← Back to blog

ISO 27001 Audit Prep: Trace SoA, Rehearse Staff, Fix Gaps

October 8, 2026
ISO 27001 Audit Prep: Trace SoA, Rehearse Staff, Fix Gaps

Getting ready for an ISO 27001 audit starts with confirming your ISMS scope, building a single evidence index mapped to Annex A, and running an internal audit or gap assessment before you book Stage 1. This applies whether you are preparing for an internal audit, a certification audit, or a surveillance visit. ISO/IEC 27001 sets the requirements auditors test against, and tools like a cybersecurity gap assessment can speed up the gap-finding stage considerably.


TL;DR:

  • Start evidence collection at least three months before Stage 2, after defining a scope that covers the systems and data clients care about.
  • Link each risk in the register to its treatment, owner, target date, and a specific Statement of Applicability rationale for every excluded control.
  • Stage 1 checks document readiness, while Stage 2 tests operating controls through interviews, observation, and samples of records from recent months.
  • Run an internal audit that tests areas with the greatest risk deeply, then track each finding to closure with an owner, corrective action, and evidence.
  • Plan for annual surveillance after certification and full recertification roughly every three years, maintaining review records and evidence that corrective actions actually closed gaps.

Anvay
Find ISO 27001 Security Gaps
Anvay’s GAPZe assessment helps identify security gaps against frameworks including ISO 27001 and provides a roadmap for improvement.
Explore cybersecurity support

Table of Contents

What an ISO 27001 audit actually assesses

An ISO 27001 audit checks whether your information security management system (ISMS) exists on paper and actually operates as described. Auditors are not grading your policies for style. They are verifying that controls are implemented, monitored, and produce evidence of effectiveness over time.

The ISO/IEC 27001:2022 standard sets the requirements for an ISMS, and certification demonstrates that an organisation can manage information security systematically. Auditors map what they find against two things: the clauses of the standard itself and your Statement of Applicability (SoA), which lists which Annex A controls you have selected or excluded and why.

During an audit, expect requests for:

  • Your information security policy and supporting procedures, current and formally approved.
  • The Statement of Applicability (SoA) with justification for every inclusion and exclusion.
  • Risk treatment plan (RTP) showing how identified risks map to chosen controls.
  • Monitoring records, access logs, and change control history covering the audit period.
  • Incident response records, including any security events logged and how they were closed out.

Clause 9 of the standard, performance evaluation, requires you to monitor, measure, analyse, and evaluate your ISMS, and to run internal audits and management reviews at planned intervals. Auditors will ask to see minutes, metrics, and follow-up actions from these reviews, not just a calendar entry confirming they happened.

Accreditation of your certification body matters more than many organisations realise. ISO/IEC 27006-1:2024 specifies the additional requirements certification bodies must meet to audit and certify ISMS, covering competence, impartiality, and consistency of judgement. A certificate issued by a body accredited under a recognised national scheme, such as UKAS in the United Kingdom, carries more weight with clients, regulators, and partners because the certifying body itself has been independently assessed against these requirements.

Internal audits, certification audits and surveillance: what differs

Three distinct audit types sit inside the ISO 27001 lifecycle, and conflating them is one of the most common planning mistakes.

  1. Internal audits are self-run readiness checks, carried out by your own staff or an independent consultant, designed to find gaps before an external body does.
  2. Certification audits are performed by an accredited certification body and split into Stage 1 (document and readiness review) and Stage 2 (verification that controls operate as described).
  3. Surveillance audits happen annually after certification, with full recertification typically required every three years, to confirm the ISMS remains active and effective.

Stage 1 usually takes a short amount of time and focuses on confirming your SoA, risk assessment, and core documentation are complete enough to proceed. Stage 2 is more intensive, often several days depending on organisation size, and involves interviews, evidence sampling, and direct observation of controls in operation. According to IBM's overview of ISO 27001, surveillance audits then follow on a periodic basis through the certification cycle, each one lighter in scope than the original Stage 2 but still evidence-based.

Strategic preparation: scope, leadership and timeline

Before you touch a single policy document, settle your ISMS scope. Scope defines which systems, locations, departments, and data types fall inside your certification boundary, and it directly determines how much evidence you will need to produce. A scope that is too broad creates unnecessary audit effort; one that is too narrow may fail to cover the systems your clients actually care about.

Leadership commitment is not a box-ticking requirement, it is something auditors actively probe. They will ask management how often they review ISMS performance, what gets escalated to them, and how resourcing decisions get made. Weak or vague answers here are a common source of findings, even when the technical controls themselves are solid.

A realistic preparation timeline for a mid-sized organisation starting from a reasonable security baseline typically runs across these phases:

  • Gap analysis and scope confirmation: establish what exists, what is missing, and where the certification boundary sits.
  • Documentation and control build-out: write or update policies, build the SoA, and implement any missing Annex A controls.
  • Evidence accumulation period: operate the ISMS long enough to generate logs, records, and review minutes that prove it works, not just that it exists.
  • Internal audit and management review: test readiness internally and correct findings before inviting an external auditor.
  • Stage 1 and Stage 2 certification audits: formal external verification.

Assign clear ownership early. A single audit coordinator, usually someone from information security or compliance, should own the evidence index and liaise with process owners across IT, HR, and operations. Without a named owner, evidence requests tend to scatter across inboxes and get lost.

Pro Tip: Start your evidence-accumulation period at least three months before Stage 2, since auditors want to see controls operating over time, not controls switched on the week before the visit.

Getting your documentation and evidence audit-ready

Auditors sample. They will not read every log file or every ticket, but they will pull threads, and if the first few samples look thin or inconsistent, they dig further. The goal of operational preparation is to make every pulled thread lead somewhere solid.

Core documents to keep current and easily retrievable include:

  • Information security policy and the subordinate policies it references (access control, acceptable use, supplier security).
  • Risk assessment methodology, risk register, and risk treatment plan.
  • Statement of Applicability with a rationale column for every control decision.
  • Internal audit programme and schedule, plus reports from completed audits.
  • Management review minutes showing inputs, decisions, and actions.
  • Incident log with classification, response actions, and closure evidence.

Beyond policy documents, auditors sample operational records: training completion logs, access review sign-offs, change control tickets, vulnerability scan results, and backup test records. The pattern they look for is consistency between what the policy says should happen and what the records show actually happened.

Evidence typeWhat auditors checkTypical source
Access reviewsReviews happened on schedule and access was revoked where neededIdentity management system exports
Change controlChanges were approved, tested and documented before deploymentChange management ticketing system
Training recordsStaff completed security awareness training within policy timeframesLearning management system
Incident recordsIncidents were logged, classified and closed with evidenceIncident response log

For remote or hybrid audits, build a sample evidence pack in advance: screenshots, exported logs, and signed-off documents organised by control, so you can share screens or send files quickly without hunting during the audit itself. Keep version control tight. Auditors frequently ask for the previous version of a policy to confirm a change was deliberate and reviewed, so retain superseded versions with dates rather than overwriting them.

Making your risk assessment and SoA audit-defensible

Your risk assessment is the backbone the auditor uses to judge whether your control choices make sense. According to practice guidance from ISO/IEC JTC 1/SC 27, auditors do not mandate a single risk methodology. What they expect is a documented process, criteria applied consistently, and clear traceability from identified risk to the control selected to treat it.

To make this traceable, keep these elements aligned and cross-referenced:

  • A risk register that names each risk, its likelihood and impact rating, and the treatment decision taken.
  • A Statement of Applicability that lists every Annex A control, whether it is included or excluded, and a specific rationale rather than a generic statement.
  • A risk treatment plan showing the actions, owners, and target dates for implementing selected controls.
  • Evidence that the risk assessment is reviewed periodically, not produced once and left static.

Where you exclude a control, write the exclusion rationale in terms the auditor can test, for example "not applicable because the organisation does not develop software in-house," rather than a vague note. Auditors will often cross-check an exclusion against your actual operations, so the rationale needs to hold up.

ISO/IEC 27005 and ISO/IEC 27002 are useful cross-references here: 27005 covers risk management guidance in more depth, and 27002 provides implementation guidance for individual Annex A controls, which helps when writing rationale that needs to show you understood what a control actually requires.

How to plan and run an effective internal audit

A well-run internal audit does most of the heavy lifting before an external auditor ever arrives. Treat it as a dress rehearsal, not a formality.

  1. Plan: define the audit objective, scope, criteria, and who conducts it, then set a schedule covering all relevant clauses and controls across the certification cycle.
  2. Prepare: build a checklist per area, prioritising high-risk or previously flagged controls, and decide your sampling approach so you are not reviewing everything with equal depth.
  3. Conduct: hold an opening meeting with the process owner, collect evidence, interview relevant staff, and observe controls operating rather than relying solely on documents.
  4. Report: structure findings with a severity rating (major nonconformity, minor nonconformity, observation), and link every finding to the specific evidence that supports it.
  5. Follow up: track corrective actions to closure, update the audit schedule, and feed lessons learned into the next cycle.

Sampling rationale matters more than coverage. An auditor, internal or external, would rather see five deeply tested samples from a high-risk area than twenty shallow ones spread thin across low-risk controls.

Pro Tip: Write your internal audit findings exactly as you would want an external auditor's findings written, with the same severity scale and evidence references, so your corrective action process does not need to be relearned later.

Getting your people ready for auditor interviews

Documentation gets you through Stage 1. People get you through Stage 2. Auditors interview process owners directly, and a confident, specific answer backed by a document reference lands very differently from a vague one.

Typical questions probe operational reality: "Walk me through what happens when a new employee joins," or "Show me the last time this control flagged an issue and what you did about it." Staff should be ready to point to a specific record rather than describe the process in the abstract.

  • Run short walkthroughs with each process owner, asking them to narrate their control exactly as an auditor would ask.
  • Use role-play for likely tricky questions, particularly around incidents or exceptions to policy.
  • Coach staff to say "I'm not certain, let me check and confirm" rather than guessing, since an uncertain correct answer later is better than a confident wrong one in the moment.
  • For technical staff, rehearse pulling configuration evidence, change logs, and access records live, since Stage 2 auditors often ask to see this on screen.

Pro Tip: Brief every interviewee on where their evidence lives and how to retrieve it in under a minute, since fumbling for a document mid-interview reads as a gap even when the control itself is sound.

What to expect during Stage 1 and Stage 2 certification audits

Stage 1 is a document-focused review. The auditor checks that your SoA is complete, your risk assessment exists and is coherent, and that you appear ready to proceed to Stage 2. Treat Stage 1 as a formal checkpoint rather than a hurdle, since IBM notes it exists precisely to confirm readiness before the more intensive verification stage begins.

Stage 2 verifies that controls operate in practice. Expect:

  • Interviews with process owners and management across the scoped areas.
  • Direct observation of controls, such as watching an access provisioning process or reviewing a live system configuration.
  • Sampling of records against the time period since your last review, often several months of logs or tickets.
  • For remote or hybrid audits, screen-sharing sessions and pre-shared evidence packs in place of physical site walks.

Logistics matter more than organisations expect. Confirm in advance who the auditor will need access to, how long each session will run, and whether any witness testing (watching a control executed live) is planned. Build in buffer time, since interviews often run long when evidence needs retrieving mid-conversation.

Common nonconformities include incomplete SoA rationale, risk assessments that have not been reviewed since the initial build-out, missing evidence of management review decisions, and gaps between documented procedure and what staff actually describe doing. The immediate response to any finding raised during the audit is to acknowledge it clearly, avoid arguing the point in the room, and commit to a corrective action timeline rather than an on-the-spot fix.

Audit evidence gaps leading to corrective action

Keeping certification: corrective actions and surveillance audits

Certification is not the finish line. Every finding raised, whether in an internal audit or an external one, needs a logged nonconformity, a corrective action plan with an owner and date, and evidence that the fix actually closed the gap, not just that a task was marked complete.

  • Log every nonconformity with its severity, root cause, and the corrective action taken.
  • Keep closure evidence distinct from the original finding record, so an auditor can trace the before-and-after.
  • Use management review and internal audits as the primary engine for showing continual operation, not just annual catch-up exercises.
  • Track KPIs such as time-to-close for corrective actions, incident response times, and training completion rates as ongoing proof the ISMS is active.

Surveillance audits typically occur annually, with full recertification required roughly every three years, according to IBM's description of the certification cycle, each surveillance visit sampling evidence lighter than the original Stage 2 but still expecting proof the ISMS has kept operating, not stalled after the certificate was issued.

How Anvay supports ISO 27001 audit preparation

Preparing for an ISO 27001 audit is largely a gap-finding and evidence-organising exercise, and that is precisely where our GAPZe assessment is built to help. We map your current controls against frameworks including ISO 27001 and Cyber Essentials, producing a clear roadmap of what is missing before you ever book a Stage 1 visit.

Beyond the initial assessment, we offer:

  • GAPZe assessment to benchmark your current controls against ISO 27001 and identify gaps quickly.
  • Cyber Assessments, Compliance & Assurance, and GRC & Risk support to close findings and build audit-ready evidence.
  • Tabletop exercises to rehearse incident response scenarios auditors frequently probe during interviews.
  • Fractional CISO support where you need ongoing leadership presence through the audit cycle rather than a one-off review.

We structure engagements around a simple sequence: assessment first, then a remediation plan, then rehearsal with your team, then support through the certification audit itself. Each stage builds directly on the evidence index and risk traceability work described above, so nothing gets rebuilt twice.

Practical priorities for audit readiness

The organisations that pass ISO 27001 audits smoothly are rarely the ones with the most polished policy documents. They are the ones whose controls visibly operate, day to day, in a way staff can describe without hesitation.

If I had to prioritise three things, I would start with evidence traceability: make sure every control in your SoA links to a real artefact an auditor could pull up in seconds. Second, rehearse people, not just paperwork, since a confident process owner covers for far more than a tidy document ever will. Third, treat your internal audit as the real test, not a formality to clear before the "real" one, because the gaps it finds are the same ones an external auditor will find, just without the pressure of a certification decision riding on them.

Perfect paperwork with no operational evidence behind it is a liability, not a readiness signal.

— Achal

Ready to close your ISO 27001 gaps before the audit

We built our GAPZe assessment specifically for the gap-finding stage of audit preparation, mapping your current controls against ISO 27001 and surfacing exactly what needs attention before you book Stage 1. That means less time guessing where your evidence is thin and more time fixing it.

Anvay

Get in touch to scope your assessment and start building the evidence trail your auditor will actually want to see.

FAQ

How long does ISO 27001 audit preparation usually take?

Preparation length depends on your starting point, but organisations typically move through gap analysis, documentation, evidence accumulation, and internal audit over several months before booking Stage 1. Running a structured gap assessment early helps set a realistic timeline for your specific scope.

What is the difference between Stage 1 and Stage 2 audits?

Stage 1 is a document review confirming your Statement of Applicability, risk assessment, and core policies are complete and coherent, according to IBM's overview of the certification process. Stage 2 is the formal verification stage, where auditors test through interviews, observation, and sampling that controls actually operate as described.

What documents do ISO 27001 auditors ask for most often?

Auditors most commonly request the information security policy, the Statement of Applicability, the risk treatment plan, and records such as access reviews, training logs, and incident reports. Consistency between what the policy states and what the records show is what auditors are really testing.

Does the accreditation of our certification body matter?

Yes, accreditation affects how much market trust your certificate carries, since ISO/IEC 27006-1 sets the competence and impartiality requirements accredited certification bodies must meet. Choosing a body accredited under a recognised national scheme is a reasonable precaution before booking an audit.

What happens after certification is granted?

Certified organisations go through annual surveillance audits and full recertification roughly every three years, with each surveillance visit sampling evidence that the ISMS has kept operating. Logging corrective actions properly and keeping internal audits and management reviews active are the main ways organisations demonstrate continual operation between visits.

Sources

Created using BabyLoveGrowth