Grade These Twelve ISMS Audit Findings: A Practice Exercise
Twelve findings from a single ISMS certification audit, for you to grade as a major nonconformity, a minor, an observation, or no finding at all. Each answer explains what the grade turns on, which is what the CQI and IRCA exam actually marks.
Twelve findings from a single ISMS certification audit, for you to grade as a major nonconformity, a minor, an observation, or no finding at all. Each answer explains what the grade turns on, which is what the CQI and IRCA exam actually marks.
Every finding below was written for this page by 3FOLD TRAINING's tutors, and the organisation they describe is invented. None is taken from a CQI and IRCA examination, and none is taken from 3FOLD TRAINING's own graded mock exams or reproduces what one of them tests.
Why practise grading separately?
Because it is a different skill from recognising a nonconformity, and the exam tests it harder. Most candidates can see that something is wrong; rather fewer can say, on the evidence in front of them, whether it is major or minor. Domain 4 is set at apply and evaluate and Domain 5 at evaluate alone, so 56 of the 80 marks turn on judgements of this kind.
The rule is short. A major is a systemic failure, a required control or process absent altogether, or a failure serious enough to put the ISMS's intended outcomes in doubt. A minor is an isolated lapse against a defined requirement. An observation flags a risk before any requirement is breached. Where none is engaged, the honest answer is no finding.
What makes it hard is that the rule says nothing about how bad something feels, and feeling is what most people grade on. Something can sound alarming and be a minor, or sound trivial and be a major. The grade comes from the evidence and the requirement, not the impression.
How should you work this exercise?
Grade each finding as a major nonconformity, a minor nonconformity, an observation, or no finding. Write the reason down before you look, because the reason is what the exam marks and the grade on its own is worth nothing without it.
One note on observation, because the term gets used loosely. Here it means what the course means: flagging a risk before any requirement is breached. Nothing below turns on separating it from an opportunity for improvement, so where an answer says observation and you would have said opportunity for improvement, you have not made the mistake this exercise tests for.
Two habits are worth building. First, name the requirement before the grade: if you cannot cite a clause, a control or the organisation's own arrangement, ask whether you have a finding at all. Second, read all twelve before committing to any, because the audit is one story and some of these findings explain each other.
None of these findings predicts what you will be shown in the examination. They ask for the same judgement the examination asks for, so working through them shows you where your grading is unreliable while there is still time to act on it.
Every finding below comes from the same audit: a Stage 2 certification audit of Brackenhoe Insurance Services, an invented broker with 400 staff across a head office and three regional branches, holding customer financial and health data. Grade each one, then check your reasoning against the answer.
The twelve findings
What should the tally have looked like?
Four majors, five minors, two observations and one that is not a finding. If your grades were mostly right but your reasons vague, that is the more useful thing to know: a right answer reached from the wrong reasoning will not survive a differently-worded question.
Four patterns account for most wrong grades.
- Grading on seriousness rather than evidence. Findings 4 and 5 both sound bad. One is a minor and one a major, and the difference is not how bad they sound.
- Treating an absence as a bad rate. Finding 7 is not a process working poorly; it is one that has never operated. Nought out of eight over four years differs in kind from two out of eight.
- Missing the pattern. Finding 12 reads as four local minors until you notice it is the same gap at every site in the same proportion. Related minors pointing to one underlying failure aggregate into a major, and that is a judgement you have to make deliberately.
- Reading each finding in isolation. Findings 6 and 7 are one story told twice: the internal audit never carried out is the supplier audit, and supplier review is the process that has never operated. One explains the other.
Frequently asked questions
How do I decide a grade under CQI IRCA exam conditions?
Evidence of a systemic failure, a required control absent altogether, or a failure that puts the ISMS's intended outcomes in doubt. An isolated lapse is a minor.
Can several minor nonconformities in ISMS Certification audit become a major?
Yes. Related minors pointing to one underlying failure aggregate into a major, and recognising that is a deliberate act rather than something the evidence does for you.
When should I raise an observation in the ISMS Audit instead?
When there is real risk and no requirement is breached. If you are stretching a control to cover the situation, an observation is what you have.
Is it wrong to raise no finding at all in an ISO 27001 Audit?
No. Raising one the evidence does not support is as serious an error as missing a real one, and if you cannot name the requirement, you do not have a finding.
Where to go next
Grading is examined hardest in the last two domains. The Domain 5 practice questions cover reporting, the closing meeting and corrective action; the Domain 4 practice questions cover conducting the audit and forming the findings in the first place. When both feel comfortable, sit the free 40-question mock exam whole — and if you have been revising from downloaded question banks, what those actually contain is worth knowing.
3FOLD TRAINING is a CQI and IRCA Approved Training Partner, ATP number 6039853. Its ISO 27001 Lead Auditor training course is the CQI and IRCA Certified ISO/IEC 27001:2022 ISMS Lead Auditor (PR373). The course identification number is 2889. Both the partner approval and the course certification are on 3FOLD TRAINING's Approved Training Partner record, and any provider's certified courses can be looked up in CQI and IRCA's own directory of certified courses and approved training partners. The ISO 27001 Lead Auditor training course page carries the schedule and what the course includes. If you would rather ask a person first, use the course enquiry form.
Booking a PR373 course? See the schedule, trainers and what's included.
View the course





Leave a Reply
Your email is safe with us.