Question 1 of 30
Consider a scenario where an ISO 27001 Lead Auditor is reviewing the implementation of a specific control related to access reviews. The auditee provides a documented procedure stating that access rights are reviewed quarterly. However, during the audit, the auditor finds no readily available records or logs demonstrating that these reviews have actually taken place in the last two quarters. The auditee\'s representative states that the reviews are conducted, but the records are stored in a separate system that is not immediately accessible and that they are confident the reviews are happening as per the procedure.\n\nWhat is the most appropriate course of action for the ISO 27001 Lead Auditor in this situation?
Request the auditee to provide evidence of the access reviews, such as logs, meeting minutes, or approval forms, and if such evidence cannot be produced or is insufficient, document a non-conformity for the control.
Accept the auditee's verbal assurance that the reviews are being conducted and proceed to the next audit area, noting the lack of immediate evidence for future follow-up.
Immediately issue a major non-conformity because the documented procedure is not being visibly supported by evidence during the audit.
Ask the auditee to provide a written statement confirming that the reviews are being performed, and consider this sufficient evidence to close the audit point.

Preparing for ISO 27001 Lead Auditor? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free