Skip to main content
RiskZeroCertifiers

Audit insight

The nonconformities we raise most often in first ISO 27001 audits

The recurring findings from first ISO 27001 certification audits, why they happen, and what a clean implementation looks like, from auditors who see hundreds of ISMSs.

By RiskZero Certifiers6 min read

We keep records of findings across audits, and the same issues come up in first-time certifications year after year. None of them are exotic. Most are the result of building the ISMS to pass an audit rather than to run the organization, which ironically makes the audit harder to pass.

1. The risk assessment does not connect to anything

What we see: a risk register listing generic threats such as “malware” and “phishing”, scored with no stated method, and a Statement of Applicability that marks nearly every control applicable with the justification “best practice”.

Why it is a finding: clause 6.1.2 requires a repeatable method that produces consistent results, and clause 6.1.3 requires the Statement of Applicability to be derived from the treatment decisions. If the controls were not chosen because of the risks, the ISMS is not doing what the standard describes.

What good looks like: a method someone can explain, risks tied to assets or processes, treatment decisions that name the controls they rely on, and a Statement of Applicability whose justifications reference those decisions.

2. The internal audit was not independent, or was not really an audit

What we see: the ISMS owner audited their own work, or a consultant audited the system they built, or the audit report is a checklist of “compliant” with no evidence recorded.

Why it is a finding: clause 9.2 requires auditors to be objective and impartial and the program to consider the importance of processes and previous results. An audit with no findings from a system in its first year is not credible.

What good looks like: an internal auditor with no responsibility for the areas audited, a plan that covers all clauses and applicable controls over a defined period, and a report with evidence, findings, and follow-up.

3. Access reviews are policy, not practice

What we see: a policy stating that access is reviewed quarterly. No records of a review. Or a review that was a list of accounts with no evidence anyone decided anything.

Why it is a finding: A.5.18 requires access rights to be reviewed at planned intervals, and the auditor needs evidence the review produced decisions and actions.

What good looks like: a record of who reviewed which systems, what was removed or changed, and when. Ticket references are enough.

4. Leavers still have access

What we see: the auditor samples recent leavers from HR records and finds active accounts in cloud consoles, code repositories, or SaaS tools.

Why it is a finding: A.5.18 and A.6.5 require access to be removed on termination. It is also one of the most direct security risks an organization can have, and one of the easiest to test.

What good looks like: an offboarding checklist tied to the HR process, executed within a defined time, with evidence for every leaver. Single sign-on and automated deprovisioning help but do not cover everything.

5. Supplier security is a spreadsheet nobody maintains

What we see: a list of suppliers with a risk rating assigned once, no evidence of due diligence, and contracts with no security clauses. Critical cloud providers missing from the list.

Why it is a finding: A.5.19 to A.5.22 require security requirements to be defined in agreements and supplier performance to be monitored. The auditor will pick your most important suppliers and trace the process.

What good looks like: a supplier inventory that includes cloud and SaaS providers, a risk-based approach to due diligence, security terms in contracts or reliance on documented supplier attestations, and periodic review of critical suppliers.

6. Incidents are not recorded, so there is nothing to learn from

What we see: an incident response procedure and an empty incident log. When asked, staff describe several events that clearly were incidents.

Why it is a finding: A.5.24 to A.5.27 require incidents to be assessed, responded to, and learned from. An empty log in a live organization is implausible and suggests the process is not used.

What good looks like: a low threshold for logging events, a record for each with the assessment and outcome, and evidence that lessons changed something.

7. Backups are configured but never tested

What we see: backup jobs running. No restore test ever performed. Recovery objectives undefined.

Why it is a finding: A.8.13 requires backups to be tested regularly, and A.5.30 requires ICT continuity to be tested against objectives.

What good looks like: documented recovery objectives, periodic restore tests with results recorded, and action when a test fails.

8. Management review happened, but only just

What we see: a single meeting with minutes that list the required inputs as headings and no content underneath. No decisions, no actions, no resources allocated.

Why it is a finding: clause 9.3 lists specific inputs and requires outputs including decisions on improvement and resource needs. Headings are not inputs.

What good looks like: a review with real data on performance, incidents, audit results, and risk changes, and minutes that record what leadership decided.

9. Awareness training exists, but completion is unknown

What we see: a training module that was rolled out. Nobody can say who completed it. New starters were not enrolled.

Why it is a finding: clause 7.3 and A.6.3 require people to be aware of the policy and their contribution, and the organization must retain evidence of competence.

What good looks like: training assigned at onboarding and periodically, completion tracked, and a way to follow up non-completion.

10. Scope creep between documents

What we see: the scope statement says one thing, the Statement of Applicability implies another, and the certificate application says a third. Sites appear and disappear.

Why it is a finding: clause 4.3 requires the scope to be documented and available, and everything else depends on it.

What good looks like: one scope statement, referenced consistently, with sites, functions, and exclusions listed.

The pattern

Nearly every one of these is a gap between what the documents say and what the organization does. Auditors are trained to find that gap because it is where risk lives. The most effective preparation is not more documentation; it is running the system for long enough to have records, and being honest in the internal audit about what is not yet working.

  • nonconformities
  • findings
  • stage 2
  • audit preparation

Read next

Ready to scope your audit?

Tell us about your organization, your ISMS scope, and your target date. We reply with a fixed-fee quote and available audit dates within two business days.