ChecklistAuditor Expectations

5 Things Auditors Always Check First

Based on real audit experience: the areas certification auditors prioritise and what they expect to find.

Updated 14 Mar 2026

What Auditors Prioritise

Experienced auditors follow a pattern. Knowing what they look for first helps you prepare effectively.

1. Management Commitment

Auditors want evidence that leadership is actively involved — not just a signature on a policy. They look for:

Minutes from management reviews
Resource allocation decisions
Security objectives set by leadership

2. Risk Assessment & Treatment

This is the engine of your ISMS. Auditors check:

Methodology documentation
Completeness of risk identification
Logical connection between risks and controls
Evidence of regular review

3. Statement of Applicability (SoA)

Every Annex A control must be addressed. For each:

Is it applicable? Why or why not?
If applicable, what's the implementation status?
What evidence supports implementation?

4. Internal Audit Results

Auditors want to see that you audit yourself honestly:

Were nonconformities identified?
Were they addressed with corrective actions?
Is there a systematic audit programme?

5. Corrective Actions

How you handle problems reveals maturity:

Are root causes identified (not just symptoms)?
Are actions tracked to completion?
Is there evidence of effectiveness review?

The Meta-Point

Auditors are looking for a *living system*, not a documentation exercise. Show them the ISMS is actively used and continuously improved.

Related Modules

Standard Controls
Documents
Corrective Actions

Related Controls / Clauses

5.1
6.1.2
9.2
10.1

26 practitioner guides — included free with your workspace

27 Launchpad generates your full compliance toolkit from a 10-minute setup: policies, risk register, legal register, controls, and AI-assisted document review.