What evidence belongs in a certification audit?
Start with evidence that ISO/IEC 27001 itself requires the organization to retain or make available: the ISMS scope, risk-assessment and treatment process and results, information security objectives, operational records needed for confidence, monitoring and measurement results, internal-audit programme and results, management-review results, and nonconformity and corrective-action records.
Then add for the necessary controls identified in the Statement of Applicability. The audit is based on sampling, so an evidence index improves retrieval but does not replace underlying records or guarantee certification.
- Index each record to the certified scope, relevant clause or SoA entry, evidence owner, period, and source system.
- Use normal operating records - tickets, approvals, logs, reviews, tests, reports, and meeting decisions - rather than audit-day reconstructions.
- Keep known gaps and exceptions visible as nonconformities, corrective actions, treatment actions, or accepted risks.
- Example: an access-control policy and review procedure show design; a dated user population, reviewer decision, removed access, exception, and follow-up ticket show operation for the sampled period.
ISO/IEC 27001:2022 identifies documented information required for scope, risk assessment and treatment, objectives, operations, monitoring, internal audit, management review, and corrective action.
ISO/IEC 27002:2022 provides implementation guidance for information security controls that may help explain suitable control-operation evidence.