Summary
Good preparation is half the work in an ISO 27001 audit. This article gives you a practical checklist and insider tips from the perspective of a lead auditor, so that your audit becomes a "walk in the park".
What does an auditor expect?
An ISO 27001 auditor assesses whether your Information Security Management System (ISMS) meets the requirements of the standard. Importantly, the auditor does not only look at documentation on paper, but above all at how your system works in practice.
An experienced auditor looks at three things: say what you do (policy and procedures), do what you say (implementation and compliance), and prove that you do it (records and evidence).
The audit checklist
Use this checklist to prepare for your ISO 27001 audit:
1. ISMS Documentation
2. Risk assessment
3. Operational evidence
4. Management involvement
Tips from a lead auditor
Tip 1: Be honest
Do not try to present things as better than they are. Auditors value honesty and quickly see through a facade. If something is not yet in order, show that you have a plan to improve it.
Tip 2: Show that it is alive
An ISMS that consists only of documents is not convincing. Show that staff know the procedures, that risks are actively managed and that your management system is genuinely used in day-to-day practice.
Tip 3: Prepare your staff
Auditors do not only speak to the person responsible for the ISMS. Make sure that other staff also know what the information security policy involves and how they should act in the event of an incident.
Tip 4: Carry out an internal audit
Carry out a thorough internal audit before the external audit. This helps you to identify and resolve weak spots before the external auditor finds them.
Tip 5: Keep your dashboard up to date
Make sure your compliance dashboard is current. A tool such as ComplianceGuard gives you an at-a-glance view of your status and shows the auditor that you are continuously in control.
Common mistakes
- Too much documentation - Better a compact, working system than an excess of policy documents that nobody reads
- Outdated risk assessment - Make sure your risk assessment is no older than 12 months
- No evidence that it works - Log activities, keep records and make sure everything is demonstrable
- Management not involved - ISO 27001 requires demonstrable commitment from the top
- Panic preparation - Do not start only two weeks before the audit. A good ISMS runs all year round
Always audit-ready with ComplianceGuard
ComplianceGuard keeps your ISMS continuously up to date with a clear dashboard, automatic reminders and real-time risk insight. That way you are always ready for the auditor, not only in the weeks beforehand.