GuideGlobalISO/IEC 27001

ISO/IEC 27001 Audit Readiness

Prepare the ISMS evidence an auditor will expect: scope, risk method, risk results, treatment plan, Statement of Applicability, Annex A control samples, internal audit findings, management review outputs, and corrective actions.

Use this guide to prepare for internal or certification audits, then follow the applicable audit criteria, scope, sampling plan, and certification-body instructions.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
7

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

Audit readiness means the organization can show how its current meets ISO/IEC 27001:2022, including Amendment 1:2024, and its own requirements. Build the evidence pack around the audit criteria and scope. A certification body's sampling plan may differ from an internal audit plan, so confirm the external plan instead of assuming every control or record will be tested.

Section 1

Start with the audit boundary

Audit readiness starts with a clear boundary. Clause 4.3 requires the organization to consider internal and external issues, relevant interested-party requirements, and interfaces and dependencies with other organizations. The documented scope should make the included activities and boundary clear; ISO/IEC 27001 does not offer a general right to exclude inconvenient requirements.

Treat the scope statement as the anchor for the rest of the evidence pack. Risk assessments, treatment plans, Annex A control decisions, internal audit samples, management review inputs, and certification claims should all map back to the same boundary.

If a product, cloud environment, acquisition, outsourced process, or customer commitment changed since the last review, audit readiness means refreshing the scope and downstream evidence before the external audit exposes the gap.

  • Keep a documented scope with included services, sites, cloud environments, business units, and material dependencies.
  • Record boundary decisions, interfaces, dependencies, and externally provided processes explicitly so auditors do not have to infer them from diagrams or sales copy.
  • Check that the certificate scope, internal scope statement, customer assurance language, and audit sampling plan do not contradict each other.
Section 2

Build the risk and SoA evidence chain

A useful ISO/IEC 27001 audit pack connects risk assessment to risk treatment and then to the Statement of Applicability. The risk method should define criteria, the results should be consistent, valid, and comparable, and the treatment plan should record the options the organization selected. ISO/IEC 27001 does not prescribe labels such as reduce, accept, avoid, or transfer.

The Statement of Applicability should not be a static Annex A checklist. Clause 6.1.3 requires all necessary controls, justification for their inclusion, whether they are implemented, and justification for excluding Annex A controls. Owners, evidence links, and risk references are useful additions but are not part of that four-item minimum.

Before the audit, reconcile the risk register, treatment plan, SoA, policy exceptions, and control evidence. If treatment relies on a control marked not implemented, or the SoA excludes an Annex A control that the treatment record treats as necessary, correct the records and route the current residual-risk decision to the risk owner.

  • Risk method: criteria for likelihood, impact, risk acceptance, ownership, review frequency, and change-triggered reassessment.
  • Risk records: scenario and scope, risk owner, confidentiality, integrity, and availability consequences, realistic likelihood, risk level, evaluation against criteria, priority, and reassessment date or trigger.
  • SoA records: Annex A control applicability, inclusion or exclusion rationale, implementation status, evidence link, control owner, and last review.
  • Treatment records: approved actions, deadlines, residual risk acceptance, dependencies, exceptions, and proof that the treatment was implemented.
Section 3

Prepare control samples

Evidence for sampled necessary controls should show design, ownership, operation, and review where those attributes are relevant to the audit criteria. A policy alone rarely proves operation. Use samples that show the process running inside the scope and period under review.

Good samples are specific: access review export and sign-off, supplier due-diligence record, incident postmortem, backup restore test, secure development review, vulnerability remediation ticket, awareness completion record, asset inventory extract, logging review, or change approval. Tie each sample to the control owner and date range.

Do not try to prove every control with the same evidence type. ISO/IEC 27002 is control guidance; audit readiness comes from mapping that guidance to real operating records, monitoring results, exceptions, and corrective actions.

  • For each sampled necessary control, keep the control purpose, implementation description, owner, authoritative repository, sample period, and evidence link together.
  • Use current operating evidence, not screenshots from implementation projects that no longer match the environment.
  • Record exceptions as risk decisions, remediation tickets, or corrective actions instead of hiding them from the audit trail.
  • Cross-check source systems before the audit: HR roster, asset inventory, identity provider, ticketing system, cloud logs, vulnerability scanner, and supplier register should tell the same story.
Section 4

Run internal audit before certification pressure

Internal audit must test whether the conforms to ISO/IEC 27001 and the organization's own ISMS requirements and is effectively implemented and maintained. Run it at planned intervals as an operating assurance process, not only as document collection before an external audit.

The audit programme must define frequency, methods, responsibilities, planning, and reporting, and consider process importance and previous audit results. ISO/IEC 27001 does not require every Annex A control to be audited in every cycle. Document each audit's criteria and scope, auditor, evidence sampled, results, and report to relevant management.

Use internal audit findings as a rehearsal for the external audit trail: can the team explain why a control was selected, where it operates, what evidence proves it operated, and how exceptions are tracked to closure?

  • Schedule internal audits at planned intervals and update the programme when prior findings, significant changes, or high-risk areas justify deeper sampling.
  • Keep auditor independence credible: avoid assigning someone to audit their own work where practical.
  • Separate observations, nonconformities, improvement opportunities, and evidence requests so owners know what must be corrected.
  • Track finding closure with root cause, corrective action, effectiveness review, and management-review visibility.
Section 5

Close the management review and certification loop

Clause 9.3 requires top management to review the at planned intervals. Inputs include prior actions; relevant changes in context and interested-party needs; trends in nonconformities, corrective actions, monitoring, audit results, and objective fulfilment; interested-party feedback; risk-assessment results; treatment-plan status; and improvement opportunities.

The required output is evidence of decisions about continual-improvement opportunities and any needed changes. Resource, scope, objective, or treatment decisions should be recorded when the review determines they are needed; ISO/IEC 27001 does not require every review to produce each of those decision types.

After the audit, update the evidence register instead of treating the audit report as a separate file. Findings should flow into corrective actions, corrective actions should be checked for effectiveness, and recurring weaknesses should influence the next internal audit programme and management review.

For accredited certification, confirm that the audit baseline is ISO/IEC 27001:2022 with Amendment 1:2024. The IAF transition period for certificates issued to the 2013 edition ended on 31 October 2025; a legacy certificate should not be presented as current ISO/IEC 27001 certification after that deadline.

  • Keep a certification evidence index: scope, policies, risk method, risk results, treatment plan, SoA, control samples, internal audit reports, management-review minutes, and corrective-action log.
  • Before surveillance audits, refresh evidence for changes since the last audit rather than rebuilding the whole pack from scratch.
  • Verify certificate status and accreditation claims through public certification or accreditation registers where applicable.
  • Use findings and near misses to improve the , not only to satisfy the next audit date.
Primary sources

References and citations

iaf.nu
Referenced sections
  • IAF CertSearch describes verification and monitoring of accredited certifications, including status changes such as suspension, withdrawal, and expiry.
"Certified Once, Accepted Everywhere"
iso.org
Referenced sections
  • Clauses 9.3, 10.1, and 10.2 define management-review inputs and outputs, continual improvement, and the required nonconformity and corrective-action process.
"Information security management systems — Requirements"
iso.org
Referenced sections
  • Amendment 1:2024 applies to ISO/IEC 27001:2022 and adds climate-action changes to the management-system context requirements.
"Climate action changes"
iso.org
Referenced sections
  • ISO/IEC 27002 provides the information security control guidance used to interpret and implement Annex A controls.
"Information security controls"
iso.org
Referenced sections
  • ISO/IEC 27005 supports the risk-management side of an ISO/IEC 27001 ISMS, including assessment, treatment, communication, monitoring, and review.
"Guidance on managing information security risks"
iso.org
Referenced sections
  • ISO/IEC 27006-1 describes requirements for bodies that audit and certify ISO/IEC 27001 ISMSs, useful context for certification-audit readiness.
"Requirements for bodies providing audit and certification of information security management systems"
Related guides

Explore more topics

ISO/IEC 27001 Annex A Control Evidence Guide
Build useful ISO/IEC 27001:2022 Annex A control evidence: selected controls, SoA rationale, owners, implementation proof, effectiveness checks, audit records, and improvement actions.
ISO/IEC 27001 Annex A Control Ownership FAQ
How to assign practical owners for ISO/IEC 27001 Annex A controls without confusing control ownership with the standard's required risk-owner accountability.
ISO/IEC 27001 Certification Body Evidence FAQ
What ISO/IEC 27001 certification auditors may sample, how to connect requirements to operating evidence, and what the certification body does not own.
ISO/IEC 27001 Certification Stage Workflow
Plan optional ISO/IEC 27001 certification from scope readiness through Stage 1, Stage 2, findings, certification decision, surveillance, and recertification.
ISO/IEC 27001 Compliance Guide: ISMS Evidence
Build ISO/IEC 27001:2022 conformity evidence for ISMS scope, leadership, risk assessment and treatment, the Statement of Applicability, operations, audits, management review, and corrective action.
ISO/IEC 27001 FAQ: ISMS Scope, Risk and SoA
Practical ISO/IEC 27001 FAQ covering ISMS scope, risk assessment, risk treatment, Statement of Applicability, Annex A controls, certification evidence, audits, management review, and surveillance readiness.
ISO/IEC 27001 Implementation Roadmap Guide
A practical ISO/IEC 27001:2022 roadmap from context and scope through risk treatment, the SoA, control operation, internal audit, management review, corrective action, and optional certification.
ISO/IEC 27001 Internal Audit and Management Review Guide
Keep ISO/IEC 27001 internal audit and management review distinct and connected: independent audit evidence, top-management decisions, corrective actions, resources, and improvement records.
ISO/IEC 27001 Internal Audit FAQ
How should teams run ISO/IEC 27001 internal audits: who should own each step, what evidence is expected, and how findings are resolved.
ISO/IEC 27001 Management Review FAQ
What ISO/IEC 27001 management review must consider, what top management must decide, what evidence to retain, and how to set the cadence.
ISO/IEC 27001 Requirements Guide
Plain-language guide to ISO/IEC 27001:2022 Clauses 4-10: context, leadership, planning, support, operation, performance evaluation, improvement, and Annex A control selection.
ISO/IEC 27001 Risk Acceptance FAQ
How ISO/IEC 27001 risk acceptance works: criteria, risk-owner approval, residual-risk evidence, external obligations, and reassessment triggers.
ISO/IEC 27001 Risk Treatment and Residual Risk Guide
Connect ISO/IEC 27001 risk-treatment choices, necessary controls, the treatment plan, Statement of Applicability, residual-risk acceptance, owners, evidence, and review triggers.
ISO/IEC 27001 Risk Treatment Register Workflow
Build an ISO/IEC 27001 risk-treatment register that links assessed risks to treatment options, controls, SoA entries, actions, owners, residual-risk approval, evidence, and review triggers.
ISO/IEC 27001 SoA Exclusions FAQ
How should teams justify Statement of Applicability exclusions under ISO/IEC 27001? Practical answer with owners, evidence, review triggers, and external source references.
ISO/IEC 27001 SoA: workflow for gathering and documenting control evidence
Operate the ISO/IEC 27001 Statement of Applicability as a live evidence index linking necessary controls, Annex A inclusion and exclusion rationale, implementation status, owners, and proof.
ISO/IEC 27001 Statement of Applicability template: Annex A control selection and justification
Practical ISO/IEC 27001:2022 Statement of Applicability template fields for necessary controls, Annex A applicability, inclusion and exclusion rationale, status, owners, evidence, and review history.
ISO/IEC 27001 Surveillance Audits FAQ
What ISO/IEC 27001 surveillance audits check, how they differ from internal audit and recertification, and what evidence to maintain between audits.
ISO/IEC 27001 vs NIS2 Comparison
Compare voluntary ISO/IEC 27001 ISMS conformity and optional certification with NIS2 legal duties, entity scope, management accountability, incident reporting, supervision, and penalties.
ISO/IEC 27001 vs NIST CSF 2.0 Comparison
Compare ISO/IEC 27001:2022's certifiable ISMS requirements with NIST CSF 2.0's cybersecurity outcomes, Profiles, Tiers, Functions, evidence uses, and adoption choices.
ISO/IEC 27001 vs SOC 2 Comparison
Compare ISO/IEC 27001 certification with SOC 2 examination reports: criteria, scope, assurance period, auditor and certification-body roles, deliverables, evidence reuse, and claim limits.