Skip to content

Evidence request lists

ISO 27005

Evidence request list. 26 controls, 26 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Communication

9.1
Risk communication and consultation

Communicate and consult with internal and external stakeholders on risk throughout the process.

Artefacts an auditor will ask for
  • Communication plan
  • Stakeholder briefings
  • Committee minutes
  • Awareness materials
Where this commonly fails
  • No external comms
  • Briefings irregular
  • Plan unwritten

ISO 27005: Risk Assessment

ISO27005-06
Risk identification methods

Risk identification methods. Control from ISO 27005 framework, domain: ISO 27005: Risk Assessment.

Artefacts an auditor will ask for
  • Risk register
  • Risk assessment methodology
  • Scenario library
  • Heat map
Where this commonly fails
  • Scenarios too generic
  • Criteria not calibrated
  • Interdependencies overlooked
ISO27005-07
Risk analysis and evaluation

Risk analysis and evaluation. Control from ISO 27005 framework, domain: ISO 27005: Risk Assessment.

Artefacts an auditor will ask for
  • Risk register
  • Risk assessment methodology
  • Scenario library
  • Heat map
Where this commonly fails
  • Scenarios too generic
  • Criteria not calibrated
  • Interdependencies overlooked
ISO27005-08
Risk criteria and thresholds

Risk criteria and thresholds. Control from ISO 27005 framework, domain: ISO 27005: Risk Assessment.

Artefacts an auditor will ask for
  • Risk register
  • Risk assessment methodology
  • Scenario library
  • Heat map
Where this commonly fails
  • Scenarios too generic
  • Criteria not calibrated
  • Interdependencies overlooked
ISO27005-09
Risk scenario development

Risk scenario development. Control from ISO 27005 framework, domain: ISO 27005: Risk Assessment.

Artefacts an auditor will ask for
  • Risk register
  • Risk assessment methodology
  • Scenario library
  • Heat map
Where this commonly fails
  • Scenarios too generic
  • Criteria not calibrated
  • Interdependencies overlooked
ISO27005-10
Risk interdependency analysis

Risk interdependency analysis. Control from ISO 27005 framework, domain: ISO 27005: Risk Assessment.

Artefacts an auditor will ask for
  • Risk register
  • Risk assessment methodology
  • Scenario library
  • Heat map
Where this commonly fails
  • Scenarios too generic
  • Criteria not calibrated
  • Interdependencies overlooked

ISO 27005: Risk Framework & Governance

ISO27005-01
Risk management policy and scope

Risk management policy and scope. Control from ISO 27005 framework, domain: ISO 27005: Risk Framework & Governance.

Artefacts an auditor will ask for
  • Risk management policy
  • Risk governance charter
  • Stakeholder map
  • Risk integration plan
Where this commonly fails
  • Risk appetite not approved by board
  • Stakeholder needs not surfaced
  • Risk culture not measured
ISO27005-02
Risk governance structure

Risk governance structure. Control from ISO 27005 framework, domain: ISO 27005: Risk Framework & Governance.

Artefacts an auditor will ask for
  • Risk management policy
  • Risk governance charter
  • Stakeholder map
  • Risk integration plan
Where this commonly fails
  • Risk appetite not approved by board
  • Stakeholder needs not surfaced
  • Risk culture not measured
ISO27005-03
Risk culture and communication

Risk culture and communication. Control from ISO 27005 framework, domain: ISO 27005: Risk Framework & Governance.

Artefacts an auditor will ask for
  • Risk management policy
  • Risk governance charter
  • Stakeholder map
  • Risk integration plan
Where this commonly fails
  • Risk appetite not approved by board
  • Stakeholder needs not surfaced
  • Risk culture not measured
ISO27005-04
Stakeholder requirements for risk

Stakeholder requirements for risk. Control from ISO 27005 framework, domain: ISO 27005: Risk Framework & Governance.

Artefacts an auditor will ask for
  • Risk management policy
  • Risk governance charter
  • Stakeholder map
  • Risk integration plan
Where this commonly fails
  • Risk appetite not approved by board
  • Stakeholder needs not surfaced
  • Risk culture not measured
ISO27005-05
Risk management integration

Risk management integration. Control from ISO 27005 framework, domain: ISO 27005: Risk Framework & Governance.

Artefacts an auditor will ask for
  • Risk management policy
  • Risk governance charter
  • Stakeholder map
  • Risk integration plan
Where this commonly fails
  • Risk appetite not approved by board
  • Stakeholder needs not surfaced
  • Risk culture not measured

ISO 27005: Risk Monitoring & Review

ISO27005-16
Risk monitoring procedures

Risk monitoring procedures. Control from ISO 27005 framework, domain: ISO 27005: Risk Monitoring & Review.

Artefacts an auditor will ask for
  • Risk monitoring report
  • Risk register update log
  • Management review minutes
  • Trend dashboard
Where this commonly fails
  • Register stale beyond 90 days
  • Trends not communicated
  • Management review skipped
ISO27005-17
Risk reporting and communication

Risk reporting and communication. Control from ISO 27005 framework, domain: ISO 27005: Risk Monitoring & Review.

Artefacts an auditor will ask for
  • Risk monitoring report
  • Risk register update log
  • Management review minutes
  • Trend dashboard
Where this commonly fails
  • Register stale beyond 90 days
  • Trends not communicated
  • Management review skipped
ISO27005-18
Risk register maintenance

Risk register maintenance. Control from ISO 27005 framework, domain: ISO 27005: Risk Monitoring & Review.

Artefacts an auditor will ask for
  • Risk monitoring report
  • Risk register update log
  • Management review minutes
  • Trend dashboard
Where this commonly fails
  • Register stale beyond 90 days
  • Trends not communicated
  • Management review skipped
ISO27005-19
Continuous improvement of risk processes

Continuous improvement of risk processes. Control from ISO 27005 framework, domain: ISO 27005: Risk Monitoring & Review.

Artefacts an auditor will ask for
  • Risk monitoring report
  • Risk register update log
  • Management review minutes
  • Trend dashboard
Where this commonly fails
  • Register stale beyond 90 days
  • Trends not communicated
  • Management review skipped
ISO27005-20
Management review of risk program

Management review of risk program. Control from ISO 27005 framework, domain: ISO 27005: Risk Monitoring & Review.

Artefacts an auditor will ask for
  • Risk monitoring report
  • Risk register update log
  • Management review minutes
  • Trend dashboard
Where this commonly fails
  • Register stale beyond 90 days
  • Trends not communicated
  • Management review skipped

ISO 27005: Risk Treatment

ISO27005-11
Risk treatment options and selection

Risk treatment options and selection. Control from ISO 27005 framework, domain: ISO 27005: Risk Treatment.

Artefacts an auditor will ask for
  • Risk treatment plan
  • Residual risk acceptance memo
  • Insurance schedule
  • Control mapping
Where this commonly fails
  • Residual risk approval missing
  • Treatment owners unassigned
  • Insurance gaps unmapped
ISO27005-12
Risk treatment plan development

Risk treatment plan development. Control from ISO 27005 framework, domain: ISO 27005: Risk Treatment.

Artefacts an auditor will ask for
  • Risk treatment plan
  • Residual risk acceptance memo
  • Insurance schedule
  • Control mapping
Where this commonly fails
  • Residual risk approval missing
  • Treatment owners unassigned
  • Insurance gaps unmapped
ISO27005-13
Residual risk acceptance

Residual risk acceptance. Control from ISO 27005 framework, domain: ISO 27005: Risk Treatment.

Artefacts an auditor will ask for
  • Risk treatment plan
  • Residual risk acceptance memo
  • Insurance schedule
  • Control mapping
Where this commonly fails
  • Residual risk approval missing
  • Treatment owners unassigned
  • Insurance gaps unmapped
ISO27005-14
Risk transfer and insurance

Risk transfer and insurance. Control from ISO 27005 framework, domain: ISO 27005: Risk Treatment.

Artefacts an auditor will ask for
  • Risk treatment plan
  • Residual risk acceptance memo
  • Insurance schedule
  • Control mapping
Where this commonly fails
  • Residual risk approval missing
  • Treatment owners unassigned
  • Insurance gaps unmapped
ISO27005-15
Control implementation and monitoring

Control implementation and monitoring. Control from ISO 27005 framework, domain: ISO 27005: Risk Treatment.

Artefacts an auditor will ask for
  • Risk treatment plan
  • Residual risk acceptance memo
  • Insurance schedule
  • Control mapping
Where this commonly fails
  • Residual risk approval missing
  • Treatment owners unassigned
  • Insurance gaps unmapped

Risk Analysis

7.7
Likelihood estimation

Estimate the likelihood of threats exploiting vulnerabilities using consistent criteria.

Artefacts an auditor will ask for
  • Likelihood scale
  • Estimation rationale
  • Reference data
  • Calibration evidence
Where this commonly fails
  • No rationale
  • Inconsistent estimates
  • No reference data
7.8
Consequence estimation

Estimate business consequences arising from successful realization of risks.

Artefacts an auditor will ask for
  • BIA results
  • Financial impact model
  • Reputational scoring
  • Regulatory impact analysis
Where this commonly fails
  • No financial model
  • Reputational ignored
  • No regulatory mapping

Risk Assessment

7.5
Threat assessment

Identify and assess threats relevant to assets and the operating environment.

Artefacts an auditor will ask for
  • Threat catalogue
  • Threat actor profiles
  • Intel sources list
  • Update log
Where this commonly fails
  • Catalogue not refreshed
  • No insider threats
  • Tactical only

Risk Treatment

8.3
Statement of Applicability linkage

Document selected controls in the Statement of Applicability and reconcile with the treatment plan.

Artefacts an auditor will ask for
  • Statement of Applicability
  • Reconciliation report
  • Exclusion justifications
  • Version history
Where this commonly fails
  • SoA stale
  • Exclusions unjustified
  • Controls not traced to risks
8.5
Control effectiveness review

Review the effectiveness of implemented risk treatment controls and adjust as needed.

Artefacts an auditor will ask for
  • Control testing plan
  • Test results
  • Effectiveness metrics
  • Remediation plan
Where this commonly fails
  • Design-only testing
  • No metrics
  • Findings not remediated
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ISO 27005 framework page.