Findings-to-closure tracker template
A sixteen-column register that carries every external audit finding from the auditor's wording to a verification date, with correction and cause kept apart.
Compliance5 Sept 20263 min read
On this page
findings-to-closure-tracker.xlsx · 9 kBLicensed CC BY 4.0
What this is
A sixteen-column register for the findings an external audit raises: one sheet for the rows, one for the licence and standing rules. It is the artefact produced by section 3.9 of Running the external audit, and it supports one decision per row. Is this finding closed, and what verified it? The certification body requires cause analysis, plus the correction and corrective actions described within a defined time 1. A register with a "fixed" column cannot answer that.
How to use it
- Delete the three example rows on the Findings sheet before the first audit.
- Fill columns A to F from the finding as the auditor wrote it. A nonconformity is recorded against a specific requirement, with the objective evidence identified in detail 2. Copy the wording. See the playbook, section 3.7.
- Fill the agreed-facts column during the audit, from the evidence request log. It holds what both sides accept as true. See the playbook, section 3.6.
- Record the grade, do not negotiate it. A major undercuts the management system's ability to reach its intended results; a minor does not 3. The standard grades nonconformities major or minor and records opportunities for improvement separately 4. Observation is industry practice, for what is not a nonconformity.
- Set the Due date by grade. A minor needs a plan the body reviews and accepts. A major needs the action verified before a certification decision 5. Treat a major's date as the implementation date.
- Keep cause, correction and action apart. Three columns, because three acts 6. See the playbook, section 3.9.
- Close on evidence. Evidence of closure, Verification date and Verifier are filled together, or the status stays open. 7
What good looks like
Six of the sixteen columns, from the rows shipped in the workbook.
| ID | Clause | Grade | Cause analysis | Corrective action | Verification date |
|---|---|---|---|---|---|
| F-001 | 9.2.2 | Major | The programme was rebuilt annually rather than planned across the cycle | Planned per cycle, with a coverage matrix reviewed at management review | 2026-05-20 |
| F-002 | 7.5.3 | Minor | New procedures were published outside document control | Publication now requires a register entry before release | 2027-04-22 |
| F-003 | 10.2 | Observation | The register had no mandatory cause field | Closure blocked until cause, action and a verification date are present | — |
Fields
| Field | Required | Meaning | Common mistake |
|---|---|---|---|
| Finding as written | yes | The auditor's wording, copied | Rewriting it into something easier to close |
| Clause / control | yes | The requirement the finding was recorded against | Citing a clause the evidence never engaged |
| Cause analysis | yes | Why it happened, not what happened | Restating the symptom |
| Correction, Corrective action | yes | What fixed the instance, and what removes the cause | Recording the first as the second |
| Owner, Due | yes | The accountable role, and the date set by grade | A plan date where implementation was needed |
| Evidence of closure, Verification date, Verifier | yes to close | What proved it, when, and by which role | A closed status with all three blank |
Download
- File:
findings-to-closure-tracker.xlsx(xlsx, 9 KB) — sheets Findings and Read first. - Markdown variant: the same tables in plain markdown, at
content/templates/assets/_findings-to-closure-tracker.md. - Licence: CC BY 4.0 — reuse and adapt with attribution to GRCIDE.
- Version: 1.0, 2026-09-05. No personal data, no organisation names; the example rows are invented.
Related
- Playbook: Running the external audit
- Playbook: Building an ISMS people actually use, section 3.7, the internal-audit side.
References
- ISO/IEC. Conformity assessment — Requirements for bodies providing audit and certification of management systems — Part 1: Requirements. ISO/IEC 17021-1:2015. https://www.iso.org/standard/61651.html 8
- ISO/IEC. Information security, cybersecurity and privacy protection — Information security management systems — Requirements. ISO/IEC 27001:2022. https://www.iso.org/obp/ui/#iso:std:iso-iec:27001:ed-3:v1:en 9
Standards and certification names are the property of their respective owners. GRCIDE is an independent publication and is not affiliated with, authorized, sponsored or endorsed by ISO, IEC, NIST or any other standards body.
Sources
- 1ISO/IEC 17021-1:2015 clause 9.4.9, licensed copy · verified 2026-09-05
- 2ISO/IEC 17021-1:2015 clause 9.4.5.3, licensed copy · verified 2026-09-05
- 3ISO/IEC 17021-1:2015 clauses 3.12 and 3.13, licensed copy · verified 2026-09-05
- 4ISO/IEC 17021-1:2015 clause 9.4.5.2, licensed copy · verified 2026-09-05
- 5ISO/IEC 17021-1:2015 clause 9.5.2, licensed copy · verified 2026-09-05
- 6ISO/IEC 27001:2022 clause 10.2, iso.org/obp · verified 2026-09-03
- 7ISO/IEC 17021-1:2015 clause 9.4.10, licensed copy · verified 2026-09-05
- 8ISO/IEC 17021-1:2015 contents, licensed copy · verified 2026-09-05
- 9ISO/IEC 27001:2022 contents, iso.org/obp · verified 2026-09-03
Related
- AI use-case triage form
Template
- EU AI Act for security governance
Briefing
- Running the external audit
Playbook