Skip to main content
All articles

Audit Readiness

ISO 27001 Readiness Checklist: Scope, Risk Assessment, and Evidence

By RiskSensai6 min read
Editorial archive date
First published
Facts checked

The archive date places this article in the editorial collection. It is not an original publication date. Guidance reflects the fact-check date above.

ISO 27001 Readiness Checklist: Scope, Risk Assessment, and Evidence: original RiskSensai editorial cover

Begin with the management system

ISO/IEC 27001:2022 concerns an information security management system, or ISMS, using a risk-based approach.1 Preparation therefore involves how your organization makes, operates and reviews security decisions, not just a collection of technical settings.

The current preparation baseline should consider the 2022 standard and its 2024 climate-action amendment.2 The SOC 2 versus ISO 27001 comparison can help explain why the selected output matters. Confirm the applicable edition and assessment expectations with your certification body and advisers. This article is an original readiness guide; it does not reproduce the licensed standard or replace its requirements.

1. Write a scope a reader can understand

Name the activities, locations, systems, people, information and interfaces included in the ISMS. Explain outsourced responsibilities and boundaries. Avoid a vague scope such as “all information” if the actual preparation covers only one service.

Ask whether the scope would make sense to customers and staff. If a shared administrative system supports both included and excluded activities, record the dependency rather than hide it behind the boundary.

For a fictional consultancy, an initial scope might cover delivery of managed client reports, its staff document environment and relevant support providers. Its separate training events might be outside scope, while their use of the same identity system remains an interface to consider.

2. Understand context and interested parties

Identify the business objectives, material dependencies and expectations relevant to information security. Record applicable obligations and commitments with an owner for interpretation. Do not treat every customer questionnaire sentence as an automatically applicable requirement.

BSI's current self-assessment resource includes context, risk treatment, selected controls and performance-evaluation topics.3 Use those as prompts for your own analysis, rather than copying a generic answer into the ISMS.

For the climate amendment, assess relevance to the organization's context and interested-party requirements. Do not invent a universal environmental control set or assume relevance without examining the actual operation.

3. Assign leadership and operating responsibilities

Identify who owns the ISMS, who approves objectives and who can authorize risk acceptance. Assign individual owners to important processes and make their authority clear.

Include resources and competence. A named owner without time or access cannot maintain the system. Staff need to understand the responsibilities relevant to their work, and external providers need clear interfaces and escalation arrangements.

Set practical objectives that can be evaluated. “Improve security” is a direction; a defined outcome with an owner, measurement and review point is easier to manage. Do not promise arbitrary response times or control frequencies merely to make the document sound stronger.

4. Establish a repeatable risk process

Define how risks are identified, analyzed, evaluated and accepted. The business risk assessment guide provides a general method to adapt to the ISMS scope. State scope, consequence dimensions, assessment horizon and the evidence or assumptions behind estimates. Owners should be able to explain why an important scenario received its rating.

Choose acceptance criteria and authority before the team confronts a difficult decision. Separate current exposure from the intended future position after treatments. Record uncertainty as part of the assessment, rather than turn missing information into an artificially favorable result.

Revisit the assessment after material change, not just at a calendar deadline. A new provider, service commitment or region can alter the assumptions used for earlier decisions.

5. Connect treatment decisions to selected controls

A risk-treatment plan explains the response, owner, required work and completion evidence. A Statement of Applicability, commonly shortened to SoA, records selected controls and the rationale for their applicability and implementation position.3

Do not treat the SoA as a list of boxes that must all be checked identically. The decisions should follow the scope, risk analysis and applicable requirements, with proper consideration of the standard's reference controls. Confirm the precise required content against the licensed standard.

For each selected control, identify its design, responsible performer and retained evidence. Keep justified exclusions visible and ensure they are not simply a way to avoid an inconvenient requirement.

6. Gather evidence of operation

Readiness questionPossible supporting record
Is access handled according to the approved process?Relevant provisioning, review and removal records
Are changes managed within scope?Change decisions, implementation and exception records
Are important providers reviewed?Scoped assessment and acceptance decisions
Are recovery assumptions checked?Authorized exercise results and identified gaps
Are responsibilities understood?Relevant communication and competence records
Are problems addressed?Corrective actions, cause analysis and verification

These are examples, not a substitute for a scoped evidence request. A policy explains intent; an operational record helps show what happened. Preserve versions, dates, populations and exceptions so reviewers can understand coverage.

Use approved access and retention arrangements. Evidence collection should not create a new unprotected copy of sensitive staff or customer information.

Worked example: a management-review package

This fictional consultancy prepares its first focused leadership review. The ISMS owner assembles a short package rather than a presentation full of green percentages.

ItemWhat leadership receivesDecision required
ScopeCurrent boundary and a proposed new supplierConfirm whether the change affects scope
RiskAn unresolved recovery dependencyFund treatment or decide on interim acceptance
EvidenceOne successful exercise with limited coverageApprove further checking of excluded records
Internal reviewAccess-process exceptions and their causesAgree owners, dates and escalation
ObjectivesActual measurements and missing dataRevise measurement work without hiding gaps

The review records decisions and assigned actions. It does not state that the company is certified. An internal discussion is one part of the management system, not the external certification decision.

7. Plan internal evaluation and corrective action

Arrange suitable internal checking with objectivity and competence. A person reviewing their own design should not imply independent assurance. Record the evaluation criteria, scope, procedures, evidence and limitations.

When an issue is found, distinguish immediate correction from action addressing its cause. Verify whether the response worked and retain the result. A new policy or closed task is not automatically sufficient evidence of effectiveness.

Bring relevant evaluation results, changed circumstances and resource needs into management review. The ISMS should show a cycle of decisions, operation, evaluation and improvement.

8. Discuss external assessment readiness

ISO does not itself issue certificates; certification is provided by external bodies.4 Evaluate the body's suitability, scope, accreditation arrangements where relevant and assessment process before entering an engagement.

Request a scoped explanation of the assessment sequence, management responsibilities and recurring work. Do not infer a universal timeline, cost or certificate outcome from a checklist or software score.

If a customer needs a particular certificate scope, confirm that need before committing to the assessment. A certificate for a limited activity should not be marketed as covering unrelated services.

A compact readiness handoff

Prepare the scope and context record, ownership map, risk-method description, risk and treatment records, selected-control rationale, relevant policies and operational evidence. Add internal-evaluation results, corrective actions and management decisions, with missing items stated plainly.

That package makes a professional readiness discussion more productive. Its value is in the supportable relationships between decisions and operation, not in the number of documents or a claim that every risk has disappeared.

Sources and references

  1. ISO. ISO/IEC 27001:2022 - Information security management systems (2022). Official overview of the ISMS requirements standard and its risk-based approach; the full standard is separately licensed. ↩

  2. ISO. ISO/IEC 27001:2022/Amd 1:2024 - Climate action changes (2024-02-23). Official catalog records the published amendment applying to the 2022 ISMS standard. ↩

  3. British Standards Institution. Information Security Management System ISO/IEC 27001 Self-assessment checklist (2025). Provider-issued checklist identifies risk treatment, Statement of Applicability and management-system review topics; it does not replace the licensed standard. ↩ ↩2

  4. ISO. Certification. Explains third-party certification and that ISO itself does not issue certificates. ↩

General educational information, not legal advice, a professional audit opinion, certification, or a guarantee. Applicability and conclusions depend on your organization and should be assessed by an appropriately qualified professional.

Prepared with AI assistance and automated editorial checks. This does not indicate independent professional review or verification of your organization.

  • ISO 27001
  • ISMS
  • Readiness
Connecting to your conversation workspace…