ISO 27005
Evidence request list. 26 controls, 26 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Communication
Communicate and consult with internal and external stakeholders on risk throughout the process.
- Communication plan
- Stakeholder briefings
- Committee minutes
- Awareness materials
- No external comms
- Briefings irregular
- Plan unwritten
ISO 27005: Risk Assessment
Risk identification methods. Control from ISO 27005 framework, domain: ISO 27005: Risk Assessment.
- Risk register
- Risk assessment methodology
- Scenario library
- Heat map
- Scenarios too generic
- Criteria not calibrated
- Interdependencies overlooked
Risk analysis and evaluation. Control from ISO 27005 framework, domain: ISO 27005: Risk Assessment.
- Risk register
- Risk assessment methodology
- Scenario library
- Heat map
- Scenarios too generic
- Criteria not calibrated
- Interdependencies overlooked
Risk criteria and thresholds. Control from ISO 27005 framework, domain: ISO 27005: Risk Assessment.
- Risk register
- Risk assessment methodology
- Scenario library
- Heat map
- Scenarios too generic
- Criteria not calibrated
- Interdependencies overlooked
Risk scenario development. Control from ISO 27005 framework, domain: ISO 27005: Risk Assessment.
- Risk register
- Risk assessment methodology
- Scenario library
- Heat map
- Scenarios too generic
- Criteria not calibrated
- Interdependencies overlooked
Risk interdependency analysis. Control from ISO 27005 framework, domain: ISO 27005: Risk Assessment.
- Risk register
- Risk assessment methodology
- Scenario library
- Heat map
- Scenarios too generic
- Criteria not calibrated
- Interdependencies overlooked
ISO 27005: Risk Framework & Governance
Risk management policy and scope. Control from ISO 27005 framework, domain: ISO 27005: Risk Framework & Governance.
- Risk management policy
- Risk governance charter
- Stakeholder map
- Risk integration plan
- Risk appetite not approved by board
- Stakeholder needs not surfaced
- Risk culture not measured
Risk governance structure. Control from ISO 27005 framework, domain: ISO 27005: Risk Framework & Governance.
- Risk management policy
- Risk governance charter
- Stakeholder map
- Risk integration plan
- Risk appetite not approved by board
- Stakeholder needs not surfaced
- Risk culture not measured
Risk culture and communication. Control from ISO 27005 framework, domain: ISO 27005: Risk Framework & Governance.
- Risk management policy
- Risk governance charter
- Stakeholder map
- Risk integration plan
- Risk appetite not approved by board
- Stakeholder needs not surfaced
- Risk culture not measured
Stakeholder requirements for risk. Control from ISO 27005 framework, domain: ISO 27005: Risk Framework & Governance.
- Risk management policy
- Risk governance charter
- Stakeholder map
- Risk integration plan
- Risk appetite not approved by board
- Stakeholder needs not surfaced
- Risk culture not measured
Risk management integration. Control from ISO 27005 framework, domain: ISO 27005: Risk Framework & Governance.
- Risk management policy
- Risk governance charter
- Stakeholder map
- Risk integration plan
- Risk appetite not approved by board
- Stakeholder needs not surfaced
- Risk culture not measured
ISO 27005: Risk Monitoring & Review
Risk monitoring procedures. Control from ISO 27005 framework, domain: ISO 27005: Risk Monitoring & Review.
- Risk monitoring report
- Risk register update log
- Management review minutes
- Trend dashboard
- Register stale beyond 90 days
- Trends not communicated
- Management review skipped
Risk reporting and communication. Control from ISO 27005 framework, domain: ISO 27005: Risk Monitoring & Review.
- Risk monitoring report
- Risk register update log
- Management review minutes
- Trend dashboard
- Register stale beyond 90 days
- Trends not communicated
- Management review skipped
Risk register maintenance. Control from ISO 27005 framework, domain: ISO 27005: Risk Monitoring & Review.
- Risk monitoring report
- Risk register update log
- Management review minutes
- Trend dashboard
- Register stale beyond 90 days
- Trends not communicated
- Management review skipped
Continuous improvement of risk processes. Control from ISO 27005 framework, domain: ISO 27005: Risk Monitoring & Review.
- Risk monitoring report
- Risk register update log
- Management review minutes
- Trend dashboard
- Register stale beyond 90 days
- Trends not communicated
- Management review skipped
Management review of risk program. Control from ISO 27005 framework, domain: ISO 27005: Risk Monitoring & Review.
- Risk monitoring report
- Risk register update log
- Management review minutes
- Trend dashboard
- Register stale beyond 90 days
- Trends not communicated
- Management review skipped
ISO 27005: Risk Treatment
Risk treatment options and selection. Control from ISO 27005 framework, domain: ISO 27005: Risk Treatment.
- Risk treatment plan
- Residual risk acceptance memo
- Insurance schedule
- Control mapping
- Residual risk approval missing
- Treatment owners unassigned
- Insurance gaps unmapped
Risk treatment plan development. Control from ISO 27005 framework, domain: ISO 27005: Risk Treatment.
- Risk treatment plan
- Residual risk acceptance memo
- Insurance schedule
- Control mapping
- Residual risk approval missing
- Treatment owners unassigned
- Insurance gaps unmapped
Residual risk acceptance. Control from ISO 27005 framework, domain: ISO 27005: Risk Treatment.
- Risk treatment plan
- Residual risk acceptance memo
- Insurance schedule
- Control mapping
- Residual risk approval missing
- Treatment owners unassigned
- Insurance gaps unmapped
Risk transfer and insurance. Control from ISO 27005 framework, domain: ISO 27005: Risk Treatment.
- Risk treatment plan
- Residual risk acceptance memo
- Insurance schedule
- Control mapping
- Residual risk approval missing
- Treatment owners unassigned
- Insurance gaps unmapped
Control implementation and monitoring. Control from ISO 27005 framework, domain: ISO 27005: Risk Treatment.
- Risk treatment plan
- Residual risk acceptance memo
- Insurance schedule
- Control mapping
- Residual risk approval missing
- Treatment owners unassigned
- Insurance gaps unmapped
Risk Analysis
Estimate the likelihood of threats exploiting vulnerabilities using consistent criteria.
- Likelihood scale
- Estimation rationale
- Reference data
- Calibration evidence
- No rationale
- Inconsistent estimates
- No reference data
Estimate business consequences arising from successful realization of risks.
- BIA results
- Financial impact model
- Reputational scoring
- Regulatory impact analysis
- No financial model
- Reputational ignored
- No regulatory mapping
Risk Assessment
Identify and assess threats relevant to assets and the operating environment.
- Threat catalogue
- Threat actor profiles
- Intel sources list
- Update log
- Catalogue not refreshed
- No insider threats
- Tactical only
Risk Treatment
Document selected controls in the Statement of Applicability and reconcile with the treatment plan.
- Statement of Applicability
- Reconciliation report
- Exclusion justifications
- Version history
- SoA stale
- Exclusions unjustified
- Controls not traced to risks
Review the effectiveness of implemented risk treatment controls and adjust as needed.
- Control testing plan
- Test results
- Effectiveness metrics
- Remediation plan
- Design-only testing
- No metrics
- Findings not remediated
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ISO 27005 framework page.