Generating Audit Findings and Working Paper Documentation
Key Takeaways
- Audit findings result from evaluating collected audit evidence against audit criteria, resulting in statements of conformity, nonconformity (Major or Minor), or Opportunity for Improvement (OFI).
- The 4-C structure (Condition, Criteria, Cause, Consequence) ensures audit finding statements are objective, defensible, clear, and unambiguous.
- Working papers serve as the official audit record, documenting audit execution, sample selections, interview notes, and evidence required to support certification decisions.
- All working papers must maintain strict confidentiality, professional indexing, clear cross-referencing, and standardized retention per ISO/IEC 17021-1 requirements.
- Interim review meetings provide continuous alignment between the audit team and auditee management, resolving factual disputes before the formal Closing Meeting.
Generating Audit Findings and Working Paper Documentation
The culmination of evidence collection in an ISO/IEC 27001 audit is the synthesis of raw data into objective audit findings. According to ISO 19011:2018 (Clause 6.4.8), audit findings are the results of the evaluation of the collected audit evidence against specified audit criteria. Audit criteria comprise the policies, procedures, standards, and requirements against which the auditor compares evidence—specifically ISO/IEC 27001:2022 Clauses 4–10, selected Annex A controls, legal/regulatory mandates, and the organization's internal ISMS documentation.
To ensure findings withstand peer review, accreditation oversight, and auditee scrutiny, Lead Auditors must document their work in standardized working papers and articulate findings using clear, evidence-based finding statements.
1. Categorization of Audit Findings
Audit findings are classified into three distinct categories under third-party certification rules (ISO/IEC 17021-1 Clause 9.4.5):
[ AUDIT EVIDENCE ]
|
Evaluated Against Criteria
|
+----------------------+----------------------+
| | |
[ CONFORMITY ] [ NONCONFORMITY ] [ OFI ]
(Meets Criteria) (Fails Criteria) (Opportunity for
| Improvement)
+----------+----------+
| |
[ MAJOR NC ] [ MINOR NC ]
(Absence/Total (Single Lapse/
Breakdown) Partial Gap)
Definitions and Thresholds
- Conformity: Fulfillment of an ISO/IEC 27001 requirement, internal policy, or control objective. Supported by verifiable evidence.
- Major Nonconformity: A nonconformity that affects the capability of the management system to achieve intended outcomes. Occurs when:
- There is a total absence or complete breakdown of a mandatory ISO/IEC 27001 requirement (e.g., no risk assessment performed, no internal audit).
- A combination of multiple minor nonconformities indicates a systemic system breakdown.
- A nonconformity directly results in a severe information security breach or unmitigated catastrophic risk.
- Impact: Prevents certification or recertification until corrective action is verified on-site.
- Minor Nonconformity: A single operational lapse or partial failure that does not undermine the overall capability of the ISMS to achieve its security objectives (e.g., one missing approval signature on a patch ticket, or an outdated contact list in an emergency procedure).
- Impact: Does not block certification issuance, provided a satisfactory Corrective Action Plan (CAP) is submitted within agreed timeframes.
- Opportunity for Improvement (OFI): A statement of fact observing a situation that is currently compliant, but where efficiency, robustness, or best practice could be enhanced.
- Constraint: Auditors must NEVER provide specific consulting solutions or advice when documenting an OFI, as this violates auditor independence under ISO/IEC 17021-1.
2. Structure of an Objective Audit Finding Statement (The 4-C Model)
To prevent ambiguity and ensure auditee understanding, every nonconformity statement must follow the 4-C Model:
| Element | Description | Example Wording |
|---|---|---|
| 1. Condition | What was observed? The exact statement of factual evidence, including sample size, location, and specific records. | "Out of a sample of 20 firewall change tickets reviewed in the IT Operations department..." |
| 2. Criteria | What was required? The specific clause of ISO/IEC 27001, Annex A control, or internal policy violated. | "...contrary to ISO/IEC 27001:2022 Annex A 8.9 (Configuration management) and Internal Change Policy v3.1 Section 4.2..." |
| 3. Cause | What is the root cause indicator? The underlying mechanism that allowed the failure to occur. | "...due to the lack of automated enforcement and independent peer review prior to rule deployment..." |
| 4. Consequence | What is the security risk or impact? The potential exposure or threat vector created by the gap. | "...resulting in 4 unapproved inbound ports remaining exposed to the public internet, creating an unmitigated risk of unauthorized external access." |
3. Working Paper Standards and Traceability Matrix
Working papers are the confidential files created and maintained by auditors during an audit engagement. They constitute the legal and professional record supporting the final audit report.
Key Requirements for Working Papers (ISO 19011 Clause 6.4.7)
- Traceability: Any third-party auditor reading the working paper must be able to trace the finding back to the exact evidence, sample item, interviewee, and criteria.
- Clarity and Objectivity: Facts must be recorded dispassionately without emotional or speculative language.
- Confidentiality and Security: Working papers contain sensitive client data and must be encrypted at rest and in transit.
Standardized Working Paper Indexing Structure
| Working Paper Ref | Document Title / Content | Covered ISO 27001 Standard Area | Status |
|---|---|---|---|
| WP-A01 | Audit Plan, Scope Statement, and Attendance Sheets | General Governance | Complete |
| WP-B01 | Context, Leadership, and Policy Review Notes | Clauses 4, 5, 6 | Complete |
| WP-C01 | Risk Assessment & Statement of Applicability Audit Notes | Clause 6.1, SoA | Complete |
| WP-D01 | Operational Control Testing: Technical Controls | Annex A Theme 8 (Technological) | Finding NC-01 |
| WP-D02 | Operational Control Testing: Physical Security | Annex A Theme 7 (Physical) | Conformity |
| WP-E01 | Internal Audit & Management Review Evidence Logs | Clauses 9.2, 9.3 | Complete |
| WP-F01 | Summary Log of Draft Audit Findings & Nonconformities | All Scope Areas | Review Ready |
4. Conducting Interim Review Meetings with Auditee Management
Prior to drafting the final audit report and holding the formal Closing Meeting, the Lead Auditor conducts interim review meetings (daily debriefings) with auditee management.
Objectives of Interim Meetings
- Present Draft Findings: Share preliminary nonconformities while evidence is fresh.
- Verify Facts: Allow the auditee to review the sample evidence and confirm factual accuracy. If the auditee produces additional verifiable evidence that was previously overlooked, the Lead Auditor adjusts the finding accordingly.
- Resolve Disagreements: Address any differences of opinion regarding criteria interpretation before the formal Closing Meeting.
5. Worked Scenario: Resolving Major vs. Minor Nonconformity Disagreements
Background
During an interim review meeting at DataVault Inc., Lead Auditor Elena presented draft finding NC-01 against Annex A 8.24 (Use of cryptography). Elena documented that during her audit of the backup storage environment, DataVault was storing database backup tapes containing unencrypted personal healthcare information (PHI) at an off-site facility.
DataVault's CISO strongly disputed the classification of the finding as a Major Nonconformity, arguing: "This should be a Minor Nonconformity or an OFI. All our live production databases are encrypted at rest using AES-256. The off-site unencrypted tapes are legacy backups from two years ago that are rarely accessed, and the physical warehouse is guarded 24/7."
Auditor Analysis & Decision
Elena reviewed the audit criteria and evidence:
- Criteria Review: ISO/IEC 27001:2022 Annex A 8.24 requires that rules for the effective use of cryptography, including key management, be defined and implemented for sensitive data across its lifecycle.
- Policy Review: DataVault’s internal Encryption Policy explicitly stated: "All electronic media containing PHI at rest, in transit, or in off-site storage MUST be encrypted using AES-256."
- Risk Analysis: The unencrypted tapes contained over 500,000 unencrypted patient records. Physical security at a third-party warehouse does not eliminate the risk of media theft, insider threat, or loss during transit.
- Systemic Absence: Cryptography was completely absent for off-site backup storage, representing a total control failure for that environment.
Outcome & Resolution
Elena explained the 4-C rationale to executive management during the interim meeting:
- Condition: 500,000 PHI records stored off-site without encryption.
- Criteria: Annex A 8.24 and DataVault Encryption Policy v2.0.
- Cause: Backup procedures omitted encryption controls during legacy archiving.
- Consequence: Severe breach exposure and catastrophic regulatory fines under health data protection laws.
Elena maintained the classification as a Major Nonconformity. Because Elena presented fully corroborated evidence and explained the 4-C framework dispassionately during the interim meeting, the CISO accepted the finding, signed the working paper acknowledgment, and initiated immediate remedial encryption prior to the Closing Meeting.
What four structural elements must be included in an objective audit finding statement under the 4-C Model?
Which finding category is defined as a total absence or complete breakdown of a mandatory ISO/IEC 27001 requirement that directly impairs the ISMS's capability to achieve its intended outcomes?
What primary purpose do auditor working papers serve in a third-party ISO/IEC 27001 certification audit?