Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

What evidence does an ISO 27001 auditor request?

Last verified

An ISO/IEC 27001 auditor samples mandatory documented information required by Clauses 4–10, then supporting operating records for Annex A controls you marked implemented. This page is not legal advice, does not determine YOUR obligations, does not start a clock, and does not file.

Evidence guide, last verified 10 September 2026. ISO 27001 is a voluntary standard, not a law. Distinguish what the standard requires as documented information from auditor-typical sampling practice. Only an IAF-MLA accredited certification body issues a recognised certificate.

What this page is, and what it is not

Audience: a compliance owner assembling a Stage 2 pack.

This page is not legal advice. It does not determine YOUR obligations, does not start a clock, and does not file evidence with a certification body. Last verified 10 September 2026.

Auditors sample. They do not usually read every ticket in the period. A complete population still has to exist so the sample is defensible.

Mandatory documented information compared with supporting records

The “mandatory” column is the typical documented-information set organisations prepare for Clauses 4–10. Supporting records are what Stage 2 samples for operating effectiveness. Last verified 10 September 2026. Not legal advice.

Artifacts an ISO 27001 auditor typically samples (mandate vs practice; not legal advice; last verified 10 September 2026)
ArtifactClause or controlMandatory documented information or supporting recordKind of text
ISMS scopeClause 4Mandatory documented information (typical).Certification standard.
Information security policyClause 5Mandatory documented information (typical).Certification standard.
Risk assessment and risk treatmentClause 6Mandatory documented information (typical).Certification standard.
Statement of ApplicabilityClause 6.1.3Mandatory documented information: necessary controls, inclusion justification, any Annex A exclusion justification, implementation status.Certification standard.
Internal-audit resultsClause 9Mandatory documented information (typical).Certification standard.
Management review recordsClause 9Mandatory documented information (typical).Certification standard.
Corrective actionsClause 10Mandatory documented information (typical).Certification standard.
Access-review exports, change records, logs, supplier assessmentsSelected Annex A controls (for example access, change, logging, suppliers)Supporting / operating records. Auditor-typical sample, not a second SoA.Mix of certification standard (if the control is in the SoA) and auditor practice.

How sampling usually works

Stage 1 concentrates on whether documented information exists and whether you appear ready. Stage 2 samples operation across the period and across Annex A controls marked implemented. A control excluded in the SoA should not be sampled as implemented — the exclusion itself will be tested for a defensible justification. Last verified 10 September 2026. Not legal advice.

Checklist

This is the checklist artifact for a Stage 2 pack. Last verified 10 September 2026. Not legal advice.

  • Can we produce scope, policy, risk records, SoA, internal-audit results, management review, and corrective actions without a scavenger hunt?
  • Does the SoA implementation status match the records we can show?
  • For each implemented technological control, can we produce a population (not only a screenshot)?
  • Have we labelled each artifact as mandatory documented information or supporting record?
  • Is the certification body IAF-MLA accredited (ISO/IEC 17021-1 / ISO/IEC 27006)?
  • Have we accepted that this page does not file the pack for us?

What to do now

These steps do not start a clock.

  • Build a two-tab index: documented information vs supporting records.
  • Fix SoA status mismatches before you polish screenshots.
  • Read the controls-explained and certification-process pages.
  • Read how ShipReady Metrics supports ISO 27001 evidence if you use this product.
  • Re-verify sources; last verified 10 September 2026.

Where this shows up in ShipReady Metrics

Only shipped behaviour is described here. ShipReady Metrics does not issue certificates, does not produce an auditor's opinion, and is not a downloadable evidence binder.

If you already have a session: signed-in app → Compliance evidence collection records control-mapped artifacts. Evidence review is the met-verdict overlay. The obligation map, policies library, and cyber risk register store scoping and YOUR documents. Annex A is crosswalked to about 72 canonical controls with a crosswalk-density honesty layer — coverage, not a pass.

ISO 27001 is in the 24-framework library. An accredited certification body still samples the live systems.

Primary sources (last verified 10 September 2026)

ISO/IEC 27001:2022 documented-information requirements (paraphrased). ISO/IEC 27002:2022 as guidance. ISO/IEC 17021-1 for how bodies sample. Not legal advice.

Frequently asked questions