FAQGlobalISO/IEC 27001

ISO/IEC 27001 FAQ Certification Body Evidence

What evidence should an organization prepare for an ISO/IEC 27001 certification-body audit?

Certification bodies sample the defined ISMS and its operation; prepare traceable records, not an artificial folder of documents created only for the audit.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Questions
4

Structured answer sets in this page tree.

Primary sources
5

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Prepare current documented information and normal operating records that show whether the scoped ISMS conforms to ISO/IEC 27001 and is effectively implemented and maintained. Include the required management-system records and evidence for sampled necessary controls. The evaluates evidence and makes its certification decision; it does not design controls, approve residual risk, or operate the ISMS.

Search this module

Find a question or answer quickly

4 of 4 questions
Question 1

What evidence belongs in a certification audit?

Start with evidence that ISO/IEC 27001 itself requires the organization to retain or make available: the ISMS scope, risk-assessment and treatment process and results, information security objectives, operational records needed for confidence, monitoring and measurement results, internal-audit programme and results, management-review results, and nonconformity and corrective-action records.

Then add for the necessary controls identified in the Statement of Applicability. The audit is based on sampling, so an evidence index improves retrieval but does not replace underlying records or guarantee certification.

  • Index each record to the certified scope, relevant clause or SoA entry, evidence owner, period, and source system.
  • Use normal operating records - tickets, approvals, logs, reviews, tests, reports, and meeting decisions - rather than audit-day reconstructions.
  • Keep known gaps and exceptions visible as nonconformities, corrective actions, treatment actions, or accepted risks.
  • Example: an access-control policy and review procedure show design; a dated user population, reviewer decision, removed access, exception, and follow-up ticket show operation for the sampled period.
Citations
ISO/IEC 27001:2022 standard page

ISO/IEC 27001:2022 identifies documented information required for scope, risk assessment and treatment, objectives, operations, monitoring, internal audit, management review, and corrective action.

ISO/IEC 27002:2022 standard page

ISO/IEC 27002:2022 provides implementation guidance for information security controls that may help explain suitable control-operation evidence.

Question 2

How should evidence show design and operation?

explains how the ISMS is meant to work: policy, scope, roles, criteria, procedures, SoA rationales, treatment plans, and control designs. shows that those arrangements actually ran during the relevant period and that results were evaluated.

A policy can support a design claim but does not prove that an access review occurred, a recovery test succeeded, a supplier was reviewed, or a corrective action was effective. Match the evidence to the claim and audited period. Protect secrets and personal data by agreeing secure access, live demonstration, or proportionate redaction with the rather than withholding evidence without explanation. The auditor still needs enough verifiable information to reach a conclusion.

  • For selected controls, retain implementation descriptions and dated samples from the systems where the control operates.
  • For performance evaluation, retain the measure, method, result, analysis, evaluator, and resulting decision.
  • For findings, retain the nonconformity, cause evaluation, correction, corrective action, and effectiveness result.
  • Do not set one evidence-retention period for every record unless another requirement supports it. Use legal, contractual, operational, certification-cycle, and internal record-control needs to set and document retention.
Citations
Question 3

Who owns the evidence and who decides certification?

The organization owns its ISMS and evidence. Process owners, control owners, risk owners, internal auditors, and top management each retain their ISO/IEC 27001 responsibilities; an external auditor should not be written into those operating roles.

The audits the ISMS and makes the certification decision under the applicable scheme. ISO/IEC 27006-1:2024 adds ISMS-specific requirements for bodies that audit and certify against ISO/IEC 27001 and complements ISO/IEC 17021-1. is a separate assessment of the certification body's competence for the relevant activity and scope.

  • Assign every evidence family to the internal owner responsible for its accuracy and retention.
  • Do not ask the to approve operational risk or design controls on the organization's behalf.
  • When relying on an accredited certificate, verify both the certificate and the 's relevant rather than treating either name alone as proof.
  • Treat consultancy and certification as separate activities. ISO/IEC 17021-1 and ISO/IEC 27006-1 place impartiality requirements on the ; the organization must still make and own its ISMS decisions.
Citations
ISO/IEC 27006-1:2024 standard page

ISO/IEC 27006-1:2024 specifies additional requirements for bodies that audit and certify ISMSs against ISO/IEC 27001, including competence, consistency, and impartiality context.

Question 4

When should the certification evidence pack change?

Update evidence through normal ISMS operation, not only before an external audit. Planned monitoring, risk reassessment, internal audit, management review, and corrective action continuously create or change the records on which certification relies.

Significant changes to scope, products, services, locations, suppliers, technology, risks, controls, or legal and contractual requirements should trigger review of the linked risk treatment, SoA, , and certification-body notification obligations. The exact external notification and audit process comes from the certification arrangement, not from this checklist.

  • Keep evidence periods and retention rules visible so samples can be traced to the audited cycle.
  • Refresh the index when owners, repositories, control implementations, or scope change.
  • Raise unresolved inconsistencies before audit; do not conceal them in a polished evidence folder.
Citations
ISO/IEC 27001:2022 standard page

ISO/IEC 27001:2022 requires planned monitoring, risk reassessment after significant change, internal audit, management review, and corrective action, all of which create or update audit evidence.

Primary sources

References and citations

iso.org
Referenced sections
  • Official ISO source for the general competence, consistency, and impartiality requirements applying to bodies that audit and certify management systems.
iso.org
Referenced sections
  • ISO/IEC 27001:2022 requires planned monitoring, risk reassessment after significant change, internal audit, management review, and corrective action, all of which create or update audit evidence.
"Information security management systems — Requirements"
iso.org
Referenced sections
  • ISO/IEC 27002:2022 provides guidance for maintaining control implementations as their context changes.
"Information security controls"
iso.org
Referenced sections
  • ISO/IEC 27005:2022 provides guidance on risk treatment and monitoring that can inform risk and control evidence.
"Guidance on managing information security risks"
iso.org
Referenced sections
  • ISO/IEC 27006-1:2024 specifies additional requirements for bodies that audit and certify ISMSs against ISO/IEC 27001, including competence, consistency, and impartiality context.
"Requirements for bodies providing audit and certification"
Related guides

Explore more topics

ISO/IEC 27001 Annex A Control Evidence Guide
Build useful ISO/IEC 27001:2022 Annex A control evidence: selected controls, SoA rationale, owners, implementation proof, effectiveness checks, audit records, and improvement actions.
ISO/IEC 27001 Annex A Control Ownership FAQ
How to assign practical owners for ISO/IEC 27001 Annex A controls without confusing control ownership with the standard's required risk-owner accountability.
ISO/IEC 27001 Audit Readiness Guide
Prepare ISO/IEC 27001 audit evidence across ISMS scope, risk assessment, risk treatment, Statement of Applicability, Annex A controls, internal audit, management review, and corrective actions.
ISO/IEC 27001 Certification Stage Workflow
Plan optional ISO/IEC 27001 certification from scope readiness through Stage 1, Stage 2, findings, certification decision, surveillance, and recertification.
ISO/IEC 27001 Compliance Guide: ISMS Evidence
Build ISO/IEC 27001:2022 conformity evidence for ISMS scope, leadership, risk assessment and treatment, the Statement of Applicability, operations, audits, management review, and corrective action.
ISO/IEC 27001 FAQ: ISMS Scope, Risk and SoA
Practical ISO/IEC 27001 FAQ covering ISMS scope, risk assessment, risk treatment, Statement of Applicability, Annex A controls, certification evidence, audits, management review, and surveillance readiness.
ISO/IEC 27001 Implementation Roadmap Guide
A practical ISO/IEC 27001:2022 roadmap from context and scope through risk treatment, the SoA, control operation, internal audit, management review, corrective action, and optional certification.
ISO/IEC 27001 Internal Audit and Management Review Guide
Keep ISO/IEC 27001 internal audit and management review distinct and connected: independent audit evidence, top-management decisions, corrective actions, resources, and improvement records.
ISO/IEC 27001 Internal Audit FAQ
How should teams run ISO/IEC 27001 internal audits: who should own each step, what evidence is expected, and how findings are resolved.
ISO/IEC 27001 Management Review FAQ
What ISO/IEC 27001 management review must consider, what top management must decide, what evidence to retain, and how to set the cadence.
ISO/IEC 27001 Requirements Guide
Plain-language guide to ISO/IEC 27001:2022 Clauses 4-10: context, leadership, planning, support, operation, performance evaluation, improvement, and Annex A control selection.
ISO/IEC 27001 Risk Acceptance FAQ
How ISO/IEC 27001 risk acceptance works: criteria, risk-owner approval, residual-risk evidence, external obligations, and reassessment triggers.
ISO/IEC 27001 Risk Treatment and Residual Risk Guide
Connect ISO/IEC 27001 risk-treatment choices, necessary controls, the treatment plan, Statement of Applicability, residual-risk acceptance, owners, evidence, and review triggers.
ISO/IEC 27001 Risk Treatment Register Workflow
Build an ISO/IEC 27001 risk-treatment register that links assessed risks to treatment options, controls, SoA entries, actions, owners, residual-risk approval, evidence, and review triggers.
ISO/IEC 27001 SoA Exclusions FAQ
How should teams justify Statement of Applicability exclusions under ISO/IEC 27001? Practical answer with owners, evidence, review triggers, and external source references.
ISO/IEC 27001 SoA: workflow for gathering and documenting control evidence
Operate the ISO/IEC 27001 Statement of Applicability as a live evidence index linking necessary controls, Annex A inclusion and exclusion rationale, implementation status, owners, and proof.
ISO/IEC 27001 Statement of Applicability template: Annex A control selection and justification
Practical ISO/IEC 27001:2022 Statement of Applicability template fields for necessary controls, Annex A applicability, inclusion and exclusion rationale, status, owners, evidence, and review history.
ISO/IEC 27001 Surveillance Audits FAQ
What ISO/IEC 27001 surveillance audits check, how they differ from internal audit and recertification, and what evidence to maintain between audits.
ISO/IEC 27001 vs NIS2 Comparison
Compare voluntary ISO/IEC 27001 ISMS conformity and optional certification with NIS2 legal duties, entity scope, management accountability, incident reporting, supervision, and penalties.
ISO/IEC 27001 vs NIST CSF 2.0 Comparison
Compare ISO/IEC 27001:2022's certifiable ISMS requirements with NIST CSF 2.0's cybersecurity outcomes, Profiles, Tiers, Functions, evidence uses, and adoption choices.
ISO/IEC 27001 vs SOC 2 Comparison
Compare ISO/IEC 27001 certification with SOC 2 examination reports: criteria, scope, assurance period, auditor and certification-body roles, deliverables, evidence reuse, and claim limits.