Use these questions in an initial workshop with management, the coordinator and process owners. Record each topic as in place, partly in place or still to be investigated. Read the ISO 27001 guide and use the roadmap to plan the actions.
1. Have the direction and scope been agreed?
- What do we want the ISMS to achieve, and who decides?
- Which services, locations, systems, information and outsourced activities are within scope?
- Which requirements from customers and other stakeholders are relevant?
- Who coordinates, who implements and how much time do they have available?
Make the scope and objectives accessible and record responsibilities. Context and boundaries form the basis of the ISMS. ISO describes the scope of the standard.
2. Are risks linked to controls?
- Which information and processes are we examining, and what could go wrong?
- Do we use consistent assessment criteria that can be reused in the next assessment?
- Who owns each risk, and who may accept the residual risk?
- Have treatment decisions been translated into controls, actions and owners?
- Is the Statement of Applicability justified, and does it reflect actual implementation?
The risk register, treatment plan and Statement of Applicability should make sense together. Check that changes in one have also been reflected in the others. See the BSI self-assessment on risk treatment.
3. Can day-to-day implementation be demonstrated?
Choose examples from your own processes and ask who can explain how they operate. Possible working questions include:
- Can we trace a request for access rights, a change and a revocation?
- Where are the outcomes and follow-up of supplier assessments recorded?
- Who records an incident and assesses the improvement action?
- What demonstrates that an agreed recovery test has been carried out?
- How do staff know which arrangements apply to their role?
4. Which documents and records should you collect?
Create an evidence file overview linking the standard's requirements to existing information. It need not become a collection of new, separate files. A practical structure is:
- Direction: scope, policies, objectives and responsibilities.
- Risk decisions: assessment method, results, treatment plan, approvals and Statement of Applicability.
- Implementation: work instructions and appropriate records from daily operations.
- Evaluation: measurements, internal audit results and management review.
- Improvement: findings, causes, actions and checking the outcome.
This structure is an aid to organising your evidence file. Always check the required records against the official standard. The BSI implementation guide describes documentation and evaluation.
5. Are assessment and improvement organised?
Plan internal audits, management review and follow-up of nonconformities. Record who assesses and how objectivity is maintained. For each outstanding finding, identify the cause, the action needed and who will check whether it works.
A completed checklist is not a certificate. The certification body assesses your ISMS independently. ISO explains the role of certification.
Who carries out the actions and what does it cost?
Let the coordinator maintain consistency across the work. Management and process owners provide information, decide on risks and organise implementation. Explicitly allocate their time; a standard or software licence does not automatically provide that capacity.
DCA can support analysis, planning, implementation and audit preparation. Use the pricing calculator to compare internal capacity and support hours. The starting point of 4 support hours per week is not a benchmark for internal effort or a guarantee of a particular completion time.
Budget separately for internal time, software, support, any improvements and audits. The article on ISO 27001 certification costs explains how to compare these items.
Frequently asked questions
Is this checklist sufficient for certification?+
No. It is a preparation aid. The official standard, scope and organisational context determine what the certification body assesses.
Does every topic need a separate document?+
Not necessarily. Make the required information accessible and manageable, and reuse existing records where they are sufficient. Check the detail against the standard.
How many internal hours should I allocate?+
Estimate the time needed for interviews, decisions, implementation, checks and follow-up for each work package. There is no universal number of internal hours; the scope and starting point determine the effort.
Sources for this article
- ISO: ISO/IEC 27001:2022Accessed on 19 September 2026
- BSI: ISMS self-assessmentAccessed on 19 September 2026
- BSI: ISO/IEC 27001:2022 implementation guideAccessed on 19 September 2026
- ISO: independent certificationAccessed on 19 September 2026
Explore this topic further
This is general guidance and does not replace an assessment of your situation or the official standard.

