5.3 Conducting the Internal Audit & Gathering Audit Evidence
Key Takeaways
- Internal audit execution follows a structured 5-phase lifecycle: Pre-audit planning, Opening meeting, Fieldwork evidence gathering, Synthesis & Closing meeting, and Audit reporting.
- Audit evidence consists of records, statements of fact, or other information that are relevant to the audit criteria and verifiable.
- Auditors categorize findings against criteria into Conformities, Nonconformities (Major or Minor), and Opportunities for Improvement (OFI).
- A compliant Nonconformity Report (NCR) must contain three essential elements: Requirement/Criteria, Verifiable Evidence, and Statement of Nonconformity.
- Corrective action requests resulting from internal audit nonconformities require root cause analysis and verification of effectiveness.
5.3 Conducting the Internal Audit & Gathering Audit Evidence
Conducting an internal audit requires translating the abstract requirements of ISO/IEC 27001 and organizational policies into concrete, verifiable audit evidence. Lead Implementers and internal auditors must follow a rigorous, standardized operational lifecycle defined in ISO 19011 (Clause 6) to ensure audit findings are objective, defensible, and actionable for organizational improvement.
1. The 5-Phase Audit Execution Lifecycle
┌────────────────┐ ┌────────────────┐ ┌────────────────┐ ┌────────────────┐ ┌────────────────┐
│ Phase 1: │ │ Phase 2: │ │ Phase 3: │ │ Phase 4: │ │ Phase 5: │
│ Pre-Audit & │──>│ Opening │──>│ Fieldwork & │──>│ Synthesis & │──>│ Reporting & │
│ Planning │ │ Meeting │ │ Evidence │ │ Closing Meeting│ │ Follow-up │
└────────────────┘ └────────────────┘ └────────────────┘ └────────────────┘ └────────────────┘
Phase 1: Pre-Audit Planning & Document Review
- Desk Study: Reviewing ISMS documentation (Scope statement, Risk Assessment report, Statement of Applicability [SoA], baseline policies, and procedures).
- Audit Plan Development: Preparing a detailed schedule detailing audit scope, objectives, dates, specific Clause/Annex A controls, audit team assignments, and target auditees.
- Working Documents: Developing audit checklists, interview guides, and evidence collection logs.
Phase 2: Opening Meeting
- Establish official communication channels with auditee management.
- Confirm audit scope, objectives, schedule, and logistical arrangements.
- Review audit methods, safety/security protocols, and confidentiality requirements.
- Confirm availability of auditee personnel and resources.
Phase 3: Fieldwork & Evidence Gathering
- Execute evidence collection through interviews, observations, and document sampling.
- Document all audit findings (both positive conformities and potential nonconformities).
- Validate findings through corroborative evidence.
Phase 4: Synthesis & Closing Meeting
- Audit team evaluates evidence against audit criteria to formulate audit conclusions.
- Categorize audit findings (Major Nonconformity, Minor Nonconformity, Opportunity for Improvement).
- Conduct formal Closing Meeting with auditee management to present findings, clarify misunderstandings, and agree on corrective action timeframes.
Phase 5: Reporting & Follow-Up
- Publish the formal, signed Internal Audit Report.
- Track auditee's Root Cause Analysis and Corrective Action Plan (Clause 10.1).
- Verify effectiveness of implemented corrective actions.
2. Core Audit Terminology & Hierarchy
To construct defensible audit reports, auditors must maintain strict precision regarding audit terminology:
[ Audit Criteria ] (What SHOULD be: ISO 27001 Clause / Policy)
│
▼ Compared against
[ Audit Evidence ] (What IS: Verifiable records, logs, interview statements)
│
▼ Yields
[ Audit Findings ] (Conformity / Minor Nonconformity / Major Nonconformity)
│
▼ Synthesized into
[ Audit Conclusion ] (Overall state of ISMS effectiveness & conformity)
| Term | ISO Definition | Example |
|---|---|---|
| Audit Criteria | Set of requirements used as a reference against which audit evidence is compared. | ISO/IEC 27001 Annex A 8.5 (Secure Authentication) & Corporate Identity Policy. |
| Audit Evidence | Records, statements of fact, or other information relevant to audit criteria and verifiable. | IAM system log showing User X logged in without Multi-Factor Authentication (MFA). |
| Audit Findings | Results of the evaluation of collected audit evidence against audit criteria. | Nonconformity: Failure to enforce MFA for privileged users as required by policy. |
| Audit Conclusion | Outcome of an audit, after considering the audit objectives and all audit findings. | The ISMS access control subsystem is partially effective but contains a minor nonconformity. |
3. Evidence Gathering Techniques & Sampling
Audit evidence must be verifiable. Uncorroborated assertions or hearsay do not constitute valid evidence. Auditors employ four primary evidence-gathering techniques:
- Document & Record Review: Examining policies, procedures, system configurations, change logs, and risk registers.
- Interviews: Questioning process owners, technical leads, and operational staff using open-ended questions ("Explain how you revoke access when an employee resigns").
- Observation: Watching operational activities in real time (e.g., observing physical security escort protocols or clean desk compliance).
- Technical Re-performance / Testing: Sampling system settings, running automated compliance scripts, or attempting access with test accounts.
Audit Sampling Methodologies
Because evaluating 100% of transactions is impractical, auditors rely on representative sampling:
- Judgmental (Non-Statistical) Sampling: Auditor selects samples based on risk, complexity, or experience (e.g., selecting top 5 highest-risk change tickets or recently onboarded administrators).
- Statistical Sampling: Random selection using mathematical probability, enabling statistical extrapolation across a large sample population (e.g., sampling 45 employee access requests out of 500 using random generation tables).
Exam Rule on Sampling Risk: Sampling inherently introduces risk. If an auditor samples 10 records out of 1,000 and finds zero errors, it does not guarantee 100% compliance across the uninspected 990 records. Audit evidence provides reasonable assurance, not absolute proof.
4. Grading Findings: Nonconformity Classification
When audit evidence reveals a failure to meet audit criteria, a Nonconformity (NC) must be raised. ISO auditing frameworks categorize findings into three distinct levels:
┌─────────────────────────────────────────────────────────────┐
│ MAJOR NONCONFORMITY │
│ Absence or total breakdown of a mandatory requirement │
└──────────────────────────────┬──────────────────────────────┘
│
┌──────────────────────────────┴──────────────────────────────┐
│ MINOR NONCONFORMITY │
│ Single isolated lapse; system capability remains intact │
└──────────────────────────────┬──────────────────────────────┘
│
┌──────────────────────────────┴──────────────────────────────┐
│ OPPORTUNITY FOR IMPROVEMENT (OFI) │
│ Conforms to criteria, but process enhancement recommended│
└─────────────────────────────────────────────────────────────┘
Detailed Classification Matrix
| Finding Type | Definition | Operational Impact Example |
|---|---|---|
| Major Nonconformity | A total absence or catastrophic breakdown of an ISO 27001 clause or control requirement; OR multiple minor NCs indicating systemic failure; OR a situation that directly results in a severe security breach or regulatory non-compliance. | No internal audits (Clause 9.2) or Management Reviews (Clause 9.3) have been conducted for 2 years; OR mandatory encryption (Annex A 8.24) is completely absent across all production databases containing PII. |
| Minor Nonconformity | A single, isolated operational failure or procedural lapse that does not compromise the overall integrity or capability of the ISMS or security control. | Out of 50 employee termination records reviewed, 1 employee’s system access was revoked 48 hours after termination instead of within the mandated 24-hour SLA, but no unauthorized access occurred. |
| Opportunity for Improvement (OFI) | A statement highlighting a potential area for optimization or efficiency where current practice conforms to criteria but could be improved. | Access control logs are backed up daily, but migrating to an automated real-time SIEM log forwarder would enhance detection capability. |
5. Structuring a Compliant Nonconformity Report (NCR)
A professional Nonconformity Report (NCR) must be unambiguous and contain three mandatory elements:
- Audit Criteria / Requirement: The exact clause, policy statement, or standard requirement violated.
- Audit Evidence: The specific, verifiable facts, sample IDs, log timestamps, or interview records observed.
- Statement of Nonconformity: A concise declaration of the exact gap between criteria and evidence.
Example Nonconformity Report (Minor NC)
NCR Reference: NC-2026-03
Clause / Control: ISO/IEC 27001:2022 Annex A 8.8 (Management of technical vulnerabilities) & Policy Sec-Pol-402 (Vulnerability Remediation Policy v3.1, Section 4.2).
Requirement: Policy Sec-Pol-402 requires all Critical severity vulnerabilities to be remediated within 7 calendar days of vendor patch publication.
Evidence: During review of vulnerability scan report (Scan ID #VS-8832 dated April 10, 2026), production database servers DB-PROD-01 and DB-PROD-02 exhibited vulnerability CVE-2026-1192 (CVSS Score 9.8). CVE-2026-1192 patch was published on March 15, 2026 (26 days unpatched).
Statement of Nonconformity: Critical vulnerability remediation was not executed within the 7-day mandatory timeframe established in organizational policy Sec-Pol-402 for 2 out of 10 sampled production servers.
6. Corrective Action Follow-Up & Root Cause Analysis
Identifying a nonconformity is only half the audit process. Clause 10.1 mandates that when a nonconformity occurs, the organization must:
- React to the nonconformity (Take immediate action to control and correct it, e.g., patch DB-PROD-01 immediately).
- Evaluate the need for action to eliminate the causes (Conduct a formal Root Cause Analysis using methods like 5 Whys or Fishbone diagram to identify why the patch was missed).
- Implement corrective action.
- Review the effectiveness of the corrective action during follow-up audit verification.
During an internal audit of ISO/IEC 27001 Clause 8.1 (Operational planning and control), an auditor finds that while all operational change tickets are documented, two out of twenty sampled changes lacked formal peer approval sign-offs prior to deployment. System security was not compromised. How should this audit finding be formally classified?
Which of the following describes the three mandatory structural components required to construct a valid Nonconformity Report (NCR) during an ISMS internal audit?
An internal auditor reviews backup logs and finds that 100% of database backups failed over a consecutive 30-day period. Furthermore, no IT personnel monitored the backup failure alerts or attempted a single data restoration test, directly violating Clause 8.1 and Annex A 8.13. How should this finding be graded?