Skip to content

ISO STANDARDS · 14 AUGUST 2026 · 2 MIN READ

Five signs you are not ready for an ISO audit

The patterns an auditor spots in the first hour, and what each one says about how the system is being run.

Auditors are pattern-matchers. They have seen hundreds of management systems and they know within an hour whether yours runs or whether it was assembled for their visit. These are the tells.

1. Every document was last modified in the same fortnight

Open the document register. If forty policies share a review date three weeks before the audit, the system did not run; it was written. A live system shows documents reviewed on their own cadence: the access control policy in March when the identity provider changed, the incident procedure in June after a near miss.

Fix: review dates come from the document, not the calendar. Version history should tell a story.

2. Nobody can find the last internal audit

Clause 9.2 requires an internal audit programme. Not one audit but a programme, covering the whole system across the cycle, with findings, and evidence the findings were closed. If the answer to "show me last year's internal audit report" involves searching email, the auditor has already written the finding.

Fix: the internal audit is a record in the system, with findings that become corrective actions with owners and due dates.

3. Corrective actions live in someone's head

A nonconformity is not a failure. An unrecorded one is. Auditors expect to see problems found, root causes identified, actions taken and effectiveness checked. A clean sheet is more suspicious than a busy one.

Fix: one corrective-action log, every entry with a root cause and a verification date.

4. The Statement of Applicability disagrees with reality

The SoA says control A.8.24 (cryptography) is implemented. The auditor asks how keys are managed. The room goes quiet. The SoA was copied from a template and nobody reconciled it to what the organisation actually does.

Fix: the SoA should be generated from control status and linked evidence, not typed. If a control is not evidenced, the SoA should say so.

5. Evidence is screenshots in a folder called "Audit 2026"

Screenshots prove a moment. The auditor wants to know the control operates continuously: exports with dates, logs, records from the tool itself. A folder assembled for the audit is the definition of not running a system.

Fix: evidence is linked at the source, dated, owned, with a collection cadence, so it exists because the control ran.

By ISO Assist. Tagged AUDIT · READINESS · NONCONFORMITY.

More in ISO standards

Reading about it is the slow way.

Book a demo and see the standard adopted in a workspace.