Learn Conducting an ISO/IEC 27001 Audit (ISO 27001 LA) with Interactive Flashcards
Master key concepts in Conducting an ISO/IEC 27001 Audit through our interactive flashcard system. Click on each card to reveal detailed explanations and enhance your understanding.
Stage 1 Audit Objectives and Activities
In ISO/IEC 27001 certification, the Stage 1 audit is the first part of the initial certification audit. It is governed by ISO/IEC 17021-1 and ISO/IEC 27006. Its main purpose is to decide whether the organization is ready for the Stage 2 audit, where the actual effectiveness of the information security management system (ISMS) is evaluated. Stage 1 does not award certification.
Key objectives include:
(1) Reviewing the auditee's documented information, such as the ISMS scope, information security policy and objectives, risk assessment and risk treatment methodology and results, the Statement of Applicability (SoA), and the documentation required by clauses 4 to 10.
(2) Evaluating site-specific conditions and holding discussions with personnel to judge preparedness for Stage 2.
(3) Reviewing the organization's understanding of the standard's requirements, especially the identification of key performance, significant aspects, processes, objectives and how the ISMS operates.
(4) Collecting information on scope, locations, processes, technologies, and applicable legal, regulatory and contractual requirements.
(5) Confirming that internal audits and management reviews are planned or have been performed, and that the level of implementation shows readiness.
(6) Reviewing resource allocation and agreeing on the details of Stage 2.
Typical activities include an opening meeting, document review, interviews with top management and the ISMS manager, a review of the scope boundaries and justified exclusions of Annex A controls, verification that the SoA is consistent with the risk treatment plan, and sometimes a site tour. Stage 1 may be performed on site or remotely, depending on risk and complexity.
The output is a documented Stage 1 report. It identifies areas of concern that could be classified as nonconformities during Stage 2, confirms or adjusts the scope, and supports planning of the Stage 2 audit, including duration, team competence and sampling. The lead auditor also decides whether to proceed to Stage 2 or to postpone it until concerns are resolved. The time between Stage 1 and Stage 2 should allow these issues to be addressed.
Documented Information Evaluation Criteria
In an ISO/IEC 27001 audit, documented information evaluation criteria are the benchmarks a lead auditor uses to judge whether an organization's ISMS documentation is adequate, effective, and conforms to the standard. The evaluation usually begins during the Stage 1 audit and continues during Stage 2, where auditors check that documented processes are actually implemented. The criteria come mainly from ISO/IEC 27001 clause 7.5 (Documented Information) and from ISO 19011 clause 6.3.1, which guides auditors in reviewing documentation.
ISO 19011 identifies four core criteria. Completeness means all expected content is present, including mandatory items such as the ISMS scope, information security policy, risk assessment and risk treatment processes, Statement of Applicability, information security objectives, and evidence of competence, monitoring, internal audits, management reviews, and corrective actions. Correctness means the content is accurate and matches reliable sources such as the risk register and actual practice. Consistency means documents agree with each other and with related records. For example, controls marked as applicable in the Statement of Applicability should appear in risk treatment plans. Currentness means the content is up to date and reflects the organization's present context, risks, and technology.
From clause 7.5, auditors also check several further criteria. Documents should have proper identification and description, such as a title, date, author, and reference number. They should use an appropriate format and media. Evidence should show that documents have been reviewed and approved for suitability and adequacy. Auditors also examine control of documented information: availability where needed, protection of confidentiality and integrity, distribution, access, storage, version control, retention, and disposal. Documents of external origin, such as legal requirements and supplier contracts, must also be identified and controlled.
Auditors consider whether the extent of documentation suits the organization's size, complexity, and risks, since ISO/IEC 27001 does not demand excessive documentation. Weaknesses found are recorded as potential nonconformities or areas of concern. These findings help determine Stage 2 readiness and shape the audit plan and sampling strategy, giving an objective, evidence-based conclusion on the ISMS.
Stage 1 Versus Stage 2 Audit
In ISO/IEC 27001 certification, the initial certification audit is conducted in two stages, as required by ISO/IEC 17021-1 and ISO/IEC 27006. Stage 1 is mainly a documentation review and readiness assessment. The auditor checks whether the organization's information security management system (ISMS) has been designed in line with the standard. Key activities include reviewing the ISMS scope, information security policy, risk assessment and risk treatment methodology, Statement of Applicability, internal audit results, and management review records. The auditor also learns about the organization's context, sites, processes, and legal and regulatory requirements. They confirm that the ISMS has been operating long enough to generate evidence. Stage 1 is often performed partly on-site and identifies areas of concern that could become nonconformities in Stage 2. The output is a Stage 1 report that confirms readiness and informs Stage 2 planning, including resources, sampling, and timing.
Stage 2 is the main evaluation of implementation and effectiveness. It is conducted on-site, or remotely where justified, and determines whether the organization actually operates its ISMS as documented and whether its controls are effective. Auditors interview personnel, observe activities, examine records, and sample evidence across clauses 4 to 10 and the Annex A controls selected in the Statement of Applicability. They verify that risks are treated, objectives are monitored, incidents are managed, and continual improvement is taking place. Findings are graded as major nonconformities, minor nonconformities, or opportunities for improvement.
The key difference is focus. Stage 1 asks whether the system is designed correctly and ready for audit. Stage 2 asks whether it is implemented effectively and conforms in practice. Significant Stage 1 concerns should be resolved before Stage 2, and the interval between the stages should allow time for corrections. Stage 2 leads to a certification recommendation by the audit team leader once any major nonconformities have been closed and correction plans for minor nonconformities have been accepted.
The Opening Meeting
The opening meeting is the formal start of the on-site (or remote) audit activities. ISO 19011 (clause 6.4.3) and ISO/IEC 17021-1 (clause 9.4.2, for certification audits) both describe it. The audit team leader chairs it, and it is usually held with the auditee's top management and, where appropriate, the people responsible for the functions or processes to be audited. Attendance should be recorded. The meeting is normally short, often 15 to 30 minutes, but it sets the tone for the whole audit.
Its main purposes are to:
- confirm that all participants agree to the audit plan
- introduce the audit team and explain their roles
- ensure that all planned audit activities can be carried out
A typical agenda includes:
1. Introductions of the audit team, guides, observers and auditee representatives.
2. Confirmation of the audit objectives, scope and criteria. For ISO/IEC 27001 this includes the ISMS scope, the Statement of Applicability and any exclusions.
3. Confirmation of the audit plan, timetable, interviews, sites and any changes.
4. Explanation of audit methods, including sampling. Because sampling is used, there is a risk that some nonconformities will not be detected.
5. Communication channels and the language of the audit.
6. Confidentiality and information security arrangements. These are especially important in an ISMS audit, for example access to sensitive records, systems and secure areas.
7. Health, safety, security and emergency arrangements for the audit team.
8. Availability of resources and facilities, and the role of guides.
9. How findings will be graded and reported, such as major or minor nonconformities and opportunities for improvement.
10. Conditions under which the audit may be terminated early.
11. Arrangements for the closing meeting, and information on complaints and appeals.
The lead auditor should invite questions and clarify concerns. A well-run opening meeting builds trust, reduces anxiety and confirms logistics. It also demonstrates the auditor's professionalism, impartiality and evidence-based approach, which are key competencies assessed in the ISO/IEC 27001 Lead Auditor role.
Stage 2 Audit Objectives and Activities
In ISO/IEC 27001 certification, the Stage 2 audit is the main assessment that follows the Stage 1 readiness review. It is guided by ISO/IEC 17021-1 and ISO/IEC 27006. Its central objective is to evaluate the implementation and effectiveness of the organization's Information Security Management System (ISMS), confirming that it conforms to all requirements of ISO/IEC 27001 and achieves the organization's information security policy and objectives. Whereas Stage 1 focuses on documentation and preparedness, Stage 2 verifies that documented processes are actually practiced, maintained and producing intended results.
Key objectives include: confirming adherence to the organization's own policies, objectives and procedures; verifying that the ISMS meets clauses 4 to 10 of the standard; assessing whether risk assessment and risk treatment processes are applied consistently; confirming that controls in the Statement of Applicability are implemented effectively; and determining whether the ISMS can be recommended for certification.
Typical activities begin with an opening meeting to confirm scope, audit plan, methods and logistics. Auditors then gather objective evidence through interviews with top management and staff, observation of activities, and review of records. They examine information security objectives, performance monitoring and measurement, internal audit results, management review outputs, incident handling, and corrective actions. Sampling is used to test Annex A controls, such as access control, supplier security, cryptography and business continuity arrangements. Auditors also confirm that issues identified in Stage 1 have been addressed and evaluate leadership commitment and continual improvement.
Findings are classified as major nonconformities, minor nonconformities, observations or opportunities for improvement. Major nonconformities must be corrected, and their correction verified, before certification can be granted. Minor nonconformities normally require an accepted corrective action plan. The audit concludes with a closing meeting presenting findings and the recommendation, followed by a formal audit report submitted to the certification body for an independent certification decision.
Communication During the Audit
Communication during the audit is a key activity in conducting an ISO/IEC 27001 audit. It follows the guidance in ISO 19011 and, for certification audits, the requirements of ISO/IEC 17021-1. Its purpose is to keep the audit on track, transparent and effective. The communication arrangements, including channels, contacts, language and reporting frequency, are usually confirmed during the opening meeting.
There are three main lines of communication. First, within the audit team, members should meet regularly, often in daily briefings. They exchange information, assess progress, compare emerging findings, resolve conflicting evidence and reassign work if needed. This keeps the team's conclusions consistent and makes sure the full scope is covered. Second, with the auditee, the audit team leader should periodically report progress, significant findings and any concerns. This often happens at end-of-day meetings. It prevents surprises at the closing meeting and gives the auditee a chance to provide more evidence or clarify misunderstandings. Third, with the audit client, the client must be informed of progress and significant issues where appropriate, such as when the auditee and the client are different parties.
Some situations need immediate escalation. Evidence of an immediate and significant risk should be reported without delay to the auditee and, if appropriate, the audit client. An example is an active security breach or a critical vulnerability exposing sensitive information. Concerns found outside the audit scope should be recorded and passed to the team leader, who decides whether to communicate them. If the available evidence shows that the audit objectives cannot be achieved, the team leader must report the reasons to the client and auditee. Possible causes include restricted access, unavailable personnel or missing documented information. The parties then agree on actions such as changing the audit plan, adjusting the objectives or scope, or ending the audit. Any change to scope must be reviewed and approved by the relevant parties.
All communication must be professional, objective and confidential. Important communications should be documented. Guides and observers must not influence the audit.
Guides and Observers
In an ISO/IEC 27001 audit, guides and observers are people who accompany the audit team without being part of it. Their roles are addressed in ISO 19011:2018 (clause 6.4.7), which certification bodies apply alongside ISO/IEC 17021-1 and ISO/IEC 27006. A Lead Auditor must manage both roles so the audit stays objective, efficient and secure.
Guides are usually appointed by the auditee to help the audit team. They act at the request of the audit team leader or the assigned auditor and do not evaluate evidence. Their typical duties are to:
- arrange contacts and schedule interviews with process owners and control operators;
- arrange access to specific sites, server rooms, secure areas or information systems;
- make sure the team knows and follows site safety, security and confidentiality rules, which is especially important where classified information or restricted zones are involved;
- witness the audit on behalf of the auditee;
- clarify information or help collect it, for example by locating records, logs or documented procedures.
Observers watch the audit but take no part in it. They may come from the auditee, the audit client, a regulator, an accreditation body assessing the certification body, or the certification body itself (such as trainee auditors or witness assessors). Their presence must be agreed in advance by the audit team leader and the auditee, and by the audit client where relevant. Observers must not influence or interfere with the audit. They are bound by the same health, safety, security and confidentiality arrangements as everyone else, and they may need to sign a non-disclosure agreement.
The Lead Auditor keeps control throughout. If an observer or guide compromises impartiality or the auditee's information security, or disrupts interviews, the Lead Auditor may restrict or refuse their participation in particular activities. Both roles should be clarified at the opening meeting. Their presence should also be recorded, which supports transparency, confidence in the findings and the integrity of the certification process.
Conflict Resolution During an Audit
Conflict resolution during an ISO/IEC 27001 audit is the set of skills and practices an auditor, especially the audit team leader, uses to handle disagreements professionally while preserving audit objectivity, evidence integrity and the relationship with the auditee. Guidance in ISO 19011 and ISO/IEC 27007 stresses integrity, fair presentation, due professional care, independence and an evidence-based approach, and these principles form the basis for managing conflict.
Conflicts commonly arise when auditees dispute nonconformities, withhold or delay access to information or personnel, become defensive or hostile during interviews, or challenge the audit scope, criteria or schedule. Conflicts can also occur within the audit team, for example over how to grade a finding, or between the auditor and technical experts.
Effective resolution starts with prevention. The auditor confirms scope, criteria, schedule, confidentiality rules and communication channels during the opening meeting, and explains that findings are based on objective evidence rather than personal opinion. During the audit, the auditor stays calm and neutral, listens actively, asks open questions and acknowledges the auditee's concerns without giving up the facts. Any disagreement should be tied back to specific requirements of ISO/IEC 27001, the Statement of Applicability or the organization's own policies, supported by verifiable evidence. Findings should be discussed in daily briefings so there are no surprises at the end.
If an auditee provides new evidence, the auditor must review it objectively and revise the finding if it is justified. If disagreement persists, the team leader should try to resolve it before the closing meeting. Where agreement cannot be reached, diverging opinions are recorded in the audit report. Serious obstacles, such as denied access or risks to the auditor's safety or impartiality, are escalated to the audit client or certification body, and may lead to modifying or terminating the audit.
Ultimately, the auditor must remain firm on evidence, flexible in communication and respectful throughout, so that the audit conclusions stay credible and defensible.
Audit Interviews
In an ISO/IEC 27001 audit, interviews are one of the main ways a Lead Auditor gathers objective evidence, alongside document review and observation. ISO 19011 guidance treats interviews as a way to confirm that the Information Security Management System (ISMS) is understood, implemented, and effective in daily operations, not just documented. The aim is to check that clauses 4 to 10 and the selected Annex A controls are actually practised by people at all levels.
Preparation is essential. The auditor reviews the Statement of Applicability, risk assessment, risk treatment plan, and previous audit results. This helps identify whom to interview, such as top management, the ISMS manager, risk owners, IT administrators, HR staff, and ordinary end users. The audit plan schedules interviews during normal working hours and, where possible, at the interviewee's workplace.
When conducting the interview, the auditor should put the interviewee at ease, introduce themselves, and explain the purpose and scope. The auditor relies mainly on open questions such as 'How do you...?', 'Show me...', and 'What happens when...?'. Closed questions are used to confirm facts, while leading questions are avoided. Active listening, neutral body language, and patience encourage honest answers. The auditor asks people to describe their actual work, for example how they report a security incident, grant access rights, or handle backups, rather than reciting policy.
Evidence obtained through interviews must be verified. Statements are cross-checked against records, system configurations, logs, and direct observation, a practice known as triangulation. The auditor takes clear notes that capture names or roles, dates, and specific facts. These notes support traceable findings.
At the end of the interview, the auditor summarises key points, clarifies any misunderstandings, and thanks the interviewee. Possible nonconformities are noted for later confirmation rather than argued on the spot. Throughout the process, auditors stay impartial, respect cultural differences and confidentiality, and adapt their techniques for remote audits. This keeps the conclusions fair, evidence-based, and reliable.
Documented Information Review
In an ISO/IEC 27001 audit, documented information review is the auditor's examination of the auditee's ISMS documents and records. ISO 19011 (clause 6.3.1) frames it as part of preparing audit activities. ISO/IEC 27006 frames it as a core element of the Stage 1 audit in certification. Its purpose is to judge whether the documented ISMS conforms to the standard's requirements and is adequate to support the audit objectives, before or alongside on-site evidence gathering.
The Lead Auditor checks that the documented information required by ISO/IEC 27001:2022 exists, is current and is controlled under clause 7.5. Key items include:
- the ISMS scope (4.3)
- the information security policy (5.2)
- the risk assessment and risk treatment processes (6.1.2, 6.1.3)
- the Statement of Applicability, including justifications for inclusions and exclusions of Annex A controls
- the risk treatment plan
- information security objectives (6.2)
- evidence of competence (7.2)
- operational planning and control records (8.1)
- risk assessment and treatment results (8.2, 8.3)
- monitoring and measurement results (9.1)
- internal audit programme and results (9.2)
- management review results (9.3)
- nonconformities and corrective actions (10.2)
The auditor evaluates three things:
- **Completeness:** are all required elements present?
- **Correctness:** do the documents accurately reflect requirements and the organization's context?
- **Consistency:** do the scope, risk assessment, SoA and policies align with each other?
The auditor also considers document control: version identification, approval, availability, protection, retention and disposition.
The review informs audit planning. It reveals areas of concern, the organization's readiness for Stage 2, and where sampling should focus. It also helps auditors prepare checklists and identify key processes and locations. If documents are inadequate, the Lead Auditor decides whether the audit can continue, should be postponed, or requires the auditee to resolve issues. Any concerns are communicated to the audit client and auditee.
Documented information review is not limited to the opening stages. Throughout the audit, auditors compare documents against actual practice through interviews and observation. The aim is to verify that the ISMS is implemented and effective, not merely written. A well-documented system that is not followed constitutes a nonconformity.
Observation and Technical Verification
In an ISO/IEC 27001 audit, Observation and Technical Verification are two key methods for collecting objective audit evidence, alongside interviews and document review, as described in ISO 19011 and taught in Lead Auditor training. Observation means the auditor directly watches activities, processes, and physical conditions as they happen to confirm that documented practices are actually followed. Examples include checking that visitors are registered and escorted, employees wear badges, screens lock when unattended, clean desk rules are respected, server rooms are access controlled, and backup or change management procedures are carried out as described. Observation gives strong evidence because the auditor sees reality firsthand. However, it shows only a snapshot in time, and people may behave differently when watched, so auditors should combine it with other evidence. Technical Verification means examining information systems and technical controls to confirm they are configured and operating effectively. Examples include reviewing firewall rules, access rights and privileged accounts, password and lockout settings, patch levels, antivirus status, encryption settings, logging and monitoring, and vulnerability scan results. A common technique is sampling, such as comparing the HR list of leavers with active user accounts to verify timely access removal. Auditors usually ask the auditee to demonstrate or extract the information rather than operate systems themselves, use read-only access where possible, avoid disrupting operations, and protect the confidentiality of the data they see. Technical verification may require a technical expert on the audit team if the auditor lacks specific competence. Both methods support triangulation: what people say in interviews and what documents state is confirmed by what the auditor sees and verifies. Evidence must be recorded accurately in working papers, noting what was observed or tested, where, when, and with whom, so that conclusions and any nonconformities against clauses or Annex A controls are traceable, verifiable, and defensible.
Audit Sampling Methods
In an ISO/IEC 27001 audit, a Lead Auditor rarely has time to examine every record, asset, user account or change ticket. Audit sampling lets the auditor examine a representative subset of a population and draw conclusions about whether the Information Security Management System (ISMS) conforms and operates effectively. ISO 19011 (Annex A) and ISO/IEC 27007 guide this practice. Sampling happens when a population is too large to examine fully, such as access requests, incident logs, risk treatment records or supplier contracts. Because it covers only part of the population, sampling carries risk: the sample may not be representative, and the conclusions may be wrong. The auditor manages this risk by choosing appropriate methods and documenting the rationale. There are two main approaches. Judgement-based sampling relies on the auditor's competence and experience. The auditor deliberately selects items based on risk, previous audit findings, critical assets, recent changes, high-privilege accounts or areas of known weakness. It suits ISMS audits well because it focuses effort where information security risk is greatest. However, its results cannot be extrapolated statistically. Statistical sampling uses methods such as random, systematic (every nth item), stratified (dividing the population into subgroups such as departments or sites) or cluster sampling. It allows conclusions with a defined confidence level, but requires a sufficiently large, homogeneous population and a clear sampling plan. Attribute sampling, which tests whether a control was performed (yes or no), is the most common type. When designing a sample, the auditor considers the audit objectives, population size and nature, risk and control criticality, required confidence level, tolerable error rate and the reliability of the auditee's records. Multi-site certification audits also follow IAF MD1 rules for site sampling. Finally, the Lead Auditor must record the sampling method, sample size and selection criteria in the working papers. This ensures audit findings are traceable, objective, evidence-based and defensible, supporting a reliable certification decision.
Audit Checklists: Advantages and Disadvantages
In ISO/IEC 27001 auditing, an audit checklist is a working document that auditors prepare during audit planning, as recommended by ISO 19011. It lists the questions, requirements, and evidence to be examined against the clauses of ISO/IEC 27001 (Clauses 4 to 10) and the Annex A controls listed in the organization's Statement of Applicability. Checklists are useful tools, but they must be used carefully.
Advantages: 1) Structure and coverage: they make sure every relevant clause, control, and process within the audit scope is addressed, which reduces the risk of overlooking requirements. 2) Preparation: building a checklist forces the auditor to study the ISMS documentation, risk assessment, and SoA in advance. 3) Consistency: they support a uniform approach across audit team members and across audits, which helps with sampling and with comparing results over time. 4) Time management: they help the auditor follow the audit plan and divide interview time sensibly. 5) Evidence recording: they give a convenient place to note objective evidence, interviewees, documents sampled, and preliminary findings, which supports traceable conclusions and reporting. 6) Training aid: they help less experienced auditors build confidence.
Disadvantages: 1) Rigidity: auditors may follow the checklist mechanically and miss emerging risks or issues outside the listed questions. 2) Closed questioning: yes/no checklists discourage the open questions needed to gather real evidence. 3) Process blindness: they can encourage clause-by-clause auditing instead of the process approach and risk-based thinking that ISO/IEC 27001 emphasizes. 4) Generic content: off-the-shelf checklists may not reflect the organization's context, risks, or technology. 5) Interpersonal barrier: reading from a list can make interviews feel like interrogations and weaken rapport. 6) False assurance: a fully ticked checklist does not prove the ISMS is effective.
Best practice: treat the checklist as an aid to memory rather than a script. Tailor it to the auditee, and follow audit trails wherever the evidence leads.
Audit Test Plans
In an ISO/IEC 27001 audit, an audit test plan is a structured working document that the lead auditor and audit team prepare before on-site activities, usually for the Stage 2 audit. It defines exactly how each requirement of the standard and each applicable Annex A control will be checked. It turns the general audit plan, which covers scope, schedule, auditees, and logistics, into specific steps for collecting objective evidence. ISO/IEC 19011 calls these work documents, and the PECB Lead Auditor methodology treats them as essential preparation. A typical test plan includes several elements. It states the audit objective and audit criteria, such as clause 6.1.2 on risk assessment or control A.5.15 on access control. It sets out the audit procedures to be used: documented information review, interviews, observation, technical verification, analysis, and sampling. It describes the expected evidence, such as policies, records, logs, and configurations. It also identifies the sampling method and sample size, the responsible auditor, the auditee or process owner, and the time allocated. Space is left to record findings, evidence references, and conclusions of conformity or nonconformity. Auditors design tests based on risk, the Statement of Applicability, the results of the Stage 1 documentation review, and the organization's context. For example, to test user access reviews, the auditor may ask for the access management procedure, interview the IT manager, select a sample of review records from the past year, and check that revoked accounts were actually disabled in the system. Test plans bring consistency, traceability, and full coverage across the audit team. They help auditors manage time and avoid missing critical areas. They also support impartial, evidence-based conclusions. They should stay flexible, however, so that auditors can follow audit trails when new information or risks emerge. Completed test plans become part of the audit records and support the audit report and certification decision.
Audit Working Papers
Audit working papers are the documents an ISO/IEC 27001 auditor prepares and uses to plan, conduct, record and support the outcome of an Information Security Management System (ISMS) audit. ISO 19011 guidance recognises them as essential tools for consistency, traceability and objectivity. During audit preparation, the lead auditor and the audit team build working papers from the audit objectives, scope and criteria. These criteria include ISO/IEC 27001 clauses 4 to 10, the Annex A controls, the Statement of Applicability, the risk assessment and treatment results, and the organisation's own policies. Typical working papers include the audit plan, checklists or audit protocols, sampling plans, interview question sets, evidence-recording forms, attendance lists for opening and closing meetings, and forms for nonconformity reports and observations. Checklists help auditors cover the required clauses and controls systematically, but they should not restrict professional judgement. Auditors should follow audit trails wherever the evidence leads. During the audit, working papers capture objective evidence. This includes who was interviewed, which records, logs, configurations or procedures were examined, sample sizes, dates, locations and observations of practice. Notes should be factual, specific and verifiable, for example by citing document identifiers, version numbers or ticket references. This allows findings to be traced back to evidence and audit criteria. Good working papers support the evaluation of conformity, the grading of nonconformities as major or minor, team reviews, and preparation of the audit report and conclusions. They also enable continuity between Stage 1 and Stage 2 audits and later surveillance audits. Because working papers often contain sensitive information about vulnerabilities, assets and security incidents, auditors must protect their confidentiality, integrity and availability. They must be handled under the certification body's procedures and the agreed retention requirements, and they must not be disclosed without authorisation. In summary, audit working papers turn an audit from opinion into evidence-based, defensible and repeatable assurance.
Corroboration and Evaluation of Evidence
In an ISO/IEC 27001 audit, corroboration and evaluation of evidence are central to the evidence-based approach described in ISO 19011 and ISO/IEC 27007. Audit evidence consists of records, statements of fact or other information that is relevant to the audit criteria and verifiable. A Lead Auditor must make sure findings rest on reliable, objective evidence rather than assumptions or a single unverified claim.
Corroboration means confirming information by checking it against independent sources or different audit methods. This is often called triangulation. An auditor normally combines three techniques: interviewing personnel, observing activities, and reviewing documents, records and technical configurations. For example, an IT manager may say that user access rights are reviewed quarterly, as Annex A control 5.18 expects. The auditor corroborates this by sampling review records, checking system logs for removed accounts, and perhaps confirming that a recent leaver's account was disabled promptly. Information from interviews alone is weaker evidence. When independent sources agree, confidence in the evidence rises. When they contradict each other, the auditor must investigate further before drawing a conclusion.
Evaluation of evidence means comparing the collected, verified evidence against the audit criteria to produce audit findings. The criteria include the clauses of ISO/IEC 27001, the organization's ISMS policies and procedures, the Statement of Applicability, and legal or contractual requirements. The auditor judges whether the evidence is sufficient in quantity, often based on sampling, and appropriate in quality, meaning relevant and reliable. Findings are then classified as conformity, major nonconformity, minor nonconformity, or an opportunity for improvement.
Key principles include objectivity, professional skepticism, traceability of evidence, and awareness of the uncertainty that sampling introduces. Nonconformities must be clearly stated, supported by verifiable evidence, and linked to the specific requirement that was not met. Done properly, corroboration and evaluation lead to credible, defensible audit conclusions. They also support fair certification decisions and give the auditee useful input for improving its information security management system.
Drafting Audit Findings
In an ISO/IEC 27001 audit, drafting audit findings is the step where the auditor turns collected evidence into clear, defensible statements about how well the information security management system (ISMS) conforms to the audit criteria. Following ISO 19011 and ISO/IEC 27007 guidance, findings result from evaluating objective evidence against criteria such as ISO/IEC 27001 clauses 4 to 10, applicable Annex A controls, the Statement of Applicability, the organization's own policies, and legal or contractual obligations. Findings fall into three main types. A conformity confirms that a requirement is met. A nonconformity is the non-fulfilment of a requirement. It is usually graded as major when it represents a systemic breakdown, a missing required process, or a failure that undermines the ISMS's ability to achieve its intended outcomes. It is graded as minor when it is an isolated lapse that does not compromise the system overall. An opportunity for improvement highlights a potential weakness or a better practice without being a breach. A well-drafted nonconformity normally has three parts. The first is the requirement, which cites the exact clause or control. The second is the objective evidence, which records what was seen, heard, or reviewed, including document references, records, dates, locations, and the roles of interviewees. The third is the statement of nonconformity, which explains concisely how the evidence fails to meet the requirement. Findings must be factual, verifiable, traceable, and impartial. They should be written in neutral language that avoids blame, opinion, or assumptions, and they should not prescribe solutions, because corrective action is the auditee's responsibility. Auditors should check that the sampled evidence is sufficient, and the audit team should review findings together to ensure consistency and correct grading and to remove duplicates. Draft findings should be discussed with the auditee during the audit or at the closing meeting so that facts can be confirmed and misunderstandings resolved. Clear, accurate findings support credible audit conclusions, enable effective root cause analysis and corrective action, and form the foundation of the audit report and the certification decision.
Major and Minor Nonconformities
In an ISO/IEC 27001 certification audit, a nonconformity is the non-fulfilment of a requirement. That requirement may come from the standard's clauses 4 to 10, the organization's own ISMS documentation, the Statement of Applicability and Annex A controls it has chosen, or legal and contractual obligations. Following ISO/IEC 17021-1 and ISO/IEC 27006, auditors grade each nonconformity as major or minor based on objective evidence.
A Major Nonconformity is one that affects the ability of the ISMS to achieve its intended results. Typical triggers include:
- the total absence or complete breakdown of a required process
- significant doubt that effective process control is in place
- several minor nonconformities against the same requirement, which together show a systemic failure
Examples include no information security risk assessment or risk treatment process, no internal audit programme, no management review, or a missing or meaningless Statement of Applicability. A major nonconformity prevents the lead auditor from recommending certification. During surveillance, it can lead to suspension. The organization must perform a correction, analyse the root cause and implement corrective action. The certification body must then verify this, often through a follow-up or special audit, within a defined period, commonly around 90 days.
A Minor Nonconformity does not affect the ISMS's ability to achieve its intended results. It is usually an isolated lapse or a partial implementation within an otherwise functioning system. Examples include one overdue access rights review, a single missing competence record, or an outdated document version in use. Certification can still be recommended once the auditor has accepted the organization's corrective action plan. Its effectiveness is normally verified at the next surveillance audit.
Lead auditors must write each nonconformity clearly. A good statement identifies the requirement, the objective evidence observed and the nature of the gap, so that it is factual, traceable and reproducible. Nonconformities differ from observations and opportunities for improvement, which are not breaches of requirements. Correct grading keeps the audit fair, consistent and credible, and it drives genuine improvement in information security.
Nonconformity Reports
In an ISO/IEC 27001 audit, a Nonconformity Report (NCR) is the formal document an auditor uses to record a failure to fulfil a requirement. The requirement may come from the ISO/IEC 27001 standard, the organization's own Information Security Management System (ISMS) policies and procedures, contractual obligations, or applicable legal and regulatory requirements. Under ISO 19011 and ISO/IEC 17021-1 principles, every nonconformity must be based on objective, verifiable audit evidence, not opinion or assumption.
A well-written NCR has three core elements. First, the requirement: the specific clause or control that applies, for example Clause 9.2 Internal Audit or Annex A control 5.15 Access Control. Second, the evidence: factual, traceable observations such as document references, records reviewed, interviewees' roles, dates and sample sizes. Third, the statement of nonconformity: a clear, concise description of what was not fulfilled. The NCR should be understandable to someone who was not present during the audit.
Nonconformities are typically graded. A major nonconformity is the absence or total breakdown of a required process, or a situation that raises significant doubt about the ISMS's ability to achieve its intended outcomes. Examples include no risk assessment performed or no management review conducted. A minor nonconformity is an isolated or partial lapse that does not undermine the system's overall effectiveness. Auditors may also record observations or opportunities for improvement, which are not nonconformities.
The Lead Auditor reviews all NCRs for accuracy and consistency, and presents them at the closing meeting so the auditee understands and acknowledges them. The auditee is then responsible for correction (immediate fixing), root cause analysis, and corrective action to prevent recurrence, as required by Clause 10.2. In certification audits, major nonconformities usually must be resolved and verified, sometimes through a follow-up visit, before certification is granted. Minor nonconformities typically require an accepted action plan, which is verified at the next surveillance audit. Auditors must remain impartial and avoid prescribing solutions.
The Benefit of the Doubt
In an ISO/IEC 27001 audit, the 'benefit of the doubt' is a principle of fairness that guides how a lead auditor handles uncertain or inconclusive evidence. Under ISO 19011, audit findings must rest on an evidence-based approach: conclusions must come from objective evidence that is verifiable, relevant and sufficient. When the evidence gathered cannot clearly show whether a requirement of ISO/IEC 27001 or an Annex A control is being met, the auditor should not raise a nonconformity based on suspicion, assumption, intuition or incomplete information. In that situation the auditee receives the benefit of the doubt.
In practice, before giving the benefit of the doubt, a competent auditor tries to resolve the uncertainty. The auditor can ask more questions, interview other personnel, review additional records, extend the sample size, observe activities directly, or trace evidence across processes. If the doubt remains after reasonable effort within the audit time and scope, the auditor should not record a nonconformity. The auditor may instead record an observation or an opportunity for improvement, or flag the area for closer attention in a later surveillance audit.
The principle has clear limits. It does not mean accepting unsupported claims. The organization must demonstrate conformity. If mandatory documented information is missing, such as the risk treatment plan, the Statement of Applicability or internal audit results, that is a lack of evidence of conformity, not a doubt. Likewise, if a process is clearly not implemented, the auditor should raise a nonconformity. The benefit of the doubt applies only when evidence is ambiguous or conflicting, not when it is absent for a required element.
Applying this principle supports the auditor's integrity, fair presentation and professional due care. It keeps findings defensible and credible during the closing meeting and certification decision. It also protects the auditee from unjust findings while preserving the reliability and impartiality of the audit process.
Audit Observations and Opportunities for Improvement
In an ISO/IEC 27001 audit, audit findings result from evaluating collected audit evidence against audit criteria such as the standard's requirements, Annex A controls, the organization's policies, and legal obligations. Findings fall into three groups: conformities, nonconformities, and the less formal categories of observations and opportunities for improvement (OFIs). ISO 19011 provides the guidance, and certification bodies apply them under ISO/IEC 27006.
An audit observation is a finding that does not yet constitute a nonconformity but shows a potential weakness or risk that could lead to one. For example, an auditor may find that access reviews are performed but documented inconsistently, or that a risk treatment plan is complete but its owners are not clearly assigned. Observations are based on objective evidence. They highlight areas where the information security management system (ISMS) is vulnerable, and they often receive extra attention in later surveillance audits. The organization is not formally required to respond, but ignoring an observation may allow it to escalate into a minor or major nonconformity.
An opportunity for improvement is a suggestion about where effectiveness, efficiency, or maturity could be enhanced, even though requirements are being met. Examples include automating log monitoring, improving the clarity of security metrics for management review, or integrating incident lessons learned more systematically. OFIs support clause 10.1 of ISO/IEC 27001, which requires continual improvement.
The Lead Auditor must handle both carefully. Auditors must remain impartial and must not provide consultancy. They may identify what could be improved, but they should not prescribe specific solutions or recommend products or vendors. Findings must be clearly worded, traceable to evidence and criteria, and presented at the closing meeting. They are then recorded in the audit report and clearly distinguished from nonconformities, which require corrective action. Used well, observations and OFIs add value to the audit, help the auditee strengthen its ISMS proactively, and reinforce a culture of continual improvement.
Quality Review of Audit Documentation
In an ISO/IEC 27001 certification audit, the quality review of audit documentation is the systematic check that all audit records are complete, accurate, consistent and defensible before conclusions are finalized and a certification decision is made. It follows the principles of ISO 19011 and the requirements of ISO/IEC 17021-1 and ISO/IEC 27006, which require certification bodies to keep reliable records that support their decisions.
The review usually happens at two levels. First, the audit team leader reviews the work of each team member during and after the audit. This covers audit plans, checklists, interview notes, sampling records, evidence logs, nonconformity reports and the draft audit report. Second, the certification body conducts an independent technical review. A competent person who did not take part in the audit evaluates the audit package before the certification decision is made.
Key review criteria include:
1) Completeness: all clauses 4 to 10 and the applicable Annex A controls in the Statement of Applicability are covered as planned, and any deviations from the audit plan are justified.
2) Traceability: every finding is linked to objective, verifiable evidence, such as documents, records, observations or interviews, and to a specific requirement.
3) Clarity and accuracy: nonconformities are written with a requirement, the evidence and a statement of the nonconformity. They are correctly graded as major or minor, and they are free of ambiguity or personal opinion.
4) Consistency: conclusions match the evidence, the audit scope and the findings recorded across team members. The overall recommendation is logically supported.
5) Impartiality and confidentiality: there is no bias or conflict of interest, and sensitive client information is handled and stored securely.
6) Compliance with procedures: the audit used correct templates, met audit duration requirements, collected signatures and approvals, and followed retention rules.
Issues found during the review are returned to the auditor for clarification or correction. A thorough quality review protects the credibility of the certificate, reduces the risk of appeals and complaints, and ensures that the certification decision rests on sound, objective evidence.
Auditing the Risk Assessment and the Statement of Applicability
In an ISO/IEC 27001 audit, the risk assessment and the Statement of Applicability (SoA) are central evidence that the ISMS is risk-based rather than a checklist exercise. A Lead Auditor examines them together because the SoA should follow logically from risk assessment and treatment decisions. When auditing the risk assessment (Clauses 6.1.2 and 8.2), the auditor first checks that the organization has defined and documented a risk assessment process. This process should include risk acceptance criteria and criteria for performing assessments, and it should produce consistent, valid and comparable results. The auditor verifies that risks to confidentiality, integrity and availability within the ISMS scope have been identified, that risk owners have been assigned, and that likelihood and consequences have been analysed and evaluated against the defined criteria. Evidence typically includes the methodology, risk registers, asset or process inventories, and records showing that assessments are repeated at planned intervals or when significant changes occur. Interviews with risk owners help confirm that the results are understood and genuinely used. Auditing the risk treatment process (Clauses 6.1.3 and 8.3) involves confirming that treatment options were selected and that a risk treatment plan exists. The auditor also checks that risk owners have approved the plan and accepted residual risks. When auditing the SoA, the auditor confirms that it contains the necessary controls, including those from Annex A (93 controls in the 2022 edition), and justifications for their inclusion. It must also justify any exclusions and state whether each control is implemented. The auditor traces samples in both directions, from identified risks to selected controls and from SoA entries back to risks, legal requirements or contractual obligations. Exclusions must be credible, for example excluding outsourced development controls when no development is outsourced. Implementation claims are then verified through observation, records and testing. Common nonconformities include generic or outdated risk assessments, unjustified exclusions, controls marked as implemented without evidence, and missing risk owner approvals. Findings should be objectively graded according to their impact on ISMS effectiveness.
Auditing the Implementation of Annex A Controls
Auditing the implementation of Annex A controls is a core part of a Stage 2 certification audit and of surveillance audits. It verifies that the controls an organization selected to treat its information security risks are actually in place and operating effectively. In ISO/IEC 27001:2022, Annex A lists 93 reference controls grouped into four themes: organizational (37), people (8), physical (14) and technological (34). Annex A is not a mandatory checklist. Under clause 6.1.3, the organization determines the controls it needs through risk treatment, compares them against Annex A, and documents the result in the Statement of Applicability (SoA). The SoA states which controls are included, why they are justified, whether they are implemented, and why any controls are excluded.
The Lead Auditor therefore starts with the SoA and the risk treatment plan. The auditor checks that exclusions are justified and that included controls trace back to identified risks. Audit sampling is then planned around the controls most significant to the organization's risk profile, scope and context, since examining all controls in equal depth is rarely practical.
Evidence is gathered in three main ways. Auditors interview personnel to confirm awareness and understanding. They review documentation and records such as policies, access reviews, incident logs, training records and supplier agreements. They also observe practices directly, for example physical entry controls, clear desk behaviour, backup processes or system configurations. The auditor assesses both design adequacy and operational effectiveness, asking whether the control exists, whether it is consistently applied, and whether it achieves its intended risk reduction.
Findings are graded as major or minor nonconformities, observations or opportunities for improvement, each supported by objective evidence and linked to a specific requirement. A control that is claimed in the SoA but not implemented is a typical nonconformity. The Lead Auditor must stay impartial, apply professional judgment, and recognise that how a control is implemented may legitimately vary with the organization's size, complexity and risk appetite.
Auditing Internal Audit and Management Review
In an ISO/IEC 27001 certification audit, the Lead Auditor must verify that the organization's Information Security Management System (ISMS) can evaluate and improve itself. Two key mechanisms are Internal Audit (Clause 9.2) and Management Review (Clause 9.3). Auditing them shows whether top management and the organization actively monitor ISMS performance.
Auditing Internal Audit (Clause 9.2): The auditor checks that the organization has planned, established, implemented and maintained an audit programme. This includes frequency, methods, responsibilities, planning requirements and reporting. The programme should reflect the importance of the processes concerned and the results of previous audits. Key evidence includes the audit programme, audit plans, checklists, reports, nonconformity records and corrective action follow-up. The auditor verifies that audit criteria and scope are defined for each audit and that the whole ISMS, including Annex A controls, is covered over the cycle. Auditors must be competent, objective and impartial, and should not audit their own work. The auditor also confirms that results are reported to relevant management and that documented information is retained. Weak findings, superficial checklists or overdue corrective actions may indicate a nonconformity.
Auditing Management Review (Clause 9.3): The auditor verifies that top management reviews the ISMS at planned intervals to ensure its continuing suitability, adequacy and effectiveness. Required inputs include the status of previous actions, changes in external and internal issues, changes in interested party needs, feedback on security performance (nonconformities, monitoring results, audit results, achievement of objectives), interested party feedback, risk assessment results and the status of the risk treatment plan, and opportunities for improvement. Outputs must include decisions on improvement opportunities and any needed changes to the ISMS. Evidence includes minutes, attendance records, presentations and action trackers.
The Lead Auditor uses interviews, document review and sampling to confirm genuine leadership engagement rather than a paper exercise. Effective internal audits and management reviews are strong indicators of ISMS maturity and readiness for certification.