12 Conclude? Certification, Defence, and the Future of Audit
An audit ends where it began: with a judgement, stated plainly, and defended under fire.
🗂️ Tessera Case: The boardroom
Twelve weeks of fieldwork collapse into forty minutes in a glass-walled room on St Georges Terrace. Tessera’s board has cleared the agenda for your readout. The CTO, who opened the engagement hoping for “pretty much there,” is watching you with the particular stillness of someone about to hear a number. The chair cuts the small talk: “So. Are we ready, or aren’t we?” That question is the whole engagement, distilled, and the honest answer is not the one the CTO wants. It is also the one you came to give.
12.1 The certification-readiness opinion
Chapter 6 ended Act I with a preliminary opinion: promising on paper; not yet proven in practice. Act II has done the proving. You have interviewed the people, walked the office, pulled the configurations, read the logs, traced the incidents, and tested the controls you could only read about. The discipline now is to turn that evidence into a single, defensible statement: a certification-readiness opinion.
Before you write a word, get one thing straight, because it is the misconception that ends careers. You are not the body that grants ISO/IEC 27001 certification. No one grants it to themselves. Certification is awarded by an accredited certification body, an independent organisation itself audited by a national accreditation authority, which sends its own auditors to run a two-stage certification audit against Clauses 4 through 10 and the Annex A controls. Your engagement with Tessera is a readiness assessment (sometimes called an internal audit, a gap assessment, or a Stage 1 dry run). Your opinion answers a narrower, honest question: on the evidence we gathered, would Tessera pass a certification audit, and what stands between them and one?
The distinction matters twice over. It protects you from overclaiming. You are not certifying Tessera; you are giving them and their board the most credible possible read on whether they are ready to be certified, and what to fix first. And it protects Tessera from a false sense of safety, the feeling that the polished security page can now add a badge because you said something nice. It cannot. What you hand over is judgement, scoped and dated, and the named conditions under which it holds.
A readiness opinion has four moving parts, and each has been built over the preceding chapters. The criteria are ISO/IEC 27001:2022 (the four themes, ninety-three controls, the management system clauses) reconciled with NIST CSF 2.0 and the ASD Essential Eight where Tessera has adopted them. The condition is what your Act II testing actually found, written up in the 5C+R format from Chapter 11. The cause is the root of each gap, because a board that does not understand the cause cannot fix the control. And the conclusion is the opinion itself: ready, ready with conditions, or not ready, each one defensible only because the evidence behind it is documented and reproducible.
There is a particular honesty to the middle option, and it is usually the right one. A clean “ready, no exceptions” is rare in a company growing as fast as Tessera, and a board that hears it should be more suspicious than relieved. A flat “not ready” wastes the nuance the fieldwork earned. The defensible opinion names what works, names what does not, and tells the board exactly what must happen for the gap between the two to close. That is the opinion you are about to defend.
12.2 Defending the opinion
An opinion you cannot defend is not an opinion. It is a guess with a letterhead. The boardroom is where this gets tested in real time, and it is the moment the whole engagement turns on the one quality no machine and no amount of drafting can supply: your willingness to stand behind your judgement when it is inconvenient.
The pressures arrive dressed as reasonableness. The enterprise deal that needs the certification badge before quarter-end. The CTO’s reputation, riding on “we were ready.” A friendly offer to “tidy up” the language so the major finding reads as a minor one. Each of these sounds like collaboration. Each is a test of independence, the same independence Chapter 1 made the foundation of the mandate, and each requires the same answer: the opinion is the evidence, restated. Change the evidence and the opinion moves. Pressure the opinion and nothing moves at all, because the evidence does not bend to deadlines.
The defence has a shape, and it is worth learning it cold. You state the conclusion. You point to the evidence that supports it. You name the criterion the evidence was tested against. You acknowledge the limitation honestly, because every audit has one (the period, the sample, the controls in scope) and conceding it is a strength, not a weakness. And you refuse, politely and absolutely, to upgrade the rating to suit the room. A board that presses you and finds you unmoved learns something more valuable than the finding: that the opinion is worth paying for, because it does not move when it is inconvenient. That is the whole commercial case for the profession, demonstrated in a single meeting. I learned this the hard way, the way most auditors do. Early on I rounded a finding down for a client I liked, told myself the gap was small and the deadline was real, and waited six months for the control I had discounted to fail. It did not fail, which is the most dangerous outcome there is, because it taught me how easily the line moves once you cross it the first time. I have not rounded a rating since.
Two pressures converge in the final week, and both are traps. The first is the certification deadline pressure: the deal, the board commitment, the CTO’s bonus, all riding on a “ready.” The second is polish pressure: the quiet temptation to round a finding down because the client is likeable, the fieldwork was hard, and a clean report feels like a kinder way to end. Both ask you to substitute a nicer conclusion for an evidenced one. The professional answer is identical: the rating is what the evidence supports, and an opinion given under deadline or social pressure is a liability you have signed your name to. Certification is not a reward for effort. It is a statement about controls. If the evidence says “ready with conditions,” that is the opinion, and the conditions are the favour you do the client, not the obstacle.
Here is a use of AI that genuinely earns its place in the final week. Ask it to play a sceptical non-executive director: “You are a board chair with a finance background and no patience for jargon. Read this opinion and probe it hard. Ask the sharpest, fairest questions a board would put to it.” Then give it the opinion and the findings. It will come back with a string of sharp, fair questions: Why is this a major and not a minor? How did you sample? What is your confidence interval? Why should we trust the AWS SOC 2 over your own eyes?
This is good practice, and it works because the AI is relentless in a way a willing colleague is not. Treat its questions as a dress rehearsal. Answer each one, out loud or in writing, and anywhere you stumble, that is a sentence in your opinion that is not yet defensible. Fix it before you walk into the room.
But notice the line you do not cross. The AI can stress-test the opinion. It cannot deliver it. When the real chair leans forward and asks the question the AI predicted, it is your name, your registration, and your judgement on the answer. The machine rehearsed you. You own every word under questioning, and that ownership is the entire point of the opinion. Rehearse with the tool. Defend the judgement yourself.
12.3 Cloud and third-party assurance
No modern SaaS company is an island, and Tessera certainly is not. AWS hosts the estate. A payment processor moves the money. A logistics API ships the product. An analytics platform chews the data. An AI service summarises customer reports. Each of those relationships is a control Tessera relies on but cannot directly inspect, and your readiness opinion has to say something credible about each one without you having audited the vendor yourself.
This is where SOC reports earn their keep, and where they most often mislead the people who cite them. The System and Organization Controls reports issued under the AICPA framework are a service organisation’s auditor’s opinion over its controls. A SOC 2 Type II covers the Trust Services Criteria (security, and any of availability, processing integrity, confidentiality, and privacy the vendor chose to include) over a defined period, and it is the report you reach for when a vendor holds Tessera’s customer data. A Type I describes design at a point in time and says nothing about whether the controls actually ran. A SOC 1 concerns financial reporting controls, not security, and is the wrong report to cite for a security assurance point, however often it gets cited.
Reading a SOC report well is an audit skill in itself, and the discipline is to read the parts everyone skips. The scope tells you which systems and which criteria the opinion actually covers, and a report that covers Security but not Privacy tells you nothing about the vendor’s privacy controls, however reassuring the cover page looks. The period tells you the window the testing covered, and a report that ended nine months ago describes a control environment you can no longer assume is current; check the bridge letter that covers the gap. The qualified or excepted opinions hide in the body, where the service auditor declined to opine cleanly on a control, and they are the sentences that decide whether the report actually supports the assurance Tessera’s board is about to rely on.
A vendor hands over a SOC 2 with a clean opinion and it gets filed as proof the vendor is secure. Then someone asks which criteria it covered, over what period, and whether the system Tessera actually uses was in scope. If you cannot answer from having read the report, you have relied on its cover page, not its opinion. The classic third-party assurance failure is a clean SOC 2 cited for a control or criterion it never opined on, by an auditor who stopped at page one.
The trap that catches even careful auditors is the complementary user entity controls. These are the controls the service organisation assumes you, the customer, have in place. AWS secures the hypervisor and the physical data centre, but the IAM configuration, the encryption keys, the public S3 buckets, and the network exposure are Tessera’s responsibility under the shared-responsibility split from Chapter 5. A clean AWS SOC 2 is evidence that AWS did its half. It is not evidence that Tessera did hers. Treating the vendor’s clean report as proof of Tessera’s security is the same error as treating a polished policy as proof of an operating control: it confuses one party’s assertion for another party’s reality.
The disciplined position for your opinion is layered. You cite the SOC 2 Type II as evidence about the vendor. You point to the shared-responsibility controls as the evidence you tested yourself. And you name, honestly, the residual gap where neither reaches: the sub-processor the vendor added since the report’s period, the criterion the report did not cover, the configuration that is technically Tessera’s but operationally opaque. Read scopes, current periods, tested user controls, and named residuals: that is third-party assurance you can defend.
12.4 The two faces of the next decade
Stand back from Tessera for a moment, because this is the last chapter and the view from here is the point. Two forces are reshaping the profession at once, and they look alike but pull in opposite directions. Both involve the letters AI. Only the discipline of this book tells them apart.
The first face is AI in audit: the machine on your side of the desk. Drafting the control matrix in seconds. Mapping a finding to the right control. Summarising a hundred pages of evidence into a brief. Sampling a population, flagging the anomalies, generating the first cut of the report. This is the commoditisation the Introduction warned about, and it is genuinely useful, the same way a calculator is useful to an accountant. Used as a thinking partner, the way the companion book Conversation, Not Delegation teaches, it makes you faster and often sharper. Used as a delegate, it quietly hollows out exactly the judgement the profession sells, and you wake up one morning to find you have outsourced the part that was worth paying for.
The second face is auditing AI: the machine on the other side of the desk, inside the estate you must now opine on. The AI service Tessera bolts into its product. The AI-assisted controls that approve transactions, triage incidents, and revoke access. The large language model that writes the security summary a customer reads. Each of these is a new control surface with new failure modes: training-data leakage, prompt injection, drift after retraining, opaque decision logic, evidence you cannot reproduce. The frameworks you already hold are where this lands. ISO/IEC 27001:2022’s cloud-services control (A.5.23) and threat-intelligence control (A.5.7) become load-bearing. The supplier controls (A.5.19 through A.5.23) govern an AI vendor the same way they govern any other, with the difference that what the vendor does with the data is harder to inspect. NIST CSF 2.0’s Govern function demands accountability for decisions an algorithm now makes on Tessera’s behalf.
This is the synthesis the whole book has been building towards. AI in audit and auditing AI are not two topics. They are the same coin, and the discipline that handles one handles the other.
The thread that connects them is the drafter-to-evaluator shift. When the machine drafts your work (AI in audit), your job is to evaluate it: catch the confabulated compliance, the generic example, the smoothed-over nuance, the rating that drifted to please. When the machine runs the client’s controls (auditing AI), your job is exactly the same: evaluate the output, test the evidence it produces, refuse to assume that because the model said “compliant” the control is operating. In both cases the work that matters is the human judgement layered on top of the machine’s first draft, and in both cases the failure mode is the same: trusting the polished output instead of substantiating it.
So the future is not auditors replaced by AI, nor auditors ignoring it. It is auditors who can do both at once: use the tool to do the technical work faster, and then turn the same sceptical eye on the AI systems inside the estate, because those systems are now part of what the opinion must cover. The auditor who can hold both faces in view, who drafts with the machine and audits the machine with equal fluency, is the auditor the next decade rewards. The opinion is still human. The estate now includes the machine. Substantiate both.
12.5 Where the engagement lands
Twelve weeks ago Tessera’s CTO believed the company was “pretty much there.” The discipline of the engagement has tested that belief against evidence, one question at a time, and the answer is now ready to be delivered. Here it is, in the form the board will receive it.
🗂️ Tessera Case: Tessera’s certification-readiness opinion and board Q&A
Certification-readiness opinion, full-access fieldwork, ISO/IEC 27001:2022.
On the basis of full-access fieldwork conducted over the engagement period, Tessera Limited has established and is operating an information security management system substantially aligned with ISO/IEC 27001:2022 across all four control themes and Clauses 4 through 10. The control set is designed and, in the majority of controls tested, operating effectively. Third-party assurance has been obtained and read for AWS, the payment processor, and the AI summarisation service, with complementary user entity controls tested by us directly.
The following were identified during testing and condition this opinion:
1. (Major nonconformity, A.5.18 / A.8.2) The quarterly privileged-access recertification for production and customer-data systems had not been performed for two consecutive quarters. Role-change reviews are not operating. This is systemic, not isolated.
2. (Minor nonconformity, A.6.5) Of eight sampled leavers, two retained production access beyond the policy window (nine and twenty-three days respectively). Root cause addressed; control now operating for current leavers.
3. (Observation, A.5.9) Asset-register reconciliation identified six unregistered assets, now added. Register currency to be monitored.
4. (Observation, A.5.23 / APP 11) The AI summarisation service’s prompt-logging is enabled; no evidence of training on customer data, but logging retention should be reviewed against APP 11’s security and destruction obligations.
Conclusion: Tessera is ready to proceed to a Stage 1 certification audit with an accredited body, conditional on remediation of the major nonconformity (item 1) and its verification. The minor and the observations should be progressed through the corrective action programme and do not, individually or collectively, preclude certification.
That is the opinion. Now the room tests it.
Chair: “You’re telling me the whole certification rides on access reviews? We do access reviews.” Auditor: The evidence says they stopped two quarters ago. I can show you the recertification log, the gap, and the three production accounts that were not reviewed. This is the one control whose absence I cannot discount, because it is exactly the gap an attacker looks for. Fix it and verify it, and the opinion moves to unconditional.
CTO: “Can’t we just call the major a minor? It’s one control.” Auditor: I cannot. The rating follows the evidence, not the deadline. A systemic, undetected gap in privileged-access governance is a major by any defensible standard. Downgrading it to ease the deal would make the opinion worthless to the very board and customers it is meant to protect. The favour I owe you is the honest rating and a clear path to fix it, which is what you have.
Non-exec: “And you’re comfortable relying on AWS’s SOC 2 for the cloud? You didn’t fly to Sydney and inspect a rack.” Auditor: I read the scope, the period, and the exceptions. AWS’s SOC 2 Type II covers the hypervisor and physical layers that are their responsibility under the shared-responsibility split. The IAM, the keys, the encryption, the public exposure, those are Tessera’s half, and I tested them directly. The opinion cites the SOC 2 for AWS’s controls and my own testing for Tessera’s. That is the honest layering.
The room goes quiet. The chair nods. The opinion stands, unchanged, because it was always the evidence restated, and the evidence did not move.
This is the capstone. By now your Evidence Locker is not a study aid; it is the audit. Lock in your final certification-readiness opinion: the conclusion, the criteria, the named findings with their 5C+R write-ups and ratings, the limitations of the engagement (period, sample, scope), and the conditions under which the opinion holds. Attach the third-party-assurance summary: each SOC report cited, its scope read, its period checked, and the complementary user controls you tested yourself. Add the board Q&A you rehearsed, with your defensible answer to each hostile question.
Do this and the locker becomes the working papers another auditor could pick up, follow, and reach the same conclusion. That reproducibility is the standard a defensible opinion is held to, and it is the standard your Assessment 3 will be marked against. The opinion is the artefact. The locker is the proof the opinion was earned.
12.6 Where to go from here
You have audited Tessera. The engagement is closed. Three next steps are worth naming, because this is a discipline you build by doing, not by finishing.
Practise on the real thing. The companion site at tessera.locoensayo.org stays open, and the cast is AI and the judgement is yours. Run the engagement again with different assumptions, interview the staff you skipped, chase the red herrings you fell for. Every pass sharpens the judgement the next engagement will pay for. The site is a rehearsal room, and auditing is a rehearsal art.
Earn the credential. ISACA’s CISA (Certified Information Systems Auditor) is the professional registration this discipline is measured against, and it is built on the standards this book has taught: the audit lifecycle, evidence and sampling, the control frameworks, the code of ethics. CISM, CGEIT, and CRISC extend the path into management and risk. The credential is not the judgement, but it is the profession’s promise to the people who rely on your opinion that you have been held to a standard.
Read the companion. Conversation, Not Delegation (https://michael-borck.github.io/conversation-not-delegation/) is the method book to this book’s discipline book. Where these chapters taught you what to verify, that one teaches how to work with the machine well: the conversation loop, staying in the loop, compensating for AI’s predictable weaknesses. The drafter-to-evaluator shift lives in the practice of the conversation, and the next decade of audit belongs to the people who can hold both.
12.7 The question, answered
Are you ready to conclude? You are, and the conclusion is this. Tessera is ready for certification conditional on one named fix, and you can defend that judgement in a boardroom because every word of it traces back to evidence you gathered on terms you set. That is what twelve weeks of substantiate, don’t assume produces: not a guess, not a vibe, not a polished page full of badges, but an opinion a board can rely on because you proved it, named what you could not, and refused to soften it when the room pushed back.
And here is the premise, returned to, one last time. The Introduction asked what a human auditor is for when a machine can draft the work. Twelve chapters have answered it. The technical craft is commoditised, and the machine does it faster than you. The opinion is not commoditised, because an opinion is a piece of judgement someone stands behind, and a machine cannot stand behind anything. In a world where the drafting is free and the controls include the machine itself, the defensible human opinion is not a leftover from an older profession. It is the whole point.
Every chapter in this book has been one rehearsal of the same habit. The polished policy is an assertion. The green dashboard is an assertion. The vendor’s clean report is an assertion. The AI’s confident summary is an assertion. The CTO’s “we’re pretty much there” is an assertion. None of them is evidence until you have seen it work. You substantiate what you can. You name what you cannot. You form an opinion you can defend, and you defend it. That is the audit mindset, and it is the only mindset worth having now that the machine can draft and the estate is half algorithm.
Substantiate, don’t assume. The cast is AI. The judgement is yours.