ISO 37301
Evidence request list. 42 controls, 42 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Context
Determine external and internal issues relevant to the compliance management system and its ability to achieve intended outcomes.
- PESTLE/SWOT analysis
- Strategic plan extract
- Compliance context register
- Industry regulatory landscape map
- Context not refreshed annually
- Compliance issues conflated with general business risk
Identify interested parties, their requirements, and which are addressed via compliance obligations.
- Interested parties register
- Stakeholder requirements matrix
- Regulator engagement log
- Workers and worker representatives omitted
- No mapping of expectations to obligations
ISO 37301: Improvement
Continual improvement methodology. Control from ISO 37301 framework, domain: ISO 37301: Improvement.
- Improvement plan
- Corrective action log
- Innovation register
- Change management procedure
- Improvement actions stale
- Corrective actions not root-caused
- Change not impact-assessed
Corrective and preventive actions. Control from ISO 37301 framework, domain: ISO 37301: Improvement.
- Improvement plan
- Corrective action log
- Innovation register
- Change management procedure
- Improvement actions stale
- Corrective actions not root-caused
- Change not impact-assessed
Innovation and change management. Control from ISO 37301 framework, domain: ISO 37301: Improvement.
- Improvement plan
- Corrective action log
- Innovation register
- Change management procedure
- Improvement actions stale
- Corrective actions not root-caused
- Change not impact-assessed
ISO 37301: Leadership & Planning
Quality policy and objectives. Control from ISO 37301 framework, domain: ISO 37301: Leadership & Planning.
- Compliance policy
- Compliance obligations register
- Compliance objectives
- Roles and responsibilities matrix
- Obligations register incomplete
- Objectives not measurable
- Compliance function under-resourced
Leadership commitment to quality. Control from ISO 37301 framework, domain: ISO 37301: Leadership & Planning.
- Compliance policy
- Compliance obligations register
- Compliance objectives
- Roles and responsibilities matrix
- Obligations register incomplete
- Objectives not measurable
- Compliance function under-resourced
Risk-based thinking and planning. Control from ISO 37301 framework, domain: ISO 37301: Leadership & Planning.
- Compliance policy
- Compliance obligations register
- Compliance objectives
- Roles and responsibilities matrix
- Obligations register incomplete
- Objectives not measurable
- Compliance function under-resourced
Resource management for quality. Control from ISO 37301 framework, domain: ISO 37301: Leadership & Planning.
- Compliance policy
- Compliance obligations register
- Compliance objectives
- Roles and responsibilities matrix
- Obligations register incomplete
- Objectives not measurable
- Compliance function under-resourced
Organizational roles and responsibilities. Control from ISO 37301 framework, domain: ISO 37301: Leadership & Planning.
- Compliance policy
- Compliance obligations register
- Compliance objectives
- Roles and responsibilities matrix
- Obligations register incomplete
- Objectives not measurable
- Compliance function under-resourced
ISO 37301: Operational Controls
Operational planning and control. Control from ISO 37301 framework, domain: ISO 37301: Operational Controls.
- Compliance operational plan
- Process control matrix
- Third party compliance clauses
- Compliance training records
- Controls not mapped to obligations
- Third party flow-down weak
- Training not role-based
Requirements for products and services. Control from ISO 37301 framework, domain: ISO 37301: Operational Controls.
- Compliance operational plan
- Process control matrix
- Third party compliance clauses
- Compliance training records
- Controls not mapped to obligations
- Third party flow-down weak
- Training not role-based
Design and development controls. Control from ISO 37301 framework, domain: ISO 37301: Operational Controls.
- Compliance operational plan
- Process control matrix
- Third party compliance clauses
- Compliance training records
- Controls not mapped to obligations
- Third party flow-down weak
- Training not role-based
Control of externally provided processes. Control from ISO 37301 framework, domain: ISO 37301: Operational Controls.
- Compliance operational plan
- Process control matrix
- Third party compliance clauses
- Compliance training records
- Controls not mapped to obligations
- Third party flow-down weak
- Training not role-based
Production and service provision controls. Control from ISO 37301 framework, domain: ISO 37301: Operational Controls.
- Compliance operational plan
- Process control matrix
- Third party compliance clauses
- Compliance training records
- Controls not mapped to obligations
- Third party flow-down weak
- Training not role-based
ISO 37301: Performance Evaluation
Monitoring, measurement, and analysis. Control from ISO 37301 framework, domain: ISO 37301: Performance Evaluation.
- Compliance monitoring report
- Internal audit plan
- Management review minutes
- Nonconformity register
- Monitoring not risk-tiered
- Audits exclude key obligations
- Nonconformities not trended
Internal audit program. Control from ISO 37301 framework, domain: ISO 37301: Performance Evaluation.
- Compliance monitoring report
- Internal audit plan
- Management review minutes
- Nonconformity register
- Monitoring not risk-tiered
- Audits exclude key obligations
- Nonconformities not trended
Management review process. Control from ISO 37301 framework, domain: ISO 37301: Performance Evaluation.
- Compliance monitoring report
- Internal audit plan
- Management review minutes
- Nonconformity register
- Monitoring not risk-tiered
- Audits exclude key obligations
- Nonconformities not trended
Customer satisfaction measurement. Control from ISO 37301 framework, domain: ISO 37301: Performance Evaluation.
- Compliance monitoring report
- Internal audit plan
- Management review minutes
- Nonconformity register
- Monitoring not risk-tiered
- Audits exclude key obligations
- Nonconformities not trended
Nonconformity and corrective action. Control from ISO 37301 framework, domain: ISO 37301: Performance Evaluation.
- Compliance monitoring report
- Internal audit plan
- Management review minutes
- Nonconformity register
- Monitoring not risk-tiered
- Audits exclude key obligations
- Nonconformities not trended
Improvement
React to nonconformities including breaches, determine causes, and implement corrective actions.
- Nonconformity log
- Root cause analysis records
- Corrective action plan and verification
- Root cause superficial
- Effectiveness not verified
Continually improve the suitability, adequacy, and effectiveness of the CMS.
- Improvement initiatives log
- Maturity assessments
- Benchmarking outputs
- No maturity baseline
Leadership
Top management and governing body demonstrate leadership and commitment to the CMS.
- Board minutes referencing CMS
- Tone from the top communications
- CEO compliance statement
- Commitment statements not refreshed
- No board agenda time for compliance
Obligations
Identify, document, evaluate, and maintain compliance obligations applicable to the organization.
- Compliance obligations register
- Horizon scanning procedure
- Obligation owner assignments
- Change log of obligations
- Register stale
- No traceability from obligation to control
Operations
Establish controls to meet compliance obligations and address risks.
- Control library mapped to obligations
- Control owner assignments
- Operating effectiveness evidence
- Controls not linked to specific obligations
Implement controls and procedures proportionate to compliance risk.
- Procedure library
- Risk-based control rationale
- Testing schedule
- Procedures exist but not followed
Establish, implement, and maintain processes for workers and others to raise concerns confidentially without retaliation.
- Speak-up policy
- Whistleblowing channel details
- Anonymity safeguards
- Anti-retaliation evidence
- No anonymous channel
- Retaliation incidents not tracked
Investigate reports of suspected or actual non-compliance fairly and consistently.
- Investigation procedure
- Case management system records
- Outcomes and corrective actions
- Confidentiality controls
- No tracking of investigation closure times
- Conflicts of interest not managed
Performance
Monitor and measure compliance performance using defined indicators.
- KPI definitions
- Monitoring reports
- Trend analysis
- Indicators not linked to objectives
Provide reports on compliance performance to relevant interested parties including the governing body.
- Board compliance report template
- Reporting cadence schedule
- Sample reports issued
- No reporting to governing body
- Reports lack trend data
Conduct internal audits of the CMS at planned intervals.
- Audit programme
- Audit reports
- Auditor competence records
- Findings and follow-up
- Auditors not independent of audited area
Top management reviews the CMS at planned intervals to ensure suitability, adequacy, and effectiveness.
- Review agenda and minutes
- Inputs and outputs documented
- Action register from review
- Reviews skipped or rolled into general ops meetings
Planning
Plan actions to address compliance risks and opportunities and integrate them into processes.
- Compliance action plan
- Risk treatment plan integration evidence
- Effectiveness measures
- Actions lack owners or due dates
Establish measurable compliance objectives at relevant functions and levels and plan to achieve them.
- Compliance objectives register
- KPI dashboard
- Cascaded objectives to functions
- Objectives not measurable
- No review of progress
Policy
Establish, communicate, and maintain a compliance policy appropriate to the organization.
- Approved compliance policy
- Policy distribution evidence
- Acknowledgment records
- Policy not signed by top management
- No worker acknowledgment record
Risk
Identify and analyze compliance risks linked to obligations and evaluate them.
- Compliance risk register
- Risk assessment methodology
- Inherent vs residual risk scoring
- Treatment plans
- No linkage between obligation and risk
- Likelihood scored without rationale
Roles
Establish a compliance function with appropriate authority, independence, resources, and access to top management.
- Compliance charter
- Org chart showing independence
- Role description for Compliance Officer
- Resourcing plan
- Compliance function reports to function it oversees
- No documented authority
Governing body and top management have defined accountabilities for the CMS.
- Terms of reference for board compliance committee
- Delegations of authority matrix
- No board oversight cadence defined
Support
Determine and ensure necessary competence for persons affecting compliance performance.
- Competence matrix
- Training records
- Qualification records for compliance staff
- No competence assessment for compliance function
Workers are aware of compliance policy, their contribution, and consequences of non-compliance.
- Annual compliance training plan
- Completion rates by role
- Targeted training for high-risk roles
- Awareness campaigns
- No role-targeted content
- Contractors excluded
Determine internal and external communications relevant to the CMS.
- Communication plan
- Channels matrix
- Examples of compliance bulletins
- No external communication plan for regulators
Create, update, and control documented information required by the CMS.
- Document register
- Version control procedure
- Retention schedule
- Out-of-date policies in active use
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ISO 37301 framework page.