7.3 Audit Reporting, Corrective Actions, and Follow-Up

Key Takeaways

  • The audit report is the permanent, confidential record of scope, findings, conclusions, and sampling limitations—and must align with closing-meeting content.
  • Correction fixes the detected issue; corrective action eliminates root cause to prevent recurrence.
  • Auditees submit Corrective Action Plans grounded in credible root-cause analysis; auditors review plans for adequacy before verification.
  • Nonconformities are closed only after objective evidence shows corrective actions were implemented and effective.
Last updated: July 2026

From Closing Meeting to Written Report

After the closing meeting, the Lead Auditor prepares the formal audit report. The report is the permanent record of the audit and must accurately reflect what was presented at closeout. Introducing brand-new nonconformities in the report that were never discussed with the auditee undermines due process and conflicts with good ISO 19011 practice. If a factual correction is needed after closeout, communicate it transparently under the audit programme's rules.

The Lead Auditor owns report quality: completeness, clarity, consistency of grading, confidentiality, and timely distribution to the audit client and agreed recipients. The report typically belongs to the audit client; the audit team must not disclose contents outside authorized channels.

Contents of an ISMS Audit Report

A comprehensive ISO/IEC 27001 audit report usually includes the elements below. Certification bodies may prescribe templates, but the substance remains consistent for PR373-aligned Lead Auditor competence.

Report elementWhat to includeWhy it matters
Audit identificationDates, locations (physical/virtual), report ID, issue dateTraceability and version control
PartiesAudit client, auditee, management representativeAccountability and distribution
Audit teamLead Auditor, auditors, technical experts, observersCompetence and role clarity
Objectives, scope, criteriaIncluding SoA version and exclusionsBoundaries of conclusions
Methodology and samplingApproaches used and sampling limitation statementHonest assurance level
Executive summaryOverall ISMS effectiveness and headline resultsSenior management readability
Detailed findingsMajor/Minor NCs (requirement, evidence, failure) and OFIsBasis for CAP and verification
Conclusions / recommendationConformity opinion and certification recommendation where applicableDecision support
Follow-up arrangementsCAP due dates, verification method, unresolved disputesCloseout pathway
AttachmentsAttendance lists, NC forms, confidentiality notesSupporting evidence pack

Writing quality expectations

  • Use precise identifiers in evidence statements.
  • Keep Major and Minor grades consistent with team calibration.
  • Separate OFIs from NCs visually and in wording.
  • Avoid consulting prescriptions ("you must buy product X").
  • Include the sampling disclaimer in language management can understand.

Correction Versus Corrective Action

When NCs are raised, the auditee must respond. Lead Auditors must distinguish two related but different concepts:

  • Correction: Immediate action to eliminate a detected nonconformity (fix the instance). Example: disable the three orphaned VPN accounts found during the audit.
  • Corrective action: Action to eliminate the cause of the nonconformity and prevent recurrence. Example: integrate HR termination workflows with identity management and add monitoring for orphaned accounts.

Correction without corrective action leaves the system vulnerable to repeat failure. Corrective action without correction may leave the original breach open. Sound responses usually need both.

Corrective Action Plans (CAP) and Root Cause Analysis

The Corrective Action Plan is the auditee's documented response. For each NC, a credible CAP typically addresses:

  1. Correction taken or planned for the specific instances.
  2. Root cause analysis (RCA) explaining why the failure occurred.
  3. Corrective actions that attack that root cause.
  4. Responsible persons and target dates.
  5. How effectiveness will be measured (what evidence will show the issue will not recur).

Root cause discipline

If RCA is shallow ("human error" or "staff forgot"), corrective action usually fails. Techniques such as 5 Whys, fishbone diagrams, or fault-tree thinking help move from symptom to system cause—for example, from "signature missing" to "competence process does not cover document-control duties for new authors," which then drives training and checklist redesign.

Auditor review of the CAP

Before verification, the auditor (often the Lead Auditor) reviews the CAP for adequacy:

  • Does RCA identify a plausible systemic cause, not only a person to blame?
  • Do corrective actions logically address that cause?
  • Are timeframes realistic relative to risk and grade (Major vs Minor)?
  • Is there a plan to evaluate related areas for similar exposure (extent analysis)?

Weak CAPs are rejected with clear reasons and returned for revision. Accepting a cosmetic plan that only restates the correction wastes the follow-up cycle.

Follow-Up and Verification of Effectiveness

Approving a CAP is not the same as closing the NC. Closure requires verification of implementation and effectiveness using objective evidence.

Verification approaches

SituationTypical verification methodEvidence examples
Minor NC, low complexityDesktop / documentary reviewUpdated procedure, new records over a period, system screenshots with dates
Major NC or high-risk process failureFollow-up audit (on-site or remote)Witnessed process, sampled post-fix records, interview confirmation
Technical control failureRe-test or re-sampleConfiguration baselines, access reports, ticket metrics
Training / competence NCRecords plus application checkTraining completions plus observed correct practice

Effectiveness versus mere implementation

Implementation evidence shows the action was done (procedure rewritten, tool installed). Effectiveness evidence shows the outcome improved and recurrence is prevented (subsequent leavers lose access on time for a sustained period; internal audits no longer find the same failure mode). If a new procedure exists but practice is unchanged, the NC remains open.

Extent and related checks

Especially for Major NCs, auditors look for extent analysis: did the auditee check whether the same failure exists elsewhere? Corrective action that fixes only the sampled examples while ignoring identical gaps in other units is incomplete.

Certification-Context Follow-Up (Without Invented Thresholds)

In third-party certification audits, certification bodies define how Major and Minor NCs affect recommendations, how many days are allowed for CAP submission, and whether documentary review or an on-site follow-up is required. CQI/IRCA Lead Auditors follow the scheme and body procedures that apply to the engagement. Do not invent universal numerical "pass marks," mandatory day counts, or score thresholds that are not stated by the governing procedure for that audit.

What remains constant across reputable schemes:

  • Majors indicate serious doubt and require robust correction, corrective action, and verified effectiveness before positive certification progression.
  • Minors still require CAP and verification, often timed to surveillance or a defined follow-up window.
  • The written report and follow-up records must support an independent certification decision.

Closing the Audit Loop

An NC is closed only when the auditor records that:

  1. Correction addressed the detected instances.
  2. Corrective action addressed verified root cause.
  3. Objective evidence demonstrates effectiveness (and extent, where relevant).
  4. Residual risk to ISMS intended outcomes is acceptably managed relative to the finding.

Unclosed NCs remain visible to future audits. Recurring identical Minors may justify escalation to Major in a later audit if they reveal systemic failure.

Lead Auditor Responsibilities After Reporting

Post-report duties commonly include coordinating CAP receipt, performing or assigning verification, updating finding status, ensuring confidentiality of follow-up evidence, and handing complete files to the audit programme or certification body. Internally, lessons learned may feed audit programme improvement—without converting the audit team into the auditee's implementation project managers.

Mastering reporting and closeout completes the audit lifecycle: plan, conduct, find, conclude, report, and verify. For the ISMS Lead Auditor, the quality of NC statements, the clarity of the report, and the rigor of effectiveness verification determine whether the audit produces lasting information security improvement rather than paperwork theatre.

Test Your Knowledge

Which statement correctly distinguishes correction from corrective action after an ISMS nonconformity?

A
B
C
D
Test Your Knowledge

When reviewing an auditee's Corrective Action Plan, what should the auditor primarily evaluate?

A
B
C
D
Test Your Knowledge

What must an auditor confirm before formally closing a nonconformity?

A
B
C
D
Congratulations!

You've completed this section

Continue exploring other exams