Foundations of Auditing & ISO 19011 Principles
Learn the seven auditing principles behind every credible management system audit, why they exist, and how violating any one of them can invalidate an otherwise technically correct audit finding.
Learning Objectives
- → List and explain the seven ISO 19011 auditing principles
- → Distinguish a first-party, second-party, and third-party audit
- → Explain why independence and evidence-based approach are structural requirements, not just good manners
- → Identify a principle violation in a described audit scenario
Foundation taught you what ISO/IEC 27001 requires. Implementer taught you how to build it. This roadmap is about a different skill entirely: independently verifying that what was built actually conforms — a skill governed by its own standard, ISO 19011 (Guidelines for auditing management systems), which applies to auditing any management system standard, not just information security.
Why auditing needs its own standard
An audit's value depends entirely on whether its conclusions can be trusted by someone who wasn't in the room — a certification decision, a management team, or a customer relying on a supplier's certificate. That trust doesn't come from the auditor's technical knowledge alone; it comes from the audit being conducted according to consistent, well-understood principles that anyone can check the audit against after the fact. ISO 19011 exists to define exactly those principles, independent of which management system standard (27001, 9001, 14001, or others) is being audited.
The seven auditing principles
- Integrity — the foundation of professionalism. An auditor performs work honestly, diligently, and within the bounds of their actual competence — not stretching into areas they aren't qualified to assess.
- Fair presentation — the obligation to report truthfully and accurately, including disagreements between the audit team and the auditee, and any unresolved issues, not just a smoothed-over summary.
- Due professional care — applying diligence and judgment proportionate to the audit's importance and the confidence placed in it by whoever relies on the outcome.
- Confidentiality — information obtained during an audit is used appropriately and protected, including from unauthorized disclosure to parties outside the audit's proper stakeholders.
- Independence — the basis for impartiality and objectivity of audit conclusions. This is why, as covered in Implementer's internal audit lesson, an auditor cannot audit their own work — the same principle scales up to external audits, where the certification body itself must have no conflicting commercial interest in the outcome.
- Evidence-based approach — a rational method for reaching reliable, reproducible conclusions. Audit conclusions must trace back to a sample of available, verifiable information — not the auditor's general impression or the auditee's self-reported claims alone.
- Risk-based approach — an audit approach that considers risks and opportunities, influencing the audit program's planning, conduct, and reporting priorities (covered in more depth in the next lesson).
These seven aren't independent trivia to memorize — they interlock. A finding that violates evidence-based approach (an auditor concluding a control is effective based only on being told so, with no sample checked) also tends to undermine fair presentation, because what gets reported no longer traces back to something verifiable.
First-party, second-party, and third-party audits
The same seven principles apply across three distinct audit types, distinguished by who is auditing whom:
| Type | Who audits whom | Example |
|---|---|---|
| First-party | An organization audits itself | The internal audit program covered in Implementer |
| Second-party | An organization audits another it has an interest in | A company audits a critical supplier's security practices |
| Third-party | An independent body audits an organization | A certification body's Stage 1/Stage 2 audit (Foundation) |
Independence requirements scale with the stakes: a first-party auditor must simply not audit their own work; a third-party certification body must have no commercial relationship that could bias the certification decision itself (e.g., the same body cannot both consult on building an ISMS and certify it — a direct conflict of interest that most accreditation schemes explicitly prohibit).
Where a technically correct finding can still be invalid
A subtle point worth internalizing early: an audit finding can be factually accurate and still be professionally invalid if it was reached by violating one of these principles. An auditor who correctly identifies a real control gap, but does so by reading confidential customer data beyond what the audit scope required (violating confidentiality), or by using evidence obtained outside their assigned audit role (violating independence), has produced a finding that a rigorous quality review would need to discard or heavily qualify — being right isn't sufficient if the process used to get there wasn't sound. This is why later lessons in this roadmap spend real time on how evidence is properly collected, not just what to look for.
During a third-party certification audit, the lead auditor is a personal friend of the company's CISO and previously worked as a paid consultant helping this same company design its ISMS two years ago. The audit findings themselves appear technically accurate. What principle is most directly at risk here, and why does technical accuracy not resolve the problem?
What principle is most directly at risk in this scenario, and why doesn't technical accuracy resolve it?
A company's internal audit team reviews its own access control implementation ahead of an upcoming certification audit. Separately, that same company sends a security questionnaire and requests an on-site visit to assess a critical cloud storage supplier. Classify each of these two audits by type (first/second/third-party) and justify each classification.
What type of audit is the internal audit team's review of its own access controls, and why?
What type of audit is the review of the cloud storage supplier, and why?
An auditor writes in their report: 'Access reviews are conducted quarterly, as confirmed by the IT manager during interview.' No access review records, tickets, or logs were requested or examined. Using the evidence-based approach principle, explain what is missing from this finding and why it matters.
What is missing from this finding, and why does it matter under the evidence-based approach principle?