All resources

Checklist 6 min read August 2026

ISO 27001 Audit-Readiness Checklist

A practical control, evidence and decision tracker for moving from scope to a reviewable ISMS.

For Security, GRC and IT teams preparing an ISO 27001 programme.

An ISO 27001 readiness system moving from scope and risk to evidence and verified closure.

A practical control, evidence and decision tracker for moving from scope to a reviewable ISMS

Use this as a working tracker—not an assertion that ISO 27001 requirements have been met. ISO 27001 readiness depends on your organisation’s scope, risk treatment, Statement of Applicability (SoA), implemented controls, records and assessment context.

The tracker follows this sequence: first establish that a control is documented, then show that it operates, then record and close the gaps that remain. Do not mark an item complete merely because a policy exists.

How to use this tracker

  1. Confirm the ISMS scope before adding tasks.
  2. Turn each material gap into an owner-backed action with a verification method.
  3. Record operating evidence as work happens; do not create an evidence folder at the end.
  4. Use the “decision / exception” field whenever scope, risk treatment or timing requires management judgement.

1. Scope and governance tracker

ItemOwnerEvidence / outputStatusDecision / exception
Define ISMS scope: service, sites, people, systems, data, interfaces and exclusionsISMS owner + leadershipApproved scope statement
Identify interested parties and relevant requirementsCompliance / legalRequirement register
Assign ISMS roles, authorities and reporting pathLeadershipRole map / charter
Establish information-security objectives and measuresSecurity leadershipObjectives, metrics and review cadence
Establish document-control and approval processISMS ownerVersioned document register

2. Risk and treatment tracker

ItemOwnerEvidence / outputStatusDecision / exception
Define risk assessment methodology and acceptance criteriaRisk ownerApproved method
Identify information-security risks in scopeControl / risk ownersRisk register
Assess and prioritise risksRisk owner + relevant SMEsRatings and rationale
Select treatment and relevant controlsISMS ownerTreatment plan
Create and maintain the Statement of ApplicabilityISMS ownerSoA with inclusion/exclusion rationale
Record residual-risk acceptanceAuthorised risk ownerApproval and expiry/review date

3. Control and evidence tracker

Control areaWhat to proveTypical source / evidenceOwnerCadenceStatus
Access managementAccess is authorised, reviewed and adjusted appropriately.IAM exports, approvals, access reviews and remediation tickets.IT / securityDefined control cadence
Asset / information managementRelevant assets and information are identified and handled appropriately.Asset inventory, classification records and owner assignments.IT / data ownersOngoing / periodic
Supplier securitySuppliers are assessed, approved and reviewed according to risk.Vendor register, due diligence, contracts and reassessments.Procurement / securityOnboarding + periodic
Secure change / developmentChanges are controlled and traceable.Tickets, code-review records, testing and deployment links.EngineeringPer change
Vulnerability managementIssues are identified, prioritised and handled.Scan results, tickets, exception and closure records.Security / infrastructureDefined cadence
Incident managementIncidents are detected, handled and learned from.Incident records, decisions, post-incident actions and closure evidence.SecurityEvent-driven
Business continuityRelevant continuity and recovery arrangements are maintained/tested.Plans, test/exercise records and follow-ups.Operations / leadershipDefined cadence
Awareness and policy managementPeople receive relevant guidance and policies remain approved/current.Policy register, approvals, acknowledgement/training records.HR / securityDefined cycle

What good looks like: for each priority control, a reviewer can move from the control to its accountable owner, approved procedure, operating activity and dated record without relying on a verbal explanation.

4. Internal review and corrective-action tracker

ItemOwnerEvidence / outputStatusFollow-up
Plan internal audit/reviewInternal audit / ISMS ownerAudit plan and scope
Conduct review and record findingsIndependent reviewerFindings, evidence and conclusions
Assign corrective actionsAccountable control ownersAction plan, due dates and owners
Verify corrective-action effectivenessReviewer / ISMS ownerClosure evidence
Hold management reviewLeadershipInputs, decisions, resources and actions

5. 90-day readiness sequence

Days 1–30: lock scope, governance, risk method, initial risk register and SoA approach.

Days 31–60: operate priority controls, collect evidence from source systems and close critical design gaps.

Days 61–90: run an internal review, validate evidence, record corrective actions and prepare management review.

Use the final 30 days to prove closure, not to rewrite documents. A closed gap has a named owner, a completed action, supporting evidence and a reviewer’s decision that the result is effective.

Final readiness check

  • Scope and exclusions are explicit and approved.
  • Risk treatment and SoA decisions are traceable.
  • Priority controls have owners, operating evidence and exception paths.
  • Policies match actual practice and have version/approval records.
  • Internal review and management-review evidence are present.
  • Open gaps have owners, dates, risk decisions and verification plans.

See it in your own environment

Ciphrix helps teams build a connected ISO 27001 workspace across scope, risks, controls, evidence and corrective actions—while human experts guide implementation and remain accountable for decisions.

Book a demo to see the approach applied to your actual systems and programme.


Source notes

This tracker synthesises Ciphrix’s published ISO 27001 audit checklist, certification process guide, gap analysis guide, Statement of Applicability guide, risk assessment guide, certification timeline guide and scope definition guide. Use the licensed ISO/IEC 27001 standard, your organisation’s scope and your auditor or certification body to determine actual requirements and evidence expectations.

Get started

Ready to see Ciphrix in action?

Built by AWS Security Leaders | AWS Partner | Certified companies across 3 continents