Skip to main content
Category: Audit Process

Audit Findings

Also known as: Findings, Audit Exceptions, Deficiencies
Simply put

Audit findings are the documented results an auditor produces when they compare how something is actually done against how it is supposed to be done according to a defined standard, policy, or requirement. When the actual situation does not match the expected criteria, the gap is recorded as a finding. Findings typically explain what was observed, why it matters, and what should be corrected.

Formal definition

Audit findings are the reported outcomes of an examination, representing deficiencies or conditions identified when the auditor evaluates the current state of controls or processes against applicable criteria (such as policies, standards, or regulatory requirements). Findings are commonly structured using the elements of criteria, condition, cause, consequence, and corrective action to establish the basis, the observed gap, its root cause, its impact, and the recommended remediation. In a SOC 2 examination, deviations from expected control performance are typically characterized as exceptions and inform the CPA firm's opinion, while in an ISO/IEC 27001 certification audit, findings such as nonconformities are raised against the ISMS requirements and selected Annex A controls. The precise terminology, severity classification, and reporting treatment vary depending on the engagement type, the applicable framework, and the practitioner or certification body involved.

Why it matters

Audit findings are the primary output through which an examination or certification audit communicates where reality diverges from expectation. Because compliance outcomes hinge on how these gaps are documented and resolved, findings directly shape the auditor's conclusions, whether that is a CPA firm's opinion in a SOC 2 report or a certification body's decision in an ISO/IEC 27001 audit. A well-articulated finding does more than flag a problem; it establishes the criteria being tested, the condition observed, and the corrective action recommended, giving the audited organization a clear basis for remediation.

The stakes are practical. In a SOC 2 examination, deviations from expected control performance are typically characterized as exceptions, and a sufficient number or severity of exceptions can move an opinion away from unqualified. In an ISO/IEC 27001 certification audit, findings raised as nonconformities against the ISMS requirements or selected Annex A controls may need to be addressed before or as a condition of certification, depending on their severity and the certification body's process. In both cases, the terminology, severity classification, and reporting treatment vary by engagement type and framework, so understanding how a given practitioner or certification body handles findings is essential to interpreting the result.

It is also important to recognize what findings do not represent. A finding documents a gap against specified criteria at the time of the examination; it is not a comprehensive statement about an organization's overall security posture, nor does the absence of findings guarantee freedom from future incidents. A SOC 2 report attests only to the controls and period covered, and an ISO 27001 certificate covers only the defined scope of the ISMS, so findings should be read within those boundaries.

Who it's relevant to

Compliance and GRC Managers
These professionals coordinate remediation once findings are documented, tracking corrective actions against the criteria that were tested. Understanding the five elements of a finding, criteria, condition, cause, consequence, and corrective action, helps them prioritize responses and demonstrate closure to auditors, keeping in mind that terminology and severity classification vary by framework and engagement.
Auditors and CPA Practitioners
Auditors produce findings by comparing the observed condition against applicable criteria and structuring the result so the gap, its cause, and its impact are clear. In a SOC 2 examination, they characterize deviations from expected control performance as exceptions that inform the firm's opinion, applying consistent criteria and reporting treatment appropriate to the engagement.
Certification Body Auditors
In an ISO/IEC 27001 certification audit, these auditors raise findings such as nonconformities against the ISMS requirements and the selected Annex A controls. How severity is classified and how a finding affects the certification decision depends on the certification body's process and the applicable version of the standard.
Security Engineers and Control Owners
The individuals responsible for the controls being tested must understand the root cause and consequence described in a finding to implement effective corrective action. Because a finding reflects a gap against specified criteria at the time of examination, addressing it typically involves both fixing the immediate condition and preventing recurrence within the defined scope.

Inside Audit Findings

Finding Description
A statement of the condition observed during the examination or audit, typically describing the control tested, the evidence reviewed, and the specific gap or deviation identified relative to the applicable criteria.
Classification or Severity
A categorization of the finding, which in an ISO 27001 audit typically distinguishes major nonconformities, minor nonconformities, and observations or opportunities for improvement. In a SOC 2 examination, deviations are described as exceptions noted in relation to the controls and period covered rather than using the ISO nonconformity taxonomy.
Affected Criteria or Requirement
A reference to the specific Trust Services Criteria (for SOC 2) or ISMS clause 4-10 requirement or selected Annex A reference control (for ISO 27001) that the finding relates to. Annex A references depend on the version cited and the Statement of Applicability.
Evidence and Context
The supporting evidence, sample results, or circumstances that led to the finding, along with the scope and period or point in time to which it applies.
Management Response or Corrective Action
Where applicable, the auditee's response, root cause analysis, and planned corrective actions. For ISO 27001 nonconformities this typically feeds a corrective action process; for SOC 2 exceptions, management may include a response within the report.

Common questions

Answers to the questions practitioners most commonly ask about Audit Findings.

Does a SOC 2 audit finding mean my organization has failed the examination?
Not necessarily. In a SOC 2 examination, findings are typically documented as exceptions or deviations noted during testing, and their presence does not automatically result in an adverse conclusion. The CPA firm evaluates whether identified exceptions affect the suitability of design (Type I) or operating effectiveness over the review period (Type II), and may issue an unqualified, qualified, adverse, or disclaimer of opinion depending on the nature and significance of the findings. A report with noted exceptions can still convey an unqualified opinion, so individual findings should be read in the context of the overall opinion rather than treated as a pass/fail outcome.
Are audit findings the same thing in a SOC 2 report and an ISO 27001 certification?
No, and the terminology and consequences differ between the frameworks. In a SOC 2 examination, findings generally take the form of exceptions or deviations that the CPA firm documents and factors into its attestation opinion. In an ISO 27001 certification, findings identified by the certification body are typically classified as nonconformities (often distinguished as major or minor) or as opportunities for improvement, and they relate to conformity with the ISMS requirements in clauses 4 through 10 and the controls selected via the Statement of Applicability. Because SOC 2 results in an attestation report and ISO 27001 results in a certification, the way findings are named, resolved, and reflected in the outcome is not directly equivalent.
How should we respond when an auditor documents a finding during fieldwork?
In most engagements, responding involves understanding the specific control or requirement the finding relates to, the evidence the auditor examined, and the reason the control did not operate or was not designed as expected. For SOC 2, this may include providing additional context or evidence for the review period, or acknowledging the exception so it can be described accurately in the report. For ISO 27001, a nonconformity typically requires corrective action, which may include root cause analysis and a remediation plan the certification body will review. The appropriate response depends on the auditor or certification body, the scope, and the significance of the finding.
Can findings be remediated before the report is issued or certification is granted?
This depends on the framework and the timing. For a SOC 2 Type I examination, which assesses the suitability of design at a point in time, remediation before the as-of date may allow controls to be evaluated as suitably designed. For a SOC 2 Type II examination, which covers operating effectiveness over a defined period, an exception occurring within that period is generally reflected in the report even if remediated later, though management responses can be included. For ISO 27001, minor nonconformities can often be addressed through a corrective action plan, while major nonconformities typically must be resolved before certification is granted. Specific handling varies by auditor, certification body, and scope.
How do we distinguish a significant finding from a minor one?
The distinction depends on the framework and the judgment of the auditor or certification body. In SOC 2, the significance of an exception is generally assessed by how it affects the suitability of design or operating effectiveness of controls relevant to the applicable Trust Services Criteria, and ultimately how it influences the opinion. In ISO 27001, findings are commonly categorized as major or minor nonconformities based on factors such as whether a requirement is systematically unmet or the ISMS is compromised. Because these evaluations rely on professional judgment and scope, there is no fixed universal threshold, and classifications can differ between engagements.
What should we track internally to manage findings across both frameworks?
In most GRC programs, teams maintain a record that links each finding to the affected control or requirement, the framework and scope it relates to, the responsible owner, the remediation status, and evidence of resolution. Because a SOC 2 report attests only to the controls and period covered and an ISO 27001 certificate covers only the defined ISMS scope, tracking should note which framework and scope each finding falls under so that remediation and evidence align with the correct examination or certification. Where controls overlap between the two frameworks, mapping can help coordinate remediation, though satisfying a requirement in one framework does not automatically resolve a corresponding finding in the other.

Common misconceptions

A finding in a SOC 2 examination means the report failed or that certification was denied.
A SOC 2 engagement results in an attestation report, not a certificate, so there is nothing to fail or deny in the ISO sense. Exceptions or deviations noted by the CPA firm are described in the report, and the auditor can still issue an opinion; the report attests only to the controls and period covered and does not guarantee freedom from breaches.
Any finding automatically prevents ISO 27001 certification.
In most ISO 27001 audits, minor nonconformities and observations typically do not block certification provided corrective action is addressed, whereas major nonconformities usually must be resolved before a certification decision. Outcomes depend on the certification body and the defined scope of the ISMS.
Clearing findings under one framework means the other framework's issues are resolved too.
SOC 2 and ISO 27001 use different criteria, structures, and outcome types, and mapping between them is only partial. Remediating a SOC 2 exception does not automatically clear a related ISO 27001 nonconformity, and satisfying one framework does not automatically satisfy the other.

Best practices

Record each finding against the specific applicable criterion, citing the relevant Trust Services Criteria for SOC 2 or the ISMS clause or Annex A reference control for ISO 27001, and note the framework version when referencing Annex A controls.
Clarify the scope and time frame each finding applies to, distinguishing point-in-time observations (as in a SOC 2 Type I) from findings spanning a review period (as in a SOC 2 Type II).
Use the correct terminology for each framework, describing SOC 2 outcomes as exceptions or deviations within a report and ISO 27001 outcomes as nonconformities or observations, rather than conflating the two.
Perform root cause analysis and document corrective actions for nonconformities, prioritizing major nonconformities that typically must be resolved before an ISO 27001 certification decision.
Avoid assuming a finding remediated under one framework resolves related issues in the other, and evaluate cross-framework impact separately given that mapping is only partial.
Retain supporting evidence, sample results, and management responses alongside each finding so that remediation can be tracked and verified in subsequent engagements or surveillance activities.