What are the pitfalls to avoid in conducting ISO 27001 audits?

Some pitfalls to avoid when organising and conducting an ISO 27001 audit include:

  • Not communicating the scope and criteria effectively enough for the audit and inadequate planning/confirmation with the departments/areas being audited.
  • Allowing auditees to assume control of the audit, potentially avoiding responses to the questions asked
  • Not collecting adequate objective evidence to support statements of conformance or nonconformance
  • Allowing subjectivity to influence audit findings and conclusions - i.e. not being objective
  • Being poorly prepared and not understanding the policies, clauses or controls that are being audited
  • Following audit trails that are inconsequential and compromise the ability to conduct the audit in the available timeframe.
No items found.
"
We are immensely grateful to URM for their unwavering support, professionalism, and expertise throughout our ISO 27001 and Cyber Essentials Plus journey. Their guidance and strategic insights have been invaluable. With URM's continued partnership and support, we are confident in our ability to proactively address emerging threats and keep our business secure.
contact US

Let us help you

Let us help you in your compliance journey by completing the form and letting us know how we can best support you.