What an ISO 27001 auditor is actually checking
A certification auditor answers two questions. Does your ISMS meet clauses 4 to 10 of ISO/IEC 27001:2022? And for every Annex A control you declared applicable in your Statement of Applicability, can you show it operating?
Stage 1 tests documentation and readiness. Stage 2 tests operation, through sampling and interviews. This checklist follows the same order, so you can self-assess in the same sequence your auditor will.
Mandatory documented information
Missing any of these stops Stage 1. There is no negotiation.
- [ ] ISMS scope statement
- [ ] Information security policy
- [ ] Risk assessment and risk treatment methodology
- [ ] Risk assessment results (the risk register)
- [ ] Risk treatment plan
- [ ] Statement of Applicability, covering all 93 Annex A controls with justification for each inclusion and exclusion
- [ ] Information security objectives, with measures
- [ ] Evidence of competence (training and qualification records)
- [ ] Operational planning and control records
- [ ] Results of monitoring and measurement
- [ ] Internal audit programme and results
- [ ] Management review minutes
- [ ] Nonconformities, corrective actions and their closure
Clause 4 — Context of the organisation
- [ ] Internal and external issues identified
- [ ] Interested parties and their requirements listed, including legal, regulatory and contractual
- [ ] Scope defines locations, business units, systems, interfaces and dependencies — and says what is excluded and why
Frequent finding: a scope that says "all information systems" while the evidence shows only the product team participating.
Clause 5 — Leadership
- [ ] Policy approved by top management, communicated and available
- [ ] Roles, responsibilities and authorities assigned in writing
- [ ] Demonstrable top-management involvement: resource decisions, review attendance, objective setting
Clause 6 — Planning
- [ ] Risk assessment applied consistently and repeatably, with defined criteria for acceptance
- [ ] Risk owners named for each risk
- [ ] Risk treatment options chosen, controls determined, and compared against Annex A
- [ ] Statement of Applicability approved
- [ ] Risk owners' approval of the treatment plan and acceptance of residual risk
- [ ] Objectives that are measurable, resourced and time-bound
- [ ] Planning of changes to the ISMS (new in 2022)
Clause 7 — Support
- [ ] Resources allocated
- [ ] Competence determined and evidenced per role, not just generic training
- [ ] Awareness activity covering the policy and personnel responsibilities
- [ ] Internal and external communication plan
- [ ] Documented information controlled: version, approval, distribution, retention
Clause 8 — Operation
- [ ] Processes planned, implemented and controlled; evidence retained that they ran as planned
- [ ] Risk assessment performed at planned intervals and on significant change
- [ ] Risk treatment plan implemented, with status tracked
Clause 9 — Performance evaluation
- [ ] Monitoring and measurement defined: what, when, by whom, by what method
- [ ] Internal audit programme covering the whole ISMS across the cycle, conducted by auditors independent of the area audited
- [ ] Internal audit reports with findings and corrective actions
- [ ] Management review covering every required input: audit results, nonconformities, risk status, objective performance, interested-party feedback, improvement opportunities
Frequent finding: a management review that discusses incidents but omits objective performance and interested-party feedback. Auditors check the input list item by item.
Clause 10 — Improvement
- [ ] Nonconformity process with root-cause analysis, not just a fix
- [ ] Corrective actions with effectiveness checks after closure
- [ ] Evidence of continual improvement over the cycle
Annex A 2022 — 93 controls in four themes
A.5 Organisational controls (37) - [ ] Policies for information security, topic-specific and approved - [ ] Roles and responsibilities; segregation of duties - [ ] Contact with authorities and special interest groups - [ ] **Threat intelligence (A.5.7 — new)**: a documented source, consumption and action path - [ ] Information security in project management - [ ] Inventory of information and other associated assets, with owners - [ ] Acceptable use and return of assets - [ ] Classification, labelling and handling of information - [ ] Access control policy, identity management, authentication information, access rights - [ ] Supplier relationships: screening, agreements, ICT supply chain, monitoring, cloud service use (A.5.23 — new) - [ ] Incident management: planning, assessment, response, learning, evidence collection - [ ] Business continuity readiness for ICT (with A.5.30) - [ ] Legal, statutory, regulatory and contractual requirements; IP; PII protection - [ ] Independent review of information security - [ ] Documented operating procedures
A.6 People controls (8) - [ ] Screening before employment - [ ] Terms and conditions including security responsibilities - [ ] Awareness, education and training records - [ ] Disciplinary process - [ ] Responsibilities after termination or change of employment - [ ] Confidentiality or NDA agreements - [ ] Remote working policy and controls - [ ] Information security event reporting route known to staff
A.7 Physical controls (14) - [ ] Security perimeters, entry controls, visitor records - [ ] Securing offices, rooms and facilities; monitoring (A.7.4 — new) - [ ] Protection against physical and environmental threats - [ ] Working in secure areas; clear desk and clear screen - [ ] Equipment siting, protection and maintenance - [ ] Security of assets off premises; storage media handling - [ ] Supporting utilities and cabling security - [ ] Secure disposal or re-use of equipment
A.8 Technological controls (34) - [ ] User endpoint devices; privileged access rights; information access restriction - [ ] Access to source code - [ ] Secure authentication; capacity management - [ ] Protection against malware; management of technical vulnerabilities - [ ] **Configuration management (A.8.9 — new)** with defined hardened baselines - [ ] **Information deletion (A.8.10 — new)** and **data masking (A.8.11 — new)** - [ ] **Data leakage prevention (A.8.12 — new)** - [ ] Information backup, with restore testing - [ ] Redundancy of information processing facilities - [ ] Logging; **monitoring activities (A.8.16 — new)**; clock synchronisation - [ ] Use of privileged utility programs; software installation restrictions - [ ] Network security, network services security, segregation of networks - [ ] **Web filtering (A.8.23 — new)**; use of cryptography - [ ] Secure development lifecycle; application security requirements - [ ] **Secure coding (A.8.28 — new)** - [ ] Secure system architecture and engineering principles - [ ] Security testing in development and acceptance; outsourced development - [ ] Separation of development, test and production environments - [ ] Change management; test information; protection during audit testing
The eleven 2022 controls that cause the most findings
If you transitioned from the 2013 standard, these are new and often thin:
| Control | What auditors want to see |
|---|---|
| A.5.7 Threat intelligence | A named feed, who reviews it, and a decision it changed |
| A.5.23 Cloud services | Cloud security requirements set before adoption, plus exit criteria |
| A.5.30 ICT readiness for continuity | ICT recovery objectives tested, not just a BCP document |
| A.7.4 Physical monitoring | CCTV/alarm coverage evidence, or a justified exclusion |
| A.8.9 Configuration management | A hardened baseline and drift detection |
| A.8.10 Information deletion | Deletion actually performed, with records |
| A.8.11 Data masking | Masking in non-production environments |
| A.8.12 Data leakage prevention | A technical control, not an acceptable-use policy |
| A.8.16 Monitoring activities | Alert rules and evidence of triage |
| A.8.23 Web filtering | Enforced policy with a category list |
| A.8.28 Secure coding | Standards, SAST in the pipeline, developer training |
Audit stages and what happens in each
| Stage | Duration | Focus | Typical outcome |
|---|---|---|---|
| Gap assessment (optional) | 1–2 weeks | Readiness against clauses and Annex A | Prioritised remediation plan |
| Stage 1 | 1–2 days | Documentation, scope, SoA, internal audit and management review completed | Findings to clear before Stage 2 |
| Stage 2 | 2–5 days | Control operation, sampling, interviews | Major and minor nonconformities |
| Certification decision | 2–6 weeks | Independent review by the certification body | Certificate, valid 3 years |
| Surveillance | Annual | Sampled controls, changes, improvement | Continued certification |
| Recertification | Year 3 | Full ISMS review | Renewed certificate |
Major vs minor: a major nonconformity is a total absence of a required process, or a breakdown with real impact — it must be corrected before certification. A minor is an isolated lapse, closed through corrective action in the next cycle.
Self-assessment shortcuts that actually work
- Pick three controls at random and trace them end to end. Policy, implementation, evidence, review. If any link is missing, the rest of your ISMS is probably the same shape.
- Ask a non-security colleague what the policy requires of them. Awareness findings come from interviews, not documents.
- Verify your internal audit was genuinely independent. The person who built a control cannot audit it.
- Reconcile your asset inventory against your cloud console. Divergence is the fastest route to a finding.
- Read your own SoA justifications. "Not applicable — we have no such systems" must match reality.
Frequently asked questions
How long does ISO 27001 certification take? Typically four to nine months from a serious start for a mid-sized organisation: two to four months building the ISMS, then the mandatory internal audit and management review, then Stage 1 and Stage 2 separated by a few weeks.
Do we need all 93 Annex A controls? No. You need a justified decision on all 93. Exclusions are allowed when supported by your risk assessment and scope.
Can we certify before an internal audit? No. A completed internal audit and management review are prerequisites to Stage 2, and auditors check their dates.
How is this different from SOC 2? ISO 27001 certifies a management system against a fixed standard; SOC 2 is an attestation report against criteria, describing controls you define. Many organisations run both from one control set — [we map them for clients](/services) so evidence is collected once.
Bring us your Statement of Applicability and risk register and we will tell you, control by control, where Stage 2 would find gaps — [get in touch](/contact).
