Independent certification, inspection and compliance services

Preparing for an ISO/IEC 27001 Audit

Preparation should connect the information-security risk assessment, treatment plan, Statement of Applicability, operating controls and measurable objectives.

Common evidence

  • Risk assessment and treatment records
  • Access, incident, supplier and continuity controls
  • Internal audit and management review
  • Corrective actions and improvement records

Need a technical scope review?

Tell us the standard, country, activities and locations involved.

Contact us →

How to apply this guidance

Use this information to prepare an internal discussion with process owners and responsible managers. Confirm the intended scope, identify applicable obligations, review current records and document any gap that could affect readiness. Assign an owner and target date for each action.

Evidence to prepare

Useful evidence may include policies, process maps, risk assessments, objectives, competence records, operational controls, monitoring results, internal audits, management review and corrective actions. The exact evidence depends on the standard, activities, sites and maturity of the organization.

Request technical clarification

Share the country, standard, sites, activities and target date. Our team can explain the assessment process, required information and next step without designing the management system being evaluated.

WhatsAppRequest a quote