I'm a lead ISO 27001 auditor. Here's what I can't see when I sign off your audit.
An honest account of what a point-in-time audit structurally cannot observe — written from the auditor's chair, not against it. The limits are in the frame, not the diligence.
I sign off ISO 27001 audits. For years before that I sat on the other side of the table — the system owner presenting the evidence, not the auditor sampling it — through more audits than I can count. Having now been in both chairs, I want to be plain about what my signature means, because I think the market has quietly inflated it into something no auditor claims.
When I sign off, I am attesting that I examined your information security management system against a standard, sampled its controls and evidence, and formed a competent, defensible opinion that it conformed on the days I was looking. That is a real statement and I stand behind it. It is also narrower than almost everyone who reads it believes. None of what follows is a confession of bad work. It’s a description of the frame. A point-in-time audit has structural blind spots that no amount of diligence on my part closes, because they belong to the method itself.
I see a sample, not the population
I cannot inspect every control on every system on every day, so I sample. I pull a set of change records, not all of them. I test a handful of joiners and leavers, not the whole year’s. I interview the people who are available. From that slice I reason to a conclusion about the whole, using trained judgement — and that inference is legitimate. But it is an inference. If the thing that will hurt you sits outside the sample, I will not have touched it, and I will have signed off honestly all the same. Sampling is how assurance works; it is also the first thing I cannot see past.
I see the day you prepared for
By the time I arrive, you have been getting ready for weeks. The evidence is collated, the access reviews are freshly run, the policies were reviewed the month before. I’m not complaining — a well-prepared audit is a professional courtesy and it makes my job possible. But I should be honest about what it means: I am looking at your organisation on one of the few days a year it is arranged to be looked at. The state I certify is, to some degree, the state you assembled for the occasion.
I can tell you the room was tidy on the day I visited. I cannot tell you what it looks like when no one is expecting me.
I cannot see the drift after I leave
This is the big one, and it’s the one my signature is least equipped to address. The moment I close the audit, the clock starts on the year until the next surveillance visit — the eleven months in which the certificate keeps making its claim and no one is continuously testing it. In that stretch a configuration changes, an engineer leaves with access still live, a supplier alters the offering a control depended on, an exception is accepted and never revisited. I will see none of it. The certificate does not dim as those things happen. It says exactly what it said on the day I signed, right up until it is contradicted by an incident. My opinion has a shelf life; the document it is printed on does not advertise one.
I certify a system, not a guarantee
There is a category error I watch readers make constantly. I certify that a management system conforms — that you have the controls, the ownership, the processes, and that on my evidence they were operating. I am not certifying that no control will ever fail, that you will not be breached, or that every day between now and my next visit will look like the day I audited. Conformance is not immunity. When a certified organisation is breached through an in-scope control that drifted after the audit, nothing false was signed. The reader simply asked the certificate to carry a promise it was never issued to make.
Why the limits are the honest part
I could pretend otherwise. Plenty of the surrounding industry does — it takes my bounded, dated opinion and resells it as a standing state of security. I would rather name the edges of what I can see, because an assurance market that hides its blind spots is not more trustworthy for the hiding; it is just less examined. The diligence is real. So is the sample, and so is the judgement. All of it still describes a photograph taken on a day, which is the most a point-in-time audit was ever built to produce.
What belongs after the signature
So the question is not “is the audit any good” — it is, or it should be. The question is what covers the eleven months the audit structurally cannot. That is a different job, and it wants a different tool: not another photograph on another day, but a current, honest account of whether the state I certified is still the state you are in — the evidence still standing, the exceptions still governed, the posture carrying an expiry you can read rather than a logo that never changes.
That is where Frank sits — after the attestation, not in place of it. It does not issue certificates and it will not pretend to be an auditor. It keeps watching once I have gone home, so that “we were compliant at the time” is a fact you can check on any given day rather than a sentence you first hear in a post-incident review. My signature tells you what was true when I looked. Something has to tell you what is true now.
You can see what your own evidence still supports, today, without waiting for the next audit. Start with obligation visibility. It won’t sign anything for you — that part is still my job — but it will show you the state after the signature.