- IAF CertSearch describes verification and monitoring of accredited certifications, including status changes such as suspension, withdrawal, and expiry.
"Certified Once, Accepted Everywhere"
Prepare the ISMS evidence an auditor will expect: scope, risk method, risk results, treatment plan, Statement of Applicability, Annex A control samples, internal audit findings, management review outputs, and corrective actions.
Use this guide to prepare for internal or certification audits, then follow the applicable audit criteria, scope, sampling plan, and certification-body instructions.
Structured answer sets in this page tree.
Cited legal and guidance references.
Audit readiness means the organization can show how its current meets ISO/IEC 27001:2022, including Amendment 1:2024, and its own requirements. Build the evidence pack around the audit criteria and scope. A certification body's sampling plan may differ from an internal audit plan, so confirm the external plan instead of assuming every control or record will be tested.
Audit readiness starts with a clear boundary. Clause 4.3 requires the organization to consider internal and external issues, relevant interested-party requirements, and interfaces and dependencies with other organizations. The documented scope should make the included activities and boundary clear; ISO/IEC 27001 does not offer a general right to exclude inconvenient requirements.
Treat the scope statement as the anchor for the rest of the evidence pack. Risk assessments, treatment plans, Annex A control decisions, internal audit samples, management review inputs, and certification claims should all map back to the same boundary.
If a product, cloud environment, acquisition, outsourced process, or customer commitment changed since the last review, audit readiness means refreshing the scope and downstream evidence before the external audit exposes the gap.
A useful ISO/IEC 27001 audit pack connects risk assessment to risk treatment and then to the Statement of Applicability. The risk method should define criteria, the results should be consistent, valid, and comparable, and the treatment plan should record the options the organization selected. ISO/IEC 27001 does not prescribe labels such as reduce, accept, avoid, or transfer.
The Statement of Applicability should not be a static Annex A checklist. Clause 6.1.3 requires all necessary controls, justification for their inclusion, whether they are implemented, and justification for excluding Annex A controls. Owners, evidence links, and risk references are useful additions but are not part of that four-item minimum.
Before the audit, reconcile the risk register, treatment plan, SoA, policy exceptions, and control evidence. If treatment relies on a control marked not implemented, or the SoA excludes an Annex A control that the treatment record treats as necessary, correct the records and route the current residual-risk decision to the risk owner.
Map risks to treatment and SoA decisions, gather current control samples, close internal-audit findings, and track management-review actions.
Create assigned evidence requests, SoA checks, internal-audit follow-up, and management-review checkpoints.
Review your ISMS scope, risk-to-control traceability, SoA gaps, certification evidence, and next audit-readiness steps.
Evidence for sampled necessary controls should show design, ownership, operation, and review where those attributes are relevant to the audit criteria. A policy alone rarely proves operation. Use samples that show the process running inside the scope and period under review.
Good samples are specific: access review export and sign-off, supplier due-diligence record, incident postmortem, backup restore test, secure development review, vulnerability remediation ticket, awareness completion record, asset inventory extract, logging review, or change approval. Tie each sample to the control owner and date range.
Do not try to prove every control with the same evidence type. ISO/IEC 27002 is control guidance; audit readiness comes from mapping that guidance to real operating records, monitoring results, exceptions, and corrective actions.
Internal audit must test whether the conforms to ISO/IEC 27001 and the organization's own ISMS requirements and is effectively implemented and maintained. Run it at planned intervals as an operating assurance process, not only as document collection before an external audit.
The audit programme must define frequency, methods, responsibilities, planning, and reporting, and consider process importance and previous audit results. ISO/IEC 27001 does not require every Annex A control to be audited in every cycle. Document each audit's criteria and scope, auditor, evidence sampled, results, and report to relevant management.
Use internal audit findings as a rehearsal for the external audit trail: can the team explain why a control was selected, where it operates, what evidence proves it operated, and how exceptions are tracked to closure?
Clause 9.3 requires top management to review the at planned intervals. Inputs include prior actions; relevant changes in context and interested-party needs; trends in nonconformities, corrective actions, monitoring, audit results, and objective fulfilment; interested-party feedback; risk-assessment results; treatment-plan status; and improvement opportunities.
The required output is evidence of decisions about continual-improvement opportunities and any needed changes. Resource, scope, objective, or treatment decisions should be recorded when the review determines they are needed; ISO/IEC 27001 does not require every review to produce each of those decision types.
After the audit, update the evidence register instead of treating the audit report as a separate file. Findings should flow into corrective actions, corrective actions should be checked for effectiveness, and recurring weaknesses should influence the next internal audit programme and management review.
For accredited certification, confirm that the audit baseline is ISO/IEC 27001:2022 with Amendment 1:2024. The IAF transition period for certificates issued to the 2013 edition ended on 31 October 2025; a legacy certificate should not be presented as current ISO/IEC 27001 certification after that deadline.
"Certified Once, Accepted Everywhere"
"36 months from the last day of publication month"
"Information security management systems — Requirements"
"Climate action changes"
"Information security controls"
"Guidance on managing information security risks"
"Requirements for bodies providing audit and certification of information security management systems"