7.3 Audit Reporting, Corrective Actions, and Follow-Up
Key Takeaways
- The audit report is the permanent, confidential record of scope, findings, conclusions, and sampling limitations—and must align with closing-meeting content.
- Correction fixes the detected issue; corrective action eliminates root cause to prevent recurrence.
- Auditees submit Corrective Action Plans grounded in credible root-cause analysis; auditors review plans for adequacy before verification.
- Nonconformities are closed only after objective evidence shows corrective actions were implemented and effective.
From Closing Meeting to Written Report
After the closing meeting, the Lead Auditor prepares the formal audit report. The report is the permanent record of the audit and must accurately reflect what was presented at closeout. Introducing brand-new nonconformities in the report that were never discussed with the auditee undermines due process and conflicts with good ISO 19011 practice. If a factual correction is needed after closeout, communicate it transparently under the audit programme's rules.
The Lead Auditor owns report quality: completeness, clarity, consistency of grading, confidentiality, and timely distribution to the audit client and agreed recipients. The report typically belongs to the audit client; the audit team must not disclose contents outside authorized channels.
Contents of an ISMS Audit Report
A comprehensive ISO/IEC 27001 audit report usually includes the elements below. Certification bodies may prescribe templates, but the substance remains consistent for PR373-aligned Lead Auditor competence.
| Report element | What to include | Why it matters |
|---|---|---|
| Audit identification | Dates, locations (physical/virtual), report ID, issue date | Traceability and version control |
| Parties | Audit client, auditee, management representative | Accountability and distribution |
| Audit team | Lead Auditor, auditors, technical experts, observers | Competence and role clarity |
| Objectives, scope, criteria | Including SoA version and exclusions | Boundaries of conclusions |
| Methodology and sampling | Approaches used and sampling limitation statement | Honest assurance level |
| Executive summary | Overall ISMS effectiveness and headline results | Senior management readability |
| Detailed findings | Major/Minor NCs (requirement, evidence, failure) and OFIs | Basis for CAP and verification |
| Conclusions / recommendation | Conformity opinion and certification recommendation where applicable | Decision support |
| Follow-up arrangements | CAP due dates, verification method, unresolved disputes | Closeout pathway |
| Attachments | Attendance lists, NC forms, confidentiality notes | Supporting evidence pack |
Writing quality expectations
- Use precise identifiers in evidence statements.
- Keep Major and Minor grades consistent with team calibration.
- Separate OFIs from NCs visually and in wording.
- Avoid consulting prescriptions ("you must buy product X").
- Include the sampling disclaimer in language management can understand.
Correction Versus Corrective Action
When NCs are raised, the auditee must respond. Lead Auditors must distinguish two related but different concepts:
- Correction: Immediate action to eliminate a detected nonconformity (fix the instance). Example: disable the three orphaned VPN accounts found during the audit.
- Corrective action: Action to eliminate the cause of the nonconformity and prevent recurrence. Example: integrate HR termination workflows with identity management and add monitoring for orphaned accounts.
Correction without corrective action leaves the system vulnerable to repeat failure. Corrective action without correction may leave the original breach open. Sound responses usually need both.
Corrective Action Plans (CAP) and Root Cause Analysis
The Corrective Action Plan is the auditee's documented response. For each NC, a credible CAP typically addresses:
- Correction taken or planned for the specific instances.
- Root cause analysis (RCA) explaining why the failure occurred.
- Corrective actions that attack that root cause.
- Responsible persons and target dates.
- How effectiveness will be measured (what evidence will show the issue will not recur).
Root cause discipline
If RCA is shallow ("human error" or "staff forgot"), corrective action usually fails. Techniques such as 5 Whys, fishbone diagrams, or fault-tree thinking help move from symptom to system cause—for example, from "signature missing" to "competence process does not cover document-control duties for new authors," which then drives training and checklist redesign.
Auditor review of the CAP
Before verification, the auditor (often the Lead Auditor) reviews the CAP for adequacy:
- Does RCA identify a plausible systemic cause, not only a person to blame?
- Do corrective actions logically address that cause?
- Are timeframes realistic relative to risk and grade (Major vs Minor)?
- Is there a plan to evaluate related areas for similar exposure (extent analysis)?
Weak CAPs are rejected with clear reasons and returned for revision. Accepting a cosmetic plan that only restates the correction wastes the follow-up cycle.
Follow-Up and Verification of Effectiveness
Approving a CAP is not the same as closing the NC. Closure requires verification of implementation and effectiveness using objective evidence.
Verification approaches
| Situation | Typical verification method | Evidence examples |
|---|---|---|
| Minor NC, low complexity | Desktop / documentary review | Updated procedure, new records over a period, system screenshots with dates |
| Major NC or high-risk process failure | Follow-up audit (on-site or remote) | Witnessed process, sampled post-fix records, interview confirmation |
| Technical control failure | Re-test or re-sample | Configuration baselines, access reports, ticket metrics |
| Training / competence NC | Records plus application check | Training completions plus observed correct practice |
Effectiveness versus mere implementation
Implementation evidence shows the action was done (procedure rewritten, tool installed). Effectiveness evidence shows the outcome improved and recurrence is prevented (subsequent leavers lose access on time for a sustained period; internal audits no longer find the same failure mode). If a new procedure exists but practice is unchanged, the NC remains open.
Extent and related checks
Especially for Major NCs, auditors look for extent analysis: did the auditee check whether the same failure exists elsewhere? Corrective action that fixes only the sampled examples while ignoring identical gaps in other units is incomplete.
Certification-Context Follow-Up (Without Invented Thresholds)
In third-party certification audits, certification bodies define how Major and Minor NCs affect recommendations, how many days are allowed for CAP submission, and whether documentary review or an on-site follow-up is required. CQI/IRCA Lead Auditors follow the scheme and body procedures that apply to the engagement. Do not invent universal numerical "pass marks," mandatory day counts, or score thresholds that are not stated by the governing procedure for that audit.
What remains constant across reputable schemes:
- Majors indicate serious doubt and require robust correction, corrective action, and verified effectiveness before positive certification progression.
- Minors still require CAP and verification, often timed to surveillance or a defined follow-up window.
- The written report and follow-up records must support an independent certification decision.
Closing the Audit Loop
An NC is closed only when the auditor records that:
- Correction addressed the detected instances.
- Corrective action addressed verified root cause.
- Objective evidence demonstrates effectiveness (and extent, where relevant).
- Residual risk to ISMS intended outcomes is acceptably managed relative to the finding.
Unclosed NCs remain visible to future audits. Recurring identical Minors may justify escalation to Major in a later audit if they reveal systemic failure.
Lead Auditor Responsibilities After Reporting
Post-report duties commonly include coordinating CAP receipt, performing or assigning verification, updating finding status, ensuring confidentiality of follow-up evidence, and handing complete files to the audit programme or certification body. Internally, lessons learned may feed audit programme improvement—without converting the audit team into the auditee's implementation project managers.
Mastering reporting and closeout completes the audit lifecycle: plan, conduct, find, conclude, report, and verify. For the ISMS Lead Auditor, the quality of NC statements, the clarity of the report, and the rigor of effectiveness verification determine whether the audit produces lasting information security improvement rather than paperwork theatre.
Which statement correctly distinguishes correction from corrective action after an ISMS nonconformity?
When reviewing an auditee's Corrective Action Plan, what should the auditor primarily evaluate?
What must an auditor confirm before formally closing a nonconformity?
You've completed this section
Continue exploring other exams