← Blog

I'm a lead ISO 27001 auditor. Here's what I can't see when I sign off your audit.

An honest account of what a point-in-time audit structurally cannot observe — written from the auditor's chair, not against it. The limits are in the frame, not the diligence.

I sign off ISO 27001 audits. For years before that I sat on the other side of the table — the system owner presenting the evidence, not the auditor sampling it — through more audits than I can count. Having now been in both chairs, I want to be plain about what my signature means, because I think the market has quietly inflated it into something no auditor claims.

When I sign off, I am attesting that I examined your information security management system against a standard, sampled its controls and evidence, and formed a competent, defensible opinion that it conformed on the days I was looking. That is a real statement and I stand behind it. It is also narrower than almost everyone who reads it believes. None of what follows is a confession of bad work. It is a description of the frame. A point-in-time audit has structural blind spots that no amount of diligence on my part closes, because they are properties of the method, not failures within it.

I see a sample, not the population

I cannot inspect every control on every system on every day, so I sample. I pull a set of change records, not all of them. I test a handful of joiners and leavers, not the whole year’s. I interview the people who are available. From that slice I reason to a conclusion about the whole, using trained judgement — and that inference is legitimate. But it is an inference. If the thing that will hurt you sits outside the sample, I will not have touched it, and I will have signed off honestly all the same. Sampling is how assurance works; it is also the first thing I cannot see past.

I see the day you prepared for

By the time I arrive, you have been getting ready for weeks. The evidence is collated, the access reviews are freshly run, the policies were reviewed the month before. I am not complaining — a well-prepared audit is a professional courtesy and it makes my job possible. But I should be honest about what it means: I am looking at your organisation on one of the few days a year it is arranged to be looked at. The state I certify is, to some degree, the state you assembled for the occasion.

I can tell you the room was tidy on the day I visited. I cannot tell you what it looks like when no one is expecting me.

I cannot see the drift after I leave

This is the big one, and it is the one my signature is least equipped to address. The moment I close the audit, the clock starts on the year until the next surveillance visit — the eleven months in which the certificate keeps making its claim and no one is continuously testing it. In that stretch a configuration changes, an engineer leaves with access still live, a supplier alters the offering a control depended on, an exception is accepted and never revisited. I will see none of it. The certificate does not dim as those things happen. It says exactly what it said on the day I signed, right up until it is contradicted by an incident. My opinion has a shelf life; the document it is printed on does not advertise one.

I certify a system, not a guarantee

There is a category error I watch readers make constantly. I certify that a management system conforms — that you have the controls, the ownership, the processes, and that on my evidence they were operating. I am not certifying that no control will ever fail, that you will not be breached, or that every day between now and my next visit will look like the day I audited. Conformance is not immunity. When a certified organisation is breached through an in-scope control that drifted after the audit, nothing false was signed. The reader simply asked the certificate to carry a promise it was never issued to make.

Why the limits are the honest part

I could pretend otherwise. Plenty of the surrounding industry does — it takes my bounded, dated opinion and resells it as a standing state of security. I would rather name the edges of what I can see, because an assurance market that hides its blind spots is not more trustworthy for the hiding; it is just less examined. The diligence is real. The sample is real. The judgement is real. And all of it describes a photograph taken on a day, which is the most a point-in-time audit was ever built to produce.

What belongs after the signature

So the question is not “is the audit any good” — it is, or it should be. The question is what covers the eleven months the audit structurally cannot. That is a different job, and it wants a different tool: not another photograph on another day, but a current, honest account of whether the state I certified is still the state you are in — the evidence still standing, the exceptions still governed, the posture carrying an expiry you can read rather than a logo that never changes.

That is where Frank sits — after the attestation, not in place of it. It does not issue certificates and it will not pretend to be an auditor. It keeps watching once I have gone home, so that “we were compliant at the time” is a fact you can check on any given day rather than a sentence you first hear in a post-incident review. My signature tells you what was true when I looked. Something has to tell you what is true now.

You can see what your own evidence still supports, today, without waiting for the next audit. Start with obligation visibility — it will not sign anything for you. It will show you the state after the signature.