ISO 27001

    ISO 27001 Audit Checklist: Clause-by-Clause and Annex A Control Evidence

    Santhosh Kapalavai
    Sep 19, 2026
    ISO 27001

    What an ISO 27001 auditor is actually checking

    A certification auditor answers two questions. Does your ISMS meet clauses 4 to 10 of ISO/IEC 27001:2022? And for every Annex A control you declared applicable in your Statement of Applicability, can you show it operating?

    Stage 1 tests documentation and readiness. Stage 2 tests operation, through sampling and interviews. This checklist follows the same order, so you can self-assess in the same sequence your auditor will.

    Mandatory documented information

    Missing any of these stops Stage 1. There is no negotiation.

    • [ ] ISMS scope statement
    • [ ] Information security policy
    • [ ] Risk assessment and risk treatment methodology
    • [ ] Risk assessment results (the risk register)
    • [ ] Risk treatment plan
    • [ ] Statement of Applicability, covering all 93 Annex A controls with justification for each inclusion and exclusion
    • [ ] Information security objectives, with measures
    • [ ] Evidence of competence (training and qualification records)
    • [ ] Operational planning and control records
    • [ ] Results of monitoring and measurement
    • [ ] Internal audit programme and results
    • [ ] Management review minutes
    • [ ] Nonconformities, corrective actions and their closure

    Clause 4 — Context of the organisation

    • [ ] Internal and external issues identified
    • [ ] Interested parties and their requirements listed, including legal, regulatory and contractual
    • [ ] Scope defines locations, business units, systems, interfaces and dependencies — and says what is excluded and why

    Frequent finding: a scope that says "all information systems" while the evidence shows only the product team participating.

    Clause 5 — Leadership

    • [ ] Policy approved by top management, communicated and available
    • [ ] Roles, responsibilities and authorities assigned in writing
    • [ ] Demonstrable top-management involvement: resource decisions, review attendance, objective setting

    Clause 6 — Planning

    • [ ] Risk assessment applied consistently and repeatably, with defined criteria for acceptance
    • [ ] Risk owners named for each risk
    • [ ] Risk treatment options chosen, controls determined, and compared against Annex A
    • [ ] Statement of Applicability approved
    • [ ] Risk owners' approval of the treatment plan and acceptance of residual risk
    • [ ] Objectives that are measurable, resourced and time-bound
    • [ ] Planning of changes to the ISMS (new in 2022)

    Clause 7 — Support

    • [ ] Resources allocated
    • [ ] Competence determined and evidenced per role, not just generic training
    • [ ] Awareness activity covering the policy and personnel responsibilities
    • [ ] Internal and external communication plan
    • [ ] Documented information controlled: version, approval, distribution, retention

    Clause 8 — Operation

    • [ ] Processes planned, implemented and controlled; evidence retained that they ran as planned
    • [ ] Risk assessment performed at planned intervals and on significant change
    • [ ] Risk treatment plan implemented, with status tracked

    Clause 9 — Performance evaluation

    • [ ] Monitoring and measurement defined: what, when, by whom, by what method
    • [ ] Internal audit programme covering the whole ISMS across the cycle, conducted by auditors independent of the area audited
    • [ ] Internal audit reports with findings and corrective actions
    • [ ] Management review covering every required input: audit results, nonconformities, risk status, objective performance, interested-party feedback, improvement opportunities

    Frequent finding: a management review that discusses incidents but omits objective performance and interested-party feedback. Auditors check the input list item by item.

    Clause 10 — Improvement

    • [ ] Nonconformity process with root-cause analysis, not just a fix
    • [ ] Corrective actions with effectiveness checks after closure
    • [ ] Evidence of continual improvement over the cycle

    Annex A 2022 — 93 controls in four themes

    A.5 Organisational controls (37) - [ ] Policies for information security, topic-specific and approved - [ ] Roles and responsibilities; segregation of duties - [ ] Contact with authorities and special interest groups - [ ] **Threat intelligence (A.5.7 — new)**: a documented source, consumption and action path - [ ] Information security in project management - [ ] Inventory of information and other associated assets, with owners - [ ] Acceptable use and return of assets - [ ] Classification, labelling and handling of information - [ ] Access control policy, identity management, authentication information, access rights - [ ] Supplier relationships: screening, agreements, ICT supply chain, monitoring, cloud service use (A.5.23 — new) - [ ] Incident management: planning, assessment, response, learning, evidence collection - [ ] Business continuity readiness for ICT (with A.5.30) - [ ] Legal, statutory, regulatory and contractual requirements; IP; PII protection - [ ] Independent review of information security - [ ] Documented operating procedures

    A.6 People controls (8) - [ ] Screening before employment - [ ] Terms and conditions including security responsibilities - [ ] Awareness, education and training records - [ ] Disciplinary process - [ ] Responsibilities after termination or change of employment - [ ] Confidentiality or NDA agreements - [ ] Remote working policy and controls - [ ] Information security event reporting route known to staff

    A.7 Physical controls (14) - [ ] Security perimeters, entry controls, visitor records - [ ] Securing offices, rooms and facilities; monitoring (A.7.4 — new) - [ ] Protection against physical and environmental threats - [ ] Working in secure areas; clear desk and clear screen - [ ] Equipment siting, protection and maintenance - [ ] Security of assets off premises; storage media handling - [ ] Supporting utilities and cabling security - [ ] Secure disposal or re-use of equipment

    A.8 Technological controls (34) - [ ] User endpoint devices; privileged access rights; information access restriction - [ ] Access to source code - [ ] Secure authentication; capacity management - [ ] Protection against malware; management of technical vulnerabilities - [ ] **Configuration management (A.8.9 — new)** with defined hardened baselines - [ ] **Information deletion (A.8.10 — new)** and **data masking (A.8.11 — new)** - [ ] **Data leakage prevention (A.8.12 — new)** - [ ] Information backup, with restore testing - [ ] Redundancy of information processing facilities - [ ] Logging; **monitoring activities (A.8.16 — new)**; clock synchronisation - [ ] Use of privileged utility programs; software installation restrictions - [ ] Network security, network services security, segregation of networks - [ ] **Web filtering (A.8.23 — new)**; use of cryptography - [ ] Secure development lifecycle; application security requirements - [ ] **Secure coding (A.8.28 — new)** - [ ] Secure system architecture and engineering principles - [ ] Security testing in development and acceptance; outsourced development - [ ] Separation of development, test and production environments - [ ] Change management; test information; protection during audit testing

    The eleven 2022 controls that cause the most findings

    If you transitioned from the 2013 standard, these are new and often thin:

    ControlWhat auditors want to see
    A.5.7 Threat intelligenceA named feed, who reviews it, and a decision it changed
    A.5.23 Cloud servicesCloud security requirements set before adoption, plus exit criteria
    A.5.30 ICT readiness for continuityICT recovery objectives tested, not just a BCP document
    A.7.4 Physical monitoringCCTV/alarm coverage evidence, or a justified exclusion
    A.8.9 Configuration managementA hardened baseline and drift detection
    A.8.10 Information deletionDeletion actually performed, with records
    A.8.11 Data maskingMasking in non-production environments
    A.8.12 Data leakage preventionA technical control, not an acceptable-use policy
    A.8.16 Monitoring activitiesAlert rules and evidence of triage
    A.8.23 Web filteringEnforced policy with a category list
    A.8.28 Secure codingStandards, SAST in the pipeline, developer training

    Audit stages and what happens in each

    StageDurationFocusTypical outcome
    Gap assessment (optional)1–2 weeksReadiness against clauses and Annex APrioritised remediation plan
    Stage 11–2 daysDocumentation, scope, SoA, internal audit and management review completedFindings to clear before Stage 2
    Stage 22–5 daysControl operation, sampling, interviewsMajor and minor nonconformities
    Certification decision2–6 weeksIndependent review by the certification bodyCertificate, valid 3 years
    SurveillanceAnnualSampled controls, changes, improvementContinued certification
    RecertificationYear 3Full ISMS reviewRenewed certificate

    Major vs minor: a major nonconformity is a total absence of a required process, or a breakdown with real impact — it must be corrected before certification. A minor is an isolated lapse, closed through corrective action in the next cycle.

    Self-assessment shortcuts that actually work

    1. Pick three controls at random and trace them end to end. Policy, implementation, evidence, review. If any link is missing, the rest of your ISMS is probably the same shape.
    2. Ask a non-security colleague what the policy requires of them. Awareness findings come from interviews, not documents.
    3. Verify your internal audit was genuinely independent. The person who built a control cannot audit it.
    4. Reconcile your asset inventory against your cloud console. Divergence is the fastest route to a finding.
    5. Read your own SoA justifications. "Not applicable — we have no such systems" must match reality.

    Frequently asked questions

    How long does ISO 27001 certification take? Typically four to nine months from a serious start for a mid-sized organisation: two to four months building the ISMS, then the mandatory internal audit and management review, then Stage 1 and Stage 2 separated by a few weeks.

    Do we need all 93 Annex A controls? No. You need a justified decision on all 93. Exclusions are allowed when supported by your risk assessment and scope.

    Can we certify before an internal audit? No. A completed internal audit and management review are prerequisites to Stage 2, and auditors check their dates.

    How is this different from SOC 2? ISO 27001 certifies a management system against a fixed standard; SOC 2 is an attestation report against criteria, describing controls you define. Many organisations run both from one control set — [we map them for clients](/services) so evidence is collected once.

    Bring us your Statement of Applicability and risk register and we will tell you, control by control, where Stage 2 would find gaps — [get in touch](/contact).

    Hi! I'm your AI Assistant 💬