A checklist is an investigation worksheet
A useful audit checklist contains more than yes/no questions. For each question, record the requirement examined, the evidence needed and what the auditor actually established. The questions below are practical examples, not a complete reproduction of ISO/IEC 27001. Use the standard and your organisation’s approved arrangements to complete your own checklist.
Example questions by topic
| Topic | Audit question | Possible evidence |
|---|---|---|
| Scope | Do the boundaries still match delivered services? | Scope decision and record of changed services |
| Risk treatment | Has a selected measure actually been implemented? | Risk register, assigned action and implementation record |
| Access | Has withdrawn permission also been removed technically? | Departure notification and account record |
| Recovery | Has the agreed recovery method been tested? | Test report, result and follow-up |
| Improvement | Did a previous action achieve its intended effect? | Finding, cause analysis and effectiveness check |
| Suppliers | Does the assessment reflect the service risk? | Risk classification, agreements and evaluation |
| Governance | Are management review decisions followed through? | Decision, assigned action and result check |
Explain sample selection
Select records that help answer the investigation question. Include relevant differences, such as routine and emergency cases or different locations. Record the period and selection method. This example checklist has no universally correct number of files. Justify the sample using the objective, risk and available information. Extend the investigation where conflicting results make that necessary.
Fictional example: approval without implementation
A fictional organisation has a completed ticket for removing access. The checklist asks about both approval and implementation. The ticket says “done”, but the application account remains active. The auditor records both observations and investigates whether the status was changed manually without technical verification. This reveals more than a question asking only whether the ticket was closed.
Use explicit outcomes
Distinguish demonstrated, not demonstrated, not examined and not applicable with a reason. An empty field is ambiguous: was evidence missing, or was the topic skipped? Describe a nonconformity through the requirement and facts before proposing a solution. Keep findings traceable to the audit report and action register. Read the internal audit guide for planning and roles, and evidence and documentation for assessing records. ISO 19011:2026 provides guidance on audit methods.