5.2 Audit Plan Development and Scope Definition

Key Takeaways

  • An Audit Plan is a dynamic operational roadmap created by the Lead Auditor to guide audit execution, governed by ISO 19011 Clause 6.3.2 and ISO/IEC 17021-1 Clause 9.2.3.
  • A critical exam distinction exists between ISMS Scope (Clause 4.3 - overall organizational boundary) and Audit Scope (ISO 19011 - specific boundaries, sites, and time period evaluated during a specific audit).
  • Risk-based audit planning requires allocating greater audit time, sampling depth, and senior auditor expertise to high-risk processes, recent incidents, and complex technical assets.
  • The Audit Plan must detail audit objectives, criteria, scope, physical/virtual locations, timetable, team assignments, meeting schedules, and remote auditing ICT protocols.
  • Only the Lead Auditor has the authority to modify an established audit plan in response to unexpected events, requiring negotiation with the auditee and formal client notification.
Last updated: July 2026

5.2 Audit Plan Development and Scope Definition

Once audit feasibility is confirmed, the Lead Auditor must transition from initial initiation to detailed operational planning. Governed by ISO 19011:2018 Clause 6.3.2 (Audit planning) and ISO/IEC 17021-1:2015 Clause 9.2.3 (Audit plan), the development of a formal Audit Plan is a mandatory prerequisite for any structured management system audit. The audit plan translates high-level audit objectives into a practical, risk-prioritized, and time-bound operational schedule that directs the activities of the audit team and sets clear expectations for the auditee.


Audit Objectives, Scope, and Criteria

Every effective audit plan is constructed upon a tripartite foundation: Objectives, Scope, and Criteria.

                     +---------------------------------------+
                     |            AUDIT FOUNDATION           |
                     +---------------------------------------+
                                         |
         +-------------------------------+-------------------------------+
         |                               |                               |
         v                               v                               v
+-----------------+             +-----------------+             +-----------------+
| AUDIT OBJECTIVES|             |   AUDIT SCOPE   |             |  AUDIT CRITERIA |
| - ISO 27001     |             | - Physical Sites|             | - ISO 27001:2022|
|   Conformity    |             | - Business Units|             | - Annex A / SoA |
| - Effectiveness |             | - Processes     |             | - ISMS Policies |
| - Certification |             | - Time Period   |             | - Legal / GDPR  |
+-----------------+             +-----------------+             +-----------------+

1. Audit Objectives

Audit objectives define what the audit intends to accomplish. Typical ISO/IEC 27001 audit objectives include:

  • Determining the degree of conformity of the auditee's ISMS against ISO/IEC 27001:2022 requirements (Clauses 4–10).
  • Evaluating the effectiveness of implemented Annex A controls in mitigating information security risks to acceptable levels.
  • Assessing ISMS compliance with applicable statutory, regulatory, and contractual obligations.
  • Evaluating the capability of the ISMS to achieve stated organizational security objectives.
  • Identifying opportunities for continual ISMS improvement (for internal audits) or determining certification suitability (for third-party audits).

2. ISMS Scope vs. Audit Scope (Critical Exam Distinction)

Candidates frequently confuse ISMS Scope with Audit Scope. Mastering this distinction is vital for passing the PECB Lead Auditor exam:

AttributeISMS Scope (ISO/IEC 27001 Clause 4.3)Audit Scope (ISO 19011 Clause 3.5)
DefinitionThe permanent boundary, physical/virtual locations, organizational units, and interfaces to which the management system applies.The specific boundaries, extent, locations, processes, and time period covered by a particular audit engagement.
Established ByThe Auditee's Top Management (documented in SoA and scope statement).The Audit Team Leader in consultation with the Audit Client.
PermanenceLong-term organizational boundary baseline.Transient; defined per audit plan.
RelationshipDefines what the organization certified.For a full initial certification Stage 2 audit, the Audit Scope must cover the entire ISMS Scope. For surveillance or special audits, the Audit Scope may cover a subset of the ISMS Scope.

3. Audit Criteria

Audit criteria serve as the reference benchmarks against which objective audit evidence is compared to determine conformity. Criteria include:

  • Normative Standards: ISO/IEC 27001:2022 Clauses 4 through 10.
  • Control Benchmarks: Selected Annex A controls cross-referenced in the auditee's Statement of Applicability (SoA).
  • Internal Organizational Mandates: Information security policies, standard operating procedures (SOPs), network baselines, and risk treatment plans.
  • Legal and Regulatory Frameworks: Data protection laws (e.g., GDPR, CCPA), industry standards (PCI-DSS), and customer SLAs.

Risk-Based Audit Planning

In accordance with ISO 19011 Clause 6.3.2.1, the Lead Auditor must adopt a risk-based approach when designing the audit plan. This involves evaluating two distinct dimensions of risk:

  1. Risks to Audit Execution: Potential events that could prevent the audit team from achieving its objectives (e.g., key staff unavailability, network outages during remote testing, inadequate sampling sizes, language barriers, or physical access delays).
  2. Organizational Information Security Risks: Prioritizing audit depth and allocating resources to operational areas associated with higher security risk profile:
    • Critical technology assets hosting sensitive data (e.g., payment databases, cloud production clusters).
    • Business processes undergoing recent major architectural changes or software migrations.
    • Controls associated with past security incidents, data breaches, or major audit non-conformities.
    • High-risk outsourced vendor interfaces and third-party supply chain connections.

By applying risk-based planning, the Lead Auditor allocates more audit mandays, deeper technical sampling, and senior audit personnel to high-risk domains while maintaining standard coverage for lower-risk administrative processes.


Structuring the Audit Plan and Timetable

The formal audit plan document must be structured logically to provide unambiguous guidance. According to ISO 19011 Clause 6.3.2.2, a comprehensive Audit Plan must contain the following core elements:

+---------------------------------------------------------------------------------+
|                            ISO/IEC 27001 AUDIT PLAN                             |
+---------------------------------------------------------------------------------+
| 1. AUDIT HEADER: Engagement ID, Auditee Name, Audit Client, Dates, Lead Auditor |
| 2. OBJECTIVES, SCOPE & CRITERIA: Stated boundaries, ISO 27001:2022, SoA version |
| 3. AUDIT TEAM & ROLES: Auditor assignments per clause/control theme             |
| 4. LOGISTICS & LOCATIONS: Physical site addresses, remote ICT portal details    |
| 5. MASTER TIMETABLE / SCHEDULE:                                                 |
|    - Day 1: Opening Meeting, Context (Cl 4), Leadership (Cl 5), Planning (Cl 6) |
|    - Day 2: Support (Cl 7), Operations (Cl 8), Tech Controls (A.8)              |
|    - Day 3: Org/People/Physical Controls (A.5-A.7), Performance & Review (Cl 9) |
|    - Day 4: Improvement (Cl 10), Team Debrief, Closing Meeting                  |
| 6. WORKING LANGUAGE, CONFIDENTIALITY & REPORTING PROTOCOLS                      |
+---------------------------------------------------------------------------------+

Sample Timetable Component: Risk-Based Allocation

Date / TimeTarget Process / Clause / ControlAudit Focus & Sample ScopeAssigned AuditorAuditee Participant
Day 1: 09:00 - 10:00All ParticipantsOpening Meeting: Introductions, scope review, schedule confirmation, logistic rules.Lead AuditorCISO, Management Team
Day 1: 10:00 - 12:30Context & Leadership (Clauses 4 & 5)Internal/external issues, interested parties, ISMS Scope, Security Policy, Top Management commitment.Lead AuditorCEO, CISO, Compliance Director
Day 1: 13:30 - 17:00Risk Management (Clauses 6 & 8)Risk assessment methodology, threat matrix, Risk Treatment Plan, SoA justification evaluation.Senior AuditorLead Risk Analyst, IT Risk Officer
Day 2: 09:00 - 12:30Technological Controls (Annex A.8)Access control (A.8.5), Privileged access (A.8.2), Cryptography (A.8.24), Secure coding (A.8.28).Tech Specialist AuditorCloud Architect, Lead DevOps Engineer
Day 2: 13:30 - 17:00Operations & Logging (Annex A.8)Log monitoring (A.8.15), Vulnerability management (A.8.8), Network security (A.8.20–22).Tech Specialist AuditorSIEM Administrator, SOC Manager
Day 3: 09:00 - 12:30Physical & People Security (Annex A.6 & A.7)Screenings (A.6.1), Remote working (A.6.7), Physical perimeters (A.7.1), Equipment protection (A.7.4).Junior AuditorHR Manager, Facilities Director
Day 3: 13:30 - 17:00Performance & Audit (Clauses 9 & 10)Monitoring metrics (9.1), Internal Audit (9.2), Management Review (9.3), Corrective Action (10.1).Lead AuditorQuality Manager, Lead Internal Auditor
Day 4: 14:00 - 15:30All ParticipantsClosing Meeting: Presentation of audit findings, non-conformity reports, certification recommendation.Lead AuditorCISO, Executive Leadership

Logistics, Location Protocols, and Remote Auditing

Physical Site Logistics

For on-site audits, the audit plan must detail logistics: visitor badge processing, escort arrangements, clean room access requirements, personal protective equipment (PPE), and secure audit team room facilities equipped with network isolation.

Remote Auditing Protocols (IAF MD 4 Compliance)

When audits involve virtual sites or remote auditing technologies, the Lead Auditor must ensure compliance with IAF MD 4 (Mandatory Document for the Use of Information and Communication Technology for Auditing/Assessment Purposes):

  • ICT Validation: Test video conferencing platforms, screen-sharing tools, and secure cloud document dropboxes prior to audit execution.
  • Data Security & Privacy: Ensure remote audit sessions utilize encrypted channels (TLS 1.3), enforce strict multi-factor authentication, and comply with privacy rules regarding session recording.
  • Connectivity Contingency: Define fallback mechanisms (e.g., secondary cellular hotspots or offline document review) if internet connectivity fails during remote interviews.

Communicating and Modifying the Audit Plan

Pre-Audit Review and Communication

The audit plan must be submitted to the auditee and audit client for review prior to on-site arrival. This allows the auditee to identify scheduling conflicts with key operational personnel and verify logistical readiness.

Dynamic Plan Modification Procedures

An audit plan is an operational guide, not an inflexible contract. Unforeseen events during audit execution frequently necessitate plan adjustments:

  • Triggers for Modification: Unexpected system outages, sudden unavailability of critical auditee staff, discovery of an unannounced system migration, or identification of a critical security vulnerability requiring deep-dive investigation.
  • Modification Protocol:
    1. The Lead Auditor evaluates the impact of the disruption on audit objectives.
    2. The Lead Auditor renegotiates the schedule, reallocates tasks, or adjusts sampling depth.
    3. The Lead Auditor formally presents the modified plan to the auditee and audit client for agreement.
    4. All plan changes and supporting rationale must be formally documented in the final audit report.

Worked Audit Scenario: Dynamic Plan Adjustment During Stage 2

Scenario: Lead Auditor Sophia is conducting a Stage 2 audit of CloudPay Solutions. On Day 2 of the four-day audit, while auditing Technological Controls (Annex A.8), Sophia discovers that CloudPay migrated its core customer database to a serverless multi-region architecture two weeks prior to the audit. This major infrastructure change was not reflected in the preliminary risk assessment or the original audit plan schedule.

Auditor Action: Recognizing a high-risk area that threatens ISMS operational integrity, Sophia applies risk-based planning principles. She pauses the scheduled low-risk audit of physical archive facilities (Annex A.7) and modifies the audit plan:

  1. She reassigns 0.5 mandays from physical security to cloud infrastructure auditing.
  2. She schedules an immediate technical interview with CloudPay's Lead Serverless Architect.
  3. She expands the audit sample to include serverless access policies (A.8.5), secrets management (A.8.24), and change management logs (A.8.32).
  4. She informs CloudPay's CISO of the schedule revision during the daily debrief, documenting the rationale in the audit log.

Exam Tips and Common Traps

  • Scope Creep Trap: An auditor cannot arbitrarily expand the Audit Scope to include non-certifiable business units or separate legal entities not included in the ISMS Scope without formal contract amendment.
  • Auditee Schedule Veto: An auditee cannot alter the audit plan to exclude mandatory clauses (e.g., demanding the auditor skip Clause 9.2 internal audits). The Lead Auditor maintains sole control over audit methodology.
  • IAF MD 4 ICT Verification: Remote audit plans must explicitly include ICT validation steps; failure to test remote access tools beforehand violates ISO 19011 remote auditing guidelines.
Test Your Knowledge

What is the primary operational distinction between an organization's ISMS Scope and an Audit Scope?

A
B
C
D
Test Your Knowledge

According to ISO 19011 Clause 6.3.2, how should a Lead Auditor apply a risk-based approach when allocating audit time and resources?

A
B
C
D
Test Your Knowledge

Who holds sole authority to approve modifications to an established Audit Plan during audit execution?

A
B
C
D
Test Your Knowledge

Under IAF MD 4, what mandatory action must a Lead Auditor take when planning a remote audit using Information and Communication Technology (ICT)?

A
B
C
D