Risk-Based Audit Planning
Risk-based audit planning is the approach, promoted by ISO 19011 and ISO/IEC 27006, in which the lead auditor allocates audit effort according to the risks relevant to the audit and to the auditee's information security management system (ISMS). Rather than examining every clause and Annex A contro… Risk-based audit planning is the approach, promoted by ISO 19011 and ISO/IEC 27006, in which the lead auditor allocates audit effort according to the risks relevant to the audit and to the auditee's information security management system (ISMS). Rather than examining every clause and Annex A control with equal depth, the auditor focuses time, sampling and expertise where nonconformities or significant information security failures are most likely and would have the greatest consequences. Planning considers two dimensions of risk. The first is audit risk, meaning the risk that the audit fails to achieve its objectives. Causes include insufficient audit time, unclear scope, lack of auditor competence, limited access to information or personnel, inadequate sampling, and threats to impartiality. The second is the auditee's information security risk. This covers the threats, vulnerabilities and impacts identified in the organization's own risk assessment, as well as its context, interested parties, legal and contractual obligations, and key business processes. To build a risk-based plan, the lead auditor reviews documented information such as the ISMS scope, the risk assessment methodology, the risk treatment plan and the Statement of Applicability. Previous audit reports, incident records and the results of the Stage 1 audit are also examined. From this review, the auditor identifies critical processes, high-value assets, outsourced services, recent organizational or technological changes, and controls that were excluded or newly implemented. These areas receive more attention in the audit plan, larger samples, and team members with the relevant technical competence. The audit plan then defines the objectives, criteria, scope, schedule, locations, methods (including remote auditing), resources and roles. It remains flexible enough to be adjusted if new risks emerge during fieldwork. Lower-risk areas still receive adequate coverage to confirm conformity with all ISO/IEC 27001 requirements. The benefits include efficient use of audit time, more meaningful findings, greater confidence in the certification decision, and added value for the auditee. The audit concentrates on what genuinely matters for protecting the confidentiality, integrity and availability of information.
Risk-Based Audit Planning in ISO/IEC 27001 Lead Auditor Practice: A Complete Guide
Introduction
Risk-based audit planning is one of the core ideas behind preparing an ISO/IEC 27001 audit. It means that the audit team decides where to spend its limited time and attention based on risk. Two kinds of risk are considered: the risks to the auditee's information security, and the risks to achieving the audit objectives themselves. ISO 19011:2018 (Guidelines for auditing management systems) and ISO/IEC 27006 (requirements for certification bodies auditing ISMS) both build this approach into how audits are planned, resourced and carried out. For the ISO 27001 Lead Auditor exam, you must understand the concept and be able to apply it to scenario questions.
Why Risk-Based Audit Planning Is Important
1. Limited time and resources: No audit can examine every process, control, record and location. A risk-based approach makes sure audit effort goes to the areas where nonconformities or security failures are most likely, or would have the greatest impact.
2. Audit effectiveness: Planning around risk raises the chance of finding significant nonconformities. This gives the audit client and other interested parties a more reliable conclusion.
3. Alignment with the ISMS philosophy: ISO/IEC 27001 is a risk-based standard (Clauses 6.1.2 and 6.1.3, risk assessment and treatment). Auditing it in a risk-based way stays consistent with how the ISMS is meant to work.
4. Compliance with ISO 19011: Risk-based thinking is one of the seven principles of auditing in ISO 19011:2018 (Clause 4, principle g: risk-based approach). Clause 5.3 also requires audit programme risks and opportunities to be addressed.
5. Credibility of certification: Certification bodies must show that their audits are planned so they reach valid conclusions. Poor planning can lead to wrong certification decisions, which harms trust in the certificate.
6. Value to the auditee: Focusing on significant risk areas produces findings that help the organization improve its security posture.
What Risk-Based Audit Planning Is
Risk-based audit planning means using risk considerations to decide the scope, focus, depth, timing, sampling, methods and resources of an audit. It works at two levels.
Level 1: Audit programme level (ISO 19011 Clause 5)
The person managing the audit programme identifies and evaluates risks and opportunities that could affect the programme's objectives. Examples include:
- Planning risks, such as failing to set relevant audit objectives or to determine the extent and number of audits
- Resource risks, such as not enough time, equipment or training
- Team selection risks, such as lacking the competence to audit cryptography, cloud services or OT environments
- Communication risks, such as ineffective internal or external communication channels
- Implementation risks, such as not coordinating audits within the programme
- Information control risks, such as failing to protect confidential audit information
- Monitoring and improvement risks
- Auditee availability and cooperation, and availability of evidence to be sampled
Level 2: Individual audit level (ISO 19011 Clause 6.3)
When preparing a specific audit, the audit team leader takes a risk-based approach to:
- Prepare the audit plan
- Decide which processes, functions, sites and controls to emphasise
- Choose sampling methods and sample sizes
- Assign tasks to team members according to competence
- Decide whether audit activities will be on-site, remote or a mix
- Allocate time to each audit activity
ISO 19011 Clause 6.3.2.1 states that the audit plan should take into account risks the audit activities may create for the auditee's processes, and the risks the audit process itself poses (for example, auditor safety, data confidentiality and disruption to operations).
Two dimensions of risk you must distinguish
- Risks to the auditee's ISMS: These are the information security risks the organization faces. They guide what you audit more deeply, for example high-risk assets, critical processes, recent incidents and controls marked as key in the Statement of Applicability.
- Risks to the audit process: These are risks that the audit fails to meet its objectives. They guide how you plan the audit, for example competence gaps, too little time, inaccessible evidence, language barriers and conflicts of interest.
How Risk-Based Audit Planning Works
Step 1: Understand the audit objectives, scope and criteria
The audit team leader confirms what the audit must achieve (for example, a Stage 2 certification audit, a surveillance audit or an internal audit). The scope covers boundaries, sites, processes and time period. The criteria are ISO/IEC 27001 requirements, the organization's policies, and legal and contractual obligations.
Step 2: Gather information about the auditee
Typical inputs include:
- The ISMS scope statement and context (Clause 4)
- The information security risk assessment and risk treatment plan
- The Statement of Applicability (SoA)
- Previous audit reports and open nonconformities
- Incident history and security breaches
- Results of management reviews and internal audits
- Significant changes, such as new systems, mergers, outsourcing, cloud migration or new regulations
- Complexity, technology used, number of personnel and number of sites
- Legal, regulatory and contractual requirements, such as GDPR, NIS2 or sector rules
- Stage 1 audit findings (for certification audits)
Step 3: Identify and evaluate risks
Determine which areas are most likely to contain nonconformities, or where nonconformities would have serious consequences. Common high-risk indicators include:
- Processes handling sensitive or regulated data
- Areas with recent incidents or repeated nonconformities
- Newly implemented or changed controls
- Outsourced processes and supplier relationships (Annex A 5.19 to 5.23)
- Access control, change management, backup and business continuity controls
- Excluded Annex A controls whose justification looks weak
- Areas where previous audits had limited coverage
Step 4: Determine audit focus and depth
Allocate more time, deeper testing and larger samples to high-risk areas. Lower-risk areas may receive lighter coverage, but no area within the scope should be ignored entirely. For a certification cycle, all clauses and applicable controls must be covered over the cycle.
Step 5: Select audit methods and sampling
Decide between interviews, observation, document review, technical verification and remote methods. Use judgement-based or statistical sampling (ISO 19011 Annex A.6). Sample size and selection should reflect risk. For example, sample more change records where change management failures have caused incidents.
Step 6: Assign competent resources
Make sure the audit team has the right competence for the risks identified. If specialist knowledge is needed, such as industrial control systems or cryptographic key management, add a technical expert. Consider independence and conflicts of interest.
Step 7: Prepare the audit plan
The audit plan (ISO 19011 Clause 6.3.2) usually covers:
- Objectives, scope and criteria
- Locations, dates, expected time and duration of activities
- Methods, including sampling
- Roles and responsibilities of team members, guides and observers
- Resource allocation for critical areas
- Confidentiality and information security of audit activities
The plan should be flexible. The team leader can adjust it during the audit if new risks emerge, such as evidence of a serious incident.
Step 8: Address risks of the audit process itself
Examples include:
- Protecting confidential information the auditors obtain
- Avoiding disruption to critical operations, such as not running tests on production systems at peak times
- Auditor health and safety
- Remote audit risks, such as reliability of the ICT tools and the authenticity of evidence shown on screen
Step 9: Review and adapt
Risk-based planning is dynamic. Audit findings feed the next audit, surveillance planning and the audit programme review (ISO 19011 Clause 5.7).
Practical Example
A cloud services provider seeks ISO/IEC 27001 certification. During Stage 1, the auditor learns of three things: a major data breach six months ago caused by misconfigured cloud storage, a recent move to a new third-party data centre, and the exclusion of Annex A 8.28 (Secure coding) even though the company develops its own software. A risk-based Stage 2 plan would:
- Allocate extra time to incident management (A 5.24 to 5.28), configuration management (A 8.9) and lessons learned from the breach
- Examine supplier management for the new data centre (A 5.19 to 5.22)
- Challenge the justification for excluding secure coding
- Assign an auditor with cloud and software development competence
- Sample more cloud configuration records and change tickets
Key Relationships to Remember
- ISO 19011 Clause 4(g): The risk-based approach is a principle of auditing.
- ISO 19011 Clause 5.3: Determine and evaluate audit programme risks and opportunities.
- ISO 19011 Clause 6.3.2: Prepare the audit plan using a risk-based approach.
- ISO/IEC 27006: Covers audit time determination and the factors that increase or decrease audit duration. Examples are complexity, risk, number of sites and technology.
- ISO/IEC 27001 Clauses 6.1.2 and 6.1.3: The auditee's risk assessment and treatment are key inputs to audit planning.
- ISO/IEC 27007: Guidelines for ISMS auditing, which apply ISO 19011 to information security.
Common Misconceptions
- Misconception: Risk-based means low-risk areas are skipped. Reality: All in-scope requirements must be covered, either within the audit or across the certification cycle. Risk only affects emphasis and depth.
- Misconception: The auditor performs the auditee's risk assessment. Reality: The auditor uses the auditee's risk assessment as an input and evaluates whether it conforms. The auditor does not redo it.
- Misconception: The audit plan is fixed once approved. Reality: It can be adjusted during the audit as risks emerge, with agreement as needed.
- Misconception: Only the auditee's risks matter. Reality: Risks to the audit process itself are equally important.
Exam Tips: Answering Questions on Risk-Based Audit Planning
1. Identify which risk the question is about.
Ask yourself whether it concerns the auditee's information security risks or risks to the audit itself. Many scenario questions turn on this distinction. Lack of auditor competence, insufficient time and unavailable evidence are audit risks. A recent breach or weak access control is an auditee risk that shapes the audit's focus.
2. Look for trigger words in scenarios.
Phrases such as recent incident, major change, new system, outsourcing, previous nonconformity, regulatory requirement, sensitive data, multiple sites or limited time signal that the correct answer involves allocating more attention, time, sampling or specialist resources to that area.
3. Choose answers that focus effort, not answers that ignore areas.
Avoid options that say to skip or exclude in-scope areas because they seem low-risk. The correct answer usually adjusts depth and emphasis while keeping coverage.
4. Remember who does what.
- The audit programme manager evaluates programme-level risks and opportunities.
- The audit team leader prepares the audit plan using a risk-based approach and assigns tasks.
- The auditee owns its risk assessment. The auditor evaluates it but does not perform it.
5. Link to ISO 19011 language.
Phrases such as risk-based approach, risks and opportunities, audit programme objectives, sampling, competence of the audit team and flexible audit plan often appear in correct answers. Be ready to name the principles of auditing, including the risk-based approach.
6. For essay or case-study questions, use a structured answer.
A strong response would:
- State the audit objective and scope
- List the information sources you would review (risk assessment, SoA, previous audit reports, incidents, changes)
- Identify the high-risk areas from the scenario and explain why they are high-risk
- Describe how you would adjust time, sampling, methods and team composition
- Mention the risks to the audit process and how you would mitigate them
- Note that the plan stays flexible and that findings feed future audits
7. Watch for questions on Stage 1 versus Stage 2.
Stage 1 findings, such as readiness, documentation gaps and an understanding of risks, are a major input into Stage 2 planning. A question asking what to use when planning Stage 2 often expects the answer: Stage 1 results plus the auditee's risk assessment and SoA.
8. Consider audit time and certification body rules.
Under ISO/IEC 27006, audit duration may increase for higher complexity, high-risk business sectors or many sites. It may decrease for lower risk or limited scope, but only within the permitted limits. Answers suggesting unjustified reductions in audit time are usually wrong.
9. Do not confuse audit risk with information security risk treatment.
The auditor does not recommend specific controls or solutions, because that would compromise independence. In planning questions, the right answer focuses on what to audit and how, not on fixing the auditee's risks.
10. Remember the remote audit and confidentiality angle.
If a scenario involves remote auditing, think about risks such as connectivity, identity verification, evidence authenticity and confidentiality of shared screens. Plan mitigations for them.
11. Eliminate extreme answers.
Options with always, never, only or audit everything equally are rarely correct. Risk-based planning relies on professional judgement and proportionality.
12. Practice applying the concept.
Take sample scenarios and ask three questions: What could go wrong in this organization's ISMS? What could prevent this audit from reaching a valid conclusion? How does each answer change my plan? This builds the reasoning the exam rewards.
Summary
Risk-based audit planning directs audit effort to where it matters most. It considers both the auditee's information security risks and the risks to the audit process. It is grounded in ISO 19011 principles and programme management, applied to ISMS audits through ISO/IEC 27007 and ISO/IEC 27006, and fits the risk-driven nature of ISO/IEC 27001. In the exam, show that you can gather the right inputs, identify high-risk areas, adjust focus, sampling, time and competence accordingly, keep coverage complete, and keep the plan flexible. This will let you answer both multiple-choice and scenario-based questions with confidence.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!