ISO 27001

ISO 27001 checklist: documents, tasks and audit evidence

For each topic, assign one owner, a location for evidence and a concrete follow-up action.

Use these questions in an initial workshop with management, the coordinator and process owners. Record each topic as in place, partly in place or still to be investigated. Read the ISO 27001 guide and use the roadmap to plan the actions.

1. Have the direction and scope been agreed?

  • What do we want the ISMS to achieve, and who decides?
  • Which services, locations, systems, information and outsourced activities are within scope?
  • Which requirements from customers and other stakeholders are relevant?
  • Who coordinates, who implements and how much time do they have available?

Make the scope and objectives accessible and record responsibilities. Context and boundaries form the basis of the ISMS. ISO describes the scope of the standard.

2. Are risks linked to controls?

  • Which information and processes are we examining, and what could go wrong?
  • Do we use consistent assessment criteria that can be reused in the next assessment?
  • Who owns each risk, and who may accept the residual risk?
  • Have treatment decisions been translated into controls, actions and owners?
  • Is the Statement of Applicability justified, and does it reflect actual implementation?

The risk register, treatment plan and Statement of Applicability should make sense together. Check that changes in one have also been reflected in the others. See the BSI self-assessment on risk treatment.

3. Can day-to-day implementation be demonstrated?

Choose examples from your own processes and ask who can explain how they operate. Possible working questions include:

  • Can we trace a request for access rights, a change and a revocation?
  • Where are the outcomes and follow-up of supplier assessments recorded?
  • Who records an incident and assesses the improvement action?
  • What demonstrates that an agreed recovery test has been carried out?
  • How do staff know which arrangements apply to their role?

4. Which documents and records should you collect?

Create an evidence file overview linking the standard's requirements to existing information. It need not become a collection of new, separate files. A practical structure is:

  • Direction: scope, policies, objectives and responsibilities.
  • Risk decisions: assessment method, results, treatment plan, approvals and Statement of Applicability.
  • Implementation: work instructions and appropriate records from daily operations.
  • Evaluation: measurements, internal audit results and management review.
  • Improvement: findings, causes, actions and checking the outcome.

This structure is an aid to organising your evidence file. Always check the required records against the official standard. The BSI implementation guide describes documentation and evaluation.

5. Are assessment and improvement organised?

Plan internal audits, management review and follow-up of nonconformities. Record who assesses and how objectivity is maintained. For each outstanding finding, identify the cause, the action needed and who will check whether it works.

A completed checklist is not a certificate. The certification body assesses your ISMS independently. ISO explains the role of certification.

Who carries out the actions and what does it cost?

Let the coordinator maintain consistency across the work. Management and process owners provide information, decide on risks and organise implementation. Explicitly allocate their time; a standard or software licence does not automatically provide that capacity.

DCA can support analysis, planning, implementation and audit preparation. Use the pricing calculator to compare internal capacity and support hours. The starting point of 4 support hours per week is not a benchmark for internal effort or a guarantee of a particular completion time.

Budget separately for internal time, software, support, any improvements and audits. The article on ISO 27001 certification costs explains how to compare these items.

Frequently asked questions

Is this checklist sufficient for certification?+

No. It is a preparation aid. The official standard, scope and organisational context determine what the certification body assesses.

Does every topic need a separate document?+

Not necessarily. Make the required information accessible and manageable, and reuse existing records where they are sufficient. Check the detail against the standard.

How many internal hours should I allocate?+

Estimate the time needed for interviews, decisions, implementation, checks and follow-up for each work package. There is no universal number of internal hours; the scope and starting point determine the effort.

Sources for this article

Explore this topic further

Further readingISO 27001 certification: roadmapRead the guide →Further readingISO 27001 certification costsRead the guide →Further readingISO 27001: the standard and our supportRead the guide →

This is general guidance and does not replace an assessment of your situation or the official standard.