What is the ISO 27001 Audit?
An ISO 27001 audit is a structured, evidence-based review of an organisation’s Information Security Management System, commonly called an ISMS. The auditor checks whether the organisation has designed its ISMS around its real information security risks, whether people follow the agreed processes, and whether the controls achieve their intended results.
The audit does not exist simply to inspect policies or search for mistakes. A good audit tests whether the management system works in practice. It connects leadership decisions, risk assessment, legal and contractual duties, employee competence, technical controls, supplier oversight, incident response, performance monitoring and continual improvement.
ISO/IEC 27001:2022 is the current published edition of the international standard, supported by Amendment 1:2024. ISO describes it as the world’s best-known standard for information security management systems and says it helps organisations establish, implement, maintain and continually improve an ISMS.
For a business seeking certification, the audit provides independent assurance that the ISMS meets the standard within a clearly defined scope. For a business that already holds certification, later audits check whether the system remains effective as risks, technology, staff, suppliers and commercial priorities change.
What an ISO 27001 Auditor Is Really Testing
The auditor wants to understand whether the organisation manages information security as a functioning business discipline. Documents provide part of the evidence, but they do not tell the whole story. The auditor also interviews employees, reviews records, samples completed activities, observes working practices and follows evidence across connected processes.
For example, a policy may state that the organisation reviews user access regularly. The auditor may then ask who owns the review, how often it happens, which systems it covers, what evidence the business retains and what happens when someone identifies inappropriate access. This approach tests implementation and effectiveness rather than the quality of the wording alone.
An auditor normally examines whether the organisation:
- understands its internal and external context;
- identifies relevant interested parties and their requirements;
- defines an appropriate ISMS scope;
- assigns leadership responsibility and authority;
- assesses and treats information security risks;
- selects and justifies controls;
- manages competence, awareness and communication;
- controls documented information;
- operates planned security processes;
- measures performance;
- completes internal audits and management reviews;
- corrects weaknesses and improves the ISMS.
ISO explains that conformity with ISO/IEC 27001 means an organisation has a system for managing risks affecting the security of information it owns or handles. The standard takes a broad approach that brings people, policies and technology together.
An Audit Is Not the Same as a Penetration Test
People sometimes assume that an ISO 27001 auditor will carry out a deep technical attack simulation. That is not the main purpose of the management system audit.
A penetration test examines selected technical assets for exploitable weaknesses. An ISO 27001 audit examines the wider management arrangements that identify risk, choose controls, assign ownership, monitor performance and improve security. Technical evidence may form part of the audit, but the auditor focuses on whether the ISMS manages that work consistently and appropriately.
For example, the auditor may review how the organisation plans security testing, approves its scope, assesses findings, assigns remediation, accepts residual risk and verifies completion. The auditor does not normally replace the specialist who carries out the technical testing.
This distinction matters because a company can pass a technical test on one day and still have weak governance. It can also operate a sound ISMS while retaining some accepted risk. ISO 27001 does not promise perfect security. It requires a disciplined, risk-based management system.
Internal Audit and Certification Audit
ISO 27001 requires the organisation to conduct internal audits at planned intervals. Certification brings a separate external review by an independent certification body.
The Internal Audit
The internal audit checks whether the ISMS conforms to the organisation’s own requirements and to ISO 27001, and whether the business has implemented and maintained it effectively. The organisation must plan an audit programme, define criteria and scope, choose competent auditors, report results and retain evidence.
Internal auditors need enough independence to reach objective findings. In a smaller company, complete separation may prove difficult, but the person should avoid auditing their own work wherever practical. External support can help when the organisation lacks internal competence or impartiality.
The internal audit should happen before the certification assessment because it helps the organisation identify and correct weaknesses. It should not become a rehearsal designed only to predict an external auditor’s questions. Its real value comes from testing whether the system protects the business and meets agreed requirements.
The Certification Audit
An external certification body conducts the certification audit. ISO develops and publishes standards, but ISO does not audit organisations or issue certificates. ISO states that external certification bodies perform certification, while accreditation gives independent recognition that a certification body operates in line with relevant international requirements.
A company should check the certification body’s competence, accreditation status and authorised scope before making an appointment. UK organisations can use UKAS CertCheck to verify UKAS-accredited management system certificates and claims.
Customer and Supplier Audits
A customer may also audit a supplier to assess contractual security obligations or supply-chain risk. This review does not replace an accredited certification audit, although it may use ISO 27001 as part of its criteria.
Supplier audits often focus on the information, services and controls relevant to the commercial relationship. The customer may review access management, incident notification, continuity, subcontractors, data handling and evidence of certification.
Why the Audit Matters to UK Businesses
The audit provides a structured challenge to assumptions. It can reveal that a control exists only on paper, that responsibilities remain unclear or that evidence does not support a management claim. It can also confirm that the organisation has built a reliable and proportionate security system.
The UK Government’s Cyber Security Breaches Survey 2025/2026 found that 43% of businesses identified a cyber breach or attack during the previous 12 months. The figure reached 69% among large businesses, while 29% of businesses that identified attacks experienced them at least once a week.
The same survey found that only 19% of businesses carried out staff training or awareness activity, although the rate reached 84% among large businesses. It also reported that only 15% of businesses formally reviewed risks from their immediate suppliers. These gaps show why an auditor looks beyond technology and examines governance, people and supply-chain processes.
An audit can support customer confidence, tender responses, regulated supply chains and leadership oversight. ISO reported more than 70,000 ISO/IEC 27001 certificates across 150 countries in its 2022 survey, covering every major economic sector.
Setting the Audit Scope
The scope defines the organisational boundaries that the audit will cover. It may include the whole company or a defined service, location, department or operational function. The certificate will refer to that scope, so it must remain accurate, meaningful and not misleading.
A weak scope can undermine the value of certification. For example, a technology provider should not define a narrow administrative scope that excludes the systems, people and services that customers rely upon. The NCSC advises organisations to make the certified scope broad enough to reflect their operations.
The auditor will usually consider:
- business activities and services;
- physical and virtual locations;
- information and supporting assets;
- internal teams and external providers;
- interfaces with excluded areas;
- legal, regulatory and contractual requirements;
- technologies and business processes;
- the statement of applicability;
- dependencies that affect information security outcomes.
The organisation should explain exclusions clearly. A boundary does not remove a dependency from consideration when that dependency can affect the scoped service. For example, a shared human resources process may sit outside the formal scope but still influence screening, joining, role changes and departures.
Audit Criteria, Evidence and Sampling
Audit criteria are the requirements against which the auditor evaluates evidence. They include ISO/IEC 27001 requirements, the organisation’s own policies and procedures, relevant legal or contractual obligations and commitments that the ISMS has adopted.
Evidence needs to be relevant, reliable and traceable. Auditors commonly review:
- risk assessments and treatment plans;
- the statement of applicability;
- policies, procedures and process records;
- information security objectives and measures;
- asset and access records;
- training and competence evidence;
- incident and corrective-action records;
- supplier assessments and agreements;
- monitoring and testing results;
- internal audit reports;
- management review records;
- decisions to accept residual risk.
An auditor uses sampling because reviewing every record, employee, system and transaction would rarely prove practical. Sampling does not mean guesswork. The auditor chooses evidence according to risk, importance, previous findings and the need to test different parts of a process.
This means one clean sample does not always prove a control works consistently. The auditor may select records from different months, teams or services and then follow anomalies. When evidence conflicts, the auditor expands the sample or asks further questions.
Preparing for the First Certification Assessment
Preparation should focus on building and operating the ISMS, not creating a temporary display for an auditor. The organisation needs enough evidence to show that its processes have worked over a meaningful period.
Confirm the Scope and Responsibilities
Leadership should approve the scope and make sure employees understand who owns key ISMS activities. Clear accountability reduces delays during the audit and helps the business answer questions consistently.
Responsibility should cover risk ownership, control operation, internal audit, management review, corrective action, evidence management and communication with the certification body.
Complete the Risk Work
The organisation should have a documented and repeatable method for assessing information security risk. It should identify risks, evaluate them against agreed criteria, decide how to treat them and record any accepted residual exposure.
The treatment plan and statement of applicability need to align. If the organisation selects a control, it should explain why and show how it operates. If it excludes an Annex A control, it should provide a sound justification based on risk and applicable requirements.
Operate the Controls
An auditor needs implementation evidence. Approved policies alone will not demonstrate that access reviews, backups, supplier checks, awareness activity, incident management or vulnerability processes operate effectively.
Teams should retain useful records as work happens. Reconstructing evidence shortly before an audit creates uncertainty and may expose wider control weaknesses.
Conduct the Internal Audit
The internal audit should cover the ISMS requirements and the organisation’s own arrangements. It should generate clear findings, evidence and follow-up actions.
Management should avoid hiding internal findings from the certification auditor. A well-run internal audit that identifies and manages weaknesses demonstrates maturity. An organisation creates greater concern when it has obvious problems but its internal audit reports claim that everything works perfectly.
Hold Management Review
Leadership should review ISMS performance and make decisions about risks, objectives, resources, findings, incidents, changes and improvement opportunities. Minutes should show meaningful discussion and action, not just attendance.
The audit will often test whether leaders understand the main information risks and whether they support the ISMS through decisions and resources.
How the Certification Works
How the Certification Works usually involves an initial assessment in two stages, followed by a certification decision, ongoing surveillance and later recertification.
Stage 1: Readiness and Planning
Stage 1 helps the certification body understand the organisation and assess whether it appears ready for the more detailed review. The auditor commonly examines the scope, key ISMS documents, risk approach, statement of applicability, internal audit, management review and the organisation’s understanding of applicable requirements.
The auditor also gathers information needed to plan Stage 2. This includes the organisation’s activities, locations, complexity, staffing, technology and outsourced processes.
Stage 1 may identify areas that could become nonconformities during Stage 2. The organisation should address these concerns before moving forward. A formal ISO committee document describes Stage 1 as a readiness audit followed by a full Stage 2 audit across the scope.
Stage 2: Implementation and Effectiveness
Stage 2 tests the ISMS in operation. The auditor interviews people, reviews records, samples processes and evaluates whether the organisation meets ISO 27001 requirements and its own commitments.
The review covers mandatory management system requirements and the controls that the organisation has selected through its risk treatment process. The auditor will test whether the statement of applicability reflects actual decisions and whether controls work as described.
Stage 2 usually includes an opening meeting, audit activity across the planned scope, regular communication about progress, a closing meeting and a written report. The audit team presents findings, but the certification body makes the formal certification decision through its own independent process.
Surveillance
Certification does not end after the initial decision. Surveillance audits take place during the certification cycle to check whether the ISMS remains effective and continues to meet requirements.
A surveillance audit normally samples part of the system while always considering essential matters such as internal audit, management review, corrective action, previous findings, complaints, objectives and significant change. Across the cycle, the certification body builds coverage of the whole ISMS.
An ISO committee document describes at least yearly surveillance after initial certification, followed by a full recertification review after the cycle.
Recertification
Recertification takes a broader view of continued conformity and effectiveness before the certificate reaches the end of its cycle. The auditor considers performance across the period, including surveillance results, changes, improvement and whether the scope remains appropriate.
The business should treat recertification as evidence of sustained management, not as a repeat of the first project. Mature organisations can show trends, lessons, risk decisions and measurable improvements.
What Happens During an Audit Day
The auditor starts with an opening meeting. This meeting confirms the plan, scope, communication routes, confidentiality arrangements and practical access to people and evidence.
Audit activity then follows planned process trails. The auditor may start with a risk, trace it to a treatment decision, inspect the selected control, speak with the control owner, review operating evidence and check how the organisation monitors results.
Interviews usually feel conversational. A competent auditor should ask employees to explain what they do in their own words. Staff do not need to memorise clause numbers. They need to understand their responsibilities, follow the relevant process and know how to report a concern.
The auditor may observe physical arrangements, review system outputs, inspect records or watch a process demonstration. The organisation should provide accurate evidence rather than attempting to guide the auditor only towards its strongest areas.
During the closing meeting, the auditor summarises the assessment and explains the findings. The organisation can correct factual misunderstandings, but it should not pressure the auditor to soften a valid finding.
Findings, Nonconformities and Corrective Action
An audit finding compares evidence with a requirement. The auditor may confirm conformity, identify a nonconformity or record an opportunity for improvement according to the certification body’s approach.
A nonconformity means the organisation has not met a requirement. Certification bodies commonly distinguish between major and minor findings, although their procedures define the exact classification.
A major finding may indicate a serious failure, a missing required process or doubt about the ISMS’s ability to achieve intended outcomes. It can prevent certification until the organisation completes acceptable correction and corrective action.
A minor finding usually represents a limited lapse that does not show a complete system failure. The organisation still needs to analyse the cause, correct the issue and prevent recurrence within the required timeframe.
Correction fixes the immediate problem. Corrective action addresses the underlying cause. If a leaver kept access, disabling the account provides correction. Improving the departure workflow, ownership and verification may provide corrective action.
The auditor or certification body will review the response and evidence. Closing an action requires more than changing a document. The organisation should show that it implemented the change and, where appropriate, checked its effectiveness.
Common Reasons Organisations Struggle
Some organisations create too many documents and too little operating evidence. Their policies look polished, but employees do not know the processes or records remain incomplete.
Others define controls without linking them to risk. This makes the statement of applicability difficult to defend and can leave teams unable to explain why a control matters.
Weak internal audits create another problem. A checklist that marks every requirement as compliant without testing evidence gives leadership false confidence and leaves external auditors to discover basic weaknesses.
Businesses also struggle when the scope remains unclear, asset records are incomplete, supplier risk receives little attention or corrective actions stay overdue. Leadership disengagement can affect every part of the ISMS because teams need decisions, priorities and resources.
A final common issue involves trying to hide mistakes. Auditors expect organisations to experience incidents, find weaknesses and make changes. Honest evidence of learning often demonstrates a healthier system than an unrealistic claim that nothing has ever gone wrong.
What is ISO 27001 Certification?
What is ISO 27001 Certification? It is independent written assurance that an organisation’s ISMS meets ISO/IEC 27001 requirements within a defined scope.
Certification applies to the management system, not to every product or service as a separate guarantee. The certificate should identify the organisation, applicable standard, scope, certification body and validity information.
ISO states that certification can reassure customers and interested parties, while accreditation adds confidence in the certification body’s competence. It also makes clear that organisations may implement ISO 27001 without seeking certification.
what is iso 27001
what is iso 27001 is a common search question from organisations that want a straightforward explanation. ISO/IEC 27001 sets requirements for establishing, implementing, maintaining and continually improving an ISMS.
The framework helps an organisation protect confidentiality, integrity and availability by managing risk across people, processes and technology. ISO says the standard supports risk awareness, resilience and operational excellence.
An audit tests whether the organisation has turned those requirements into a functioning management system.
Who needs iso 27001 certification
Who needs iso 27001 certification depends on customer expectations, contracts, sector obligations, information risk and business strategy.
Certification can help technology firms, professional services, healthcare organisations, public-sector suppliers, manufacturers, charities, education providers and any business that handles valuable or sensitive information.
The decision should reflect commercial need and risk rather than company scale alone. A small service provider may process highly sensitive client information or support a critical supply chain, making independent assurance particularly valuable.
ISO 27001 Certification Levels
The phrase ISO 27001 Certification Levels can be misleading because ISO/IEC 27001 does not award bronze, silver or gold grades. An organisation either receives certification for its defined scope or it does not.
A business may use internal maturity stages to manage its programme, but these do not create official ISO 27001 grades. Customers should read the certificate scope and verify its status rather than relying on informal labels.
The audit findings also do not create certification grades. They show whether the organisation meets requirements and what corrective action it needs.
Which UK-based firms offer ISO 27001 consultancy services?
Organisations researching Which UK-based firms offer ISO 27001 consultancy services? should assess practical experience, clarity, platform capability, sector understanding and support across implementation, internal audit preparation and ongoing improvement.
UK Cyber Compliance (a part of UK Cyber Security Group) provides these services and has a platform to make certification much easier and cheaper.
The UK Cyber Compliance website describes an AI-driven platform that supports compliance work, risk management, progress tracking and audit-ready evidence. It also states that users can generate evidence packs, risk reports and statement of applicability records from a central system.
Automation can reduce repetitive administration, flag incomplete work and keep evidence connected to risks and controls. Responsible people still need to review the output, approve decisions and make sure the ISMS reflects the real organisation.
Making the Audit a Business Benefit
The strongest organisations do not view the ISO 27001 audit as a test to survive. They use it as an independent check on whether security governance supports the business.
A well-prepared audit gives leaders better visibility of risk, confirms that responsibilities work and exposes gaps before they lead to greater harm. It can also show customers that the organisation treats information security as an ongoing management commitment.
Success depends on honest evidence, engaged leadership and processes that operate throughout the year. Policies matter, but people, records, decisions and results show whether the ISMS truly works.
When an organisation builds its system around genuine risk and daily operations, the audit becomes far more manageable. It then serves its proper purpose: testing the system, strengthening confidence and helping the business protect information as it grows and changes.
UK Cyber Compliance is here to help
For more information, please do get in touch.
Please check out our Free Cyber Insurance
Other blog posts, Your ISO 27001 Questions Answered, Get ISO 27001 Certified ,
If you would like to know more, do get in touch as we are happy to answer any questions. Looking to improve your cybersecurity but not sure where to start? Begin by getting certified in Cyber Essentials, the UK government’s scheme that covers all the technical controls that will provide the protection that you need to help guard against criminal attacks.

