Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
What evidence does an ISO 27001 auditor request?
Last verifiedAn ISO/IEC 27001 auditor samples mandatory documented information required by Clauses 4–10, then supporting operating records for Annex A controls you marked implemented. This page is not legal advice, does not determine YOUR obligations, does not start a clock, and does not file.
Evidence guide, last verified 10 September 2026. ISO 27001 is a voluntary standard, not a law. Distinguish what the standard requires as documented information from auditor-typical sampling practice. Only an IAF-MLA accredited certification body issues a recognised certificate.
What this page is, and what it is not
Audience: a compliance owner assembling a Stage 2 pack.
This page is not legal advice. It does not determine YOUR obligations, does not start a clock, and does not file evidence with a certification body. Last verified 10 September 2026.
Auditors sample. They do not usually read every ticket in the period. A complete population still has to exist so the sample is defensible.
Mandatory documented information compared with supporting records
The “mandatory” column is the typical documented-information set organisations prepare for Clauses 4–10. Supporting records are what Stage 2 samples for operating effectiveness. Last verified 10 September 2026. Not legal advice.
| Artifact | Clause or control | Mandatory documented information or supporting record | Kind of text |
|---|---|---|---|
| ISMS scope | Clause 4 | Mandatory documented information (typical). | Certification standard. |
| Information security policy | Clause 5 | Mandatory documented information (typical). | Certification standard. |
| Risk assessment and risk treatment | Clause 6 | Mandatory documented information (typical). | Certification standard. |
| Statement of Applicability | Clause 6.1.3 | Mandatory documented information: necessary controls, inclusion justification, any Annex A exclusion justification, implementation status. | Certification standard. |
| Internal-audit results | Clause 9 | Mandatory documented information (typical). | Certification standard. |
| Management review records | Clause 9 | Mandatory documented information (typical). | Certification standard. |
| Corrective actions | Clause 10 | Mandatory documented information (typical). | Certification standard. |
| Access-review exports, change records, logs, supplier assessments | Selected Annex A controls (for example access, change, logging, suppliers) | Supporting / operating records. Auditor-typical sample, not a second SoA. | Mix of certification standard (if the control is in the SoA) and auditor practice. |
Legal requirement, regulatory guidance, best practice, or our recommendation
Do not tell the board that “the auditor always asks for X” as if X were a clause. Last verified 10 September 2026. Not legal advice.
| Statement | Which kind of authority | What it does not mean |
|---|---|---|
| Documented information required by Clauses 4–10. | Certification standard. | Does not list every operating record the auditor may sample. |
| ISO/IEC 17021-1 evidence and sampling expectations for the certification body. | Standard the body is accredited against. | Does not give you a fixed shopping list. |
| ISO/IEC 27002:2022 examples of implementation evidence. | Guidance. | Does not make those examples mandatory documents. |
| Keep a control-to-evidence index with owner and freshness date. | Industry best practice. | Does not substitute for the artifacts. |
| Accept or reject each manual evidence row with a named human and a timestamp. | ShipReady Metrics recommendation. | Does not produce an auditor's opinion or a downloadable evidence binder. |
How sampling usually works
Stage 1 concentrates on whether documented information exists and whether you appear ready. Stage 2 samples operation across the period and across Annex A controls marked implemented. A control excluded in the SoA should not be sampled as implemented — the exclusion itself will be tested for a defensible justification. Last verified 10 September 2026. Not legal advice.
Checklist
This is the checklist artifact for a Stage 2 pack. Last verified 10 September 2026. Not legal advice.
- Can we produce scope, policy, risk records, SoA, internal-audit results, management review, and corrective actions without a scavenger hunt?
- Does the SoA implementation status match the records we can show?
- For each implemented technological control, can we produce a population (not only a screenshot)?
- Have we labelled each artifact as mandatory documented information or supporting record?
- Is the certification body IAF-MLA accredited (ISO/IEC 17021-1 / ISO/IEC 27006)?
- Have we accepted that this page does not file the pack for us?
What to do now
These steps do not start a clock.
- Build a two-tab index: documented information vs supporting records.
- Fix SoA status mismatches before you polish screenshots.
- Read the controls-explained and certification-process pages.
- Read how ShipReady Metrics supports ISO 27001 evidence if you use this product.
- Re-verify sources; last verified 10 September 2026.
Where this shows up in ShipReady Metrics
Only shipped behaviour is described here. ShipReady Metrics does not issue certificates, does not produce an auditor's opinion, and is not a downloadable evidence binder.
If you already have a session: signed-in app → Compliance evidence collection records control-mapped artifacts. Evidence review is the met-verdict overlay. The obligation map, policies library, and cyber risk register store scoping and YOUR documents. Annex A is crosswalked to about 72 canonical controls with a crosswalk-density honesty layer — coverage, not a pass.
ISO 27001 is in the 24-framework library. An accredited certification body still samples the live systems.
Primary sources (last verified 10 September 2026)
ISO/IEC 27001:2022 documented-information requirements (paraphrased). ISO/IEC 27002:2022 as guidance. ISO/IEC 17021-1 for how bodies sample. Not legal advice.