On-Site Assessment
An on-site assessment is a part of an audit or certification process where the assessor physically visits an organization's premises to observe operations, inspect facilities, and gather evidence directly rather than only reviewing documents remotely. In security compliance, on-site visits let the assessor see how controls actually work in practice at a location. Whether an on-site visit is needed depends on the framework, the scope, and the judgment of the auditor or certification body.
An on-site assessment refers to assessment activities conducted at an organization's physical location, where the auditor or assessor performs observation, physical inspection, walkthroughs, and personnel interviews to obtain evidence about the design and operation of controls. In an ISO/IEC 27001 certification engagement, an on-site component is typically expected during the Stage 2 audit, where the certification body evaluates the implementation and effectiveness of the Information Security Management System (ISMS) against the requirements in clauses 4 through 10 and the applicable Annex A reference controls; the extent and location of on-site activity are governed by accreditation requirements for certification bodies and by the audit plan. In a SOC 2 examination conducted by a licensed CPA firm under the AICPA SSAE 18 standard, on-site procedures may be performed at the auditor's discretion when deemed necessary to test controls against the applicable Trust Services Criteria, though many procedures are increasingly performed remotely depending on scope and the nature of the controls. The value and outcome of an on-site assessment are bounded by the defined scope, the review period (for a SOC 2 Type II engagement) or point in time (for a Type I), and the specific controls examined; it does not, by itself, guarantee freedom from breaches or attest to matters outside the engagement scope. The specific extent, duration, and frequency of on-site activity vary by certification body, CPA firm, framework, and scoping decisions.
Why it matters
On-site assessments matter because certain security controls are difficult or impossible to verify through documentation alone. Physical access controls, environmental safeguards in server rooms, badge systems, visitor logs, and the way staff actually handle sensitive information are best evaluated by direct observation. Reviewing a policy document tells an assessor what an organization intends to do; visiting the premises helps confirm whether those intentions are reflected in daily practice at a specific location.
Who it's relevant to
Inside On-Site Assessment
Common questions
Answers to the questions practitioners most commonly ask about On-Site Assessment.