Most audit failures are process failures, not security failures. Organisations with genuinely good security still collect findings because of how they prepared, scoped and communicated. These are the mistakes that recur most often, and what to do instead.
1. Collecting evidence at the last minute
The single most damaging mistake. Auditors sample across the audit period, so evidence created the week before fieldwork proves only that the control works now.
Instead: make evidence a by-product of the control. Scheduled exports, ticket workflows and automated reports produce dated records continuously - no scramble required.
2. Scoping too broadly
Teams often include every system and location "to be thorough", multiplying the controls, evidence and interviews required - and the opportunities to fail.
Instead: scope to what the certificate or report must cover for your customers, and expand at recertification. A clean narrow certificate beats a failed broad one.
3. Policies that nobody follows
Downloading a template policy set creates an immediate exposure: the auditor tests you against your own document. If your policy promises quarterly access reviews and you do them annually, you have manufactured a nonconformity.
Instead: write policies that describe what you actually do, then raise the bar deliberately. Never commit on paper to a cadence you cannot sustain.
4. Confusing documentation with implementation
A documented process is not an operating control. Auditors test both design and effectiveness.
Instead: for every policy statement, ask "what record proves this happened?" If there is no answer, the control is not implemented yet.
5. Sending unprepared people into interviews
Control owners who cannot describe their own control, or who contradict a colleague, create findings on the spot.
Instead: run mock interviews. Each owner should be able to explain what they do, how often, and where the record lives. Consistency across owners matters as much as accuracy.
Find your gaps before your auditor does
GRC Copilot runs a readiness assessment against your framework, flags stale and missing evidence, and tracks remediation to closure - so fieldwork holds no surprises.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
6. Volunteering information
Answering beyond the question asked routinely opens new lines of enquiry into systems that were never in scope.
Instead: answer precisely and completely, then stop. If you do not know, say you will confirm - never speculate.
7. Skipping the internal audit and management review
For ISO 27001 these are mandatory, and their absence is an automatic nonconformity. Even where optional, they are the cheapest way to find problems while you can still fix them.
Instead: complete both well before the external audit, and evidence the corrective actions you raised.
8. Treating findings as accusations
Arguing with an auditor rarely removes a finding. Poor finding management - vague remediation, unrealistic dates, fixing symptoms - guarantees the same issue returns next cycle.
Instead: ask for potential findings early so you can supply clarifying evidence before the report is drafted. For confirmed findings, perform root cause analysis and commit to dates you can meet.
9. Forgetting the recurring activities
Access reviews, restore tests, awareness training, vulnerability scans and tabletop exercises are the most commonly missed controls, because each one is somebody's side task.
Instead: put every recurring control on a calendar with a named owner and an automated reminder, and store the output in a known location.
10. One-person dependency
When a single person holds the entire compliance context, their absence during fieldwork is a crisis.
Instead: keep the evidence index and control ownership in a shared system, not in one person's head or laptop.
The organisations that audit well are not the ones that scramble hardest in the final month - they are the ones whose controls generate evidence continuously, so the audit is a readout rather than a project.
Frequently asked questions
What is the most common audit finding?
Access management - reviews not performed, or leaver accounts still active. It is heavily sampled and easy to verify, so gaps surface immediately.
Should we disclose an issue we already know about?
If it is in scope, yes - together with your documented remediation plan. Self-identified issues with corrective action demonstrate a functioning management system.
Can a finding be removed after the report is drafted?
Sometimes, if you can produce evidence that the auditor had not seen. This is why asking for potential findings early in fieldwork matters so much.
How do we stop the same findings recurring?
Perform root cause analysis rather than fixing the sampled instance, and feed each finding into your risk register and next internal audit plan.
Key takeaways
- Late evidence collection is the leading cause of avoidable findings.
- Write policies that match reality - you are tested against your own documents.
- Rehearse interviews; inconsistency between owners creates findings.
- Ask for potential findings early, and fix root causes rather than symptoms.