An ISO 27001 certification audit is a sampled check of your information security management system, run by an accredited certification body to the rules in ISO/IEC 17021-1:2015. Every audit, from stage 1 to each yearly surveillance visit, follows the same shape: an opening meeting that agrees how the audit will run; evidence gathered by sampling, through interviews, observation of processes and review of documents and records; findings recorded against a specific requirement with the evidence behind them; and a closing meeting followed by a written report and a recommendation. The auditor may point out opportunities for improvement but may not tell you how to fix them, because the certification body is barred from consultancy on the system it certifies.
Knowing that shape changes how you prepare. The question is not whether your policies read well but whether a sample drawn from your records, on a day you do not choose, shows the controls working. This guide walks through each part of the audit, says what an open primary source requires at that point, and ends with a checklist you can fill in. When each audit happens, and how long the whole route takes, is in our guide to how long ISO 27001 certification takes; the evidence side is in how to collect audit evidence.
| Moment | What happens | Where it comes from |
|---|---|---|
| Opening meeting | Channels, confidentiality, how findings will be graded, the sampling method, when the audit could be stopped | ISO/IEC 17021-1, clause 9.4.2 |
| Gathering evidence | Sampling, verified through interviews, observation of processes and review of documents and records | ISO/IEC 17021-1, clause 9.4.4 |
| Findings | Each nonconformity tied to a specific requirement, with the objective evidence, discussed with you | ISO/IEC 17021-1, clause 9.4.5 |
| Grading | Major if it affects the system's capability to achieve its intended results; minor if it does not | ISO/IEC 17021-1, definitions 3.12 and 3.13 |
| Closing meeting | Sampling caveat, how nonconformities are handled, the deadline for your correction plan, appeals | ISO/IEC 17021-1, clause 9.4.7 |
| Report | A written report with a statement on conformity and effectiveness and the team's recommendation | ISO/IEC 17021-1, clause 9.4.8 |
What should you expect from an ISO 27001 audit?
A structured, sampled examination, not a conversation about intentions. The two stage initial audit, the yearly surveillance audits and the recertification audit in the third year all run through the same steps, which an accreditation body checks the certification body against. The SADCAS assessment checklist for ISO/IEC 17021-1, which accreditation assessors use, sets them out in order: an opening meeting at the start, communication during the audit, obtaining and verifying information, identifying and recording findings, a closing meeting at the end, and a written report for each audit. What changes between audits is the scope of what is sampled, not the method.
What happens at the opening meeting?
The ground rules are agreed. Under clause 9.4.2, as the SADCAS checklist lists it, the opening meeting confirms the formal communication channels between the audit team and you, confirms matters of confidentiality, explains the method of reporting including any grading of findings, sets out the conditions under which the audit may be prematurely terminated, describes the sampling methods to be used, and gives you the opportunity to ask questions. Use it. If you do not understand how findings will be graded, or which sites and teams will be sampled, this is the cheapest moment to find out.
During the audit the team leader keeps you informed. Clause 9.4.3 requires the progress of the audit and any concerns to be communicated to you periodically, and any need to change the audit scope to be reviewed with you. A concern raised on day one and fixed by day two is still recorded if it is a nonconformity, but you will at least not hear about it for the first time at the closing meeting.
How do auditors gather evidence?
By sampling. The text of ISO/IEC 17021-1 requires that information relevant to the audit objectives, scope and criteria be "obtained by appropriate sampling and verified to become audit evidence", and lists the methods, starting with "a) interviews", followed by observation of processes and activities and review of documentation and records. In practice that means an auditor will pick a handful of joiners and leavers and ask for their access records, choose a change ticket and follow it to approval, or ask the person who runs backups to show the last restore test. The control owner, not the compliance lead, should expect to answer.
For an ISMS the sample is drawn against the whole standard. Stage 2 evaluates conformity with all the requirements of ISO/IEC 27001, which reaches the risk assessment in clause 6.1.2 and the Statement of Applicability in clause 6.1.3 d), which must state "the necessary controls", the "justification for their inclusion", "whether the necessary controls are implemented or not", and "the justification for excluding any of the Annex A controls", in the words of the ISO/IEC 27001:2022 text. If the SoA says a control is implemented, expect to be asked to show it operating. Our guide to the 93 Annex A controls covers how that document is built.

What is the difference between a major and a minor nonconformity?
Whether it affects the system's ability to work. ISO/IEC 17021-1 defines a nonconformity as "non-fulfilment of a requirement", a major nonconformity as one "that affects the capability of the management system to achieve the intended results", and a minor nonconformity as one "that does not affect the capability of the management system to achieve the intended results." A note to the definition adds that a finding can be major where there is "significant doubt that effective process control is in place", and that "a number of minor nonconformities associated with the same requirement or issue could demonstrate a systemic failure and thus constitute a major nonconformity." Three minor findings about missed access reviews in three teams can add up to one major.
Each finding has to be specific. Clause 9.4.5, as the SADCAS checklist sets it out, requires a nonconformity to be recorded against a specific requirement of the audit criteria, with a clear statement of the nonconformity and the objective evidence it rests on, and to be discussed with you so the evidence is accurate. If you think a finding is wrong, the time to show the record that contradicts it is while the auditor is still on site.

What happens at the closing meeting and in the report?
The findings are presented and the next steps fixed. Clause 9.4.7, as the SADCAS checklist lists it, requires the closing meeting to advise you that the evidence was based on a sample, "thereby introducing an element of uncertainty" in the words of the standard, to explain the certification body's process for handling nonconformities including any consequences for the status of your certification, to set the timeframe for you to present a plan for correction and corrective action, and to tell you about the complaint and appeal processes. The written report that follows, under clause 9.4.8, carries a statement on the conformity and effectiveness of the management system and the audit team's recommendation. What has to be closed before the certification decision, and the six month limit on major findings, is covered in the certification timeline guide.
Can the auditor tell you how to fix a finding?
No. ISO/IEC 17021-1 clause 5.2.5 provides that the certification body "shall not offer or provide management system consultancy", and clause 5.2.6 that it "shall not offer or provide internal audits to its certified clients". A note allows "explanation of findings or clarification of requirements". ISO/IEC 27006-1:2024 clause 5.2.2, in the standard's own text, lets the auditor add value "by identifying opportunities for improvement, as they become evident during the audit, without recommending specific solutions", and requires the certification body to "be independent from the body or bodies (including any individuals) which provide the internal ISMS audit." Bring your own internal auditor and your own remediation plan.
Can the audit be done remotely?
Partly, by agreement. IAF MD 4:2025, Issue 3, applicable from 30 January 2026, governs the use of information and communication technology in audits. It states that the use of ICT "is not mandatory", but that when it is used "it is mandatory to conform to this document", and that its use "shall be mutually agreed upon by the body being audited/assessed and the body performing the conformity assessment activities in accordance with information security and data protection measures and regulations before ICT is used." The audit plan must identify how ICT will be used and the extent, and the report must say how far it was used and how effective it was. Screen sharing your production consoles to an auditor is itself an information security decision; agree the method in writing before the audit.
What do surveillance audits look at?
Whether the system kept running. The audit programme covers a two stage initial audit, surveillance audits in the first and second years and a recertification audit in the third, with surveillance at least once a calendar year outside recertification years. Clause 9.6.2.2, as the SADCAS checklist lists it, requires each surveillance audit to cover at least internal audits and management review, the action taken on nonconformities from previous audits, the treatment of complaints, effectiveness in achieving objectives, progress in continual improvement, any changes, and the use of marks or other references to certification. Last year's findings are the first thing an auditor will look for, so close them on the timetable you agreed.
One recent change is now audited too. In February 2024 ISO and the IAF amended ISO/IEC 27001:2022, among other standards, so that clause 4.1 requires the organisation to "determine whether climate change is a relevant issue." The IAF announcement says certification bodies should include the new text in their auditing and raise "a suitable finding" where an organisation cannot show it has been considered. Record the decision either way.
What the other results get wrong
Page one for this query is almost entirely compliance software vendors and consultancies. Three errors recur. Several describe stage 1 as a documentation review; the SADCAS checklist also has it evaluate site specific conditions and whether internal audits and management reviews are being planned and performed, and recommends that for most management systems at least part of it be carried out at your premises. Some say a failed surveillance audit means the certificate is withdrawn; what follows a finding is set by the certification body's process for handling nonconformities, which it must explain at the closing meeting, and for a minor nonconformity clause 9.5.2 asks for an accepted plan for correction and corrective action, not an automatic withdrawal. And a few present the auditor as an adviser who will help you design controls, which clause 5.2.5 forbids.
Prepare for your own audit
Answer these before the auditor arrives. A blank row is where a sample will find a gap.
| Question | Your answer | Why it matters |
|---|---|---|
| Who are the control owners the auditor is likely to interview, and are they briefed? | Clause 9.4.4: interviews come first. | |
| Does every control the SoA marks as implemented have a current record? | Clause 6.1.3 d) of ISO/IEC 27001. | |
| Which findings from the last audit are still open? | Clause 9.6.2.2 reviews action on previous nonconformities. | |
| When were the last internal audit and management review held? | Stage 1 and every surveillance audit look for both. | |
| Is the climate change determination recorded under clause 4.1? | IAF and ISO expect a finding if it is missing. | |
| Has remote access for the auditor been agreed in writing? | IAF MD 4 requires mutual agreement first. | |
| Who presents the correction plan, and by when? | The closing meeting sets the deadline. |
If most rows are empty, start with a baseline. The free compliance check gives you one, and Venvera's ISO 27001 module keeps the Statement of Applicability, the evidence behind each control, internal audits and open findings in one place, so the sample an auditor draws lands on records that already exist. What the audit costs is in our ISO 27001 certification cost guide.
Frequently asked questions
Who carries out an ISO 27001 audit?
A certification body. ISO states: "No. ISO doesn't provide certification or conformity assessment." To check that a certificate was issued under accreditation, ISO points to the IAF CertSearch database in its help centre.
Does the auditor check every control?
No. Evidence is gathered by sampling, and the closing meeting must tell you that this introduces an element of uncertainty. Every control has to be ready, because you do not choose the sample.
Can one audit produce a major nonconformity from minor ones?
Yes. Under the note to definition 3.12 of ISO/IEC 17021-1, a number of minor nonconformities associated with the same requirement or issue can demonstrate a systemic failure and constitute a major one.
Can our certification body also run our internal audit?
No. ISO/IEC 17021-1 clause 5.2.6 bars it from providing internal audits to its certified clients, and ISO/IEC 27006-1 requires it to be independent of whoever provides the internal ISMS audit.
Is a remote audit allowed?
Yes, if you and the certification body agree it in advance and it follows IAF MD 4. The report must state how far remote techniques were used.
Primary sources
Definitions 3.11 to 3.13, clause 9.4.4 wording and clauses 5.2.5 and 5.2.6 are from the published preview of ISO/IEC 17021-1:2015; clauses 9.1.3, 9.4.2 to 9.4.8 and 9.6.2.2 are as set out in the SADCAS F 40 (a) checklist, which restates the standard as assessment questions. ISO/IEC 27006-1:2024 clause 5.2.2 is from the published preview, and ISO/IEC 27001:2022 clause 6.1.3 d) from its published preview. Remote auditing is from IAF MD 4:2025; the climate amendment from the IAF and ISO communique; certification from ISO's help centre. Certification body practice varies; ask yours for its grading and nonconformity process before the audit.





