ISO 27001 • Internal Audit Findings • Stage 2 Certification • NCRs • Audit Readiness

Common ISO 27001 Internal Audit Findings That Delay Stage 2 Certification

Stage 2 certification is where ISO 27001 becomes real. The auditor expects proof that your ISMS is implemented, operating, reviewed, and improving.

Quick Answer

Common ISO 27001 internal audit findings that delay Stage 2 include unclear scope, outdated risk registers, weak SoA justifications, incomplete access reviews, missing vendor reviews, unapproved policies, weak evidence, incomplete management review, untested incident response, missing restore tests, poor corrective action tracking, and unprepared control owners.

Practical takeaway: Stage 2 auditors need proof that the ISMS is operating. Documents alone are not enough.

Quick Snapshot

Common Finding Why It Delays Stage 2
Unclear Scope The auditor cannot confirm what should be tested.
Outdated Risk Register Risk management does not look active.
Weak SoA Control decisions are not clearly justified.
Missing Access Reviews Access control cannot be proven.
Incomplete Management Review Leadership involvement is not evidenced.
Unverified Corrective Actions Continual improvement is weak.

Why Stage 2 Certification Gets Delayed

Stage 2 certification focuses on implementation and operating effectiveness.

The auditor wants to see whether the organization is actually doing what its ISMS says it does.

Many organizations reach Stage 2 with documents in place. However, their evidence is still weak.

Stage 2 may be delayed when internal audit findings remain open, poorly fixed, or poorly evidenced.

Stage 2 is not passed by having documents. Stage 2 depends on evidence that the ISMS is working.

Who This Blog Is For

  • Organizations preparing for ISO 27001 Stage 2 certification.
  • Companies that completed Stage 1 and are moving toward Stage 2.
  • ISMS managers, internal auditors, and compliance leads.
  • Security managers, IT managers, risk owners, and control owners.
  • vCISO teams supporting ISO 27001 programs.
  • SaaS, MSP, FinTech, HealthTech, manufacturing, and professional services firms.
  • Canadian businesses using Microsoft 365 or SharePoint for ISMS evidence.

Finding 1: ISMS Scope Is Too Vague

One common Stage 2 blocker is unclear scope.

The scope may say the ISMS covers “company operations” or “information security services.” However, it may not clearly define products, systems, people, data, vendors, and boundaries.

Why this delays Stage 2:

If scope is unclear, the auditor cannot easily determine what should be tested.

Evidence to fix it:

  • Updated ISMS scope statement.
  • Process map and system inventory.
  • Data flow diagram and asset inventory.
  • Vendor list and organization chart.
  • Cloud architecture summary and scope approval record.

Practical rule: The ISMS scope should be clear enough that an executive, control owner, and auditor can explain it the same way.

Finding 2: Risk Register Is Outdated or Superficial

ISO 27001 is risk-based.

A weak risk register can delay Stage 2 because it suggests the ISMS is not being actively managed.

Common risk register problems:

  • Risks were created once and never reviewed.
  • Risk owners are missing.
  • Risk treatment plans are incomplete.
  • Residual risks are not approved.
  • Vendor, cloud, AI, or support access risks are missing.
  • Risk treatment actions have no evidence.

Evidence to fix it:

  • Risk assessment methodology.
  • Current risk register and risk owner assignments.
  • Risk treatment plan and review history.
  • Accepted risk approvals and management review risk summary.

Finding 3: Statement of Applicability Has Weak Justifications

The Statement of Applicability is one of the most important ISO 27001 documents.

It should explain which Annex A controls apply, which do not apply, and why.

Common SoA findings:

  • Controls are marked applicable without explanation.
  • Controls are marked not applicable without justification.
  • Implementation status is inaccurate.
  • The SoA is not linked to risk treatment.
  • Evidence does not match the control status.

Evidence to fix it:

  • Updated Statement of Applicability.
  • Control applicability rationale.
  • Risk treatment links and control owner list.
  • Control implementation evidence and SoA approval record.

The SoA should tell a clear story: why the control applies, how it is implemented, and where the evidence exists.

Finding 4: Policies Are Approved but Not Followed

Many organizations have policies ready for Stage 2.

But the auditor may find that actual practice does not match the policy.

Examples:

  • The policy says access is reviewed quarterly, but no review happened.
  • The policy says vendors are reviewed annually, but evidence is missing.
  • The policy says incidents are tested annually, but no tabletop was performed.
  • The policy says employees acknowledge policies, but acknowledgments are incomplete.

Evidence to fix it:

  • Approved policies and procedure documents.
  • Policy acknowledgments and control evidence.
  • Exception and corrective action records.
  • Updated policy where practice changed.

Practical rule: If a policy promises a control, the organization must prove it happens.

Finding 5: Access Reviews Are Missing or Incomplete

Access control is one of the most common ISO 27001 internal audit finding areas.

Common access review issues:

  • No quarterly access review.
  • Admin, cloud, or support access is not reviewed.
  • Contractor or guest access is excluded.
  • Terminated users are not tested.
  • Review sign-off is missing.

Evidence to fix it:

  • User access review and privileged access review.
  • Cloud admin and support access review.
  • Offboarding evidence and MFA report.
  • Exception register, removed access evidence, and reviewer sign-off.

Access review evidence should show who reviewed access, what they found, what was removed, and when it was completed.

Finding 6: Offboarding Evidence Is Weak

Offboarding is a high-risk control.

The organization must prove that users are removed from systems when they leave.

Common offboarding problems:

  • Termination checklist is missing.
  • HR notification is not documented.
  • IT removal evidence is incomplete.
  • Contractors are not tracked.
  • Former users are still active.

Evidence to fix it:

  • Termination records and offboarding checklist.
  • Access removal logs and identity provider evidence.
  • Device return records and contractor end-date tracker.
  • Sample offboarding tests and manager confirmation.

Finding 7: Vendor Reviews Are Missing

Supplier relationships are often underprepared before Stage 2.

Many organizations use cloud providers, MSPs, SaaS tools, AI tools, support systems, and development tools. These vendors must be reviewed properly.

Common vendor findings:

  • Vendor register is incomplete.
  • Critical vendors are not identified.
  • Vendors are not risk-rated.
  • SOC 2 or ISO reports are not reviewed.
  • DPAs, subprocessors, or AI vendors are not tracked.

Evidence to fix it:

  • Vendor register and critical vendor list.
  • Vendor risk assessments and contracts.
  • DPAs, SOC 2 reports, and ISO certificates.
  • Subprocessor list, AI vendor reviews, and vendor owner assignments.

Worried Findings Could Delay Stage 2?

Canadian Cyber helps review internal audit findings, verify corrective actions, and prepare audit-ready evidence before certification.

Finding 8: Management Review Is Incomplete

Management review is leadership evidence.

It proves that top management reviews ISMS performance and makes decisions.

Common management review findings:

  • Management review was not completed.
  • Required inputs are missing.
  • Risks, incidents, vendor issues, or audit results were not discussed.
  • Decisions are not documented.
  • Actions are not assigned.

Evidence to fix it:

  • Management review agenda and attendee list.
  • Input pack and risk dashboard.
  • Internal audit summary and corrective action tracker.
  • Meeting minutes, decision log, and action tracker.

Finding 9: Internal Audit Findings Are Not Closed

An internal audit may identify findings.

Stage 2 can be delayed if those findings remain unmanaged.

Common corrective action issues:

  • Findings are not tracked.
  • NCRs and OFIs are not classified.
  • Root cause is missing.
  • Owners and deadlines are vague.
  • Actions are marked complete without verification.

Evidence to fix it:

  • Finding register, NCR register, and OFI tracker.
  • Corrective action tracker and root cause records.
  • Owner assignments and closure evidence.
  • Verification records and management review status.

Practical rule: A finding is not closed because someone says it is closed. It is closed when evidence proves the fix works.

Finding 10: Incident Response Was Never Tested

Many organizations have an incident response plan.

However, they have never tested it.

Common incident response findings:

  • Incident response plan exists but is untested.
  • Roles and severity levels are unclear.
  • Employees do not know how to report incidents.
  • Tabletop exercise was not performed.
  • Lessons learned and corrective actions are missing.

Evidence to fix it:

  • Incident response plan and severity matrix.
  • Escalation list and incident register.
  • Tabletop report and lessons learned.
  • Corrective action tracker and employee awareness evidence.

Finding 11: Backup Restore Testing Is Missing

Backups may be configured.

But Stage 2 auditors often want evidence that recovery has been tested.

Common backup findings:

  • Backup reports exist, but no restore test exists.
  • Critical systems are not listed.
  • Backup failures are not reviewed.
  • Backup owner is unclear.
  • Disaster recovery plan is outdated.

Evidence to fix it:

  • Backup policy and backup schedule.
  • Backup reports and backup failure review.
  • Restore test report and critical system list.
  • Disaster recovery plan and recovery owner assignment.

Backups show that data is copied. Restore tests show that recovery is possible.

Finding 12: Security Training Evidence Is Incomplete

Training is a common Stage 2 evidence gap.

Employees must understand their information security responsibilities.

Common training findings:

  • New hires missed training.
  • Contractors were excluded.
  • Policy acknowledgments are missing.
  • Overdue users were not followed up.
  • AI acceptable use training is missing where relevant.

Evidence to fix it:

  • Training completion report.
  • New hire and contractor training records.
  • Policy acknowledgments and overdue follow-up.
  • Role-based training and AI acceptable use acknowledgment.

Finding 13: Evidence Is Scattered and Hard to Retrieve

Sometimes controls exist, but the evidence is difficult to find.

This creates audit stress and weakens confidence.

Common evidence problems:

  • Files are stored in personal folders.
  • Screenshots have no dates.
  • Approvals are buried in email or chats.
  • Evidence is not mapped to controls.
  • There is no audit request tracker.

Evidence to fix it:

  • Central evidence library.
  • Control-to-evidence map.
  • Evidence owner list and naming rules.
  • Audit request tracker and evidence status dashboard.

Practical rule: Evidence is only useful if it is current, complete, mapped, and retrievable.

Finding 14: Control Owners Are Not Prepared

Stage 2 auditors may interview control owners.

If owners cannot explain their processes, the audit may become difficult.

Common interview problems:

  • Owner does not know the control.
  • Owner cannot explain evidence.
  • Owner does not know control frequency.
  • Owner cannot explain exceptions or risk.
  • Owner says practice is different from policy.

Evidence to fix it:

  • Control owner list and responsibility matrix.
  • Interview preparation notes.
  • Process walkthroughs and evidence links.
  • Training records and control operation summaries.

Finding 15: Change Management Evidence Is Weak

Change management matters for systems, applications, cloud platforms, and production environments.

Common change management findings:

  • Changes are approved informally.
  • Production changes are not documented.
  • Emergency changes are not recorded.
  • Testing evidence is missing.
  • Deployment logs are not retained.

Evidence to fix it:

  • Change management procedure and change tickets.
  • Pull request approvals and release records.
  • Deployment logs and testing evidence.
  • Emergency change records, security review evidence, and rollback evidence.

Change evidence should show request, review, approval, testing, deployment, and exception handling.

Stage 2 Delay Risk Checklist

Internal Audit Finding Could Delay Stage 2?
ISMS scope is unclear.
Risk register is outdated.
Statement of Applicability has weak justifications.
Policies are not approved or not followed.
Access reviews are incomplete.
Offboarding evidence is weak.
Vendor reviews are missing.
Management review is incomplete.
Internal audit findings are not closed.
Incident response is untested.
Backup restore testing is missing.
Training evidence is incomplete.
Evidence is scattered.
Control owners are not prepared.
Change management evidence is weak.

How to Fix Findings Before Stage 2

  • Prioritize high-risk findings. Focus first on access, vendors, incidents, backups, risk treatment, and management review.
  • Assign owners. Each finding should have a named accountable owner.
  • Define root cause. Do not only fix the symptom.
  • Set deadlines. Use realistic deadlines before the Stage 2 audit date.
  • Collect closure evidence. Define exactly what proof is required.
  • Verify closure. Confirm that the action is complete and effective.
  • Update management review. Leadership should review major findings and overdue actions.
  • Prepare control owners. Owners should be able to explain controls and evidence.

Practical rule: Stage 2 readiness improves when findings are not only fixed, but verified.

How SharePoint Can Help Prevent Stage 2 Delays

A structured SharePoint ISMS can help organizations manage evidence and findings before Stage 2.

It helps teams see what is ready, what is missing, what is overdue, and what could delay certification.

Canadian Cyber’s ISMS SharePoint Solution can organize:

  • Policy and procedure libraries.
  • Risk register and SoA tracker.
  • Control register and evidence library.
  • Access review tracker and vendor register.
  • Incident, training, backup, and change evidence.
  • Management review dashboard.
  • Internal audit workspace, NCR tracker, and OFI tracker.
  • Corrective action tracker and audit request tracker.
  • Client-ready evidence room, Power Automate reminders, and Teams notifications.

Stage 2 preparation is easier when evidence, owners, deadlines, and corrective actions live in one controlled workspace.

How Canadian Cyber Helps

Canadian Cyber helps organizations prepare for ISO 27001 Stage 2 certification by fixing internal audit findings before they become certification blockers.

We help review evidence, verify corrective actions, prepare management review, organize SharePoint ISMS workspaces, and strengthen control owner readiness.

Canadian Cyber can support:

  • ISO 27001 Stage 2 readiness reviews.
  • ISO 27001 internal audits.
  • Internal audit finding reviews.
  • NCR and OFI classification.
  • Corrective action planning and closure evidence verification.
  • Risk register and SoA review.
  • Management review preparation.
  • Access and vendor evidence checks.
  • Incident tabletop and backup restore evidence review.
  • SharePoint ISMS implementation and vCISO services.

Senior Advisory Support

Canadian Cyber also provides senior advisory support for ISO 27001 Stage 2 readiness, internal audit findings, corrective action verification, SharePoint ISMS implementation, and vCISO oversight.

View Waqar Mehboob’s Profile

Frequently Asked Questions

What internal audit findings commonly delay ISO 27001 Stage 2 certification?

Common findings include unclear scope, outdated risk register, weak SoA justifications, incomplete access reviews, missing vendor reviews, incomplete management review, untested incident response, missing restore tests, weak training evidence, scattered evidence, and unverified corrective actions.

Can open internal audit findings delay Stage 2?

Yes. Open or poorly managed findings can delay Stage 2 if they show that the ISMS is not operating effectively or corrective actions are not being managed.

Does Stage 2 require management review evidence?

Yes. Management review evidence shows that leadership reviewed ISMS performance, risks, audit results, corrective actions, incidents, objectives, and improvement needs.

Is a policy enough evidence for Stage 2?

No. A policy shows intent. Stage 2 requires evidence that the policy is implemented and followed.

Why do access reviews cause ISO 27001 findings?

Access reviews often cause findings when they are missing, incomplete, not signed off, exclude privileged accounts, exclude contractors, or lack evidence of access removal.

Can Canadian Cyber help fix findings before Stage 2?

Yes. Canadian Cyber helps organizations review findings, verify corrective actions, organize evidence, prepare control owners, and improve readiness before ISO 27001 Stage 2 certification.

Takeaway

ISO 27001 Stage 2 certification is where implementation must be proven.

The most common delays happen when internal audit findings are not fixed before the certification audit.

Organizations should pay close attention to scope, risks, SoA, policies, access reviews, offboarding, vendor reviews, management review, corrective actions, incident response, restore testing, training, change management, evidence organization, and control owner readiness.

Stage 2 success depends on proof. Not assumptions, scattered files, incomplete trackers, or unfinished findings.

Preparing for ISO 27001 Stage 2?

Canadian Cyber can help you avoid certification delays by fixing findings before they become blockers.

We provide ISO 27001 Stage 2 readiness reviews, ISO 27001 internal audits, evidence reviews, corrective action verification, management review preparation, control owner interview preparation, vCISO services, cybersecurity assessments, SOC 2 readiness, ISO 42001 AI governance, ISO 27017, ISO 27018, and SharePoint ISMS implementation. You can also learn more through Waqar Mehboob’s profile.

Stay Connected With Canadian Cyber

Follow Canadian Cyber for practical guidance on ISO 27001 Stage 2 certification, internal audits, audit findings, corrective actions, evidence readiness, SOC 2, ISO 42001, ISO 27017, ISO 27018, SharePoint ISMS, cybersecurity assessments, and vCISO support.