Why Confidentiality Is a Core Auditing Obligation
Every audit involves access to information that organisations would not ordinarily share with outsiders. Financial records, personnel files, supplier contracts, incident reports, customer complaints, trade processes and strategic plans all sit behind the scenes of a management system. When an auditor walks through the door, they are trusted with access to that world. Confidentiality for auditors is not a courtesy or a soft expectation. It is a professional obligation that sits at the very heart of ethical audit practice.
On this page
ISO 19011:2018 lists confidentiality as one of the seven principles of auditing. It requires auditors to exercise discretion in the use and protection of information acquired during an audit. The 2026 revision of ISO 19011 reinforces this, particularly in the context of remote auditing and the growing use of digital tools. If you are building a career as an internal auditor, lead auditor or ISO consultant, understanding how to handle sensitive information properly is not optional. It is part of what makes you trustworthy and, frankly, employable.
This article covers what confidentiality means in practice, where auditors most commonly get it wrong, and how to build habits that protect both the auditee and your own professional reputation.
What Information Is Considered Sensitive in an Audit
Before you can protect sensitive information, you need to recognise it. The obvious categories are easy enough: financial data, payroll records, personal employee information, medical records, and legally privileged documents. But audits surface a much wider range of sensitive material than most new auditors expect.
Categories of Sensitive Information Auditors Commonly Encounter
- Personnel information: Training records, performance reviews, disciplinary histories, competency assessments and attendance records. These are personal in nature and protected under privacy legislation.
- Commercial information: Supplier pricing, customer contracts, tender submissions, profit margins, business plans and intellectual property. Disclosure of this information could cause direct commercial harm.
- Incident and investigation records: Workplace injury investigations, near miss reports, environmental spill records and corrective action files. These often contain sensitive details about individuals or systemic failures the organisation has not yet resolved.
- Nonconformity records: Internal audit findings, previous certification audit reports, and corrective action registers. Auditees share these in good faith, expecting they will not be used against them outside the audit context.
- Customer information: Complaint records, customer satisfaction data, and anything that identifies customers by name or project.
- Strategic and operational plans: Expansion plans, restructuring documents, risk registers that contain commercially sensitive risk descriptions, and quality objectives tied to market positioning.
The challenge is that auditors often encounter this material without warning. You are reviewing a training matrix and notice a note about a disciplinary matter. You are checking a corrective action and the root cause analysis refers to a specific manager by name. You are auditing a procurement process and the supplier list contains pricing that would be valuable to a competitor. Your obligation to treat that information with care applies regardless of whether anyone has formally flagged it as sensitive.
Exemplar Global Recognised Training ProviderRTP No. 310970The ISO 19011 Confidentiality Principle in Plain Language
ISO 19011 defines confidentiality as the obligation to exercise discretion in the use and protection of information acquired in the course of an audit. It goes on to note that audit information should not be used inappropriately for personal advantage or to the disadvantage of the auditee.
What does that mean in practice? It means three things.
- You use audit information only for audit purposes. Information gathered during an audit is used to form findings, write the report, and support corrective action. It is not used for any other purpose, including satisfying your own curiosity, informing a competitor, or building a consulting pitch.
- You do not disclose audit information without authorisation. The audit client authorises the scope of disclosure. If you are an internal auditor, that is typically top management or the management review process. If you are a third party auditor, it is the certification body and the auditee under the terms of the audit agreement. You do not share findings with parties outside that arrangement without explicit permission.
- You protect information from accidental disclosure. This is where many auditors fall short. Leaving notes visible in a shared space, discussing findings in a hotel lobby, emailing draft reports to the wrong address, or storing audit records on an unsecured personal device are all failures of confidentiality even when there is no malicious intent.
For a deeper look at how the seven principles of auditing shape professional practice, including confidentiality, see our article on ISO 19011 Audit Principles Explained.
Where Auditors Most Commonly Get Confidentiality Wrong
Most confidentiality failures in auditing are not deliberate. They happen through carelessness, habit, or a failure to think through the implications of everyday actions. Here are the situations that come up most often in practice.
Casual Conversation After the Audit
You finish an audit, get in the car with a colleague, and debrief on the way to the airport. You mention the name of the organisation, describe what you found, and share your opinion of how well the management system is functioning. If anyone overhears that conversation, or if your colleague later mentions it to someone outside the audit team, you have breached confidentiality. The same applies to conversations at industry events, over dinner with peers, or on professional networking platforms.
The rule is straightforward: you do not discuss audit findings, auditee details, or anything you observed during an audit with people who were not part of that audit team, unless the audit client has explicitly authorised disclosure.
Sharing Findings Across Audits
Lead auditors who conduct multiple audits across an industry sometimes fall into the habit of benchmarking. They mention to one auditee that another organisation in the same sector handles a particular process differently. Even without naming the other organisation, this can constitute a breach. You are drawing on confidential information from one audit to inform a conversation in another. The information belongs to the auditee who shared it, not to you.
Insecure Handling of Audit Records
Audit notes, checklists, photographs taken during site inspections, and draft reports all contain sensitive information. Common failures include leaving printed notes in hotel rooms or shared vehicles, storing audit files in personal cloud accounts without adequate access controls, emailing draft reports through unencrypted channels, and keeping audit records on personal devices after the audit is complete.
If you are conducting remote audits, the risks multiply. Screen sharing during a video call can expose information to people in the background. Recordings of audit interviews may capture sensitive disclosures. Screenshots taken during document reviews may be stored in locations the auditee did not anticipate.
Social Media and Online Commentary
This is an increasingly common problem. An auditor visits a well-known site, takes a photograph, and posts it on LinkedIn with a comment about the audit. Even a vague post that does not name the organisation can be enough to identify it, particularly in niche industries. Any public commentary about an audit, its findings, or the auditee is a breach of confidentiality unless you have explicit written permission from the audit client.
Discussing Findings with the Wrong People On Site
During an audit, you will gather information from multiple people across the organisation. What you hear from one person should not be repeated to another in a way that identifies the source. If a worker tells you that a particular supervisor routinely bypasses a safety control, you note the evidence and raise it as a finding. You do not go back to the supervisor and say that a worker told you this. You do not share the worker's name with management. Protecting the confidentiality of interview sources is a specific obligation under ISO 19011 and a practical necessity for maintaining trust with the people you interview.
Confidentiality Agreements and Audit Arrangements
In many professional audit contexts, confidentiality is formalised through a written agreement. Certification bodies include confidentiality provisions in their contracts with clients. Organisations conducting supplier audits often require auditors to sign non-disclosure agreements before commencing. Internal audit programmes may include a formal confidentiality policy as part of the audit procedure.
Even where no formal agreement exists, the professional obligation remains. ISO 19011 does not make confidentiality conditional on having signed a document. It is a principle that applies to every audit, regardless of whether anyone has asked you to formalise it.
If you are setting up an internal audit programme from scratch, it is worth including a confidentiality clause in your audit procedure and briefing auditors on it as part of their induction. This is particularly important when you are using staff from one department to audit another, where the potential for inappropriate information sharing within the organisation is real.
Confidentiality in Remote and Digital Auditing
Remote auditing has introduced a new set of confidentiality challenges that the profession is still working through. When you conduct an audit via video conference, the auditee is sharing their screen, their documents, and their workspace with you across a digital channel. The confidentiality obligations are identical to those in a face to face audit, but the practical risks are different.
Practical Steps for Remote Audit Confidentiality
- Use platforms that encrypt data in transit and at rest. Avoid using personal or free accounts for audit communications.
- Do not record audit sessions without the explicit consent of all parties. If you do record with consent, confirm how the recording will be stored, who can access it, and when it will be deleted.
- Be mindful of who else can see your screen during a video call. If you are working from a shared space, use a privacy screen.
- Delete temporary files, screenshots, and downloaded documents from your device promptly after the audit is complete, in accordance with the agreed retention arrangements.
- Confirm with the audit client how digital records will be transferred and stored before the audit begins.
ISO 19011:2026 specifically addresses remote auditing and the use of digital tools, recognising that these create new risks for audit programme integrity. Auditors who work remotely need to be as disciplined about information security as they are about the technical content of their audits.
Confidentiality and Integrity: Two Principles That Work Together
Confidentiality does not mean hiding things that should be reported. There is sometimes a tension between the obligation to protect information and the obligation to report findings honestly and completely. It is worth being clear about how this works.
The confidentiality principle governs who receives audit information and how it is handled. The integrity principle requires that what is reported is accurate, truthful, and complete. These two obligations are not in conflict. You report findings fully and honestly to the appropriate parties, which are the audit client and those authorised to receive the report. You do not share those findings with anyone outside that authorised group.
Where things get complicated is when an audit surfaces information that suggests a serious legal breach, a safety risk, or potential fraud. In those situations, your obligations may extend beyond the audit client. This is territory where you need to take advice, whether from your certification body, your employer, or a legal professional. ISO 19011 does not resolve every scenario, but it is clear that confidentiality does not override obligations imposed by law.
For a broader look at how integrity shapes audit reporting, our article on Fair Presentation: Reporting Audit Findings Truthfully and Accurately covers this in detail.
Exemplar Global Recognised Training ProviderRTP No. 310970Building Confidentiality into Your Audit Habits
The most effective way to protect sensitive information is to build good habits that operate automatically, regardless of the specific audit you are conducting. Here are the practices that make a real difference.
Before the Audit
- Review the audit agreement or terms of engagement and understand what confidentiality obligations apply.
- Brief any co-auditors or technical experts on their confidentiality obligations before the audit begins.
- Set up secure storage for audit records before you start collecting them.
During the Audit
- Take notes in a way that does not expose sensitive information to bystanders. Use shorthand or coded references where appropriate.
- Do not photograph documents, screens, or areas of the site without permission. Even where photography is permitted, be selective about what you capture.
- Keep audit notes and checklists out of sight when not in use.
- Protect interview sources. Do not attribute specific comments to specific individuals in your notes or your report.
After the Audit
- Send the audit report only to the parties authorised to receive it. Double check email addresses before sending.
- Retain audit records only for as long as required under your audit programme or the terms of the engagement.
- Destroy physical notes and documents securely. Shred rather than bin.
- Clear digital records from personal devices once the audit is finalised and records have been transferred to secure storage.
These habits are particularly important for auditors who work across multiple organisations. The discipline required to keep information compartmentalised, to resist the temptation to benchmark or compare, and to treat every auditee's information as if it were your own, is what separates a professional auditor from someone who is simply going through the motions.
For those interested in the broader ethical framework that governs auditor conduct, including confidentiality, our article on Auditor Code of Conduct and Professional Ethics Explained provides a thorough overview.
Confidentiality as a Foundation of Audit Trust
Organisations open their doors to auditors because they trust that what they share will be handled with care. That trust is not automatic. It is earned through consistent, professional behaviour over time. When an auditee believes their information is safe with you, they are more likely to be candid, to show you the real state of their system rather than the polished version, and to engage genuinely with the findings you raise.
Conversely, a reputation for indiscretion travels fast, particularly in specialist industries where everyone knows everyone. An auditor who is known to discuss client details, share findings informally, or use information gathered in one context to inform another, will find doors closing. The professional consequences of confidentiality failures are serious and they are often irreversible.
This is one of the reasons that formal auditor training covers ethics and professional conduct, not just technical auditing skills. If you are working towards your internal auditor or lead auditor credentials, understanding your confidentiality obligations is part of the competence you need to demonstrate.
At Audit Workshop, our ISO auditor training courses cover the full spectrum of professional auditing skills, including the ethical principles that underpin every audit. Whether you are just starting out with a Foundation or Internal Auditor course, or working towards Lead Auditor certification across ISO 9001, ISO 14001, or ISO 45001, you will learn how to conduct audits that are not only technically rigorous but professionally sound. Explore our What Does a Lead Auditor Actually Do Day to Day? article to understand the full scope of the role, including how confidentiality plays out in real audit situations.










