Back to templates
    Template

    Findings-to-closure tracker template

    A sixteen-column register that carries every external audit finding from the auditor's wording to a verification date, with correction and cause kept apart.

    Compliance5 Sept 20263 min read

    ISO/IEC 17021-1:2015ISO/IEC 27001:2022
    On this page
    Download the template

    findings-to-closure-tracker.xlsx · 9 kBLicensed CC BY 4.0

    What this is

    A sixteen-column register for the findings an external audit raises: one sheet for the rows, one for the licence and standing rules. It is the artefact produced by section 3.9 of Running the external audit, and it supports one decision per row. Is this finding closed, and what verified it? The certification body requires cause analysis, plus the correction and corrective actions described within a defined time 1. A register with a "fixed" column cannot answer that.

    How to use it

    1. Delete the three example rows on the Findings sheet before the first audit.
    2. Fill columns A to F from the finding as the auditor wrote it. A nonconformity is recorded against a specific requirement, with the objective evidence identified in detail 2. Copy the wording. See the playbook, section 3.7.
    3. Fill the agreed-facts column during the audit, from the evidence request log. It holds what both sides accept as true. See the playbook, section 3.6.
    4. Record the grade, do not negotiate it. A major undercuts the management system's ability to reach its intended results; a minor does not 3. The standard grades nonconformities major or minor and records opportunities for improvement separately 4. Observation is industry practice, for what is not a nonconformity.
    5. Set the Due date by grade. A minor needs a plan the body reviews and accepts. A major needs the action verified before a certification decision 5. Treat a major's date as the implementation date.
    6. Keep cause, correction and action apart. Three columns, because three acts 6. See the playbook, section 3.9.
    7. Close on evidence. Evidence of closure, Verification date and Verifier are filled together, or the status stays open. 7

    What good looks like

    Six of the sixteen columns, from the rows shipped in the workbook.

    IDClauseGradeCause analysisCorrective actionVerification date
    F-0019.2.2MajorThe programme was rebuilt annually rather than planned across the cyclePlanned per cycle, with a coverage matrix reviewed at management review2026-05-20
    F-0027.5.3MinorNew procedures were published outside document controlPublication now requires a register entry before release2027-04-22
    F-00310.2ObservationThe register had no mandatory cause fieldClosure blocked until cause, action and a verification date are present

    Fields

    FieldRequiredMeaningCommon mistake
    Finding as writtenyesThe auditor's wording, copiedRewriting it into something easier to close
    Clause / controlyesThe requirement the finding was recorded againstCiting a clause the evidence never engaged
    Cause analysisyesWhy it happened, not what happenedRestating the symptom
    Correction, Corrective actionyesWhat fixed the instance, and what removes the causeRecording the first as the second
    Owner, DueyesThe accountable role, and the date set by gradeA plan date where implementation was needed
    Evidence of closure, Verification date, Verifieryes to closeWhat proved it, when, and by which roleA closed status with all three blank

    Download

    • File: findings-to-closure-tracker.xlsx (xlsx, 9 KB) — sheets Findings and Read first.
    • Markdown variant: the same tables in plain markdown, at content/templates/assets/_findings-to-closure-tracker.md.
    • Licence: CC BY 4.0 — reuse and adapt with attribution to GRCIDE.
    • Version: 1.0, 2026-09-05. No personal data, no organisation names; the example rows are invented.

    References

    1. ISO/IEC. Conformity assessment — Requirements for bodies providing audit and certification of management systems — Part 1: Requirements. ISO/IEC 17021-1:2015. https://www.iso.org/standard/61651.html 8
    2. ISO/IEC. Information security, cybersecurity and privacy protection — Information security management systems — Requirements. ISO/IEC 27001:2022. https://www.iso.org/obp/ui/#iso:std:iso-iec:27001:ed-3:v1:en 9

    Standards and certification names are the property of their respective owners. GRCIDE is an independent publication and is not affiliated with, authorized, sponsored or endorsed by ISO, IEC, NIST or any other standards body.

    Sources

    1. 1ISO/IEC 17021-1:2015 clause 9.4.9, licensed copy · verified 2026-09-05
    2. 2ISO/IEC 17021-1:2015 clause 9.4.5.3, licensed copy · verified 2026-09-05
    3. 3ISO/IEC 17021-1:2015 clauses 3.12 and 3.13, licensed copy · verified 2026-09-05
    4. 4ISO/IEC 17021-1:2015 clause 9.4.5.2, licensed copy · verified 2026-09-05
    5. 5ISO/IEC 17021-1:2015 clause 9.5.2, licensed copy · verified 2026-09-05
    6. 6ISO/IEC 27001:2022 clause 10.2, iso.org/obp · verified 2026-09-03
    7. 7ISO/IEC 17021-1:2015 clause 9.4.10, licensed copy · verified 2026-09-05
    8. 8ISO/IEC 17021-1:2015 contents, licensed copy · verified 2026-09-05
    9. 9ISO/IEC 27001:2022 contents, iso.org/obp · verified 2026-09-03