What evidence is required to pass the ISO 27001 audit?
Passing an ISO 27001 audit requires more than having a folder full of policies. An auditor needs evidence that your Information Security Management System, commonly called an ISMS, operates in practice and that the organisation actively manages information security risk.
There is no single universal evidence pack that every business must provide. The evidence depends on your ISMS scope, risks, selected controls, legal obligations, suppliers, systems and business processes. A small consultancy will not produce exactly the same records as a cloud software provider or managed service provider.
The central principle remains consistent. You need to show what your organisation says it does, demonstrate that people actually do it and provide reliable records that support those claims.
ISO explains that an organisation claiming conformity with a management system standard needs evidence that it meets the requirements, with auditing providing the mechanism for gathering and evaluating that evidence. ISO/IEC 27001 provides the requirements for the ISMS, while accredited certification bodies operate within the management system certification framework.
UK Cyber Compliance helps organisations organise this work through an automated and AI-driven platform. UK Cyber Compliance (a part of UK Cyber Security Group) provides these services and has a platform to make certification much easier and cheaper. The platform brings risk assessment, controls, policies, evidence, actions and audit readiness into one place.
Evidence proves that your ISMS really works
An auditor does not want to see documents created solely for audit day. They want evidence that information security forms part of normal business management.
Consider an access control policy. The policy may state that managers review user permissions regularly. That document shows the organisation has defined a requirement, but it does not prove that reviews take place.
The stronger evidence includes completed access reviews, decisions made during those reviews, records showing permissions removed and evidence that leaver accounts no longer remain active.
The same principle applies across ISO 27001.
A backup policy states what the organisation intends to do. Backup reports and recovery testing show that the process operates.
An incident policy explains reporting expectations. Incident records show whether staff use the process.
A supplier policy defines security requirements. Completed supplier assessments and contractual records show whether the organisation follows those requirements.
The auditor therefore looks for consistency between written requirements, employee behaviour and operational evidence.
What is ISO 27001 Certification?
ISO 27001 certification provides independent assurance that an organisation operates an ISMS that meets ISO/IEC 27001 requirements.
ISO describes ISO/IEC 27001 as the best-known international standard for information security management systems. It gives organisations a structured way to establish, implement, maintain and improve information security while applying risk management to their own circumstances.
The ISMS connects several parts of the business, including:
Information security risk
Leadership
Policies
Responsibilities
People
Suppliers
Technology
Physical security
Legal obligations
Objectives
Control monitoring
Internal audit
Management review
Corrective action
Continual improvement
Certification does not prove that a business will never experience a cyber incident. No credible information security framework can promise that.
Instead, certification demonstrates that the organisation manages information security through a structured system and can produce evidence showing how that system works.
That distinction matters during audit. The auditor does not simply ask whether you have security software. They examine why controls exist, who manages them, how you know they work and what happens when something fails.
what is iso 27001
ISO 27001 is the commonly used name for ISO/IEC 27001, the international requirements standard for information security management systems.
The standard uses a risk-based approach. The organisation identifies information security risks, assesses their significance, determines how to treat them and selects appropriate controls.
ISO explains that the standard allows organisations to adapt risk management to their own structure and operational needs.
This means evidence should reflect your real business.
A small professional firm may rely heavily on evidence relating to cloud security, remote working, staff awareness, client confidentiality, backups and supplier management.
A software company may need substantial evidence relating to secure development, source code access, vulnerability management, testing, logging and change management.
A managed service provider may need evidence around privileged access, monitoring, customer systems, supplier relationships, incident response and administrator activity.
The auditor should be able to trace your evidence back to the risks and controls that matter to your organisation.
Start with evidence of your ISMS scope
Your scope tells the auditor what the ISMS covers.
The scope should identify the organisational boundaries and activities included within certification. It may cover the whole business or a clearly defined service, location, department or operational function.
Useful scope evidence may include:
An approved ISMS scope statement
Organisation charts
Business process information
Network or service diagrams
Office and location information
Cloud service records
Supplier dependencies
Asset information
Service descriptions
Customer-facing processes
An auditor may challenge a scope that appears artificially narrow or ignores dependencies essential to the certified service.
For example, a company may describe its customer platform as being inside scope while excluding the cloud infrastructure, identity service or support team that keeps the platform running.
Your evidence should make the boundary clear and defensible.
Show that you understand your business context
ISO 27001 expects the organisation to understand the internal and external issues relevant to the ISMS.
The business should therefore maintain evidence showing what influences its information security requirements.
This may include:
Business objectives
Customer expectations
Contractual requirements
Technology dependencies
Regulatory responsibilities
Supply chain relationships
Remote working arrangements
Operational priorities
Security threats
Business changes
Interested party records also matter. Customers, employees, regulators, suppliers, directors and other stakeholders may have information security expectations that influence the ISMS.
The auditor may ask how the organisation identified those requirements and how it keeps them current.
A list created three years ago and never reviewed provides weak assurance. Current records connected with real decisions provide much stronger evidence.
Risk assessment evidence sits at the centre
Risk assessment forms one of the most important evidence areas in an ISO 27001 audit.
The organisation should be able to demonstrate how it identifies, analyses, evaluates and reviews information security risk.
Useful evidence includes:
The risk assessment methodology
Likelihood criteria
Impact criteria
Risk acceptance criteria
A current risk register
Named risk owners
Risk assessment workshop records
Review dates
Management decisions
Changes to risk ratings
Links between risks and controls
The method should produce consistent results. Two similar risks should not receive dramatically different ratings simply because different managers assessed them.
The auditor may select a risk from the register and trace it through the entire process.
They may ask why the organisation gave it a particular rating, what controls reduce it, what actions remain open and who accepted the residual exposure.
The evidence needs to support those answers.
Risk treatment needs its own records
Once the organisation evaluates a risk, it needs to decide what to do about it.
Treatment may involve reducing the risk, avoiding the activity, sharing part of the exposure or accepting the remaining risk within agreed criteria.
Evidence may include:
Risk treatment plans
Assigned actions
Control references
Action owners
Target dates
Management approvals
Risk acceptance decisions
Evidence of completed actions
Residual risk reviews
Do not mark planned controls as though they already operate.
If the organisation plans to introduce multi-factor authentication next month, that action does not provide the same risk reduction as a control that already works across all relevant accounts.
Auditors may identify inconsistencies when risk scores assume controls exist but technical or operational evidence shows that implementation remains incomplete.
Your Statement of Applicability is a major audit document
The Statement of Applicability, usually called the SoA, provides a central record of control decisions.
It should identify the controls the organisation has determined are necessary, explain why they apply, show their implementation status and justify exclusions from Annex A.
ISO committee guidance emphasises the relationship between risk treatment and the SoA. The organisation determines necessary controls through risk treatment and uses Annex A as a reference check so that relevant measures are not overlooked.
Useful supporting evidence for the SoA includes:
Risk links
Control ownership
Policies
Procedures
System settings
Reports
Supplier evidence
Operational records
Review activity
The SoA should not contradict the rest of the ISMS.
If it says a control is fully implemented, the auditor should be able to find evidence supporting that statement.
Policies need approval and evidence of use
ISO 27001 requires documented information in several areas, but auditors also expect policies to support real business activity.
Typical evidence may include approved documents covering:
Information security
Access control
Acceptable use
Remote working
Supplier security
Incident management
Backup
Information classification
Asset management
Cryptography
Secure development where relevant
Physical security
Human resources security
Change management
The exact policy set depends on your organisation.
Avoid creating unnecessary documents simply to make the ISMS look substantial. A shorter policy that staff understand and follow usually provides more value than a long document that nobody reads.
Keep approval records and version history. The auditor may ask who authorised the policy, when the business last reviewed it and how staff receive relevant information.
Leadership evidence matters
ISO 27001 places responsibility on leadership rather than allowing the entire ISMS to sit with one technical employee.
Auditors may look for evidence that senior management supports information security and understands the organisation’s key risks.
Useful evidence includes:
Approved security policies
Management review records
Information security objectives
Risk acceptance approvals
Resource decisions
Meeting records
Assigned ISMS responsibilities
Evidence of management involvement in corrective action
Senior management does not need to configure firewalls or investigate every alert.
It does need to show oversight, direction and accountability.
A strong audit trail demonstrates that information security decisions reach the appropriate level of management rather than remaining isolated within IT.
Information security objectives need measurable evidence
ISO 27001 expects the organisation to establish information security objectives.
The strongest objectives connect with business priorities and allow management to measure progress.
Examples may include improving staff security awareness, reducing overdue access reviews, increasing completion of vulnerability remediation or improving incident response performance.
Evidence may include:
Approved objectives
Named owners
Performance measures
Progress reports
Meeting records
Completed actions
Changes made when targets are missed
An auditor may ask how an objective supports the ISMS and how the organisation knows whether it has succeeded.
An objective with no measurement or review activity provides limited evidence.
Staff competence and awareness need records
People form an important part of the ISMS.
The organisation should demonstrate that employees understand information security responsibilities relevant to their roles.
Evidence may include:
Induction records
Security awareness completion records
Role-specific learning
Phishing awareness activity
Policy acknowledgements
Security communications
Competence assessments
Training attendance
Follow-up activity
Records for specialist security roles may need to show deeper competence.
For example, staff managing cloud administration, vulnerability scanning or internal audits may require knowledge beyond general employee awareness.
The auditor may interview employees. Those conversations often reveal whether awareness works in practice.
Staff do not need to memorise ISO clauses. They should understand how to protect information and how to report security concerns.
Joiner, role change and leaver records provide strong proof
Access management often produces some of the clearest operational evidence.
The organisation should be able to show how it manages access through the employee life cycle.
Useful evidence includes:
Access requests
Management approval
New account records
Role-based permissions
Administrator approval
Periodic access reviews
Role change records
Leaver notifications
Account disablement records
Equipment return records
The auditor may select an employee who left recently and ask you to prove when their access ended.
They may choose an administrator and ask why that person needs elevated permissions.
These records help demonstrate that access control works as a process rather than existing only as policy wording.
Asset management evidence shows what you protect
An organisation cannot manage information security effectively if it does not know which assets support its services.
Evidence may include:
Device inventories
Server records
Cloud service inventories
Software records
Information asset registers
Asset owners
Location records
Data classifications
Lifecycle information
Supplier-managed assets
The level of detail should remain useful and manageable.
The asset information should also connect with risk assessment and control decisions. Critical customer information should receive treatment that reflects its sensitivity and business importance.
Supplier evidence has become increasingly important
Modern organisations rely heavily on cloud platforms, managed IT providers, software companies, hosting services, payroll platforms and other external organisations.
Your audit evidence should show how you identify and manage supplier security risk.
Useful evidence includes:
Supplier registers
Supplier risk assessments
Due diligence questionnaires
Contracts
Data processing terms
Security clauses
Certificates or assurance reports
Supplier review records
Service performance reviews
Incident notification requirements
Exit arrangements
A supplier claiming strong security does not remove your organisation’s responsibility to assess the relationship.
The auditor may ask how you determined whether a supplier presents significant risk and what evidence you review over time.
Technical evidence needs to support your control claims
ISO 27001 does not require the same technical evidence from every organisation. The evidence depends on the selected controls and your technology environment.
Common examples include:
Multi-factor authentication reports
Administrator account listings
Security configuration records
Endpoint security dashboards
Vulnerability scan reports
Security update records
Firewall reviews
Cloud configuration reports
Encryption settings
Network diagrams
Monitoring alerts
Event logs
Web filtering evidence
Backup status reports
Recovery test results
Change records
Secure development records
The purpose is not to overwhelm the auditor with screenshots.
Each record should support a claim made elsewhere in the ISMS.
If the SoA says privileged access receives regular review, produce the access review.
If the risk treatment plan says the business reduced ransomware exposure through backups and recovery testing, show those records.
Vulnerability management needs evidence of action
A scan alone does not prove effective vulnerability management.
The organisation should show how it receives vulnerability information, evaluates relevance, prioritises remediation and follows actions through to completion.
Evidence can include:
Scanning reports
Vendor notifications
Security advisories
Remediation tickets
Patch records
Exception approvals
Risk assessments
Follow-up scans
Management escalation for overdue issues
The auditor may select a vulnerability and ask what happened after detection.
A report showing months of unresolved high-risk findings can weaken the organisation’s claim that the control operates effectively.
Backup evidence should include recovery testing
A dashboard showing successful backup jobs provides useful evidence, but it does not prove that the organisation can restore information.
Recovery testing strengthens the evidence considerably.
Keep records showing:
What the organisation backs up
Backup frequency
Retention arrangements
Protection of backup information
Monitoring
Failed job handling
Recovery tests
Test results
Improvement actions
Business requirements should guide the process.
Critical systems may require stronger recovery arrangements than low-impact information.
Incident records demonstrate whether your response process works
Security incidents provide valuable evidence because they show how the ISMS operates under real pressure.
Records may include:
Incident reports
Dates and times
Affected services
Actions taken
Escalation
Management involvement
External notifications
Root cause findings
Lessons learned
Corrective actions
Follow-up reviews
An organisation with no reported incidents should still demonstrate that it has a working reporting and response process.
Testing through exercises can provide evidence when appropriate.
Current UK Government research found that 43 per cent of businesses identified a cyber breach or attack in the previous 12 months, while phishing affected 38 per cent of businesses. Only 25 per cent of businesses had a formal incident response plan. These figures underline the practical value of retaining good incident and response evidence.
Physical security needs evidence too
ISO 27001 does not focus exclusively on digital systems.
Physical controls may require evidence covering offices, secure areas, equipment, storage media and environmental protection.
Useful records can include:
Visitor logs
Door access records
Key registers
Secure area reviews
Office security checks
Clear desk reviews
Equipment maintenance
Media disposal records
Device disposal certificates
Environmental monitoring
Physical security responsibilities
A remote-first organisation may need less office evidence but should still consider home working, staff devices and physical handling of confidential information.
Legal and regulatory evidence supports compliance
The organisation should understand which legal, regulatory and contractual obligations apply to information security.
Evidence may include:
A legal and regulatory register
UK GDPR considerations
Data Protection Act responsibilities
Contract requirements
Confidentiality obligations
Retention requirements
Software licensing obligations
Intellectual property requirements
Customer security clauses
Review records
The organisation should show how it keeps this information current.
A list of laws copied from the internet provides weak evidence if nobody has assessed how those requirements apply to the business.
The auditor wants to see relevance, ownership and action.
Internal audit evidence is essential
Before external certification, the organisation needs to conduct internal audits at planned intervals.
Internal audit checks whether the ISMS conforms to the organisation’s own requirements and ISO 27001 and whether it operates effectively.
Evidence may include:
An internal audit programme
Audit plans
Audit scope
Auditor competence
Audit notes
Findings
Reports
Nonconformities
Corrective actions
Follow-up activity
Independence matters. The person auditing an area should avoid simply approving their own work without meaningful objectivity.
Internal audit provides one of the best opportunities to identify weaknesses before the certification body does.
ISO guidance recognises internal audit as first-party auditing, while third-party audits can support certification.
Management review records are another critical requirement
Management review demonstrates leadership oversight.
Senior managers should review whether the ISMS remains suitable, adequate and effective.
Evidence may include discussion of:
Previous review actions
Changes affecting the ISMS
Risk status
Audit results
Security objectives
Incidents
Control performance
Supplier issues
Resource needs
Improvement opportunities
Corrective actions
Meeting minutes should record decisions rather than merely stating that a meeting happened.
An auditor may ask what management changed because of the review. Good evidence shows that leadership used the information to make decisions.
Corrective action shows that you learn from problems
ISO 27001 does not expect perfection.
Auditors often gain greater confidence from an organisation that identifies problems and manages them properly than from one claiming that nothing ever goes wrong.
Evidence may include:
Nonconformity records
Root cause analysis
Correction activity
Corrective action plans
Named owners
Target dates
Evidence of completion
Effectiveness reviews
Repeated findings deserve particular attention.
If the same issue returns after the organisation closes a corrective action, the auditor may question whether the original response addressed the underlying cause.
Stage 1 evidence focuses heavily on readiness
Initial management system certification follows a two-stage audit approach under the recognised certification framework. UKAS identifies initial Stage 1 and Stage 2 audits within accredited management system certification activity, while ISO/IEC 17021-1 provides the requirements framework for bodies conducting management system certification.
Stage 1 generally focuses on whether the organisation has established the foundations needed for a deeper assessment.
You should expect particular attention around:
ISMS scope
Business context
Risk methodology
Risk assessment
Risk treatment
Statement of Applicability
Policies
Objectives
Internal audit readiness
Management review readiness
Key documented information
The auditor uses Stage 1 findings to understand whether the organisation can proceed effectively to the deeper assessment.
Treat Stage 1 seriously. It provides an opportunity to identify gaps before the auditor tests operational effectiveness more extensively.
Stage 2 needs evidence of operation
Stage 2 moves beyond design and looks much more closely at whether the ISMS works.
The auditor may:
Interview staff
Select control samples
Review system records
Check risk decisions
Inspect supplier evidence
Review access records
Follow incidents
Examine internal audit activity
Inspect corrective actions
Check management review decisions
Review technical reports
Compare written policies with actual practice
This is where audit readiness built into daily operations makes a major difference.
A company that creates documents shortly before the audit may struggle to produce months of operational evidence.
A company that manages its ISMS continuously already has those records.
ISO 27001 Certification Levels
ISO 27001 does not use formal achievement bands such as bronze, silver or gold.
An organisation either meets the requirements for certification within its stated scope or it does not.
Businesses do move through different stages of the certification journey.
They define scope, assess risk, select controls, gather evidence, conduct internal audit, complete management review and undergo external assessment.
After initial certification, the organisation continues operating the ISMS and undergoes further certification activity according to the certification cycle.
Security maturity can continue improving throughout that period.
A mature ISMS usually produces stronger evidence because records arise naturally from business processes rather than from a last-minute audit exercise.
How the Certification Works
The process starts with defining what the ISMS covers.
The organisation then identifies relevant business and stakeholder requirements, carries out information security risk assessment and decides how to treat unacceptable risks.
Controls support the treatment decisions. The organisation compares its control requirements with Annex A and records the resulting position in the Statement of Applicability.
Policies, procedures and technical safeguards then need to operate in practice.
The business gathers evidence while those activities take place.
Internal audit tests the ISMS independently from within the organisation. Management review gives senior leadership an opportunity to evaluate performance and make decisions.
The certification body then completes the external assessment using the recognised management system certification framework. UKAS accredits management system certification bodies in the UK and confirms that ISO/IEC 17021-1 forms part of that framework. UKAS also published updated arrangements for ISO/IEC 27006-1:2024, which sets additional requirements for bodies providing ISMS certification.
Auditors use sampling, so keep evidence available
You cannot predict every record that an auditor will select.
That is why building an artificial audit folder around a few carefully chosen examples creates risk.
Keep normal business records current and accessible.
An auditor might choose:
One employee
One leaver
One supplier
One vulnerability
One incident
One risk
One change
One administrator
One backup test
One corrective action
They may then trace that example across several parts of the ISMS.
For instance, they could choose a cloud supplier, review its risk assessment, inspect the contract, check its SoA links and ask the supplier owner how reviews work.
Good evidence should survive that trace.
Quality matters more than volume
More evidence does not automatically create a stronger audit.
A thousand screenshots stored without context can be harder to use than a smaller number of accurate, current and clearly labelled records.
Strong evidence should be:
Relevant
Current
Traceable
Owned
Consistent
Easy to retrieve
Connected with the appropriate risk or control
Supported by dates where relevant
Clear enough for another person to understand
Avoid duplicate records when one authoritative source already exists.
The aim is to demonstrate control and accountability, not to create administrative clutter.
Who needs iso 27001 certification
ISO 27001 can benefit organisations that handle important information or need to demonstrate structured information security management.
This commonly includes technology providers, software businesses, managed service providers, consultancies, professional services firms, financial organisations, healthcare suppliers, manufacturers, charities and public sector suppliers.
Customer expectations frequently drive certification.
A customer may want evidence that a supplier manages confidential information properly, controls access, manages risk, reviews suppliers and responds to incidents.
Tender requirements and supply chain assurance can also influence the decision.
ISO states that the ISO/IEC 27000 family enables organisations across sectors to manage assets such as financial information, intellectual property, employee information and information entrusted by third parties.
Which UK-based firms offer ISO 27001 consultancy services?
UK organisations can obtain ISO 27001 support from information security consultancies, specialist compliance providers, managed service providers and platform-led compliance services.
UK Cyber Compliance provides ISO 27001 support through an automated and AI-driven platform.
Its current platform describes functionality covering guided risk assessment, control coverage, audit reports, policy generation, real-time progress tracking and central management of certification activity.
A capable consultancy provider should help the organisation understand the standard rather than simply produce documents on its behalf.
Good support should help with:
ISMS scope
Risk assessment
Risk treatment
Statement of Applicability
Policies
Control implementation
Evidence mapping
Internal audit readiness
Management review
Corrective action
External assessment preparation
The organisation should remain able to explain its own ISMS during the audit.
If only the consultant can answer the auditor’s questions, the management system has not become properly embedded within the business.
How UK Cyber Compliance can simplify evidence management
Evidence management becomes difficult when information sits across spreadsheets, shared drives, email messages, cloud dashboards and individual computers.
UK Cyber Compliance provides a central platform that can help organisations track ISO 27001 activity, identify gaps and maintain audit readiness with improved visibility.
The platform can support a clearer relationship between:
Risks
Controls
Policies
Owners
Actions
Evidence
Audit readiness
This connection matters because an auditor rarely examines evidence in isolation.
They want to understand why the control exists, which risk it addresses, who manages it and whether records prove that it works.
Automation can reduce repetitive administration, but management still owns the decisions. Risk owners still need to understand their exposure. Control owners still need to operate controls. Leaders still need to review the ISMS.
A practical evidence checklist before audit
Before your certification assessment, check whether you can quickly produce evidence for the following areas:
The approved ISMS scope
Business context
Interested parties
Legal and contractual requirements
Information security policy
Roles and responsibilities
Risk assessment methodology
Risk register
Risk treatment plan
Risk acceptance decisions
Statement of Applicability
Security objectives
Asset records
Staff awareness
Competence records
User access management
Administrator reviews
Joiner and leaver records
Supplier assessments
Supplier agreements
Incident records
Backup evidence
Recovery testing
Vulnerability management
Security update records
Monitoring and logs
Change management
Physical security
Internal audit programme
Internal audit reports
Management review
Nonconformities
Corrective actions
Continual improvement activity
Not every organisation will produce identical evidence for every control. Your scope, risks and selected measures determine what matters.
The key question remains simple: can you demonstrate that the ISMS operates as described?
Make evidence part of everyday operations
The strongest way to prepare for an ISO 27001 audit is to stop thinking of evidence as something collected for the auditor.
Evidence should come naturally from the way your organisation works.
When someone joins, keep the access approval.
When somebody leaves, record account removal.
When a supplier receives approval, retain the assessment.
When the business identifies a vulnerability, record remediation.
When an incident occurs, record the response and lessons.
When management reviews the ISMS, record decisions.
When an internal audit finds a weakness, track the corrective action.
When a control changes, update the supporting records.
This approach creates an ISMS that remains audit-ready throughout the year.
UK Cyber Compliance supports that model by helping organisations bring risks, controls, policies, actions and evidence together rather than managing them through disconnected records.
To pass the ISO 27001 audit, you do not need a perfect organisation. You need a working ISMS, honest records, clear ownership and reliable evidence that shows the organisation understands its information security risks and manages them consistently.
UK Cyber Compliance is here to help
For more information, please do get in touch.
Please check out our Free Cyber Insurance
Other blog posts, Your ISO 27001 Questions Answered, Get ISO 27001 Certified ,
If you would like to know more, do get in touch as we are happy to answer any questions. Looking to improve your cybersecurity but not sure where to start? Begin by getting certified in Cyber Essentials, the UK government’s scheme that covers all the technical controls that will provide the protection that you need to help guard against criminal attacks.

