Before the Audit
Define audit scope and objectives
Create audit schedule covering all ISMS processes over audit cycle
Select auditors who are independent of the area being audited
Review previous audit findings and corrective actions
Prepare audit checklists based on ISO 27001 clauses and Annex A controls
Notify auditees and schedule interviews
During the Audit
Hold opening meeting to confirm scope and approach
Review documentation: policies, procedures, records
Interview process owners and staff
Observe actual practices (don't just read documents)
Verify evidence of control implementation
Check that previous nonconformities have been addressed
Document findings as you go — with evidence references
Classifying Findings
•Major nonconformity A requirement is not met at all, or a systematic failure
•Minor nonconformity A partial failure or isolated incident
•Observation An area for improvement (not a formal nonconformity)
•Positive finding Something working particularly well
After the Audit
Hold closing meeting to present findings
Write audit report with clear findings and evidence
Raise corrective actions for all nonconformities
Track corrective actions to completion
Verify effectiveness of corrective actions
Present results to management review
What Auditors Expect
Certification auditors will review your internal audit programme for:
•Coverage of all ISMS requirements over the audit cycle
•Independence of auditors
•Quality of findings (not just "everything is fine")
•Evidence that corrective actions were effective