Audit Conclusions

Objectives of Audit Conclusions

  • Preparing audit conclusions
  • Discussing audit conclusions with the auditee
  • Closing meeting
  • Audit report
  • Audit follow-up
  • Certification decision
  • Content of a certificate

Preparing Audit Conclusions

ISO 19011, clause 6.4.9

Before the closing meeting, the auditors meeting consult each other to:

  • Review the audit findings, and any other appropriate information collected during the audit, against the audit objectives
  • Agree on the audit conclusions
  • Prepare the recommendations, if specified in the audit objectives
  • Discuss the audit follow-up steps if this was predetermined in the audit plan

Discussing Audit Conclusions with the Auditee

It is important to discuss audit findings and conclusions with the management before the closing meeting and submitting the final report to:

  • Avoid any oversight, or misunderstanding Corroborate conclusions with the management
  • Give the management the possibility to answer certain questions and provide new evidence
  • Encourage the implementation of corrective actions as soon as possible

Closing Meeting Agenda

Model

  1. Attendance list
  2. Acknowledgements
  3. Recap of audit objectives and scope
  4. Presentation of conclusions and recommendation related to certification
  5. Presentation of non-conformities
  6. Recommendation for improvement (optional)
  7. Limitations
  8. Question &Answer period
  9. Audit follow-up

Preparing & Distributing the Audit Report

The audit team leader must be responsible for the preparation and the content of the audit report

  • The audit report must provide a clear, accurate, concise and complete picture of the audit
  • It must be a written report
  • The certification body maintains ownership of the audit report

The audit report shall be Published after a predetermined time period

  • Dated, verified and approved
  • Distribute to recipients

Contents of the Audit Report

ISO 1901 1, clause 6.5.1

The audit report must include or make reference to the following elements:

  • Audit objectives and Audit scope
  • Identification of the audit client
  • Identification of audit team and auditee’s participants in the audit
  • Dates and locations where the audit activities were conducted
  • Audit criteria
  • Audit findings and related evidence
  • Audit conclusions
  • A statement on the extent of the conformity to the audit criteria
  • Any unresolved diverging opinions between the audit team and the auditee
  • Audits by nature are a sampling exercise; as such there is a risk that the audit evidence examined is not representative.

Audit Follow-up

ISO 19011, clause 6.7 & ISO 17021, clause 9.1.12-13

• Based on the audit conclusions, the auditor may have to conduct a follow-up audit before the organization is recommended for certification

• Subject is the review of the corrections, identified causes and corrective actions related to the non-conformities identified in the audit report as well as the verification of the effectiveness of all corrections and corrective actions

A major non-conformity will often involve a follow-up audit

Certification Decision

ISO 17021, clauses 7.5.2, 9.2.5.1, 9.2.5.2 & 9.1.14

The certification body must make the certification decision based on:

  • An evaluation of the results and conclusions of the audit
  • Any other relevant information (for example, public information, client comments on the audit report)

The auditors having taken part in the audit never take part in the certification decision.

Content of the Certificate

The certificate issued by the certification body contains the following information:

  • Name and geographical location of audit client
  • Date of certification and expiration of said certification Unique identification code
  • Standard for which the audit client is certified Scope of the management system
  • Name and address of the certification body

Completing Audit

  • The audit is complete when all the activities described in the audit plan have been performed and approved and when the audit report is distributed
  • It is appropriate to archive, return or destroy documents related to the audit as agreed by participating parties.

Discover more from Information Security Blogs

Subscribe to get the latest posts sent to your email.

Leave a comment

Discover more from Information Security Blogs

Subscribe now to keep reading and get access to the full archive.

Continue reading