Evaluating Audit Evidence & Determining Findings
Learn how to move from collected evidence to a defensible audit finding — separating a fact from an inference, checking evidence against criteria rather than personal opinion, and recognizing when evidence is too thin to support a conclusion either way.
Learning Objectives
- → Distinguish an audit finding from a fact and from a personal opinion
- → Explain the process of evaluating evidence against criteria to reach a finding
- → Recognize when evidence is genuinely inconclusive rather than forcing a premature conclusion
- → Identify a finding that isn't actually supported by the evidence cited
Lesson 6 covered how to collect credible evidence. This lesson covers the step that turns collected evidence into an actual audit finding — and why that step is where a surprising amount of audit quality is won or lost.
What a finding actually is
An audit finding is the result of evaluating collected evidence against audit criteria — nothing more, and nothing less. This definition matters because it excludes two things people sometimes mistake for findings:
- A raw fact alone isn't yet a finding ("the SIEM logged 340 alerts last month" is a fact; whether that indicates conformity or a gap depends on evaluating it against a specific criterion, like whether alerts are meant to be reviewed within a defined timeframe).
- A personal opinion isn't a finding either ("I don't think this team takes security seriously" is an impression, not something traceable to specific evidence evaluated against a specific criterion).
A finding is always the output of a specific process: evidence, evaluated against criteria, produces a conclusion of conformity or nonconformity (or, in some frameworks, an observation — covered in the next lesson) for that specific criterion.
The evaluation process
For each checklist item (Lesson 4), the process is roughly: gather evidence (Lesson 6) → compare what the evidence actually shows against what the specific criterion requires → reach a conclusion. The critical discipline is keeping these steps separate and in order — an auditor who has already formed a conclusion (perhaps from a first impression, or from a prior audit's history with this client) and then selectively gathers evidence to support it has reversed the process, and violated both the evidence-based approach and fair presentation principles from Lesson 1.
When evidence is genuinely inconclusive
Not every checklist item resolves cleanly. Sometimes the evidence gathered is genuinely insufficient to support either a conformity or nonconformity conclusion — perhaps the sample was too small, or the relevant records weren't available during the audit window. The correct response to inconclusive evidence isn't to force a conclusion in either direction to avoid an awkward gap in the report; it's to document that the evidence was insufficient and, where the objective and timeline allow, seek additional evidence (an expanded sample, an additional interview) before the audit concludes. Reporting a conformity finding on genuinely thin evidence is just as much a violation of evidence-based approach as reporting an unsupported nonconformity.
Separating fact from inference in practice
A useful discipline: write down the specific fact observed, separately from the conclusion drawn from it, and check that the conclusion actually follows. "The access review log shows the Q2 review was completed 11 days after its scheduled date" is a fact. "This is a nonconformity against the policy's stated 5-business-day review window" is the finding — and it only holds if the criterion (the policy's stated window) is correctly cited and the fact genuinely falls outside it. An auditor who writes "reviews seem inconsistently timed" without citing the specific criterion and the specific dates has blurred fact and inference into something a report reviewer can't actually verify.
Why this step deserves real care
Every subsequent stage of this roadmap — classifying nonconformities (next lesson), writing the report, and the closing meeting — depends entirely on findings that were reached soundly at this stage. A rushed or sloppy evaluation here doesn't just risk one wrong finding; it risks the credibility of the entire audit, since a report reviewer (or a certification body's own internal quality process) who spots one finding that doesn't actually trace back to its cited evidence has reason to scrutinize every other finding in the same report far more skeptically.
An auditor writes in their notes: 'The vulnerability scan report shows 12 unpatched critical CVEs older than 90 days, while the patch management policy requires critical patches within 30 days.' Later, in the draft report, they write: 'Patch management here is basically ignored.' Using this lesson's reasoning, explain the problem with the second statement given the first.
What is the problem with 'patch management here is basically ignored' as a stated finding?
An auditor samples 2 records to check quarterly access reviews across a 500-person organization and finds both compliant. Time runs short and the auditor writes 'access reviews conform' as a finding rather than requesting a larger sample. Using this lesson's reasoning, explain what should have happened instead.
What should the auditor have done instead of writing 'access reviews conform' based on 2 records?
Before reviewing any evidence, an auditor tells a colleague: 'Based on this client's history, I already expect their incident management to be weak.' They then selectively request only records likely to confirm this expectation. Using this lesson's reasoning, name the two principles this approach violates.
What two principles does forming a conclusion before gathering evidence, then selectively confirming it, violate?
💪 Exercises & Challenges
Evaluating Evidence & Determining Findings — MCQ
Evaluating Evidence & Determining Findings — MCQ
Turn Raw Evidence into a Defensible Finding
Turn Raw Evidence into a Defensible Finding
The Unsupported Finding
The Unsupported Finding