Audit Criteria
Audit criteria are the benchmarks or standards that an auditor uses as a reference point when examining an organization's policies, procedures, and controls. The auditor compares the evidence they gather against these criteria to determine whether the organization meets the expected requirements. In practice, the specific criteria depend on the type of engagement and the framework being applied.
Audit criteria are the policies, procedures, or requirements against which audit evidence is compared during an examination or verification activity. They serve as the defined reference points that auditors use to assess conformity, and may be drawn from internal documents (such as an organization's own policies and processes) or from external frameworks and regulatory requirements, depending on the scope and objectives of the engagement. In attestation and certification contexts, the selection of suitable criteria is a scoping decision that shapes what the audit evaluates; the criteria applied to a SOC 2 examination (the Trust Services Criteria) differ from those applied to an ISO/IEC 27001 certification (the ISMS requirements in clauses 4-10 and the Annex A reference controls selected via the Statement of Applicability), so criteria are not interchangeable across frameworks.
Why it matters
Audit criteria are the foundation of any credible examination or certification because they define exactly what "passing" means. Without clearly established criteria, an auditor has no objective reference point to compare evidence against, and the resulting conclusions become subjective and difficult to defend. In compliance engagements, the choice of criteria determines the scope of what is evaluated and what falls outside it, which is why the selection of suitable criteria is treated as a deliberate scoping decision rather than a formality.
The distinction matters most when organizations pursue different frameworks. A SOC 2 examination evaluates evidence against the Trust Services Criteria, while an ISO/IEC 27001 certification evaluates conformity against the ISMS requirements in clauses 4 through 10 and the Annex A reference controls selected through the Statement of Applicability. Because these criteria are not interchangeable, satisfying one framework does not automatically satisfy the other, and mapping between them is only partial. Misunderstanding which criteria apply can lead an organization to prepare for the wrong benchmarks and receive findings it did not anticipate.
Criteria also define the boundaries of what an audit outcome actually asserts. A SOC 2 report speaks only to the controls and criteria within its defined scope over the period covered, and an ISO 27001 certificate covers only the ISMS scope certified against the applicable requirements. Recognizing that criteria bound the conclusion helps stakeholders avoid over-reading a report or certificate as a broader guarantee than it provides.
Who it's relevant to
Inside Audit Criteria
Common questions
Answers to the questions practitioners most commonly ask about Audit Criteria.