Back to ISO 27001

ISO 27001 Checklist: Clauses 4 to 10, All 93 Annex A Controls and Audit Prep

Photo: Unsplash

ISO 27001 checklist

ISO/IEC 27001:2022 has two distinct halves, and you are certified against one of them. Most checklists online only cover the other one.

This page covers both: the mandatory management system requirements in Clauses 4 to 10, which is what certification is actually granted against, and the 93 Annex A controls you select from and justify in your Statement of Applicability.

Key takeaways

  • You are certified against Clauses 4 to 10, not against Annex A. Annex A is a catalogue of controls you choose from. A perfect control set with no management system will fail certification.
  • Annex A:2022 contains 93 controls in four themes: Organizational (37), People (8), Physical (14), Technological (34). The 2013 version had 114 across 14 domains, so older checklists will not match your audit.
  • Seven categories of documented information are explicitly required. The Statement of Applicability is the one auditors open first.
  • Certification runs on a three-year cycle: Stage 1, Stage 2, then annual surveillance audits and recertification in year three.

The mistake almost every checklist makes

Search for an ISO 27001 checklist and you will mostly find lists of Annex A controls. That is the wrong starting point.

Annex A is normative but selective. Clause 6.1.3 requires you to compare your chosen controls against Annex A to check you have not missed anything, and to document which ones apply. You can exclude controls, and you can add controls that are not in Annex A at all.

Clauses 4 to 10 are not selective. Every requirement in them applies to every organisation, with no exclusions permitted. An auditor who finds a working control set but no risk assessment methodology, no internal audit programme and no management review will raise major nonconformities and you will not be certified.

Work the clauses first.

Part 1: the mandatory ISMS requirements (Clauses 4 to 10)

Clause 4: Context of the organization

  • Identify internal and external issues relevant to your ISMS
  • Identify interested parties (customers, regulators, staff, investors) and what each requires of you
  • Define and document the ISMS scope, including boundaries and anything excluded, with reasons
  • Establish the ISMS itself

Auditors read the scope statement first and test everything against it. A scope that says "all company operations" when you meant one product line creates work you did not intend.

Clause 5: Leadership

  • Demonstrable top management commitment: resourcing decisions, not a signed statement
  • An approved information security policy, communicated and available
  • Roles, responsibilities and authorities assigned and understood

Clause 6: Planning

This is where most first-time programmes are weakest.

  • A documented risk assessment methodology, consistently applied. Auditors check that the same method produces the same result for two similar risks.
  • A risk register with identified risks, owners, analysis and evaluation against your criteria
  • A risk treatment plan linking each risk to the controls that address it
  • The Statement of Applicability, comparing your controls to Annex A
  • Measurable information security objectives with owners and dates
  • Planning for changes to the ISMS

Clause 7: Support

  • Resources allocated to the ISMS
  • Competence: a matrix showing who needs what skills, plus evidence they have them
  • Awareness across the organisation, not just the security team
  • A communication plan covering what, when, to whom and by whom
  • Control of documented information: version control, approval, access, retention

Clause 8: Operation

  • Operational planning and control, with documented procedures where needed
  • Risk assessments performed at planned intervals and when significant change occurs
  • The risk treatment plan actually executed, with evidence

Clause 9: Performance evaluation

  • Monitoring and measurement: defined metrics, and reporting against them
  • An internal audit programme covering the entire ISMS over a defined period, with reports and findings
  • Management review at planned intervals, covering every input the standard lists, with documented decisions and actions

Missing internal audits and management reviews are the two most common reasons a first certification attempt fails. Both are explicitly required and neither can be produced retroactively.

Clause 10: Improvement

  • Continual improvement of the ISMS
  • Nonconformity and corrective action: a register with root cause analysis, actions, and verification that the action worked

The documents ISO 27001 explicitly requires

Auditors will ask for these by name:

  1. ISMS scope (Clause 4.3)
  2. Information security policy (Clause 5.2)
  3. Risk assessment and risk treatment methodology (Clause 6.1.2)
  4. Statement of Applicability (Clause 6.1.3)
  5. Risk treatment plan (Clause 6.1.3 and 6.2)
  6. Information security objectives (Clause 6.2)
  7. Evidence of competence (Clause 7.2)

Plus records of: monitoring and measurement results, the internal audit programme and its results, management review results, and nonconformities with corrective actions.

Part 2: the Annex A controls (93 across four themes)

The 2022 revision restructured Annex A from 14 domains into four themes. Each control also carries attributes (control type, information security property, cybersecurity concept, operational capability, security domain) that you can use for filtering, though attributes are not themselves auditable requirements.

Theme Controls What it covers Where teams underinvest
A.5 Organizational 37 Policies, roles, asset inventory, classification, access control policy, supplier and cloud security, incident management planning, legal and regulatory requirements, business continuity Supplier chain controls and the legal register
A.6 People 8 Screening, employment terms, awareness and training, disciplinary process, post-employment obligations, NDAs, remote working, event reporting Evidence that training actually completed
A.7 Physical 14 Perimeters, entry controls, monitoring, environmental threats, clear desk, equipment protection, storage media, secure disposal Cloud-only teams assuming these are all not applicable
A.8 Technological 34 Endpoints, privileged access, authentication, malware, vulnerability management, configuration, backup, logging, monitoring, cryptography, secure development, change management, environment separation Logging retention and secure development lifecycle evidence

A note for cloud-native teams: you cannot mark the whole of A.7 not applicable because you have no data centre. Some physical controls still apply to your offices and employee equipment, and for the rest the right answer is usually that the control is applicable and satisfied by your cloud provider, evidenced by their audit report. "Not applicable" and "inherited from provider" are different answers, and auditors treat them differently.

The three areas that generate the most findings in practice:

  • A.5.19 to A.5.23 (supplier and cloud security). A vendor list with no risk tiers, no due diligence and no review dates.
  • A.8.8 (technical vulnerabilities). Scanning happens, but remediation has no SLA and no tracking.
  • A.8.15 and A.8.16 (logging and monitoring). Logs exist but retention is undefined and nobody reviews alerts.

Building the Statement of Applicability

The SoA is the bridge between your risk assessment and Annex A, and it is the single document auditors scrutinise hardest. For each of the 93 controls it records:

  • Whether the control is applicable
  • Justification for inclusion, traceable to a risk in your register or a legal, contractual or regulatory requirement
  • Justification for exclusion, where you have marked it not applicable
  • Implementation status and where the evidence lives

Two rules that save rework:

  1. Every exclusion needs a reason that is not "we are small". Valid exclusions are structural: no in-house software development, so secure coding controls do not apply; no physical data centre of your own.
  2. Every inclusion needs a traceable source. If a control is applicable but no risk in your register points to it, your risk assessment is incomplete.

Our ISO 27001 Statement of Applicability template is a free Excel workbook with all 93 controls, applicability and justification fields, evidence links and a readiness view.

What Stage 1 and Stage 2 auditors actually check

Stage 1: documentation review

Usually one to two days, often remote. The auditor checks your ISMS exists and is coherent on paper:

  • Is the scope defined and sensible?
  • Does the risk methodology exist and has it been applied?
  • Is the SoA complete, with justifications?
  • Are the mandatory documents present and approved?
  • Is there an internal audit programme and a management review scheduled?

Stage 1 findings are not nonconformities. They are a list of things to fix before Stage 2, and the gap between the two stages is typically four to twelve weeks.

Stage 2: implementation audit

Longer, and the real test. The auditor samples evidence to check controls operate as documented:

  • Interviews with control owners, not just the compliance lead. If your CTO cannot describe the change management process, that is a finding.
  • Sampled records: access reviews, change tickets, training completion, supplier reviews, incident records
  • Completed internal audits covering the ISMS, with findings and corrective actions
  • A management review with all required inputs and documented decisions
  • Traceability from risk to treatment to control to evidence

Findings are graded. Minor nonconformities need a corrective action plan. Major nonconformities block certification until they are closed and verified.

After certification

Annual surveillance audits sample a subset of the ISMS, and recertification in year three repeats a full Stage 2. The ISMS has to keep running: the most common surveillance finding is that internal audits and management reviews stopped happening after the certificate arrived.

A realistic certification timeline

For a company starting without a formal ISMS, six to twelve months is typical:

  1. Months 1 to 2: scope, gap analysis, risk methodology, leadership engagement
  2. Months 2 to 5: risk assessment, control implementation, policy set approved, SoA drafted
  3. Months 4 to 6: controls start generating records, internal audit programme begins
  4. Month 6: first internal audit completed, first management review held
  5. Months 6 to 8: Stage 1 audit, then remediation
  6. Months 8 to 12: Stage 2 audit, then certificate issued

You cannot compress steps 3 and 4. An auditor needs records of controls operating and a completed internal audit and management review cycle. That floor is roughly three months of the ISMS genuinely running.

The nonconformities auditors raise most

  1. No internal audit, or an internal audit that only covers part of the ISMS. Clause 9.2 requires the programme to cover everything over time.
  2. Management review missing required inputs. Clause 9.3.2 lists them; auditors check against the list.
  3. A risk assessment done once and never repeated. Clause 8.2 requires planned intervals.
  4. SoA exclusions with no justification, or justifications that amount to inconvenience.
  5. Risk register disconnected from the SoA. Controls applicable for no traceable reason.
  6. Policies approved but not communicated. No acknowledgement records.
  7. Corrective actions closed without root cause or verification. Clause 10.2 requires both.
  8. Scope that does not match reality. The certificate scope excludes a system that clearly processes in-scope data.

How SecureSlate helps

SecureSlate maintains your risk register, Statement of Applicability and control evidence in one place, so the traceability from risk to control to proof is there when an auditor asks for it. Access reviews, supplier reviews and policy acknowledgements run on a schedule, and internal audit and management review cycles are tracked rather than remembered.

Get started for free

Related guides:

FAQ

How many controls are in ISO 27001?
ISO/IEC 27001:2022 Annex A contains 93 controls across four themes: 37 Organizational, 8 People, 14 Physical and 34 Technological. The previous 2013 version had 114 controls in 14 domains. You select which apply and document the decision in your Statement of Applicability.

Do we have to implement all 93 Annex A controls?
No. Annex A is a reference set you compare your controls against. You must consider every control and document whether it applies, but you can exclude controls with a documented justification. What you cannot exclude is any requirement in Clauses 4 to 10.

Is there an official ISO 27001 checklist?
No. ISO publishes the standard itself, which is a paid document, and ISO/IEC 27002 which gives implementation guidance on the Annex A controls. Any checklist, including this one, is an interpretation and not a substitute for the standard.

What is the difference between ISO 27001 and ISO 27002?
ISO 27001 contains the certifiable requirements. ISO 27002 is guidance explaining how to implement the Annex A controls. You are audited against 27001; you read 27002 while implementing.

Can we get certified without an internal audit?
No. A completed internal audit is explicitly required by Clause 9.2 and is one of the first things a Stage 2 auditor asks for. The same applies to management review under Clause 9.3.

How long is an ISO 27001 certificate valid?
Three years, with annual surveillance audits during that period and a full recertification audit before it expires.

Disclaimer (legal note)

This article is for general information only and is not legal, regulatory, or professional advice, and it is not a substitute for the text of ISO/IEC 27001:2022. Requirements are interpreted by your certification body and vary by scope, industry, and jurisdiction. Consult an accredited certification body and qualified advisors for your specific obligations.

Need compliance without the complexity?

SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.

Find compliance gaps in 30 seconds

Keep reading

Jul 7, 2026 · TemplatesISO 27001

ISO 27001 Statement of Applicability Template: Free SoA Excel Download

Jul 5, 2026 · ISO 27001

ISO 27001 Consultant vs Compliance Automation Platform: Which Is Right for You?

Jul 5, 2026 · ISO 27001

ISO 27001 introduction: ISMS basics, certification, and first steps for 2026

View more posts
Jamie
Virtual Agent

Hi! I'm Jamie. Curious about your current compliance challenges and how automation might help your team?