5.3 Conducting the Internal Audit & Gathering Audit Evidence

Key Takeaways

  • Internal audit execution follows a structured 5-phase lifecycle: Pre-audit planning, Opening meeting, Fieldwork evidence gathering, Synthesis & Closing meeting, and Audit reporting.
  • Audit evidence consists of records, statements of fact, or other information that are relevant to the audit criteria and verifiable.
  • Auditors categorize findings against criteria into Conformities, Nonconformities (Major or Minor), and Opportunities for Improvement (OFI).
  • A compliant Nonconformity Report (NCR) must contain three essential elements: Requirement/Criteria, Verifiable Evidence, and Statement of Nonconformity.
  • Corrective action requests resulting from internal audit nonconformities require root cause analysis and verification of effectiveness.
Last updated: July 2026

5.3 Conducting the Internal Audit & Gathering Audit Evidence

Conducting an internal audit requires translating the abstract requirements of ISO/IEC 27001 and organizational policies into concrete, verifiable audit evidence. Lead Implementers and internal auditors must follow a rigorous, standardized operational lifecycle defined in ISO 19011 (Clause 6) to ensure audit findings are objective, defensible, and actionable for organizational improvement.


1. The 5-Phase Audit Execution Lifecycle

┌────────────────┐   ┌────────────────┐   ┌────────────────┐   ┌────────────────┐   ┌────────────────┐
│ Phase 1:       │   │ Phase 2:       │   │ Phase 3:       │   │ Phase 4:       │   │ Phase 5:       │
│ Pre-Audit &    │──>│ Opening        │──>│ Fieldwork &    │──>│ Synthesis &    │──>│ Reporting &    │
│ Planning       │   │ Meeting        │   │ Evidence       │   │ Closing Meeting│   │ Follow-up      │
└────────────────┘   └────────────────┘   └────────────────┘   └────────────────┘   └────────────────┘

Phase 1: Pre-Audit Planning & Document Review

  • Desk Study: Reviewing ISMS documentation (Scope statement, Risk Assessment report, Statement of Applicability [SoA], baseline policies, and procedures).
  • Audit Plan Development: Preparing a detailed schedule detailing audit scope, objectives, dates, specific Clause/Annex A controls, audit team assignments, and target auditees.
  • Working Documents: Developing audit checklists, interview guides, and evidence collection logs.

Phase 2: Opening Meeting

  • Establish official communication channels with auditee management.
  • Confirm audit scope, objectives, schedule, and logistical arrangements.
  • Review audit methods, safety/security protocols, and confidentiality requirements.
  • Confirm availability of auditee personnel and resources.

Phase 3: Fieldwork & Evidence Gathering

  • Execute evidence collection through interviews, observations, and document sampling.
  • Document all audit findings (both positive conformities and potential nonconformities).
  • Validate findings through corroborative evidence.

Phase 4: Synthesis & Closing Meeting

  • Audit team evaluates evidence against audit criteria to formulate audit conclusions.
  • Categorize audit findings (Major Nonconformity, Minor Nonconformity, Opportunity for Improvement).
  • Conduct formal Closing Meeting with auditee management to present findings, clarify misunderstandings, and agree on corrective action timeframes.

Phase 5: Reporting & Follow-Up

  • Publish the formal, signed Internal Audit Report.
  • Track auditee's Root Cause Analysis and Corrective Action Plan (Clause 10.1).
  • Verify effectiveness of implemented corrective actions.

2. Core Audit Terminology & Hierarchy

To construct defensible audit reports, auditors must maintain strict precision regarding audit terminology:

[ Audit Criteria ]  (What SHOULD be: ISO 27001 Clause / Policy)
       │
       ▼  Compared against
[ Audit Evidence ]  (What IS: Verifiable records, logs, interview statements)
       │
       ▼  Yields
[ Audit Findings ]  (Conformity / Minor Nonconformity / Major Nonconformity)
       │
       ▼  Synthesized into
[ Audit Conclusion ] (Overall state of ISMS effectiveness & conformity)
TermISO DefinitionExample
Audit CriteriaSet of requirements used as a reference against which audit evidence is compared.ISO/IEC 27001 Annex A 8.5 (Secure Authentication) & Corporate Identity Policy.
Audit EvidenceRecords, statements of fact, or other information relevant to audit criteria and verifiable.IAM system log showing User X logged in without Multi-Factor Authentication (MFA).
Audit FindingsResults of the evaluation of collected audit evidence against audit criteria.Nonconformity: Failure to enforce MFA for privileged users as required by policy.
Audit ConclusionOutcome of an audit, after considering the audit objectives and all audit findings.The ISMS access control subsystem is partially effective but contains a minor nonconformity.

3. Evidence Gathering Techniques & Sampling

Audit evidence must be verifiable. Uncorroborated assertions or hearsay do not constitute valid evidence. Auditors employ four primary evidence-gathering techniques:

  1. Document & Record Review: Examining policies, procedures, system configurations, change logs, and risk registers.
  2. Interviews: Questioning process owners, technical leads, and operational staff using open-ended questions ("Explain how you revoke access when an employee resigns").
  3. Observation: Watching operational activities in real time (e.g., observing physical security escort protocols or clean desk compliance).
  4. Technical Re-performance / Testing: Sampling system settings, running automated compliance scripts, or attempting access with test accounts.

Audit Sampling Methodologies

Because evaluating 100% of transactions is impractical, auditors rely on representative sampling:

  • Judgmental (Non-Statistical) Sampling: Auditor selects samples based on risk, complexity, or experience (e.g., selecting top 5 highest-risk change tickets or recently onboarded administrators).
  • Statistical Sampling: Random selection using mathematical probability, enabling statistical extrapolation across a large sample population (e.g., sampling 45 employee access requests out of 500 using random generation tables).

Exam Rule on Sampling Risk: Sampling inherently introduces risk. If an auditor samples 10 records out of 1,000 and finds zero errors, it does not guarantee 100% compliance across the uninspected 990 records. Audit evidence provides reasonable assurance, not absolute proof.


4. Grading Findings: Nonconformity Classification

When audit evidence reveals a failure to meet audit criteria, a Nonconformity (NC) must be raised. ISO auditing frameworks categorize findings into three distinct levels:

┌─────────────────────────────────────────────────────────────┐
│                     MAJOR NONCONFORMITY                     │
│    Absence or total breakdown of a mandatory requirement    │
└──────────────────────────────┬──────────────────────────────┘
                               │
┌──────────────────────────────┴──────────────────────────────┐
│                     MINOR NONCONFORMITY                     │
│   Single isolated lapse; system capability remains intact   │
└──────────────────────────────┬──────────────────────────────┘
                               │
┌──────────────────────────────┴──────────────────────────────┐
│                OPPORTUNITY FOR IMPROVEMENT (OFI)             │
│     Conforms to criteria, but process enhancement recommended│
└─────────────────────────────────────────────────────────────┘

Detailed Classification Matrix

Finding TypeDefinitionOperational Impact Example
Major NonconformityA total absence or catastrophic breakdown of an ISO 27001 clause or control requirement; OR multiple minor NCs indicating systemic failure; OR a situation that directly results in a severe security breach or regulatory non-compliance.No internal audits (Clause 9.2) or Management Reviews (Clause 9.3) have been conducted for 2 years; OR mandatory encryption (Annex A 8.24) is completely absent across all production databases containing PII.
Minor NonconformityA single, isolated operational failure or procedural lapse that does not compromise the overall integrity or capability of the ISMS or security control.Out of 50 employee termination records reviewed, 1 employee’s system access was revoked 48 hours after termination instead of within the mandated 24-hour SLA, but no unauthorized access occurred.
Opportunity for Improvement (OFI)A statement highlighting a potential area for optimization or efficiency where current practice conforms to criteria but could be improved.Access control logs are backed up daily, but migrating to an automated real-time SIEM log forwarder would enhance detection capability.

5. Structuring a Compliant Nonconformity Report (NCR)

A professional Nonconformity Report (NCR) must be unambiguous and contain three mandatory elements:

  1. Audit Criteria / Requirement: The exact clause, policy statement, or standard requirement violated.
  2. Audit Evidence: The specific, verifiable facts, sample IDs, log timestamps, or interview records observed.
  3. Statement of Nonconformity: A concise declaration of the exact gap between criteria and evidence.

Example Nonconformity Report (Minor NC)

NCR Reference: NC-2026-03
Clause / Control: ISO/IEC 27001:2022 Annex A 8.8 (Management of technical vulnerabilities) & Policy Sec-Pol-402 (Vulnerability Remediation Policy v3.1, Section 4.2).
Requirement: Policy Sec-Pol-402 requires all Critical severity vulnerabilities to be remediated within 7 calendar days of vendor patch publication.
Evidence: During review of vulnerability scan report (Scan ID #VS-8832 dated April 10, 2026), production database servers DB-PROD-01 and DB-PROD-02 exhibited vulnerability CVE-2026-1192 (CVSS Score 9.8). CVE-2026-1192 patch was published on March 15, 2026 (26 days unpatched).
Statement of Nonconformity: Critical vulnerability remediation was not executed within the 7-day mandatory timeframe established in organizational policy Sec-Pol-402 for 2 out of 10 sampled production servers.


6. Corrective Action Follow-Up & Root Cause Analysis

Identifying a nonconformity is only half the audit process. Clause 10.1 mandates that when a nonconformity occurs, the organization must:

  1. React to the nonconformity (Take immediate action to control and correct it, e.g., patch DB-PROD-01 immediately).
  2. Evaluate the need for action to eliminate the causes (Conduct a formal Root Cause Analysis using methods like 5 Whys or Fishbone diagram to identify why the patch was missed).
  3. Implement corrective action.
  4. Review the effectiveness of the corrective action during follow-up audit verification.
Test Your Knowledge

During an internal audit of ISO/IEC 27001 Clause 8.1 (Operational planning and control), an auditor finds that while all operational change tickets are documented, two out of twenty sampled changes lacked formal peer approval sign-offs prior to deployment. System security was not compromised. How should this audit finding be formally classified?

A
B
C
D
Test Your Knowledge

Which of the following describes the three mandatory structural components required to construct a valid Nonconformity Report (NCR) during an ISMS internal audit?

A
B
C
D
Test Your Knowledge

An internal auditor reviews backup logs and finds that 100% of database backups failed over a consecutive 30-day period. Furthermore, no IT personnel monitored the backup failure alerts or attempted a single data restoration test, directly violating Clause 8.1 and Annex A 8.13. How should this finding be graded?

A
B
C
D