Summary

Good preparation is half the work in an ISO 27001 audit. This article gives you a practical checklist and insider tips from the perspective of a lead auditor, so that your audit becomes a "walk in the park".

What does an auditor expect?

An ISO 27001 auditor assesses whether your Information Security Management System (ISMS) meets the requirements of the standard. Importantly, the auditor does not only look at documentation on paper, but above all at how your system works in practice.

An experienced auditor looks at three things: say what you do (policy and procedures), do what you say (implementation and compliance), and prove that you do it (records and evidence).

The audit checklist

Use this checklist to prepare for your ISO 27001 audit:

1. ISMS Documentation

☐ The ISMS scope document is current and approved by management
☐ The information security policy is signed and communicated
☐ The Statement of Applicability (SoA) is complete and current
☐ Roles and responsibilities are documented and assigned

2. Risk assessment

☐ The risk assessment has been carried out recently (no older than 12 months)
☐ A risk treatment plan has been drawn up with concrete controls
☐ Risk acceptance criteria have been established and approved
☐ Accepted risks are documented with a rationale

3. Operational evidence

☐ An internal audit has been carried out and the findings have been followed up
☐ A management review has been held and documented
☐ Incidents are recorded and dealt with
☐ Corrective actions are documented and verified
☐ Awareness training has demonstrably taken place

4. Management involvement

☐ Management can explain the information security policy
☐ Budget and resources have been made available
☐ Information security objectives have been established

Tips from a lead auditor

Tip 1: Be honest

Do not try to present things as better than they are. Auditors value honesty and quickly see through a facade. If something is not yet in order, show that you have a plan to improve it.

Tip 2: Show that it is alive

An ISMS that consists only of documents is not convincing. Show that staff know the procedures, that risks are actively managed and that your management system is genuinely used in day-to-day practice.

Tip 3: Prepare your staff

Auditors do not only speak to the person responsible for the ISMS. Make sure that other staff also know what the information security policy involves and how they should act in the event of an incident.

Tip 4: Carry out an internal audit

Carry out a thorough internal audit before the external audit. This helps you to identify and resolve weak spots before the external auditor finds them.

Tip 5: Keep your dashboard up to date

Make sure your compliance dashboard is current. A tool such as ComplianceGuard gives you an at-a-glance view of your status and shows the auditor that you are continuously in control.

Common mistakes

Always audit-ready with ComplianceGuard

ComplianceGuard keeps your ISMS continuously up to date with a clear dashboard, automatic reminders and real-time risk insight. That way you are always ready for the auditor, not only in the weeks beforehand.

Request a demo → Or request an internal audit →

More articles