placed in separate groups or audited individually.
f) Legal or contractual link: All sites have a legal or contractual relationship with the central function.
If these conditions are not met, sampling is not permitted and each site must be audited. For example, if a subsidiary runs its own separate ISMS with its own risk assessment and internal audit, it cannot be sampled as part of the parent's multi-site scheme.
4. How It Works: The Sampling Process
Step 1 - Understand the organization during the application review: Collect a full list of sites, the activities and number of personnel at each, the information assets and processes involved, legal and regulatory differences, outsourced processes, and internal audit results. This information feeds the audit programme and audit time calculation.
Step 2 - Verify eligibility: Confirm that the conditions above are met, typically during the Stage 1 audit. Review how the central function controls the sites.
Step 3 - Group the sites: Group sites by similarity of activities, processes, risks and controls. A data center, a software development center and a retail branch would normally be different groups.
Step 4 - Determine sample size: IAF MD 1 provides a minimum sample size based on the square root of the number of sites (excluding the central function), rounded up to the next whole number:
- Initial certification audit: y = √x
- Surveillance audit: y = 0.6 √x
- Recertification audit: y = 0.8 √x
Where x is the number of sites and y is the minimum number of sites to sample. Example: 25 similar sites at initial certification gives √25 = 5 sites, plus the central function. At surveillance: 0.6 x 5 = 3 sites. At recertification: 0.8 x 5 = 4 sites.
Step 5 - Adjust for risk and complexity: The minimum size must be increased where there are higher risks, for example: sites with high information security risk or critical assets, significant differences in size or processes, variations in legal or regulatory requirements, poor internal audit results, many complaints or security incidents, major changes since the last audit, geographical or cultural diversity, or a history of nonconformities. Sample size may only be reduced in very limited justified cases, and never below what ensures confidence.
Step 6 - Select which sites: Selection combines judgement and randomness. IAF MD 1 expects part of the sample (commonly at least 25%) to be selected randomly, with the rest chosen based on factors such as results of internal audits and previous certification audits, records of incidents and complaints, significant differences in site size or activities, variations in shifts or working practices, changes since the last audit, and geographic spread. The organization must not choose the sites to be audited. The selection should be made by the certification body and, ideally, sites should not know too far in advance which will be visited.
Step 7 - Plan across the certification cycle: Over the three-year cycle, the audit programme should aim to cover different sites, so that, as far as practical, all sites or all significant site groups are visited. Sites selected at initial certification are usually not repeated in surveillance unless justified by risk.
Step 8 - Calculate audit time: Audit time is determined using ISO/IEC 27006-1 (which defines the audit time calculation for ISMS, based on number of persons doing work under the organization's control and complexity factors). Time is allocated to the central function and to each sampled site. Sampling does not mean that the total time can be reduced to an unrealistically low level; each sampled site requires sufficient time to collect objective evidence.
Step 9 - Conduct the audit: The central function is audited at each initial certification and recertification audit, and at least annually as part of surveillance. At sampled sites, auditors verify that central policies, risk treatment and controls are actually implemented locally, for example physical security, access control, local incident handling, awareness, asset handling and supplier interfaces.
Step 10 - Report and decide: The report must identify which sites were audited and the evidence obtained, and support a conclusion for the whole ISMS.
5. Handling Nonconformities in a Multi-Site Audit
This is a frequent exam topic.
Nonconformities apply to the network: When a nonconformity is found at one site, the organization must investigate whether other sites are affected. The central function must determine the root cause and take corrective action across the network where relevant, not only at the site where it was found.
Systemic implications: A nonconformity may indicate that the central function is not effectively controlling the ISMS.
Certification is all-or-nothing for the sample: The certificate cannot be issued, maintained or extended to the network until the nonconformities are adequately addressed, because sampling assumes all sites are equivalent.
No removing sites to avoid a nonconformity: During the certification process, an organization cannot simply remove a problematic site from the scope to avoid a major nonconformity being raised. A site may be excluded from scope only through a legitimate scope change, but not as a way to escape the finding during that process.
Increased sampling: Where nonconformities or poor performance arise, the certification body may increase the sample size at subsequent audits.
Suspension or withdrawal: If the central function or any site fails to meet requirements, the certification of the whole network may be affected, including suspension.
6. Special Considerations for ISMS Multi-Site Audits
Risk-centred sampling: ISO/IEC 27006-1 stresses that sampling must reflect information security risk. A site hosting critical systems or processing sensitive data generally cannot be treated the same as a low-risk sales office.
Statement of Applicability (SoA): There is normally one ISMS and one SoA. If sites apply different controls, auditors must understand why and verify that the risk assessment covers each site context.
Data centers and server rooms: These are often treated as separate site types because physical and environmental controls (Annex A physical controls) are critical there.
Remote and virtual sites: Where activities occur online or at home, remote auditing techniques (per IAF MD 4 on the use of ICT for auditing) may be used, and auditors must verify controls such as secure remote access and endpoint security.
Outsourced locations: Locations of an external provider are not sites of the organization; they are handled through supplier relationship controls, unless they are under the organization's ISMS control and contract.
Legal differences: Sites in different countries may face different data protection or legal requirements, which increases complexity and may justify a larger sample.
Adding new sites: New sites can be added to an existing certificate after the certification body verifies they meet the conditions, which may require a special audit of a sample of new sites.
7. Roles of the Lead Auditor When Preparing a Multi-Site Audit
- Confirm the scope and the list of sites with the client.
- Verify eligibility for sampling or escalate to the certification body if conditions are not met.
- Apply the certification body's sampling procedure and justify site selection in writing.
- Allocate audit team members and audit time to sites based on competence and risk (for example, technical experts for data centers).
- Prepare the audit plan showing which sites are audited, when, by whom and against which processes and controls.
- Ensure the central function is included and that its interfaces with sites are tested (for example, how site incidents reach the central incident process).
- Communicate the plan to the auditee while protecting the element of randomness where appropriate.
8. Worked Example
A bank has a head office (central function) and 36 branches with identical processes, plus 2 data centers. At initial certification:
- The head office is always audited.
- The 2 data centers are a separate high-risk group and, due to criticality, both are audited.
- Branches: √36 = 6 branches minimum. Internal audits showed repeated access control weaknesses at branches, so the auditor increases the sample to 8. Two are chosen randomly, and six are selected based on size, incident history, location and recent changes.
- At the first surveillance: 0.6 x 6 = 3.6, rounded to 4 branches minimum, preferably different branches from initial certification, plus the head office, with data center coverage based on risk.
If an auditor finds that a branch does not revoke access for leavers, the bank must assess all branches and the central HR/IT leaver process, not only fix the one branch.
Exam Tips: Answering Questions on Multi-Site Audits and Site Sampling
Tip 1 - Remember the central function is never sampled. If an option suggests skipping the head office or central function, it is almost certainly wrong.
Tip 2 - Check eligibility first. In scenario questions, look for clues that sampling is not allowed: separate ISMSs, different management, no central internal audit, sites that do not report to the central function, or sites with very different activities and risks. If conditions are not met, the correct answer is usually that each site must be audited, or sites must be grouped differently.
Tip 3 - Know the formulas and rounding. Initial = √x, surveillance = 0.6√x, recertification = 0.8√x, always rounded up. The result is a minimum, and the central function is in addition to the sample.
Tip 4 - Risk increases the sample. When a question mentions high-risk sites, incidents, poor internal audit results, legal differences or major changes, the correct answer usually increases the sample or targets those sites.
Tip 5 - The auditee does not choose the sites. Any answer where the client selects the sites, or where only the best-performing sites are visited, is wrong. Selection is by the certification body, combining random and risk-based selection.
Tip 6 - One nonconformity affects the network. If a nonconformity is found at one site, the best answer involves investigating other sites and requiring corrective action from the central function across the network. Removing the site to avoid the finding during certification is not acceptable.
Tip 7 - Distinguish sites from suppliers. An outsourced provider's premises are not organization sites for sampling; they are addressed through supplier controls and evidence of control over outsourced processes.
Tip 8 - Think across the three-year cycle. Good answers rotate sites so that coverage improves over the cycle, rather than visiting the same sites every time.
Tip 9 - Do not confuse audit sampling of records with site sampling. Site sampling selects locations; audit sampling (per ISO 19011) selects records, people or transactions within a site. Exams sometimes test this difference.
Tip 10 - Justify your answers with references. In essay or scenario questions, cite ISO/IEC 27006-1, IAF MD 1, ISO/IEC 17021-1 and ISO 19011 where relevant, and explain the reasoning: representativeness, risk, central control and confidence in conformity.
Tip 11 - Watch for keywords. Words like always, never, only and minimum matter. For example: "the sample size calculated is the maximum number of sites" is false; it is a minimum.
Tip 12 - Structure scenario answers. A strong answer follows this order: (1) Is the organization eligible for sampling? (2) How are sites grouped? (3) What is the minimum sample and how is it adjusted for risk? (4) How are sites selected? (5) How are time and team allocated? (6) How will findings be handled across the network?
Summary
Multi-site auditing allows a certification body to certify an ISMS operated across many locations by auditing the central function plus a representative, risk-based sample of sites. Sampling is only permitted when there is a single, centrally controlled ISMS with internal audits and management review covering all sites. The sample size starts from the square-root formulas and is increased for risk and complexity; selection is partly random and partly judgement-based, and never chosen by the client. Nonconformities at any site are treated as potential network-wide issues. In the exam, focus on eligibility, the central function, risk-based adjustment, impartial selection and network-wide corrective action, and you will answer most multi-site questions correctly.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!