Skip to main content
Category: Audit Process

On-Site Assessment

Also known as: on-site audit, on-site evaluation
Simply put

An on-site assessment is a part of an audit or certification process where the assessor physically visits an organization's premises to observe operations, inspect facilities, and gather evidence directly rather than only reviewing documents remotely. In security compliance, on-site visits let the assessor see how controls actually work in practice at a location. Whether an on-site visit is needed depends on the framework, the scope, and the judgment of the auditor or certification body.

Formal definition

An on-site assessment refers to assessment activities conducted at an organization's physical location, where the auditor or assessor performs observation, physical inspection, walkthroughs, and personnel interviews to obtain evidence about the design and operation of controls. In an ISO/IEC 27001 certification engagement, an on-site component is typically expected during the Stage 2 audit, where the certification body evaluates the implementation and effectiveness of the Information Security Management System (ISMS) against the requirements in clauses 4 through 10 and the applicable Annex A reference controls; the extent and location of on-site activity are governed by accreditation requirements for certification bodies and by the audit plan. In a SOC 2 examination conducted by a licensed CPA firm under the AICPA SSAE 18 standard, on-site procedures may be performed at the auditor's discretion when deemed necessary to test controls against the applicable Trust Services Criteria, though many procedures are increasingly performed remotely depending on scope and the nature of the controls. The value and outcome of an on-site assessment are bounded by the defined scope, the review period (for a SOC 2 Type II engagement) or point in time (for a Type I), and the specific controls examined; it does not, by itself, guarantee freedom from breaches or attest to matters outside the engagement scope. The specific extent, duration, and frequency of on-site activity vary by certification body, CPA firm, framework, and scoping decisions.

Why it matters

On-site assessments matter because certain security controls are difficult or impossible to verify through documentation alone. Physical access controls, environmental safeguards in server rooms, badge systems, visitor logs, and the way staff actually handle sensitive information are best evaluated by direct observation. Reviewing a policy document tells an assessor what an organization intends to do; visiting the premises helps confirm whether those intentions are reflected in daily practice at a specific location.

Who it's relevant to

Compliance and GRC managers
These professionals coordinate on-site visits, prepare facilities and personnel, and ensure evidence is available for observation. Understanding when an on-site component is typically expected, such as during an ISO/IEC 27001 Stage 2 audit, helps them plan logistics and set internal expectations about what assessors will inspect.
ISO 27001 certification bodies and auditors
Certification bodies rely on on-site activity, typically during the Stage 2 audit, to evaluate the implementation and effectiveness of the ISMS against clauses 4 through 10 and the applicable Annex A controls. The extent and location of on-site work are governed by accreditation requirements and the audit plan.
CPA firms performing SOC 2 examinations
Under the AICPA SSAE 18 standard, the CPA firm decides whether on-site procedures are necessary to test controls against the applicable Trust Services Criteria. Because many procedures are increasingly performed remotely, the firm's professional judgment and the nature of the controls determine when a physical visit adds value.
Security engineers and facilities staff
These personnel are often the subjects of walkthroughs, interviews, and physical inspections. They demonstrate how physical and technical controls operate in practice at a location, providing the direct evidence that on-site assessments are designed to capture.

Inside On-Site Assessment

On-Site Stage 2 Audit (ISO/IEC 27001)
In an ISO/IEC 27001 certification cycle, the Stage 2 audit normally involves on-site activity by the accredited certification body's audit team to evaluate the implementation and operating effectiveness of the ISMS. On-site procedures are contemplated by the accreditation requirements applicable to certification bodies (such as ISO/IEC 17021-1 and the ISO/IEC 27006 sector-specific guidance), which govern how conformity assessment is conducted.
On-Site Procedures in a SOC 2 Examination
SOC 2 is an attestation examination performed by a licensed CPA firm under the AICPA SSAE 18 standard. On-site work is not itself a defined deliverable; rather, the service auditor may perform on-site procedures, such as observation, inspection of physical controls, or interviews, when the auditor determines it is necessary to obtain sufficient appropriate evidence. Whether and how much on-site work occurs depends on the engagement, scope, and auditor judgment.
Evidence-Gathering Techniques
On-site assessment typically supports techniques such as direct observation of processes, physical inspection of facilities and controls, walkthroughs, and personnel interviews. These techniques complement, rather than replace, review of documentation and remotely provided artifacts.
Scope Dependence
The extent of on-site assessment is set by scoping decisions. For ISO 27001, the defined scope of the ISMS and the number and nature of physical sites influence on-site planning; for SOC 2, the Trust Services Criteria selected and the nature of the controls in scope influence whether on-site procedures add evidentiary value.

Common questions

Answers to the questions practitioners most commonly ask about On-Site Assessment.

Does an on-site assessment apply only to ISO 27001 and not to SOC 2?
No. While the on-site element is most commonly associated with ISO/IEC 27001 certification, it is not exclusive to it. ISO/IEC 27001 certification audits normally include an on-site Stage 2 audit, consistent with the requirements applicable to accredited certification bodies under ISO/IEC 17021-1 and ISO/IEC 27006. SOC 2 examinations, performed by a CPA firm under the AICPA SSAE 18 standard, may likewise involve on-site procedures when the CPA firm deems them necessary based on the nature of the controls and evidence being evaluated. The extent of on-site work in a SOC 2 engagement depends on the auditor's judgment and the scope.
Does completing an on-site assessment mean an organization has passed and is free from security risk?
No. An on-site assessment is one evidence-gathering activity, not a guarantee of security. For ISO/IEC 27001, a successful audit supports certification of the defined ISMS scope but does not assure freedom from breaches or cover matters outside that scope. For SOC 2, on-site procedures contribute to a report that attests only to the controls and, for a Type II, the period covered; it does not guarantee an absence of incidents. In both frameworks, outcomes depend on the certification body or CPA firm, the scope, and the applicable criteria.
When during an ISO 27001 engagement is the on-site assessment typically performed?
On-site assessment is most often associated with the Stage 2 audit, which evaluates the implementation and operating effectiveness of the ISMS. A Stage 1 review of documentation and readiness typically precedes it. The specific sequencing, duration, and whether any activities are conducted remotely depend on the certification body and the defined scope of the ISMS.
How should an organization prepare for the on-site portion of an assessment?
Preparation typically involves ensuring that relevant personnel are available for interviews, that documentation and records supporting the in-scope controls are accessible, and that the physical and system environments within scope can be observed. For ISO/IEC 27001, alignment between the Statement of Applicability, the risk assessment, and the operating controls is commonly reviewed. For SOC 2, availability of evidence supporting the controls mapped to the selected Trust Services Criteria is generally important. Exact expectations vary by certification body, CPA firm, and scope.
Can on-site procedures be replaced entirely by remote work?
This depends on the framework, the assessor, and the scope. ISO/IEC 27001 certification audits normally include an on-site Stage 2 audit, though some activities may be conducted remotely where the certification body considers it appropriate. For SOC 2, the balance between on-site and remote procedures is determined by the CPA firm based on what it deems necessary to gather sufficient evidence. Neither framework treats a fully remote approach as universally acceptable; it is a scoping and professional-judgment decision.
How does the scope of an on-site assessment affect the resulting report or certificate?
The on-site assessment covers only the defined scope of the engagement. For ISO/IEC 27001, the resulting certificate covers only the defined scope of the ISMS, so locations, systems, or processes excluded from scope are not covered even if visited or observed elsewhere. For SOC 2, on-site procedures inform a report that attests only to the controls and period within scope. Organizations should confirm that the assessment scope reflects the systems and locations they intend to represent to customers or stakeholders.

Common misconceptions

On-site assessment produces a pass/fail certificate for SOC 2 just as it does for ISO 27001.
These are different outcomes. A SOC 2 engagement results in an attestation report by a CPA firm, not a certificate. ISO/IEC 27001 results in a certification issued by an accredited certification body. On-site procedures may occur in both, but they feed into fundamentally different deliverables.
Modern audits are entirely remote, so on-site assessment no longer occurs.
For ISO/IEC 27001, the Stage 2 audit normally includes on-site activity under the certification body's accreditation requirements, though remote techniques may supplement it. For SOC 2, on-site procedures may still be performed when the CPA firm deems them necessary to obtain sufficient appropriate evidence. On-site work remains part of the toolkit rather than an obsolete practice.
A successful on-site assessment guarantees the organization is free from breaches or that all locations are covered.
An ISO 27001 certificate covers only the defined ISMS scope, and a SOC 2 report attests only to the controls and, for Type II, the period covered. On-site assessment supports these conclusions within their stated boundaries; it does not guarantee freedom from security incidents or coverage of sites outside scope.

Best practices

Confirm during scoping which physical sites and controls warrant on-site evaluation, since on-site coverage depends on the defined ISMS scope (ISO 27001) or the Trust Services Criteria and controls in scope (SOC 2).
For an ISO/IEC 27001 engagement, prepare for on-site Stage 2 activity by ensuring implementation evidence, records, and personnel are available at the relevant sites, as on-site work is normally expected under the certification body's accreditation requirements.
For a SOC 2 examination, coordinate with the CPA firm early to understand where on-site procedures such as observation or physical inspection may be applied, recognizing that this depends on auditor judgment and the evidence needed.
Make physical and environmental controls, facility access, and relevant personnel readily accessible so that observation and inspection procedures can be completed efficiently.
Document the boundaries assessed on-site and clearly distinguish covered sites and controls from those out of scope, to avoid overstating what the resulting report or certificate covers.
Use on-site findings to complement, not replace, documentation review, and avoid treating a favorable on-site visit as assurance beyond the covered scope and, for Type II, the covered period.