ISO 27001 & SOC 2

    ISO 27001 Audit Evidence: Lessons from Joseph Kirkpatrick

    ICyberWave Editorial
    Sep 26, 2026
    ISO 27001 & SOC 2
    Compliance operations team monitoring cloud controls and automated audit evidence

    A control is only as strong as its evidence

    Auditor Joseph Kirkpatrick’s discussion of ISO 27001 reinforces a rule that applies equally to SOC 2: a control must be designed, operated and evidenced. A policy may describe intent, but an auditor needs reliable proof that the activity happened across the review period.

    This does not mean creating screenshots for auditors. The best evidence is produced naturally by a well-designed process.

    Separate design from operation

    Evidence should answer two different questions. First, is the control designed to address the risk? Second, did it operate consistently?

    ControlDesign evidenceOperating evidence
    Access reviewProcedure, scope, frequency and reviewerComplete population, review decisions and removals
    Change managementWorkflow and approval criteriaSampled tickets, testing, approval and deployment logs
    Vulnerability managementScanning and remediation standardScan results, tickets, exceptions and closure proof
    Supplier reviewDue-diligence method and risk tiersAssessments, contracts, findings and follow-up
    Incident responsePlan, roles and severity modelIncident records, exercise results and improvements

    Prove population completeness

    A sample is only meaningful when the source population is complete. Before selecting access reviews, changes, incidents or suppliers, retain how the population was generated, the period covered and any filters applied.

    Reconcile totals to an independent source where possible. For example, compare the change export to deployment records or the employee list to the identity platform. This prevents a clean sample from hiding omitted items.

    Build evidence ownership into the control

    Every control should identify its operator, reviewer, frequency, source system, evidence location and exception route. Avoid shared folders filled with unexplained screenshots. Evidence should show who acted, when, on what population and with what result.

    Evidence quality test

    1. Relevant: Does it prove the control objective?
    2. Reliable: Is the source trustworthy and tamper-resistant?
    3. Complete: Does it cover the required systems, people and period?
    4. Timely: Was the control performed at the defined frequency?
    5. Reviewable: Can another competent person reproduce the conclusion?

    Reuse evidence across ISO 27001 and SOC 2 carefully

    One access-review record may support both frameworks, but mappings do not remove differences in scope, criteria or reporting period. Maintain one control description and evidence source, then map it to the applicable ISO clauses, Annex A controls and SOC 2 criteria.

    Document any gap. A control operating annually may satisfy one internal decision but be too infrequent for the risk or customer commitment being tested.

    Create an evidence calendar

    Continuous readiness requires scheduled collection and review. Monthly controls should not be reconstructed at year-end. Use a calendar that flags missed operation, incomplete evidence and overdue exceptions while there is still time to correct them.

    Priority evidence often includes access reviews, security training, vulnerability remediation, backup tests, incident exercises, supplier reviews, risk treatment, internal audit and management review.

    Readiness questions before the auditor arrives

    • Is the scope consistent across the ISMS, systems and customer commitments?
    • Can each control owner explain the risk and evidence?
    • Are populations complete and samples traceable?
    • Do exceptions show approval, expiry and remediation?
    • Has internal audit challenged effectiveness, not just documentation?
    • Has management review made recorded decisions?

    ICyberWave perspective

    Evidence-first design reduces audit disruption and improves the control environment between audits. ICyberWave supports ISO 27001 implementation, SOC 2 readiness, evidence mapping, internal audit and corrective action. Use our ISO 27001 audit checklist and SOC 2 compliance checklist to assess readiness.

    Hi! I'm your AI Assistant 💬