Skip to content

Evidence request lists

ISO 37301

Evidence request list. 42 controls, 42 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Context

ISO37301-4.1
Understanding the Organization and Context

Determine external and internal issues relevant to the compliance management system and its ability to achieve intended outcomes.

Artefacts an auditor will ask for
  • PESTLE/SWOT analysis
  • Strategic plan extract
  • Compliance context register
  • Industry regulatory landscape map
Where this commonly fails
  • Context not refreshed annually
  • Compliance issues conflated with general business risk
ISO37301-4.2
Needs and Expectations of Interested Parties

Identify interested parties, their requirements, and which are addressed via compliance obligations.

Artefacts an auditor will ask for
  • Interested parties register
  • Stakeholder requirements matrix
  • Regulator engagement log
Where this commonly fails
  • Workers and worker representatives omitted
  • No mapping of expectations to obligations

ISO 37301: Improvement

ISO37301-16
Continual improvement methodology

Continual improvement methodology. Control from ISO 37301 framework, domain: ISO 37301: Improvement.

Artefacts an auditor will ask for
  • Improvement plan
  • Corrective action log
  • Innovation register
  • Change management procedure
Where this commonly fails
  • Improvement actions stale
  • Corrective actions not root-caused
  • Change not impact-assessed
ISO37301-17
Corrective and preventive actions

Corrective and preventive actions. Control from ISO 37301 framework, domain: ISO 37301: Improvement.

Artefacts an auditor will ask for
  • Improvement plan
  • Corrective action log
  • Innovation register
  • Change management procedure
Where this commonly fails
  • Improvement actions stale
  • Corrective actions not root-caused
  • Change not impact-assessed
ISO37301-18
Innovation and change management

Innovation and change management. Control from ISO 37301 framework, domain: ISO 37301: Improvement.

Artefacts an auditor will ask for
  • Improvement plan
  • Corrective action log
  • Innovation register
  • Change management procedure
Where this commonly fails
  • Improvement actions stale
  • Corrective actions not root-caused
  • Change not impact-assessed

ISO 37301: Leadership & Planning

ISO37301-01
Cl. 4.1-4.6 Compliance management policy - compliance obligations, objectives, and applicable compliance requirements

Quality policy and objectives. Control from ISO 37301 framework, domain: ISO 37301: Leadership & Planning.

Artefacts an auditor will ask for
  • Compliance policy
  • Compliance obligations register
  • Compliance objectives
  • Roles and responsibilities matrix
Where this commonly fails
  • Obligations register incomplete
  • Objectives not measurable
  • Compliance function under-resourced
ISO37301-02
Leadership commitment to quality

Leadership commitment to quality. Control from ISO 37301 framework, domain: ISO 37301: Leadership & Planning.

Artefacts an auditor will ask for
  • Compliance policy
  • Compliance obligations register
  • Compliance objectives
  • Roles and responsibilities matrix
Where this commonly fails
  • Obligations register incomplete
  • Objectives not measurable
  • Compliance function under-resourced
ISO37301-03
Risk-based thinking and planning

Risk-based thinking and planning. Control from ISO 37301 framework, domain: ISO 37301: Leadership & Planning.

Artefacts an auditor will ask for
  • Compliance policy
  • Compliance obligations register
  • Compliance objectives
  • Roles and responsibilities matrix
Where this commonly fails
  • Obligations register incomplete
  • Objectives not measurable
  • Compliance function under-resourced
ISO37301-04
Resource management for quality

Resource management for quality. Control from ISO 37301 framework, domain: ISO 37301: Leadership & Planning.

Artefacts an auditor will ask for
  • Compliance policy
  • Compliance obligations register
  • Compliance objectives
  • Roles and responsibilities matrix
Where this commonly fails
  • Obligations register incomplete
  • Objectives not measurable
  • Compliance function under-resourced
ISO37301-05
Organizational roles and responsibilities

Organizational roles and responsibilities. Control from ISO 37301 framework, domain: ISO 37301: Leadership & Planning.

Artefacts an auditor will ask for
  • Compliance policy
  • Compliance obligations register
  • Compliance objectives
  • Roles and responsibilities matrix
Where this commonly fails
  • Obligations register incomplete
  • Objectives not measurable
  • Compliance function under-resourced

ISO 37301: Operational Controls

ISO37301-06
Operational planning and control

Operational planning and control. Control from ISO 37301 framework, domain: ISO 37301: Operational Controls.

Artefacts an auditor will ask for
  • Compliance operational plan
  • Process control matrix
  • Third party compliance clauses
  • Compliance training records
Where this commonly fails
  • Controls not mapped to obligations
  • Third party flow-down weak
  • Training not role-based
ISO37301-07
Requirements for products and services

Requirements for products and services. Control from ISO 37301 framework, domain: ISO 37301: Operational Controls.

Artefacts an auditor will ask for
  • Compliance operational plan
  • Process control matrix
  • Third party compliance clauses
  • Compliance training records
Where this commonly fails
  • Controls not mapped to obligations
  • Third party flow-down weak
  • Training not role-based
ISO37301-08
Design and development controls

Design and development controls. Control from ISO 37301 framework, domain: ISO 37301: Operational Controls.

Artefacts an auditor will ask for
  • Compliance operational plan
  • Process control matrix
  • Third party compliance clauses
  • Compliance training records
Where this commonly fails
  • Controls not mapped to obligations
  • Third party flow-down weak
  • Training not role-based
ISO37301-09
Control of externally provided processes

Control of externally provided processes. Control from ISO 37301 framework, domain: ISO 37301: Operational Controls.

Artefacts an auditor will ask for
  • Compliance operational plan
  • Process control matrix
  • Third party compliance clauses
  • Compliance training records
Where this commonly fails
  • Controls not mapped to obligations
  • Third party flow-down weak
  • Training not role-based
ISO37301-10
Production and service provision controls

Production and service provision controls. Control from ISO 37301 framework, domain: ISO 37301: Operational Controls.

Artefacts an auditor will ask for
  • Compliance operational plan
  • Process control matrix
  • Third party compliance clauses
  • Compliance training records
Where this commonly fails
  • Controls not mapped to obligations
  • Third party flow-down weak
  • Training not role-based

ISO 37301: Performance Evaluation

ISO37301-11
Monitoring, measurement, and analysis

Monitoring, measurement, and analysis. Control from ISO 37301 framework, domain: ISO 37301: Performance Evaluation.

Artefacts an auditor will ask for
  • Compliance monitoring report
  • Internal audit plan
  • Management review minutes
  • Nonconformity register
Where this commonly fails
  • Monitoring not risk-tiered
  • Audits exclude key obligations
  • Nonconformities not trended
ISO37301-12
Internal audit program

Internal audit program. Control from ISO 37301 framework, domain: ISO 37301: Performance Evaluation.

Artefacts an auditor will ask for
  • Compliance monitoring report
  • Internal audit plan
  • Management review minutes
  • Nonconformity register
Where this commonly fails
  • Monitoring not risk-tiered
  • Audits exclude key obligations
  • Nonconformities not trended
ISO37301-13
Management review process

Management review process. Control from ISO 37301 framework, domain: ISO 37301: Performance Evaluation.

Artefacts an auditor will ask for
  • Compliance monitoring report
  • Internal audit plan
  • Management review minutes
  • Nonconformity register
Where this commonly fails
  • Monitoring not risk-tiered
  • Audits exclude key obligations
  • Nonconformities not trended
ISO37301-14
Customer satisfaction measurement

Customer satisfaction measurement. Control from ISO 37301 framework, domain: ISO 37301: Performance Evaluation.

Artefacts an auditor will ask for
  • Compliance monitoring report
  • Internal audit plan
  • Management review minutes
  • Nonconformity register
Where this commonly fails
  • Monitoring not risk-tiered
  • Audits exclude key obligations
  • Nonconformities not trended
ISO37301-15
Nonconformity and corrective action

Nonconformity and corrective action. Control from ISO 37301 framework, domain: ISO 37301: Performance Evaluation.

Artefacts an auditor will ask for
  • Compliance monitoring report
  • Internal audit plan
  • Management review minutes
  • Nonconformity register
Where this commonly fails
  • Monitoring not risk-tiered
  • Audits exclude key obligations
  • Nonconformities not trended

Improvement

ISO37301-10.1
Nonconformity and Corrective Action

React to nonconformities including breaches, determine causes, and implement corrective actions.

Artefacts an auditor will ask for
  • Nonconformity log
  • Root cause analysis records
  • Corrective action plan and verification
Where this commonly fails
  • Root cause superficial
  • Effectiveness not verified
ISO37301-10.2
Continual Improvement

Continually improve the suitability, adequacy, and effectiveness of the CMS.

Artefacts an auditor will ask for
  • Improvement initiatives log
  • Maturity assessments
  • Benchmarking outputs
Where this commonly fails
  • No maturity baseline

Leadership

ISO37301-5.1
Leadership and Commitment

Top management and governing body demonstrate leadership and commitment to the CMS.

Artefacts an auditor will ask for
  • Board minutes referencing CMS
  • Tone from the top communications
  • CEO compliance statement
Where this commonly fails
  • Commitment statements not refreshed
  • No board agenda time for compliance

Obligations

ISO37301-4.5
Compliance Obligations

Identify, document, evaluate, and maintain compliance obligations applicable to the organization.

Artefacts an auditor will ask for
  • Compliance obligations register
  • Horizon scanning procedure
  • Obligation owner assignments
  • Change log of obligations
Where this commonly fails
  • Register stale
  • No traceability from obligation to control

Operations

ISO37301-8.1
Operational Planning and Control

Establish controls to meet compliance obligations and address risks.

Artefacts an auditor will ask for
  • Control library mapped to obligations
  • Control owner assignments
  • Operating effectiveness evidence
Where this commonly fails
  • Controls not linked to specific obligations
ISO37301-8.2
Establishing Controls and Procedures

Implement controls and procedures proportionate to compliance risk.

Artefacts an auditor will ask for
  • Procedure library
  • Risk-based control rationale
  • Testing schedule
Where this commonly fails
  • Procedures exist but not followed
ISO37301-8.3
Raising Concerns

Establish, implement, and maintain processes for workers and others to raise concerns confidentially without retaliation.

Artefacts an auditor will ask for
  • Speak-up policy
  • Whistleblowing channel details
  • Anonymity safeguards
  • Anti-retaliation evidence
Where this commonly fails
  • No anonymous channel
  • Retaliation incidents not tracked
ISO37301-8.4
Investigation Processes

Investigate reports of suspected or actual non-compliance fairly and consistently.

Artefacts an auditor will ask for
  • Investigation procedure
  • Case management system records
  • Outcomes and corrective actions
  • Confidentiality controls
Where this commonly fails
  • No tracking of investigation closure times
  • Conflicts of interest not managed

Performance

ISO37301-9.1.1
Monitoring, Measurement, Analysis, and Evaluation

Monitor and measure compliance performance using defined indicators.

Artefacts an auditor will ask for
  • KPI definitions
  • Monitoring reports
  • Trend analysis
Where this commonly fails
  • Indicators not linked to objectives
ISO37301-9.1.5
Reporting

Provide reports on compliance performance to relevant interested parties including the governing body.

Artefacts an auditor will ask for
  • Board compliance report template
  • Reporting cadence schedule
  • Sample reports issued
Where this commonly fails
  • No reporting to governing body
  • Reports lack trend data
ISO37301-9.2
Internal Audit

Conduct internal audits of the CMS at planned intervals.

Artefacts an auditor will ask for
  • Audit programme
  • Audit reports
  • Auditor competence records
  • Findings and follow-up
Where this commonly fails
  • Auditors not independent of audited area
ISO37301-9.3
Management Review

Top management reviews the CMS at planned intervals to ensure suitability, adequacy, and effectiveness.

Artefacts an auditor will ask for
  • Review agenda and minutes
  • Inputs and outputs documented
  • Action register from review
Where this commonly fails
  • Reviews skipped or rolled into general ops meetings

Planning

ISO37301-6.1
Actions to Address Risks and Opportunities

Plan actions to address compliance risks and opportunities and integrate them into processes.

Artefacts an auditor will ask for
  • Compliance action plan
  • Risk treatment plan integration evidence
  • Effectiveness measures
Where this commonly fails
  • Actions lack owners or due dates
ISO37301-6.2
Compliance Objectives and Planning

Establish measurable compliance objectives at relevant functions and levels and plan to achieve them.

Artefacts an auditor will ask for
  • Compliance objectives register
  • KPI dashboard
  • Cascaded objectives to functions
Where this commonly fails
  • Objectives not measurable
  • No review of progress

Policy

ISO37301-5.2
Compliance Policy

Establish, communicate, and maintain a compliance policy appropriate to the organization.

Artefacts an auditor will ask for
  • Approved compliance policy
  • Policy distribution evidence
  • Acknowledgment records
Where this commonly fails
  • Policy not signed by top management
  • No worker acknowledgment record

Risk

ISO37301-4.6
Compliance Risk Assessment

Identify and analyze compliance risks linked to obligations and evaluate them.

Artefacts an auditor will ask for
  • Compliance risk register
  • Risk assessment methodology
  • Inherent vs residual risk scoring
  • Treatment plans
Where this commonly fails
  • No linkage between obligation and risk
  • Likelihood scored without rationale

Roles

ISO37301-5.3.2
Compliance Function

Establish a compliance function with appropriate authority, independence, resources, and access to top management.

Artefacts an auditor will ask for
  • Compliance charter
  • Org chart showing independence
  • Role description for Compliance Officer
  • Resourcing plan
Where this commonly fails
  • Compliance function reports to function it oversees
  • No documented authority
ISO37301-5.3.3
Governance Body and Top Management Responsibilities

Governing body and top management have defined accountabilities for the CMS.

Artefacts an auditor will ask for
  • Terms of reference for board compliance committee
  • Delegations of authority matrix
Where this commonly fails
  • No board oversight cadence defined

Support

ISO37301-7.2
Competence

Determine and ensure necessary competence for persons affecting compliance performance.

Artefacts an auditor will ask for
  • Competence matrix
  • Training records
  • Qualification records for compliance staff
Where this commonly fails
  • No competence assessment for compliance function
ISO37301-7.3
Awareness and Training

Workers are aware of compliance policy, their contribution, and consequences of non-compliance.

Artefacts an auditor will ask for
  • Annual compliance training plan
  • Completion rates by role
  • Targeted training for high-risk roles
  • Awareness campaigns
Where this commonly fails
  • No role-targeted content
  • Contractors excluded
ISO37301-7.4
Communication

Determine internal and external communications relevant to the CMS.

Artefacts an auditor will ask for
  • Communication plan
  • Channels matrix
  • Examples of compliance bulletins
Where this commonly fails
  • No external communication plan for regulators
ISO37301-7.5
Documented Information

Create, update, and control documented information required by the CMS.

Artefacts an auditor will ask for
  • Document register
  • Version control procedure
  • Retention schedule
Where this commonly fails
  • Out-of-date policies in active use
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ISO 37301 framework page.