5.1 Audit Initiation and Feasibility Assessment
Key Takeaways
- Audit initiation formally establishes communication between the audit team leader and the auditee, confirming audit authority, scope, and criteria per ISO 19011 Clause 6.2 and ISO/IEC 17021-1 Clause 9.2.
- Initial contact requires confirming communication channels, obtaining preliminary documented information (including the ISMS Scope Statement and Statement of Applicability), and establishing site access protocols.
- Feasibility assessment is mandatory under ISO 19011 Clause 6.2.3 and relies on four core factors: information sufficiency, auditee cooperation, adequate time/resources, and audit team competence.
- If an audit is determined to be unfeasible, the audit team leader must formally document the rationale and propose alternative actions to the audit client, such as scope adjustment, postponement, or termination.
- Stage 1 readiness evaluations heavily inform feasibility assessments by verifying whether mandatory ISMS documentation (e.g., internal audits, management reviews) is sufficiently mature for a Stage 2 audit.
5.1 Audit Initiation and Feasibility Assessment
The initiation phase of an ISO/IEC 27001 management system audit establishes the operational foundation for the entire auditing lifecycle. Governed by ISO 19011:2018 Clause 6.2 (Initiating the audit) and ISO/IEC 17021-1:2015 Clause 9.2 (Audit planning), audit initiation is the formal process through which the audit team leader establishes contact with the auditee, confirms legal and managerial authority to audit, defines preliminary engagement parameters, and determines whether the audit is actually feasible to conduct. A thorough initiation and feasibility evaluation prevents wasted resources, mitigates audit failure, and ensures that audit findings provide credible, objective evidence regarding the maturity and conformity of the organization's Information Security Management System (ISMS).
Regulatory Framework and Standards Foundation
Audit initiation operates at the intersection of guidance standards and accreditation requirements:
- ISO 19011:2018: Provides guidelines for auditing management systems, defining generic principles for audit initiation, initial contact, and feasibility determination applicable to internal (first-party) and supplier (second-party) audits.
- ISO/IEC 17021-1:2015: Specifies mandatory requirements for bodies providing audit and certification of management systems. It imposes strict normative rules on certification bodies regarding pre-audit communications, application reviews, and Stage 1 feasibility assessments for third-party audits.
- ISO/IEC 27006:2015/Amd 1:2021: Outlines specific requirements for certification bodies auditing ISMS implementations under ISO/IEC 27001, defining audit day calculations (mandays) and sector-specific competence baselines that directly influence feasibility.
Establishing Initial Contact with the Auditee
According to ISO 19011 Clause 6.2.2, responsibility for establishing initial contact rests strictly with the designated Audit Team Leader (Lead Auditor). Initial contact may be formal or informal but must occur well in advance of scheduled audit execution dates to allow adequate preparation time.
+-----------------------------------------------------------------------+
| AUDIT TEAM LEADER (LEAD AUDITOR) |
+-----------------------------------------------------------------------+
| (Establishes Initial Contact)
v
+-----------------------------------------------------------------------+
| AUDITEE REPRESENTATIVE |
| (CISO / ISMS Manager / Management Rep) |
+-----------------------------------------------------------------------+
|
+--------------------------+--------------------------+
| |
v v
+-------------------------------+ +--------------------------------+
| COMMUNICATION & LOGISTICS | | DOCUMENTED INFORMATION REQUEST |
| - Confirm communication channels| | - ISMS Scope Statement |
| - Confirm authority to audit | | - Statement of Applicability |
| - Confirm audit scope/criteria| | - Security Policies & Risk Plan|
| - Schedule dates and logistics| | - Internal Audit & Mgmt Review |
+-------------------------------+ +--------------------------------+
Primary Objectives of Initial Contact
- Establish Formal Communication Channels: Identify designated auditee representatives, including the ISMS Manager, Chief Information Security Officer (CISO), operational process owners, and legal/compliance contacts.
- Confirm Authority to Conduct the Audit: Verify the mandate authorizing the audit. For internal audits, this is the internal audit charter or executive directive. For third-party audits, this is the signed certification agreement between the Audit Client and the Certification Body.
- Provide Preliminary Audit Information: Inform the auditee of the audit objectives, scope boundaries, audit criteria (ISO/IEC 27001:2022 Clauses 4–10 and Annex A controls), audit team composition, and proposed schedule.
- Request Documented Information: Request access to essential ISMS documentation needed for audit planning and desk review.
- Identify Statutory, Regulatory, and Contractual Requirements: Clarify applicable legal frameworks governing the auditee (e.g., GDPR, HIPAA, NIS2, PCI-DSS, national privacy laws) to ensure the audit team includes relevant legal expertise.
- Establish Site and Security Access Protocols: Agree upon physical security clearance procedures, visitor passes, non-disclosure agreements (NDAs), remote access credentials, and occupational health and safety protocols.
- Coordinate Logistics and Observer Arrangements: Confirm working room availability, network access, interview facilities, and the participation of guides or observers.
Preliminary Documented Information Request
During initial contact, the Lead Auditor formally requests key ISMS documents to conduct a preliminary desk review:
- ISMS Scope Statement (Clause 4.3): Documented boundaries and applicability of the ISMS.
- Information Security Policy (Clause 5.2): High-level managerial commitment and security objectives.
- Statement of Applicability - SoA (Clause 6.1.3): The authoritative matrix detailing selected Annex A controls, implementation status, and justifications for control exclusions.
- Risk Assessment and Treatment Methodology & Results (Clauses 6.1.2 and 6.1.3): Risk criteria, asset inventory, threat/vulnerability matrix, and Risk Treatment Plan (RTP).
- Internal Audit and Management Review Minutes (Clauses 9.2 and 9.3): Evidence that the ISMS has executed at least one full cycle of internal oversight and executive review prior to third-party certification.
Evaluating Audit Feasibility
Under ISO 19011 Clause 6.2.3, the Lead Auditor must determine whether the audit is feasible. The objective of feasibility assessment is to establish reasonable confidence that the audit objectives can be achieved within the allocated constraints. If an audit is conducted without establishing feasibility, the resulting audit findings may be unreliable, invalid, or legally compromised.
The Four Core Feasibility Factors
| Feasibility Factor | Evaluation Criteria & Assessment Metrics | Common Red Flags / Indicators of Failure |
|---|---|---|
| 1. Information Sufficiency & Appropriateness | Documented information is complete, accessible, up to date, and written in a language understood by the audit team. Core ISMS mandatory records exist. | Missing Statement of Applicability (SoA), incomplete risk assessment, unmapped scope boundaries, or missing mandatory policies. |
| 2. Auditee Cooperation & Commitment | Top management and operational process owners demonstrate willingness to participate, provide honest responses, and grant access to facilities, systems, and records. | Management withholding key system logs, refusing auditor access to cloud administration portals, or restricting staff interviews. |
| 3. Time & Resource Allocation | Calculated audit mandays are sufficient to cover the ISMS scope, multi-site locations, and technical complexity per ISO/IEC 27006 rules. | Audit Client imposing an unrealistically short schedule (e.g., allocating 2 mandays for a 5,000-employee multi-national enterprise). |
| 4. Team Competence & Capacity | The audit team possesses necessary sector knowledge, technical capability (e.g., cloud security, cryptography), and language fluency without conflicts of interest. | Absence of a technical expert fluent in proprietary industrial control systems (ICS/SCADA) audited within scope. |
Handling Unfeasible Audits: Protocols and Remedial Pathways
When a feasibility evaluation reveals significant deficiencies, the audit cannot proceed as originally planned. ISO 19011 Clause 6.2.3 mandates a strict protocol for managing unfeasible audit engagements:
- Document Evidence of Unfeasibility: The Lead Auditor must compile objective evidence detailing why the audit cannot achieve its objectives (e.g., non-existence of an internal audit report, refusal to grant network access, active disaster recovery scenario).
- Formal Communication with the Audit Client: The Lead Auditor must immediately inform the Audit Client (the entity requesting the audit, such as the Certification Body or Executive Management). Note: The Audit Client may be distinct from the Auditee.
- Formulate Remedial Proposals: In consultation with the Audit Client and Auditee, the Lead Auditor must recommend one of three formal actions:
+-------------------------------+
| UNFEASIBLE AUDIT DETERMINATION |
+-------------------------------+
|
v
+-------------------------------+
| FORMAL REPORT TO AUDIT CLIENT |
+-------------------------------+
|
+---------------------------------------+---------------------------------------+
| | |
v v v
+-----------------------+ +-----------------------+ +-----------------------+
| OPTION A: POSTPONEMENT| | OPTION B: SCOPE REDUX | | OPTION C: TERMINATION |
| Delay audit to allow | | Restrict audit scope | | Cancel contract due |
| auditee to complete | | to stable, compliant | | to irreconcilable |
| missing mandatory items| | operational units | | missing prerequisites |
+-----------------------+ +-----------------------+ +-----------------------+
- Option A: Postponement / Rescheduling: Granting the auditee time to remediate missing prerequisites (e.g., delaying a Stage 2 audit by 60 days to allow the auditee to complete its mandatory management review).
- Option B: Scope Modification: Adjusting the audit scope to exclude unready operational units, uncooperative geographic sites, or unstable technology stacks, provided the revised scope remains coherent and viable under ISO/IEC 27001 rules.
- Option C: Audit Termination: Formally canceling the audit engagement if the auditee demonstrates active bad faith, misrepresentation, or total lack of cooperation.
Worked Audit Scenario: Stage 1 Feasibility Assessment
Scenario: Lead Auditor Marcus is assigned by a Certification Body to conduct a Stage 1 audit for FinTech Global, a financial software provider seeking ISO/IEC 27001:2022 certification. FinTech Global's ISMS scope covers its cloud payment gateway. During initial contact, Marcus requests the ISMS Scope Statement, Statement of Applicability (SoA), Risk Assessment report, Internal Audit report, and Management Review minutes.
FinTech Global's CISO provides the Scope Statement and Risk Assessment but admits that due to a recent product launch, FinTech Global has not yet conducted an internal audit or held a management review. Furthermore, the SoA is still a draft spreadsheet missing justifications for excluded Annex A controls.
Auditor Evaluation & Action: Marcus reviews ISO/IEC 17021-1 Clause 9.2.1.1, which specifies that Stage 1 audit objectives include evaluating the auditee's internal audit and management review status. Conducting a Stage 2 certification audit without a completed internal audit, management review, and finalized SoA is completely unfeasible.
Marcus formally documents the missing normative prerequisites and contacts the Audit Client (the Certification Body's scheme manager). Marcus recommends Option A (Postponement): delaying the Stage 2 audit by 90 days. This provides FinTech Global the required time to finalize its SoA, execute a full internal audit, conduct an executive management review, and demonstrate ISMS operational maturity.
Exam Tips and Common Traps
- Audit Client vs. Auditee: The Audit Client is the organization or person requesting the audit (e.g., the Certification Body or Board of Directors). The Auditee is the organization being audited. When an audit is unfeasible, the Lead Auditor reports to the Audit Client, not just the auditee.
- Stage 1 vs. Stage 2 Feasibility: Stage 1 audit primary purpose is to assess document readiness and feasibility for Stage 2. Never recommend proceeding to Stage 2 if mandatory Clause 9 requirements (Internal Audit / Management Review) are unfulfilled.
- Authority Boundaries: A Lead Auditor cannot unilaterally cancel a third-party certification contract; the Lead Auditor recommends cancellation or scope modification to the Certification Body (Audit Client).
- Manday Reduction Trap: If an auditee demands reducing audit mandays below ISO/IEC 27006 standards to cut costs, the Lead Auditor must flag this as a time/resource feasibility violation.
Under ISO 19011 Clause 6.2.2, who holds primary responsibility for establishing initial contact with the auditee?
During an initial contact review for a Stage 1 audit, a Lead Auditor discovers that the auditee has not yet conducted an internal audit or management review. Which action should the Lead Auditor take?
Which of the following is NOT one of the four core feasibility evaluation factors specified in ISO 19011 Clause 6.2.3?
If an auditee refuses to provide access to system administration logs and cloud architecture diagrams during feasibility evaluation, which feasibility factor is directly breached?