Audit Findings
Audit findings are the documented results an auditor produces when they compare how something is actually done against how it is supposed to be done according to a defined standard, policy, or requirement. When the actual situation does not match the expected criteria, the gap is recorded as a finding. Findings typically explain what was observed, why it matters, and what should be corrected.
Audit findings are the reported outcomes of an examination, representing deficiencies or conditions identified when the auditor evaluates the current state of controls or processes against applicable criteria (such as policies, standards, or regulatory requirements). Findings are commonly structured using the elements of criteria, condition, cause, consequence, and corrective action to establish the basis, the observed gap, its root cause, its impact, and the recommended remediation. In a SOC 2 examination, deviations from expected control performance are typically characterized as exceptions and inform the CPA firm's opinion, while in an ISO/IEC 27001 certification audit, findings such as nonconformities are raised against the ISMS requirements and selected Annex A controls. The precise terminology, severity classification, and reporting treatment vary depending on the engagement type, the applicable framework, and the practitioner or certification body involved.
Why it matters
Audit findings are the primary output through which an examination or certification audit communicates where reality diverges from expectation. Because compliance outcomes hinge on how these gaps are documented and resolved, findings directly shape the auditor's conclusions, whether that is a CPA firm's opinion in a SOC 2 report or a certification body's decision in an ISO/IEC 27001 audit. A well-articulated finding does more than flag a problem; it establishes the criteria being tested, the condition observed, and the corrective action recommended, giving the audited organization a clear basis for remediation.
The stakes are practical. In a SOC 2 examination, deviations from expected control performance are typically characterized as exceptions, and a sufficient number or severity of exceptions can move an opinion away from unqualified. In an ISO/IEC 27001 certification audit, findings raised as nonconformities against the ISMS requirements or selected Annex A controls may need to be addressed before or as a condition of certification, depending on their severity and the certification body's process. In both cases, the terminology, severity classification, and reporting treatment vary by engagement type and framework, so understanding how a given practitioner or certification body handles findings is essential to interpreting the result.
It is also important to recognize what findings do not represent. A finding documents a gap against specified criteria at the time of the examination; it is not a comprehensive statement about an organization's overall security posture, nor does the absence of findings guarantee freedom from future incidents. A SOC 2 report attests only to the controls and period covered, and an ISO 27001 certificate covers only the defined scope of the ISMS, so findings should be read within those boundaries.
Who it's relevant to
Inside Audit Findings
Common questions
Answers to the questions practitioners most commonly ask about Audit Findings.