ISO 27001 Lead Auditor · Domain 5
Findings, Nonconformity and Corrective Action
About 18% of the exam
Grading a finding
- Major
- requirement absent or systemically failing
- Minor
- isolated lapse in a working process
- Observation
- concern short of a nonconformity
- Opportunity
- improvement suggestion carrying no obligation
- Escalation
- many minors can become major
- Coverage gap
- judge whether the risk stays untreated
- Consistency
- the same grade from any auditor
Grade against the criterion and the consequence, never against how cooperative the auditee has been
Anatomy of a nonconformity
- The requirement that was not met
- The objective evidence observed
- A clear statement of the gap
- Reference to clause or control
- Date, location and source recorded
- Written so a stranger understands
Correction versus corrective action
- Correction
- fixes the instance found
- Corrective action
- removes the underlying cause
- Containment
- limits exposure while fixing
- Effectiveness review
- proves the cause is gone
- Extension check
- look for the same elsewhere
- Recurrence
- the analysis was wrong
Root cause analysis
- Push past the first plausible answer
- Five whys suits a simple chain
- Fishbone suits many contributing factors
- Ask why the control missed it
- Separate human error from system design
- Repeated failure demands a different technique
Evaluating a corrective action plan
- Correction addresses the immediate exposure
- Cause named, not merely described
- Actions match the stated cause
- Owner and date for each action
- Phasing justified by risk, not convenience
- Verification evidence promised up front
- Extension to similar areas considered
Weak responses to a finding
- Retrain the individual and close it
- Update the procedure and close it
- Move the activity to a supplier
- Eighteen month plan for an urgent gap
- Claim the risk is negligible
- Argue the auditor misunderstood, without evidence
Verifying closure
- Receive the response
- Accept or reject the plan
- Allow implementation time
- Collect verification evidence
- Confirm effectiveness
- Close the finding
- Verification is documentary or on site
- Major findings usually need a visit
- Timescale reflects risk and complexity
- Closure needs evidence, not a promise
- Reopen when the same issue returns
Closed on paper and closed in practice are two different states
When the auditee disagrees
- Restate the requirement and the evidence
- Ask what evidence would change it
- Verify any new claim properly
- Withdraw the finding if it is wrong
- Otherwise record the diverging opinion
- Escalate through the audit team leader
- Never soften wording to buy agreement
Conformity and risk are separate questions; a requirement not met stays not met even where the risk looks small
Findings that repeat
- A third recurrence signals systemic weakness
- Question the corrective action process itself
- Check whether management review saw it
- Look for resourcing or competence causes
- Grade the pattern, not the instance
Writing that survives challenge
- State facts before conclusions
- Quantify wherever you can
- Avoid blaming named individuals
- Offer no solution inside the finding
- Same wording in report and register
Findings and clause 10.2
- 10.2 a
- react, correct, handle the consequences
- 10.2 b
- evaluate the need for action
- 10.2 c
- implement action on the cause
- 10.2 d
- review the action effectiveness
- 10.2 e
- change the ISMS if needed
- Records
- nature, actions and results retained
Rapid recall: grade it
- Process never performed
- graded as major
- One missed signature
- usually a minor
- Control misses key accounts
- check the untreated risk
- Trend of minors
- consider raising a major
- Good idea, no gap
- opportunity for improvement
- Concern, no evidence yet
- record an observation
Reference strip: grade, state, cause, act, verify
Grade
- Major when a requirement fails
- Minor for an isolated lapse
- Observation carries no obligation
State
- Requirement, evidence, gap
- Clause or control referenced
- No names, no solutions
Cause
- Look past the first answer
- Ask why detection failed
- Check for the same elsewhere
Act
- Correction then corrective action
- Owner, date and evidence promised
- Phasing justified by risk
Verify
- Evidence of implementation collected
- Effectiveness confirmed afterwards
- Recurrence reopens the finding
Quick exam traps
- Trap: Any nonconformity found during a certification audit is automatically major
- Trap: Retraining the person involved is a complete corrective action
- Trap: A finding must be withdrawn whenever the auditee objects
- Trap: Completing the action on time proves it was effective
- Trap: Low risk means a missed requirement is not a nonconformity
- Trap: Observations must be corrected before the certificate is issued
- Trap: Moving the activity to a supplier removes the requirement
cybercertprep.com · original revision sheet written from the public body of knowledge