A practical ISO 27001 internal audit case study showing how to choose defensible audit evidence samples. Includes sampling logic, traceability steps, and a copy/paste sampling record template.
Most internal audit findings don’t happen because controls are missing. They happen because sampling is weak, inconsistent,
or not traceable to evidence. This case study shows how to pick samples auditors trust so your audit results stand up in
certification and surveillance audits.
A Canadian SaaS company (250 employees) was preparing for ISO 27001 certification.
They had completed an internal audit. They had a long checklist. They had “evidence” in a SharePoint folder.
The company wasn’t failing security. They were failing audit evidence credibility.
Good sampling answers four questions clearly:
If you can’t answer those questions, you will eventually see weak internal audit results or a nonconformity in certification.
Canadian Cyber (vCISO support) helped them rebuild their sampling method in one week.
The goal was not more samples. The goal was defensible samples.
Use this template for each control you audit. It makes sampling repeatable and defensible.
There’s no single ISO rule. Auditors expect sampling to be defensible, consistent, and risk-based.
After implementing the sampling method: