Common ISO 27001 Audit Issues and How to Fix Them

Common ISO 27001 Audit Issues and How to Fix Them

Written by Matthew Hale

Share This Blog


If you have ever sat across the table from an ISO 27001 auditor, you know the feeling. You have prepared for months, your documents are in order, and yet the auditor still finds something. Many organisations encounter at least one finding during certification audits, particularly when their ISMS processes have not been tested thoroughly before the external assessment.

Here is a number worth knowing before you build your ISO 27001 audit checklist: according to the ISO Survey 2024, the number of valid ISO/IEC 27001 certificates worldwide reached 96,709, a rise of roughly 35% compared with 2022. More companies than ever are pursuing this certificate, which also means more companies than ever are sitting through audits and running into the same avoidable issues.

This blog walks you through what those issues usually are, why they keep showing up, and exactly how to fix each one before your next audit.

What Happens During an ISO 27001 Audit?

Before looking at the problems, it helps to understand the ISO 27001 audit process itself, since the type of audit changes what the auditor is actually checking.

  • Stage 1 audit: The auditor reviews your documentation, risk assessment, and Statement of Applicability (SoA) to see if you are ready to move forward.
  • Stage 2 audit (ISO 27001 certification audit): The auditor checks whether your ISMS is actually implemented and working, not just written down.
  • Surveillance audit: Conducted annually after certification. An ISO 27001 surveillance audit does not review everything again; it samples parts of your ISMS to confirm you are still compliant.
  • Recertification audit: Every three years, a full ISO 27001 external audit is carried out to renew your certificate.
  • Internal audit: Carried out by your own team, or a hired consultant, before the certification body ever shows up. Many organisations assign this to someone trained as a Certified ISO 27001:2022 Lead Auditor internally, since the role is built around spotting gaps before an external assessor does. 

Since the 2022 revision reorganised Annex A into 93 controls across four themes (organisational, people, physical, and technological), auditors now check your ISO 27001 audit requirements against this newer structure, which has created some fresh confusion for teams still working from older templates.

what-happens-during-an-iso-27001-audit

Common ISO 27001 Audit Findings and How to Fix Them

The following issues are widely reported by certification bodies and ISO consultants as the ones auditors raise most often, whether it is a first certification audit or a routine surveillance visit. Exact frequency varies by industry and certification body, but these are the patterns that come up repeatedly across audit reports.

Common IssueWhat Auditors FindWhy It HappensHow to Fix It
Risk assessmentNo structured or repeatable process; risk register exists but is outdatedRisk assessment treated as a one-time exercise instead of an ongoing activityReview the risk register on a defined schedule, and whenever systems, suppliers, or threats change
Statement of Applicability (SoA)Controls are listed but not clearly linked to the risks they addressSoA built from a template instead of mapped to actual risk decisionsDocument why each control was selected and tie it directly to a specific risk
Internal auditsInternal audit programme does not cover all ISMS processes or controlsInternal audits done for compliance, not to genuinely test the systemRotate audit scope each cycle so every process and control gets tested over time
Management reviewMeetings happen but lack real discussion, data, or decisionsReview treated as a checkbox exercise rather than a strategic discussionRecord decisions, actions, responsibilities, and follow-up dates, not just attendance
Access controlUser access not reviewed regularly; former employees still have system accessNo formal process to revoke or review access on a scheduleSet periodic access reviews and a documented offboarding procedure
DocumentationPolicies describe one process, but staff follow a different one in practicePolicies written once and never updated to match real operationsReview and update policies alongside any process change, not just once a year
Corrective actionsRoot cause not properly investigated; the same nonconformity repeats next auditFixes address symptoms rather than the underlying causeUse a root cause method (such as the "5 whys") before closing any corrective action
Business continuityPlans exist but are untested or incompleteBCP written to satisfy the standard rather than tested against a real scenarioRun regular exercises to test the plan and update it based on the results
Awareness trainingStaff cannot explain basic security policies when askedTraining delivered once at onboarding, never refreshedRefresh awareness training regularly and track participation and completion

These gaps come up so often that they now shape how ISMS training itself is designed. Programs such as those from the Global Skill Development Council (GSDC) are structured around this exact list, risk assessment, access control, internal audits, and corrective action handling, because these are the areas where auditors consistently find real-world practice falling short of the documentation.

Major vs Minor Nonconformities

A quick way to read your audit findings:

  • Major nonconformity: A required element is missing entirely, or the system has broken down completely. This must be fixed before certification is granted.
  • Minor nonconformity: A single lapse in an otherwise working process. You get time to submit a corrective action plan.
  • Observation: Not a failure yet, but a signal the auditor wants addressed before it becomes one.
major-vs-minor-nonconformities

ISO 27001 Audit Checklist Before Your Audit

A well-built ISO 27001 checklist is the most reliable way to avoid the issues listed above. Break it into three parts.

Documentation checklist

  • Information security policy and objectives
  • Risk assessment methodology and current risk register
  • Statement of Applicability, mapped to specific risks
  • Internal audit reports and results
  • Management review minutes with decisions recorded
  • Corrective action log with root cause analysis
  • Business continuity and incident response plans, tested and dated

Process checklist

  • Access rights reviewed on a fixed schedule
  • Asset inventory kept current
  • Supplier and third-party risk assessed
  • Awareness training refreshed at least annually

Evidence checklist

  • A clear evidence trail for every control listed in the SoA
  • Records that show controls are followed, not just documented
  • Dates and owners attached to every review, test, and training record

If you want a structured starting point, an ISO 27001 gap analysis checklist run six to eight weeks before your audit is one of the most effective ways to catch gaps while there is still time to close them.

How to Prepare for an ISO 27001 Internal Audit

Your ISO 27001 internal audit checklist should mirror what the external auditor will actually check: sampling evidence, interviewing staff, and testing whether controls work in practice, not just whether they exist on paper. A few habits that make internal audits more useful:

  • Assign a different reviewer than the person who owns the process, where possible
  • Sample real evidence (logs, tickets, access records) instead of only reviewing policy documents
  • Log findings the same way an external auditor would, using major, minor, and observation categories
  • Track every internal finding through to a documented fix before the external audit

After every audit, whether internal or external, you should receive an ISO 27001 audit report that lists the scope reviewed, nonconformities found, evidence referenced, and the timeline for corrective action. Keep past reports on file. Repeated findings across multiple reports are one of the fastest ways to turn a minor nonconformity into a major one at the next audit.

Download the checklist for the following benefits:

  • 📋 Prepare for your next ISO 27001 audit with confidence.
  • 🔍 Review your documentation, processes, evidence, and common audit gaps.
  • ⬇️ Download the free checklist and get audit-ready before the external auditor arrives! 

How Much Does an ISO 27001 Audit Cost?

ISO 27001 audit cost is one of the most common questions, and it depends on a few factors: number of employees and sites covered by the ISMS, complexity of your IT environment, which audit stage you are booking, and the certification body and country you work with. Beyond the certification body's fees, budget for internal costs too, staff time, gap analysis, and remediation of findings, which often add up to more than the audit fee itself.

How an ISO 27001 Lead Auditor Can Help

A lot of the issues in the table above come down to one thing: nobody in the organisation is trained to audit the ISMS the way a certification body will. This is where having a Certified ISO 27001:2022 Lead Auditor on your team, or working with one, makes a real difference. They know how to test controls the way an external auditor does, spot the gap between documented policy and actual practice, and write findings the business can act on before the real audit ever starts.

For organisations or individuals looking to build this capability in-house, the Global Skill Development Council (GSDC) offers ISO 27001 lead auditor training as one of its certification programs.

common-iso-27001-audit-issues-and-how-to-fix-them-cta

Final Thoughts

No ISO 27001 audit is ever completely clean, and that is fine. What separates organisations that sail through recertification from those that struggle is not perfection. It is whether they treat their ISMS as a living system that gets reviewed, tested, and improved between audits, rather than a folder of documents dusted off once a year.

Build your checklist early, run your internal audits honestly, and treat every finding, major or minor, as a chance to close a real gap rather than just satisfy an auditor.

The best time to find an ISO 27001 audit gap is before your external auditor does. Keep your ISMS active throughout the year, test controls with real evidence, and use internal audits to challenge your processes honestly.

Author Details

Jane Doe

Matthew Hale

Learning Advisor

Matthew is a dedicated learning advisor who is passionate about helping individuals achieve their educational goals. He specializes in personalized learning strategies and fostering lifelong learning habits.

Related Certifications

Frequently Asked Questions

An ISO 27001 certification audit checks whether your ISMS meets the requirements of the standard and whether it is actually working in practice. Auditors review your risk assessment, Statement of Applicability, policies, records, and interview staff to confirm that documented controls are followed day-to-day, not just written down.

Duration depends on the size and complexity of the organisation. A Stage 1 audit is usually shorter, focused on document review, while a Stage 2 audit takes longer since auditors sample evidence and speak with multiple teams. Surveillance audits are typically shorter than the original certification audit since they only sample parts of the ISMS.

An internal audit can be carried out by a trained employee who is independent of the process being audited, or by an external consultant. What matters most is that the person understands the standard and can objectively test whether controls are working, rather than simply confirming documents exist.

A single audit rarely results in outright failure. If major nonconformities are raised, certification is paused until they are corrected and verified. Minor nonconformities allow certification to proceed alongside an agreed corrective action plan and a follow-up review.

Surveillance audits are typically conducted annually after initial certification, in the first and second year of the three-year certification cycle. A full recertification audit, covering the whole ISMS again, takes place at the end of that three-year cycle.

Enjoyed this blog? Share this with someone who’d find this useful


If you like this read then make sure to check out our previous blogs: Cracking Onboarding Challenges: Fresher Success Unveiled

Not sure which certification to pursue? Our advisors will help you decide!

+91

Already decided? Claim 20% discount from Author. Use Code REVIEW20.

Related Blogs

Recently Added