Common ISO 27001 Audit Issues and How to Fix Them
Written by Matthew Hale
- What Happens During an ISO 27001 Audit?
- Common ISO 27001 Audit Findings and How to Fix Them
- Major vs Minor Nonconformities
- ISO 27001 Audit Checklist Before Your Audit
- How to Prepare for an ISO 27001 Internal Audit
- How Much Does an ISO 27001 Audit Cost?
- How an ISO 27001 Lead Auditor Can Help
- Final Thoughts
If you have ever sat across the table from an ISO 27001 auditor, you know the feeling. You have prepared for months, your documents are in order, and yet the auditor still finds something. Many organisations encounter at least one finding during certification audits, particularly when their ISMS processes have not been tested thoroughly before the external assessment.
Here is a number worth knowing before you build your ISO 27001 audit checklist: according to the ISO Survey 2024, the number of valid ISO/IEC 27001 certificates worldwide reached 96,709, a rise of roughly 35% compared with 2022. More companies than ever are pursuing this certificate, which also means more companies than ever are sitting through audits and running into the same avoidable issues.
This blog walks you through what those issues usually are, why they keep showing up, and exactly how to fix each one before your next audit.
What Happens During an ISO 27001 Audit?
Before looking at the problems, it helps to understand the ISO 27001 audit process itself, since the type of audit changes what the auditor is actually checking.
- Stage 1 audit: The auditor reviews your documentation, risk assessment, and Statement of Applicability (SoA) to see if you are ready to move forward.
- Stage 2 audit (ISO 27001 certification audit): The auditor checks whether your ISMS is actually implemented and working, not just written down.
- Surveillance audit: Conducted annually after certification. An ISO 27001 surveillance audit does not review everything again; it samples parts of your ISMS to confirm you are still compliant.
- Recertification audit: Every three years, a full ISO 27001 external audit is carried out to renew your certificate.
- Internal audit: Carried out by your own team, or a hired consultant, before the certification body ever shows up. Many organisations assign this to someone trained as a Certified ISO 27001:2022 Lead Auditor internally, since the role is built around spotting gaps before an external assessor does.
Since the 2022 revision reorganised Annex A into 93 controls across four themes (organisational, people, physical, and technological), auditors now check your ISO 27001 audit requirements against this newer structure, which has created some fresh confusion for teams still working from older templates.

Common ISO 27001 Audit Findings and How to Fix Them
The following issues are widely reported by certification bodies and ISO consultants as the ones auditors raise most often, whether it is a first certification audit or a routine surveillance visit. Exact frequency varies by industry and certification body, but these are the patterns that come up repeatedly across audit reports.
| Common Issue | What Auditors Find | Why It Happens | How to Fix It |
| Risk assessment | No structured or repeatable process; risk register exists but is outdated | Risk assessment treated as a one-time exercise instead of an ongoing activity | Review the risk register on a defined schedule, and whenever systems, suppliers, or threats change |
| Statement of Applicability (SoA) | Controls are listed but not clearly linked to the risks they address | SoA built from a template instead of mapped to actual risk decisions | Document why each control was selected and tie it directly to a specific risk |
| Internal audits | Internal audit programme does not cover all ISMS processes or controls | Internal audits done for compliance, not to genuinely test the system | Rotate audit scope each cycle so every process and control gets tested over time |
| Management review | Meetings happen but lack real discussion, data, or decisions | Review treated as a checkbox exercise rather than a strategic discussion | Record decisions, actions, responsibilities, and follow-up dates, not just attendance |
| Access control | User access not reviewed regularly; former employees still have system access | No formal process to revoke or review access on a schedule | Set periodic access reviews and a documented offboarding procedure |
| Documentation | Policies describe one process, but staff follow a different one in practice | Policies written once and never updated to match real operations | Review and update policies alongside any process change, not just once a year |
| Corrective actions | Root cause not properly investigated; the same nonconformity repeats next audit | Fixes address symptoms rather than the underlying cause | Use a root cause method (such as the "5 whys") before closing any corrective action |
| Business continuity | Plans exist but are untested or incomplete | BCP written to satisfy the standard rather than tested against a real scenario | Run regular exercises to test the plan and update it based on the results |
| Awareness training | Staff cannot explain basic security policies when asked | Training delivered once at onboarding, never refreshed | Refresh awareness training regularly and track participation and completion |
These gaps come up so often that they now shape how ISMS training itself is designed. Programs such as those from the Global Skill Development Council (GSDC) are structured around this exact list, risk assessment, access control, internal audits, and corrective action handling, because these are the areas where auditors consistently find real-world practice falling short of the documentation.
Major vs Minor Nonconformities
A quick way to read your audit findings:
- Major nonconformity: A required element is missing entirely, or the system has broken down completely. This must be fixed before certification is granted.
- Minor nonconformity: A single lapse in an otherwise working process. You get time to submit a corrective action plan.
- Observation: Not a failure yet, but a signal the auditor wants addressed before it becomes one.

ISO 27001 Audit Checklist Before Your Audit
A well-built ISO 27001 checklist is the most reliable way to avoid the issues listed above. Break it into three parts.
Documentation checklist
- Information security policy and objectives
- Risk assessment methodology and current risk register
- Statement of Applicability, mapped to specific risks
- Internal audit reports and results
- Management review minutes with decisions recorded
- Corrective action log with root cause analysis
- Business continuity and incident response plans, tested and dated
Process checklist
- Access rights reviewed on a fixed schedule
- Asset inventory kept current
- Supplier and third-party risk assessed
- Awareness training refreshed at least annually
Evidence checklist
- A clear evidence trail for every control listed in the SoA
- Records that show controls are followed, not just documented
- Dates and owners attached to every review, test, and training record
If you want a structured starting point, an ISO 27001 gap analysis checklist run six to eight weeks before your audit is one of the most effective ways to catch gaps while there is still time to close them.
How to Prepare for an ISO 27001 Internal Audit
Your ISO 27001 internal audit checklist should mirror what the external auditor will actually check: sampling evidence, interviewing staff, and testing whether controls work in practice, not just whether they exist on paper. A few habits that make internal audits more useful:
- Assign a different reviewer than the person who owns the process, where possible
- Sample real evidence (logs, tickets, access records) instead of only reviewing policy documents
- Log findings the same way an external auditor would, using major, minor, and observation categories
- Track every internal finding through to a documented fix before the external audit
After every audit, whether internal or external, you should receive an ISO 27001 audit report that lists the scope reviewed, nonconformities found, evidence referenced, and the timeline for corrective action. Keep past reports on file. Repeated findings across multiple reports are one of the fastest ways to turn a minor nonconformity into a major one at the next audit.
How Much Does an ISO 27001 Audit Cost?
ISO 27001 audit cost is one of the most common questions, and it depends on a few factors: number of employees and sites covered by the ISMS, complexity of your IT environment, which audit stage you are booking, and the certification body and country you work with. Beyond the certification body's fees, budget for internal costs too, staff time, gap analysis, and remediation of findings, which often add up to more than the audit fee itself.
How an ISO 27001 Lead Auditor Can Help
A lot of the issues in the table above come down to one thing: nobody in the organisation is trained to audit the ISMS the way a certification body will. This is where having a Certified ISO 27001:2022 Lead Auditor on your team, or working with one, makes a real difference. They know how to test controls the way an external auditor does, spot the gap between documented policy and actual practice, and write findings the business can act on before the real audit ever starts.
For organisations or individuals looking to build this capability in-house, the Global Skill Development Council (GSDC) offers ISO 27001 lead auditor training as one of its certification programs.

Final Thoughts
No ISO 27001 audit is ever completely clean, and that is fine. What separates organisations that sail through recertification from those that struggle is not perfection. It is whether they treat their ISMS as a living system that gets reviewed, tested, and improved between audits, rather than a folder of documents dusted off once a year.
Build your checklist early, run your internal audits honestly, and treat every finding, major or minor, as a chance to close a real gap rather than just satisfy an auditor.
The best time to find an ISO 27001 audit gap is before your external auditor does. Keep your ISMS active throughout the year, test controls with real evidence, and use internal audits to challenge your processes honestly.
Related Certifications
Frequently Asked Questions
An ISO 27001 certification audit checks whether your ISMS meets the requirements of the standard and whether it is actually working in practice. Auditors review your risk assessment, Statement of Applicability, policies, records, and interview staff to confirm that documented controls are followed day-to-day, not just written down.
Duration depends on the size and complexity of the organisation. A Stage 1 audit is usually shorter, focused on document review, while a Stage 2 audit takes longer since auditors sample evidence and speak with multiple teams. Surveillance audits are typically shorter than the original certification audit since they only sample parts of the ISMS.
An internal audit can be carried out by a trained employee who is independent of the process being audited, or by an external consultant. What matters most is that the person understands the standard and can objectively test whether controls are working, rather than simply confirming documents exist.
A single audit rarely results in outright failure. If major nonconformities are raised, certification is paused until they are corrected and verified. Minor nonconformities allow certification to proceed alongside an agreed corrective action plan and a follow-up review.
Surveillance audits are typically conducted annually after initial certification, in the first and second year of the three-year certification cycle. A full recertification audit, covering the whole ISMS again, takes place at the end of that three-year cycle.
Stay up-to-date with the latest news, trends, and resources in GSDC
If you like this read then make sure to check out our previous blogs: Cracking Onboarding Challenges: Fresher Success Unveiled
Not sure which certification to pursue? Our advisors will help you decide!