Home | News | What evidence is required to pass the ISO 27001 audit?

News

What evidence is required to pass the ISO 27001 audit?

What Evidence Is Required To Pass The Iso 27001 Audit?

What evidence is required to pass the ISO 27001 audit?

Passing an ISO 27001 audit requires more than having a folder full of policies. An auditor needs evidence that your Information Security Management System, commonly called an ISMS, operates in practice and that the organisation actively manages information security risk.

There is no single universal evidence pack that every business must provide. The evidence depends on your ISMS scope, risks, selected controls, legal obligations, suppliers, systems and business processes. A small consultancy will not produce exactly the same records as a cloud software provider or managed service provider.

The central principle remains consistent. You need to show what your organisation says it does, demonstrate that people actually do it and provide reliable records that support those claims.

ISO explains that an organisation claiming conformity with a management system standard needs evidence that it meets the requirements, with auditing providing the mechanism for gathering and evaluating that evidence. ISO/IEC 27001 provides the requirements for the ISMS, while accredited certification bodies operate within the management system certification framework.

UK Cyber Compliance helps organisations organise this work through an automated and AI-driven platform. UK Cyber Compliance (a part of UK Cyber Security Group) provides these services and has a platform to make certification much easier and cheaper. The platform brings risk assessment, controls, policies, evidence, actions and audit readiness into one place.

Evidence proves that your ISMS really works

An auditor does not want to see documents created solely for audit day. They want evidence that information security forms part of normal business management.

Consider an access control policy. The policy may state that managers review user permissions regularly. That document shows the organisation has defined a requirement, but it does not prove that reviews take place.

The stronger evidence includes completed access reviews, decisions made during those reviews, records showing permissions removed and evidence that leaver accounts no longer remain active.

The same principle applies across ISO 27001.

A backup policy states what the organisation intends to do. Backup reports and recovery testing show that the process operates.

An incident policy explains reporting expectations. Incident records show whether staff use the process.

A supplier policy defines security requirements. Completed supplier assessments and contractual records show whether the organisation follows those requirements.

The auditor therefore looks for consistency between written requirements, employee behaviour and operational evidence.

What is ISO 27001 Certification?

ISO 27001 certification provides independent assurance that an organisation operates an ISMS that meets ISO/IEC 27001 requirements.

ISO describes ISO/IEC 27001 as the best-known international standard for information security management systems. It gives organisations a structured way to establish, implement, maintain and improve information security while applying risk management to their own circumstances.

The ISMS connects several parts of the business, including:

Information security risk

Leadership

Policies

Responsibilities

People

Suppliers

Technology

Physical security

Legal obligations

Objectives

Control monitoring

Internal audit

Management review

Corrective action

Continual improvement

Certification does not prove that a business will never experience a cyber incident. No credible information security framework can promise that.

Instead, certification demonstrates that the organisation manages information security through a structured system and can produce evidence showing how that system works.

That distinction matters during audit. The auditor does not simply ask whether you have security software. They examine why controls exist, who manages them, how you know they work and what happens when something fails.

what is iso 27001

ISO 27001 is the commonly used name for ISO/IEC 27001, the international requirements standard for information security management systems.

The standard uses a risk-based approach. The organisation identifies information security risks, assesses their significance, determines how to treat them and selects appropriate controls.

ISO explains that the standard allows organisations to adapt risk management to their own structure and operational needs.

This means evidence should reflect your real business.

A small professional firm may rely heavily on evidence relating to cloud security, remote working, staff awareness, client confidentiality, backups and supplier management.

A software company may need substantial evidence relating to secure development, source code access, vulnerability management, testing, logging and change management.

A managed service provider may need evidence around privileged access, monitoring, customer systems, supplier relationships, incident response and administrator activity.

The auditor should be able to trace your evidence back to the risks and controls that matter to your organisation.

Start with evidence of your ISMS scope

Your scope tells the auditor what the ISMS covers.

The scope should identify the organisational boundaries and activities included within certification. It may cover the whole business or a clearly defined service, location, department or operational function.

Useful scope evidence may include:

An approved ISMS scope statement

Organisation charts

Business process information

Network or service diagrams

Office and location information

Cloud service records

Supplier dependencies

Asset information

Service descriptions

Customer-facing processes

An auditor may challenge a scope that appears artificially narrow or ignores dependencies essential to the certified service.

For example, a company may describe its customer platform as being inside scope while excluding the cloud infrastructure, identity service or support team that keeps the platform running.

Your evidence should make the boundary clear and defensible.

Show that you understand your business context

ISO 27001 expects the organisation to understand the internal and external issues relevant to the ISMS.

The business should therefore maintain evidence showing what influences its information security requirements.

This may include:

Business objectives

Customer expectations

Contractual requirements

Technology dependencies

Regulatory responsibilities

Supply chain relationships

Remote working arrangements

Operational priorities

Security threats

Business changes

Interested party records also matter. Customers, employees, regulators, suppliers, directors and other stakeholders may have information security expectations that influence the ISMS.

The auditor may ask how the organisation identified those requirements and how it keeps them current.

A list created three years ago and never reviewed provides weak assurance. Current records connected with real decisions provide much stronger evidence.

Risk assessment evidence sits at the centre

Risk assessment forms one of the most important evidence areas in an ISO 27001 audit.

The organisation should be able to demonstrate how it identifies, analyses, evaluates and reviews information security risk.

Useful evidence includes:

The risk assessment methodology

Likelihood criteria

Impact criteria

Risk acceptance criteria

A current risk register

Named risk owners

Risk assessment workshop records

Review dates

Management decisions

Changes to risk ratings

Links between risks and controls

The method should produce consistent results. Two similar risks should not receive dramatically different ratings simply because different managers assessed them.

The auditor may select a risk from the register and trace it through the entire process.

They may ask why the organisation gave it a particular rating, what controls reduce it, what actions remain open and who accepted the residual exposure.

The evidence needs to support those answers.

Risk treatment needs its own records

Once the organisation evaluates a risk, it needs to decide what to do about it.

Treatment may involve reducing the risk, avoiding the activity, sharing part of the exposure or accepting the remaining risk within agreed criteria.

Evidence may include:

Risk treatment plans

Assigned actions

Control references

Action owners

Target dates

Management approvals

Risk acceptance decisions

Evidence of completed actions

Residual risk reviews

Do not mark planned controls as though they already operate.

If the organisation plans to introduce multi-factor authentication next month, that action does not provide the same risk reduction as a control that already works across all relevant accounts.

Auditors may identify inconsistencies when risk scores assume controls exist but technical or operational evidence shows that implementation remains incomplete.

Your Statement of Applicability is a major audit document

The Statement of Applicability, usually called the SoA, provides a central record of control decisions.

It should identify the controls the organisation has determined are necessary, explain why they apply, show their implementation status and justify exclusions from Annex A.

ISO committee guidance emphasises the relationship between risk treatment and the SoA. The organisation determines necessary controls through risk treatment and uses Annex A as a reference check so that relevant measures are not overlooked.

Useful supporting evidence for the SoA includes:

Risk links

Control ownership

Policies

Procedures

System settings

Reports

Supplier evidence

Operational records

Review activity

The SoA should not contradict the rest of the ISMS.

If it says a control is fully implemented, the auditor should be able to find evidence supporting that statement.

Policies need approval and evidence of use

ISO 27001 requires documented information in several areas, but auditors also expect policies to support real business activity.

Typical evidence may include approved documents covering:

Information security

Access control

Acceptable use

Remote working

Supplier security

Incident management

Backup

Information classification

Asset management

Cryptography

Secure development where relevant

Physical security

Human resources security

Change management

The exact policy set depends on your organisation.

Avoid creating unnecessary documents simply to make the ISMS look substantial. A shorter policy that staff understand and follow usually provides more value than a long document that nobody reads.

Keep approval records and version history. The auditor may ask who authorised the policy, when the business last reviewed it and how staff receive relevant information.

Leadership evidence matters

ISO 27001 places responsibility on leadership rather than allowing the entire ISMS to sit with one technical employee.

Auditors may look for evidence that senior management supports information security and understands the organisation’s key risks.

Useful evidence includes:

Approved security policies

Management review records

Information security objectives

Risk acceptance approvals

Resource decisions

Meeting records

Assigned ISMS responsibilities

Evidence of management involvement in corrective action

Senior management does not need to configure firewalls or investigate every alert.

It does need to show oversight, direction and accountability.

A strong audit trail demonstrates that information security decisions reach the appropriate level of management rather than remaining isolated within IT.

Information security objectives need measurable evidence

ISO 27001 expects the organisation to establish information security objectives.

The strongest objectives connect with business priorities and allow management to measure progress.

Examples may include improving staff security awareness, reducing overdue access reviews, increasing completion of vulnerability remediation or improving incident response performance.

Evidence may include:

Approved objectives

Named owners

Performance measures

Progress reports

Meeting records

Completed actions

Changes made when targets are missed

An auditor may ask how an objective supports the ISMS and how the organisation knows whether it has succeeded.

An objective with no measurement or review activity provides limited evidence.

Staff competence and awareness need records

People form an important part of the ISMS.

The organisation should demonstrate that employees understand information security responsibilities relevant to their roles.

Evidence may include:

Induction records

Security awareness completion records

Role-specific learning

Phishing awareness activity

Policy acknowledgements

Security communications

Competence assessments

Training attendance

Follow-up activity

Records for specialist security roles may need to show deeper competence.

For example, staff managing cloud administration, vulnerability scanning or internal audits may require knowledge beyond general employee awareness.

The auditor may interview employees. Those conversations often reveal whether awareness works in practice.

Staff do not need to memorise ISO clauses. They should understand how to protect information and how to report security concerns.

Joiner, role change and leaver records provide strong proof

Access management often produces some of the clearest operational evidence.

The organisation should be able to show how it manages access through the employee life cycle.

Useful evidence includes:

Access requests

Management approval

New account records

Role-based permissions

Administrator approval

Periodic access reviews

Role change records

Leaver notifications

Account disablement records

Equipment return records

The auditor may select an employee who left recently and ask you to prove when their access ended.

They may choose an administrator and ask why that person needs elevated permissions.

These records help demonstrate that access control works as a process rather than existing only as policy wording.

Asset management evidence shows what you protect

An organisation cannot manage information security effectively if it does not know which assets support its services.

Evidence may include:

Device inventories

Server records

Cloud service inventories

Software records

Information asset registers

Asset owners

Location records

Data classifications

Lifecycle information

Supplier-managed assets

The level of detail should remain useful and manageable.

The asset information should also connect with risk assessment and control decisions. Critical customer information should receive treatment that reflects its sensitivity and business importance.

Supplier evidence has become increasingly important

Modern organisations rely heavily on cloud platforms, managed IT providers, software companies, hosting services, payroll platforms and other external organisations.

Your audit evidence should show how you identify and manage supplier security risk.

Useful evidence includes:

Supplier registers

Supplier risk assessments

Due diligence questionnaires

Contracts

Data processing terms

Security clauses

Certificates or assurance reports

Supplier review records

Service performance reviews

Incident notification requirements

Exit arrangements

A supplier claiming strong security does not remove your organisation’s responsibility to assess the relationship.

The auditor may ask how you determined whether a supplier presents significant risk and what evidence you review over time.

Technical evidence needs to support your control claims

ISO 27001 does not require the same technical evidence from every organisation. The evidence depends on the selected controls and your technology environment.

Common examples include:

Multi-factor authentication reports

Administrator account listings

Security configuration records

Endpoint security dashboards

Vulnerability scan reports

Security update records

Firewall reviews

Cloud configuration reports

Encryption settings

Network diagrams

Monitoring alerts

Event logs

Web filtering evidence

Backup status reports

Recovery test results

Change records

Secure development records

The purpose is not to overwhelm the auditor with screenshots.

Each record should support a claim made elsewhere in the ISMS.

If the SoA says privileged access receives regular review, produce the access review.

If the risk treatment plan says the business reduced ransomware exposure through backups and recovery testing, show those records.

Vulnerability management needs evidence of action

A scan alone does not prove effective vulnerability management.

The organisation should show how it receives vulnerability information, evaluates relevance, prioritises remediation and follows actions through to completion.

Evidence can include:

Scanning reports

Vendor notifications

Security advisories

Remediation tickets

Patch records

Exception approvals

Risk assessments

Follow-up scans

Management escalation for overdue issues

The auditor may select a vulnerability and ask what happened after detection.

A report showing months of unresolved high-risk findings can weaken the organisation’s claim that the control operates effectively.

Backup evidence should include recovery testing

A dashboard showing successful backup jobs provides useful evidence, but it does not prove that the organisation can restore information.

Recovery testing strengthens the evidence considerably.

Keep records showing:

What the organisation backs up

Backup frequency

Retention arrangements

Protection of backup information

Monitoring

Failed job handling

Recovery tests

Test results

Improvement actions

Business requirements should guide the process.

Critical systems may require stronger recovery arrangements than low-impact information.

Incident records demonstrate whether your response process works

Security incidents provide valuable evidence because they show how the ISMS operates under real pressure.

Records may include:

Incident reports

Dates and times

Affected services

Actions taken

Escalation

Management involvement

External notifications

Root cause findings

Lessons learned

Corrective actions

Follow-up reviews

An organisation with no reported incidents should still demonstrate that it has a working reporting and response process.

Testing through exercises can provide evidence when appropriate.

Current UK Government research found that 43 per cent of businesses identified a cyber breach or attack in the previous 12 months, while phishing affected 38 per cent of businesses. Only 25 per cent of businesses had a formal incident response plan. These figures underline the practical value of retaining good incident and response evidence.

Physical security needs evidence too

ISO 27001 does not focus exclusively on digital systems.

Physical controls may require evidence covering offices, secure areas, equipment, storage media and environmental protection.

Useful records can include:

Visitor logs

Door access records

Key registers

Secure area reviews

Office security checks

Clear desk reviews

Equipment maintenance

Media disposal records

Device disposal certificates

Environmental monitoring

Physical security responsibilities

A remote-first organisation may need less office evidence but should still consider home working, staff devices and physical handling of confidential information.

Legal and regulatory evidence supports compliance

The organisation should understand which legal, regulatory and contractual obligations apply to information security.

Evidence may include:

A legal and regulatory register

UK GDPR considerations

Data Protection Act responsibilities

Contract requirements

Confidentiality obligations

Retention requirements

Software licensing obligations

Intellectual property requirements

Customer security clauses

Review records

The organisation should show how it keeps this information current.

A list of laws copied from the internet provides weak evidence if nobody has assessed how those requirements apply to the business.

The auditor wants to see relevance, ownership and action.

Internal audit evidence is essential

Before external certification, the organisation needs to conduct internal audits at planned intervals.

Internal audit checks whether the ISMS conforms to the organisation’s own requirements and ISO 27001 and whether it operates effectively.

Evidence may include:

An internal audit programme

Audit plans

Audit scope

Auditor competence

Audit notes

Findings

Reports

Nonconformities

Corrective actions

Follow-up activity

Independence matters. The person auditing an area should avoid simply approving their own work without meaningful objectivity.

Internal audit provides one of the best opportunities to identify weaknesses before the certification body does.

ISO guidance recognises internal audit as first-party auditing, while third-party audits can support certification.

Management review records are another critical requirement

Management review demonstrates leadership oversight.

Senior managers should review whether the ISMS remains suitable, adequate and effective.

Evidence may include discussion of:

Previous review actions

Changes affecting the ISMS

Risk status

Audit results

Security objectives

Incidents

Control performance

Supplier issues

Resource needs

Improvement opportunities

Corrective actions

Meeting minutes should record decisions rather than merely stating that a meeting happened.

An auditor may ask what management changed because of the review. Good evidence shows that leadership used the information to make decisions.

Corrective action shows that you learn from problems

ISO 27001 does not expect perfection.

Auditors often gain greater confidence from an organisation that identifies problems and manages them properly than from one claiming that nothing ever goes wrong.

Evidence may include:

Nonconformity records

Root cause analysis

Correction activity

Corrective action plans

Named owners

Target dates

Evidence of completion

Effectiveness reviews

Repeated findings deserve particular attention.

If the same issue returns after the organisation closes a corrective action, the auditor may question whether the original response addressed the underlying cause.

Stage 1 evidence focuses heavily on readiness

Initial management system certification follows a two-stage audit approach under the recognised certification framework. UKAS identifies initial Stage 1 and Stage 2 audits within accredited management system certification activity, while ISO/IEC 17021-1 provides the requirements framework for bodies conducting management system certification.

Stage 1 generally focuses on whether the organisation has established the foundations needed for a deeper assessment.

You should expect particular attention around:

ISMS scope

Business context

Risk methodology

Risk assessment

Risk treatment

Statement of Applicability

Policies

Objectives

Internal audit readiness

Management review readiness

Key documented information

The auditor uses Stage 1 findings to understand whether the organisation can proceed effectively to the deeper assessment.

Treat Stage 1 seriously. It provides an opportunity to identify gaps before the auditor tests operational effectiveness more extensively.

Stage 2 needs evidence of operation

Stage 2 moves beyond design and looks much more closely at whether the ISMS works.

The auditor may:

Interview staff

Select control samples

Review system records

Check risk decisions

Inspect supplier evidence

Review access records

Follow incidents

Examine internal audit activity

Inspect corrective actions

Check management review decisions

Review technical reports

Compare written policies with actual practice

This is where audit readiness built into daily operations makes a major difference.

A company that creates documents shortly before the audit may struggle to produce months of operational evidence.

A company that manages its ISMS continuously already has those records.

ISO 27001 Certification Levels

ISO 27001 does not use formal achievement bands such as bronze, silver or gold.

An organisation either meets the requirements for certification within its stated scope or it does not.

Businesses do move through different stages of the certification journey.

They define scope, assess risk, select controls, gather evidence, conduct internal audit, complete management review and undergo external assessment.

After initial certification, the organisation continues operating the ISMS and undergoes further certification activity according to the certification cycle.

Security maturity can continue improving throughout that period.

A mature ISMS usually produces stronger evidence because records arise naturally from business processes rather than from a last-minute audit exercise.

How the Certification Works

The process starts with defining what the ISMS covers.

The organisation then identifies relevant business and stakeholder requirements, carries out information security risk assessment and decides how to treat unacceptable risks.

Controls support the treatment decisions. The organisation compares its control requirements with Annex A and records the resulting position in the Statement of Applicability.

Policies, procedures and technical safeguards then need to operate in practice.

The business gathers evidence while those activities take place.

Internal audit tests the ISMS independently from within the organisation. Management review gives senior leadership an opportunity to evaluate performance and make decisions.

The certification body then completes the external assessment using the recognised management system certification framework. UKAS accredits management system certification bodies in the UK and confirms that ISO/IEC 17021-1 forms part of that framework. UKAS also published updated arrangements for ISO/IEC 27006-1:2024, which sets additional requirements for bodies providing ISMS certification.

Auditors use sampling, so keep evidence available

You cannot predict every record that an auditor will select.

That is why building an artificial audit folder around a few carefully chosen examples creates risk.

Keep normal business records current and accessible.

An auditor might choose:

One employee

One leaver

One supplier

One vulnerability

One incident

One risk

One change

One administrator

One backup test

One corrective action

They may then trace that example across several parts of the ISMS.

For instance, they could choose a cloud supplier, review its risk assessment, inspect the contract, check its SoA links and ask the supplier owner how reviews work.

Good evidence should survive that trace.

Quality matters more than volume

More evidence does not automatically create a stronger audit.

A thousand screenshots stored without context can be harder to use than a smaller number of accurate, current and clearly labelled records.

Strong evidence should be:

Relevant

Current

Traceable

Owned

Consistent

Easy to retrieve

Connected with the appropriate risk or control

Supported by dates where relevant

Clear enough for another person to understand

Avoid duplicate records when one authoritative source already exists.

The aim is to demonstrate control and accountability, not to create administrative clutter.

Who needs iso 27001 certification

ISO 27001 can benefit organisations that handle important information or need to demonstrate structured information security management.

This commonly includes technology providers, software businesses, managed service providers, consultancies, professional services firms, financial organisations, healthcare suppliers, manufacturers, charities and public sector suppliers.

Customer expectations frequently drive certification.

A customer may want evidence that a supplier manages confidential information properly, controls access, manages risk, reviews suppliers and responds to incidents.

Tender requirements and supply chain assurance can also influence the decision.

ISO states that the ISO/IEC 27000 family enables organisations across sectors to manage assets such as financial information, intellectual property, employee information and information entrusted by third parties.

Which UK-based firms offer ISO 27001 consultancy services?

UK organisations can obtain ISO 27001 support from information security consultancies, specialist compliance providers, managed service providers and platform-led compliance services.

UK Cyber Compliance provides ISO 27001 support through an automated and AI-driven platform.

Its current platform describes functionality covering guided risk assessment, control coverage, audit reports, policy generation, real-time progress tracking and central management of certification activity.

A capable consultancy provider should help the organisation understand the standard rather than simply produce documents on its behalf.

Good support should help with:

ISMS scope

Risk assessment

Risk treatment

Statement of Applicability

Policies

Control implementation

Evidence mapping

Internal audit readiness

Management review

Corrective action

External assessment preparation

The organisation should remain able to explain its own ISMS during the audit.

If only the consultant can answer the auditor’s questions, the management system has not become properly embedded within the business.

How UK Cyber Compliance can simplify evidence management

Evidence management becomes difficult when information sits across spreadsheets, shared drives, email messages, cloud dashboards and individual computers.

UK Cyber Compliance provides a central platform that can help organisations track ISO 27001 activity, identify gaps and maintain audit readiness with improved visibility.

The platform can support a clearer relationship between:

Risks

Controls

Policies

Owners

Actions

Evidence

Audit readiness

This connection matters because an auditor rarely examines evidence in isolation.

They want to understand why the control exists, which risk it addresses, who manages it and whether records prove that it works.

Automation can reduce repetitive administration, but management still owns the decisions. Risk owners still need to understand their exposure. Control owners still need to operate controls. Leaders still need to review the ISMS.

A practical evidence checklist before audit

Before your certification assessment, check whether you can quickly produce evidence for the following areas:

The approved ISMS scope

Business context

Interested parties

Legal and contractual requirements

Information security policy

Roles and responsibilities

Risk assessment methodology

Risk register

Risk treatment plan

Risk acceptance decisions

Statement of Applicability

Security objectives

Asset records

Staff awareness

Competence records

User access management

Administrator reviews

Joiner and leaver records

Supplier assessments

Supplier agreements

Incident records

Backup evidence

Recovery testing

Vulnerability management

Security update records

Monitoring and logs

Change management

Physical security

Internal audit programme

Internal audit reports

Management review

Nonconformities

Corrective actions

Continual improvement activity

Not every organisation will produce identical evidence for every control. Your scope, risks and selected measures determine what matters.

The key question remains simple: can you demonstrate that the ISMS operates as described?

Make evidence part of everyday operations

The strongest way to prepare for an ISO 27001 audit is to stop thinking of evidence as something collected for the auditor.

Evidence should come naturally from the way your organisation works.

When someone joins, keep the access approval.

When somebody leaves, record account removal.

When a supplier receives approval, retain the assessment.

When the business identifies a vulnerability, record remediation.

When an incident occurs, record the response and lessons.

When management reviews the ISMS, record decisions.

When an internal audit finds a weakness, track the corrective action.

When a control changes, update the supporting records.

This approach creates an ISMS that remains audit-ready throughout the year.

UK Cyber Compliance supports that model by helping organisations bring risks, controls, policies, actions and evidence together rather than managing them through disconnected records.

To pass the ISO 27001 audit, you do not need a perfect organisation. You need a working ISMS, honest records, clear ownership and reliable evidence that shows the organisation understands its information security risks and manages them consistently.

UK Cyber Compliance is here to help

For more information, please do get in touch.

Please check out our Free Cyber Insurance

Other blog posts, Your ISO 27001 Questions AnsweredGet ISO 27001 Certified ,

If you would like to know more, do get in touch as we are happy to answer any questions. Looking to improve your cybersecurity but not sure where to start? Begin by getting certified in Cyber Essentials, the UK government’s scheme that covers all the technical controls that will provide the protection that you need to help guard against criminal attacks.