Terms of the Audit Engagement
In the ISO/IEC 27001 Lead Auditor framework, the terms of the audit engagement are the formal, agreed conditions under which an audit will be carried out. They are set during audit preparation, after initial contact between the certification body (or audit team leader) and the auditee, and before d… In the ISO/IEC 27001 Lead Auditor framework, the terms of the audit engagement are the formal, agreed conditions under which an audit will be carried out. They are set during audit preparation, after initial contact between the certification body (or audit team leader) and the auditee, and before detailed planning begins. Their purpose is to make sure both parties share the same expectations, which reduces misunderstandings, disputes and surprises during the audit. The terms are usually documented in a contract or engagement letter, in line with ISO/IEC 17021-1, ISO/IEC 27006 and the guidance in ISO 19011. Key elements typically include: - Audit objectives: what the audit must achieve, such as initial certification, surveillance or recertification. - Audit scope: the ISMS boundaries, including sites, processes, organizational units, technologies and the Statement of Applicability. - Audit criteria: ISO/IEC 27001 requirements, applicable legal and contractual obligations, and the organization's own policies. - Audit duration: the number of audit days, often calculated with the ISO/IEC 27006 methodology based on the number of employees and the complexity of the ISMS. - Schedule and logistics: dates, locations, the use of remote auditing, working language and the facilities needed. - Audit team composition: auditor names, technical experts, observers and guides, giving the auditee the right to object to specific members. - Roles and responsibilities: who provides access to documents, people and premises, and who acts as the main point of contact. - Confidentiality and information security: how sensitive information will be handled, including any restrictions on access or copying. - Reporting and follow-up: report format, distribution, handling of nonconformities and timelines for corrective actions. - Commercial and legal conditions: fees, cancellation terms, liability, and procedures for appeals and complaints. The audit team leader must also confirm that the audit is feasible. This means checking that enough information, cooperation, time and resources are available. Clearly agreed terms protect auditor independence and impartiality, and they create a sound basis for an effective, credible ISO/IEC 27001 audit.
Terms of the Audit Engagement in ISO/IEC 27001 Audits: A Complete Guide for Lead Auditors
Introduction
Before an ISO/IEC 27001 certification audit can begin, the certification body and the organization must agree on the terms of the audit engagement. This agreement turns a request for certification into a defined, enforceable arrangement. It sets out what will be audited, against which requirements, by whom, over how many days, at what cost and under which rules.
In the PECB ISO/IEC 27001 Lead Auditor course, this topic belongs to the domain Preparing an ISO/IEC 27001 audit. It draws on three standards:
- ISO 19011, the guidelines for auditing management systems.
- ISO/IEC 17021-1, the requirements for bodies providing audit and certification of management systems.
- ISO/IEC 27006, the additional requirements for bodies certifying information security management systems (ISMS).
1. What Are the Terms of the Audit Engagement?
The terms of the audit engagement are the mutually agreed conditions under which the audit will be performed. In third-party certification they are formalized in a legally enforceable agreement between the certification body and its client (ISO/IEC 17021-1, clause 5.1.2). This is usually a contract, often supported by a certification proposal or quotation.
The terms define:
- The audit objectives: why the audit is performed, for example initial certification, surveillance or recertification.
- The audit scope: the physical locations, organizational units, activities, processes, information assets and time period covered. For an ISMS, the scope must align with the ISMS scope defined under clause 4.3 of ISO/IEC 27001.
- The audit criteria: the references against which conformity is checked. These include ISO/IEC 27001 requirements, the Statement of Applicability (SoA), applicable legal and contractual requirements, and the organization's own policies and procedures.
- Audit duration and dates: the auditor-days required, calculated using ISO/IEC 27006 and IAF MD 5 guidance.
- Audit team composition: the auditors, technical experts, observers or translators involved.
- Audit methods: for example on-site, remote or hybrid, and the sampling approach for multi-site organizations.
- Roles and responsibilities of the certification body and the client.
- Confidentiality and access to information.
- Commercial terms: fees, travel costs and payment conditions.
- Reporting and certification rules: how the report will be delivered, how the certification decision is made, and how certificates and marks may be used.
- Complaints, appeals, suspension and withdrawal conditions.
- Language of the audit and of the report.
2. Why Is It Important?
- Prevents misunderstandings: Clear terms avoid disputes over scope, cost, timing or deliverables. A common source of conflict is the client expecting a site or process to be certified that was never in the audit scope.
- Ensures feasibility: Agreeing terms forces both parties to confirm the audit can actually be done. This requires sufficient information, cooperation, time and resources, and access to evidence.
- Protects impartiality and credibility: ISO/IEC 17021-1 requires the certification body to manage risks to impartiality. Defined terms help ensure that consultancy is not mixed with auditing and that no conflicts of interest exist.
- Safeguards confidential information: ISMS audits often involve sensitive data, such as risk assessments, vulnerability reports and network diagrams. The terms set rules on how this information is accessed, handled and protected, including any restrictions the client places on certain records.
- Provides legal enforceability: A signed agreement establishes obligations for both sides. For example, the client must comply with certification requirements and notify the certification body of significant changes.
- Supports audit planning: The objectives, scope and criteria agreed here are the foundation of the audit plan, the Stage 1 review and the competence requirements for the audit team.
3. How It Works: The Process Step by Step
Step 1: Application and initial contact
The organization submits an application with the information needed to evaluate the request. ISO/IEC 17021-1, clause 9.1.1 expects this to include:
- the desired scope of certification;
- company details and locations;
- the number of personnel, including part-time staff and contractors;
- processes, outsourced processes and the applicable standards;
- any use of consultancy related to the management system.
For an ISMS, ISO/IEC 27006 adds factors such as:
- the complexity of the IT infrastructure;
- the number of servers, workstations and networks;
- reliance on outsourcing and cloud providers;
- the extent of development activities;
- the criticality of information processed;
- legal and regulatory requirements.
Step 2: Application review
The certification body reviews the application (clause 9.1.2) to confirm several points:
- The information is sufficient.
- Any differences in understanding have been resolved.
- The scope sought is clearly defined.
- The certification body has the competence and capability to perform the audit, including the relevant technical areas.
- Any threats to impartiality have been considered.
If the scope is unclear, for example because it excludes processes that clearly affect information security, the certification body must clarify it before accepting the engagement.
Step 3: Determining audit time
Audit duration is calculated from the number of persons doing work under the organization's control. The baseline figure is then adjusted for ISMS complexity factors and business or organizational factors, according to ISO/IEC 27006 Annex tables and IAF MD 5. Reductions and increases must be justified and documented. Auditor-days cannot be reduced simply to win a contract.
Step 4: Multi-site and sampling considerations
For organizations with several sites, the certification body decides whether sampling is permitted under IAF MD 1 and ISO/IEC 27006. It then documents the sampling approach in the audit programme.
Step 5: Defining the audit programme
For initial certification, the audit programme covers the full three-year cycle:
- a two-stage initial audit (Stage 1 and Stage 2);
- surveillance audits in the first and second years;
- a recertification audit before the certificate expires.
Step 6: Proposal and agreement
The certification body issues a proposal, and both parties sign a legally enforceable agreement. Typical client obligations include:
- implementing the relevant requirements;
- providing access to documents, records, personnel and locations;
- making provisions for observers, such as accreditation body assessors;
- informing the certification body of changes;
- using certificates and marks correctly.
Step 7: Feasibility confirmation and audit team appointment
Following ISO 19011 (clause 6.2), the audit team leader confirms the audit is feasible. This means checking that:
- sufficient and appropriate information is available for planning and conducting the audit;
- the auditee cooperates adequately;
- adequate time and resources are available.
If the audit is not feasible, the team leader proposes an alternative to the audit client, for example postponing it or changing the scope. The certification body then appoints a competent team and gives the client the team members' names, allowing the client to object to any appointment on legitimate grounds such as a conflict of interest.
Step 8: Establishing contact with the auditee
The audit team leader then makes first contact with the auditee to:
- confirm communication channels and representatives;
- confirm authority to conduct the audit;
- discuss objectives, scope, criteria, methods and dates;
- request access to documented information;
- identify areas of concern, safety or security rules, and confidentiality restrictions;
- agree on observers and guides.
Key distinction: client versus auditee
- The audit client is the organization or person requesting the audit.
- The auditee is the organization being audited.
In certification they are usually the same organization. In second-party audits, such as a customer auditing a supplier, they differ.
4. Common Issues and How They Are Handled
- Scope too narrow or misleading: The certification body must ensure the scope does not mislead stakeholders, for example by excluding a data centre that processes in-scope information. It should challenge unjustified exclusions.
- Confidential information the client refuses to share: The certification body assesses whether the ISMS can still be adequately audited without it. If not, the audit may need to be postponed until access is possible (ISO/IEC 27006 addresses access to organizational records).
- Client requests a reduced audit time: This is acceptable only if justified by documented factors. Commercial pressure is not a valid reason.
- Prior consultancy by the certification body or its related bodies: This is a threat to impartiality. The certification body must not certify an ISMS it helped implement, and ISO/IEC 17021-1 sets cooling-off expectations for individuals who provided consultancy to the client.
- Changes after signing: Changes to scope, sites or headcount require the application review to be repeated and the audit time to be adjusted.
Exam Tips: Answering Questions on Terms of the Audit Engagement
1. Know which standard says what.
- ISO 19011 provides guidance on establishing contact and determining feasibility.
- ISO/IEC 17021-1 sets requirements for the application, application review, audit time, multi-site sampling and the legally enforceable agreement.
- ISO/IEC 27006 adds ISMS-specific factors, such as audit time adjustments and IT complexity.
When an answer can be supported by a standard reference, cite it.
2. Remember the core trio: objectives, scope and criteria.
Many questions test whether you can tell these apart:
- Objectives are why the audit is performed.
- Scope is the extent and boundaries of the audit.
- Criteria are the references used to judge conformity.
A frequent trap is presenting ISO/IEC 27001 as the 'scope'. It is a criterion.
3. Read scenario questions for red flags.
PECB exams are scenario-based. Look for clues such as:
- the client excluding a critical process;
- the certification body having provided consultancy;
- insufficient information in the application;
- pressure to cut audit days;
- refusal to share records.
For each one, ask what the certification body or audit team leader should do before accepting or proceeding.
4. Choose the answer that preserves impartiality, competence and feasibility.
When options compete, the correct answer usually:
- clarifies the scope with the client;
- documents justifications;
- confirms feasibility;
- declines or postpones the engagement when requirements cannot be met.
Answers that 'proceed anyway to satisfy the client' are almost always wrong.
5. Distinguish the certification body's role from the audit team leader's role.
- The certification body reviews the application, determines audit time, defines the audit programme and signs the agreement.
- The audit team leader confirms feasibility, establishes contact with the auditee, and prepares the audit plan.
Questions often hinge on 'who is responsible'.
6. Remember the audit cycle.
Initial certification uses a two-stage audit. It is followed by annual surveillance audits and recertification within a three-year cycle. Terms of engagement typically cover the entire cycle, not just one audit.
7. Treat confidentiality as central in ISMS audits.
Expect questions on handling sensitive information. Good answers mention:
- non-disclosure commitments;
- agreed methods for reviewing restricted records, for example on-site only or viewed but not copied;
- secure handling of audit evidence;
- assessing whether restrictions prevent a reliable audit conclusion.
8. Structure essay or open answers clearly.
In written questions, use this structure:
(a) identify the issue;
(b) cite the relevant requirement or guideline;
(c) state the action to take;
(d) explain the consequence of not acting, such as invalid certification, loss of credibility or misleading scope.
9. Use precise terminology.
Say 'audit client', 'auditee', 'audit criteria', 'audit programme', 'audit plan', 'legally enforceable agreement' and 'feasibility of the audit'. Precise wording signals competence to examiners.
10. Avoid common mistakes.
- Confusing the audit programme (multi-audit, cycle level) with the audit plan (single audit activities).
- Assuming audit time can be freely negotiated.
- Forgetting that scope changes require a new application review.
- Overlooking outsourced processes and cloud services when discussing ISMS scope.
Summary
The terms of the audit engagement form the contractual and practical foundation of every ISO/IEC 27001 certification audit. They:
- define objectives, scope, criteria, duration, team, methods, confidentiality, responsibilities and certification rules;
- are established through application, application review, audit time calculation, audit programme definition and a legally enforceable agreement;
- are then confirmed by the audit team leader through feasibility checks and initial contact with the auditee.
In the exam, always favour answers that ensure clarity, feasibility, impartiality and compliance with ISO/IEC 17021-1, ISO/IEC 27006 and ISO 19011.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!