Skip to content

Evidence request lists

ISO/IEC 27003:2017

Evidence request list. 45 controls, 45 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Context

27003-4.1
Understanding the Organization and Its Context

Determine external and internal issues relevant to ISMS purpose that affect ability to achieve intended outcomes.

Artefacts an auditor will ask for
  • Context analysis report
  • PESTLE assessment
  • Internal issues register
Where this commonly fails
  • Context not refreshed
  • External issues omitted
27003-4.2
Interested Parties and Their Requirements

Identify interested parties relevant to the ISMS and their information security requirements.

Artefacts an auditor will ask for
  • Stakeholder register
  • Requirements matrix
  • Legal and contractual obligations log
Where this commonly fails
  • Requirements not tracked
  • Stakeholders incomplete

Context of the Organization (Clause 4)

ISO27003-4.1
Understanding the Organization and Its Context

Guidance on continuously analyzing internal and external issues (political, legal, technological, competitive, market, cultural) that affect information security objectives.

Artefacts an auditor will ask for
  • Scope statement signed by management
  • Stakeholder and interested party register
  • Process owner attestation
  • Tooling configuration export
  • Meeting minutes referencing the control
  • Training material referencing the control
Where this commonly fails
  • Scope boundaries unclear for cloud services
  • Stakeholder needs not refreshed annually
  • Evidence is point in time rather than ongoing
  • Control owner unclear or vacant
  • No metric tracks control effectiveness
ISO27003-4.2
Understanding Needs and Expectations of Interested Parties

Guidance on identifying all interested parties (customers, regulators, employees, suppliers, shareholders) and their requirements relevant to the ISMS.

Artefacts an auditor will ask for
  • Scope statement signed by management
  • Stakeholder and interested party register
  • Process owner attestation
  • Tooling configuration export
  • Meeting minutes referencing the control
  • Training material referencing the control
Where this commonly fails
  • Scope boundaries unclear for cloud services
  • Stakeholder needs not refreshed annually
  • Evidence is point in time rather than ongoing
  • Control owner unclear or vacant
  • No metric tracks control effectiveness
ISO27003-4.3
Determining the Scope of the ISMS

Guidance on defining boundaries and applicability of the ISMS, considering interfaces and dependencies, organizational units, locations, and technologies.

Artefacts an auditor will ask for
  • Scope statement signed by management
  • Stakeholder and interested party register
  • Process owner attestation
  • Tooling configuration export
  • Meeting minutes referencing the control
  • Training material referencing the control
Where this commonly fails
  • Scope boundaries unclear for cloud services
  • Stakeholder needs not refreshed annually
  • Evidence is point in time rather than ongoing
  • Control owner unclear or vacant
  • No metric tracks control effectiveness
ISO27003-4.4
Information Security Management System

Guidance on establishing, implementing, maintaining, and continually improving the ISMS including required processes and their interactions.

Artefacts an auditor will ask for
  • Scope statement signed by management
  • Stakeholder and interested party register
  • Process owner attestation
  • Tooling configuration export
  • Meeting minutes referencing the control
  • Training material referencing the control
Where this commonly fails
  • Scope boundaries unclear for cloud services
  • Stakeholder needs not refreshed annually
  • Evidence is point in time rather than ongoing
  • Control owner unclear or vacant
  • No metric tracks control effectiveness

Improvement

27003-10.1
Nonconformity and Corrective Action

React to nonconformities, evaluate need for action to eliminate causes, implement corrections, and review effectiveness.

Artefacts an auditor will ask for
  • NC register
  • Root-cause analyses
  • Effectiveness checks
Where this commonly fails
  • No root cause
  • Effectiveness not verified
27003-10.2
Continual Improvement

Continually improve suitability, adequacy, and effectiveness of the ISMS.

Artefacts an auditor will ask for
  • Improvement register
  • Trend analysis
  • Lessons-learned records
Where this commonly fails
  • No trend analysis
  • Lessons not captured

Improvement (Clause 10)

ISO27003-10.1
Continual Improvement

Guidance on continually improving the suitability, adequacy, and effectiveness of the ISMS through use of corrective actions, audit results, analysis of events, and management reviews.

Artefacts an auditor will ask for
  • CAPA register with root cause and verification
  • Improvement programme tracker
  • Process owner attestation
  • Tooling configuration export
  • Meeting minutes referencing the control
  • Training material referencing the control
Where this commonly fails
  • Root cause analysis is symptomatic only
  • Effectiveness checks not performed
  • Evidence is point in time rather than ongoing
  • Control owner unclear or vacant
  • No metric tracks control effectiveness
ISO27003-10.2
Nonconformity and Corrective Action

Guidance on reacting to nonconformities, evaluating need for action to eliminate causes, implementing corrective actions, reviewing effectiveness, and making changes to the ISMS if necessary.

Artefacts an auditor will ask for
  • CAPA register with root cause and verification
  • Improvement programme tracker
  • Process owner attestation
  • Tooling configuration export
  • Meeting minutes referencing the control
  • Training material referencing the control
Where this commonly fails
  • Root cause analysis is symptomatic only
  • Effectiveness checks not performed
  • Evidence is point in time rather than ongoing
  • Control owner unclear or vacant
  • No metric tracks control effectiveness

Leadership

27003-5.1
Leadership and Commitment

Top management demonstrates leadership and commitment to the ISMS via policy, resourcing, and integration.

Artefacts an auditor will ask for
  • Signed ISMS policy
  • Management review minutes
  • Resource allocation evidence
Where this commonly fails
  • No management review
  • Policy unsigned

Leadership (Clause 5)

ISO27003-5.1
Leadership and Commitment

Guidance on how top management demonstrates leadership by ensuring information security policy and objectives are established, resources are allocated, and the ISMS achieves intended outcomes.

Artefacts an auditor will ask for
  • Board or executive committee charter with security or risk remit
  • RACI matrix for accountable owners
  • Process owner attestation
  • Tooling configuration export
  • Meeting minutes referencing the control
  • Training material referencing the control
Where this commonly fails
  • Board reporting cadence not formalised
  • Roles overlap without clear accountable owner
  • Evidence is point in time rather than ongoing
  • Control owner unclear or vacant
  • No metric tracks control effectiveness
ISO27003-5.2
Information Security Policy

Guidance on establishing the policy including appropriate scope, framework for objectives, commitment to requirements, and commitment to continual improvement.

Artefacts an auditor will ask for
  • Board or executive committee charter with security or risk remit
  • RACI matrix for accountable owners
  • Signed and dated policy set with version history
  • Annual review and approval records
  • Process owner attestation
  • Tooling configuration export
Where this commonly fails
  • Board reporting cadence not formalised
  • Roles overlap without clear accountable owner
  • Policies past their review date
  • No evidence policies were communicated to staff
  • Evidence is point in time rather than ongoing
ISO27003-5.3
Organizational Roles, Responsibilities, and Authorities

Guidance on assigning and communicating roles and responsibilities for information security, ensuring reporting lines and accountability.

Artefacts an auditor will ask for
  • Board or executive committee charter with security or risk remit
  • RACI matrix for accountable owners
  • Process owner attestation
  • Tooling configuration export
  • Meeting minutes referencing the control
  • Training material referencing the control
Where this commonly fails
  • Board reporting cadence not formalised
  • Roles overlap without clear accountable owner
  • Evidence is point in time rather than ongoing
  • Control owner unclear or vacant
  • No metric tracks control effectiveness

Operation

27003-8.1
Operational Planning and Control

Plan, implement, and control processes needed to meet requirements and implement actions from Clause 6.

Artefacts an auditor will ask for
  • Process documentation
  • Operational records
  • Change control
Where this commonly fails
  • Processes undocumented
  • Changes uncontrolled
27003-8.2
Risk Assessment Performance

Perform information security risk assessments at planned intervals or when significant changes occur, with retained results.

Artefacts an auditor will ask for
  • Assessment cadence schedule
  • Triggered assessments
  • Retained results
Where this commonly fails
  • No trigger-based assessments
  • Cadence missed
27003-8.3
Risk Treatment Implementation

Implement the information security risk treatment plan and retain evidence of results.

Artefacts an auditor will ask for
  • Treatment evidence
  • Control implementation logs
  • Effectiveness reviews
Where this commonly fails
  • No closure tracking
  • Effectiveness untested

Operation (Clause 8)

ISO27003-8.1
Operational Planning and Control

Guidance on planning, implementing, and controlling processes needed to meet information security requirements, including managing planned changes and outsourced processes.

Artefacts an auditor will ask for
  • Scope statement signed by management
  • Stakeholder and interested party register
  • Process maps with defined controls and owners
  • Change control records
  • Process owner attestation
  • Tooling configuration export
Where this commonly fails
  • Scope boundaries unclear for cloud services
  • Stakeholder needs not refreshed annually
  • Operational controls not linked to risks
  • Change records missing rollback evidence
  • Evidence is point in time rather than ongoing
ISO27003-8.2
Information Security Risk Assessment

Guidance on performing information security risk assessments at planned intervals or when significant changes occur, and retaining documented results.

Artefacts an auditor will ask for
  • Risk register with likelihood, impact, and treatment plans
  • Risk assessment methodology document
  • Process maps with defined controls and owners
  • Change control records
  • Process owner attestation
  • Tooling configuration export
Where this commonly fails
  • Risk register not refreshed on a defined cadence
  • Inherent vs residual risk scoring not documented
  • Operational controls not linked to risks
  • Change records missing rollback evidence
  • Evidence is point in time rather than ongoing
ISO27003-8.3
Information Security Risk Treatment

Guidance on implementing the risk treatment plan, applying selected controls, and retaining documented results of risk treatment.

Artefacts an auditor will ask for
  • Process maps with defined controls and owners
  • Change control records
  • Process owner attestation
  • Tooling configuration export
  • Meeting minutes referencing the control
  • Training material referencing the control
Where this commonly fails
  • Operational controls not linked to risks
  • Change records missing rollback evidence
  • Evidence is point in time rather than ongoing
  • Control owner unclear or vacant
  • No metric tracks control effectiveness

Organization

27003-5.3
Roles, Responsibilities, Authorities

Assign and communicate responsibilities and authorities for ISMS roles including reporting on performance.

Artefacts an auditor will ask for
  • RACI matrix
  • Role descriptions
  • Org chart
Where this commonly fails
  • No CISO appointed
  • RACI incomplete

Performance

27003-9.1
Monitoring, Measurement, Analysis, Evaluation

Determine what, how, and when to monitor and measure; analyse and evaluate results to assess ISMS performance.

Artefacts an auditor will ask for
  • Measurement plan
  • KPI dashboards
  • Evaluation reports
Where this commonly fails
  • No measurement plan
  • KPIs unrelated to objectives
27003-9.2
Internal Audit

Conduct internal audits at planned intervals to verify ISMS conformance and effective implementation.

Artefacts an auditor will ask for
  • Audit programme
  • Audit reports
  • Auditor independence evidence
Where this commonly fails
  • Auditor not independent
  • Programme missed
27003-9.3
Management Review

Top management reviews ISMS at planned intervals for continuing suitability, adequacy, and effectiveness.

Artefacts an auditor will ask for
  • Review minutes
  • Inputs and outputs
  • Action register
Where this commonly fails
  • Inputs incomplete
  • Actions not tracked

Performance Evaluation (Clause 9)

ISO27003-9.1
Monitoring, Measurement, Analysis and Evaluation

Guidance on determining what needs to be monitored/measured, methods, timing, and responsibilities. Evaluating ISMS performance and effectiveness.

Artefacts an auditor will ask for
  • Incident response plan with playbooks per scenario
  • SIEM log retention and alerting configuration
  • Internal audit programme and findings log
  • Management review meeting minutes with actions
  • Process owner attestation
  • Tooling configuration export
Where this commonly fails
  • Tabletop exercises not run in last 12 months
  • Detection coverage not mapped to MITRE ATT&CK
  • Audit findings without closure dates
  • Management review skipped one or more cycles
  • Evidence is point in time rather than ongoing
ISO27003-9.2
Internal Audit

Guidance on planning and conducting internal audits at planned intervals to verify ISMS conformance and effective implementation.

Artefacts an auditor will ask for
  • Internal audit programme and findings log
  • Management review meeting minutes with actions
  • Process owner attestation
  • Tooling configuration export
  • Meeting minutes referencing the control
  • Training material referencing the control
Where this commonly fails
  • Audit findings without closure dates
  • Management review skipped one or more cycles
  • Evidence is point in time rather than ongoing
  • Control owner unclear or vacant
  • No metric tracks control effectiveness
ISO27003-9.3
Management Review

Guidance on top management review of the ISMS at planned intervals, including required inputs (status of actions, changes, feedback, risk results) and outputs (improvement decisions, resource needs).

Artefacts an auditor will ask for
  • Internal audit programme and findings log
  • Management review meeting minutes with actions
  • Process owner attestation
  • Tooling configuration export
  • Meeting minutes referencing the control
  • Training material referencing the control
Where this commonly fails
  • Audit findings without closure dates
  • Management review skipped one or more cycles
  • Evidence is point in time rather than ongoing
  • Control owner unclear or vacant
  • No metric tracks control effectiveness

Planning

27003-6.1.1
Actions to Address Risks and Opportunities

Plan actions to address risks and opportunities that ensure ISMS achieves intended outcomes.

Artefacts an auditor will ask for
  • Risk and opportunity register
  • Action plans
  • Effectiveness reviews
Where this commonly fails
  • Opportunities ignored
  • Actions not tracked
27003-6.2
Information Security Objectives

Establish measurable security objectives at relevant functions and levels, with plans to achieve them.

Artefacts an auditor will ask for
  • Objectives register
  • KPI definitions
  • Achievement reports
Where this commonly fails
  • Objectives not measurable
  • Owners missing

Planning (Clause 6)

ISO27003-6.1
Actions to Address Risks and Opportunities

Guidance on the risk assessment process including risk identification, analysis, evaluation, and selection of risk treatment options. Creation of the Statement of Applicability.

Artefacts an auditor will ask for
  • Scope statement signed by management
  • Stakeholder and interested party register
  • Process owner attestation
  • Tooling configuration export
  • Meeting minutes referencing the control
  • Training material referencing the control
Where this commonly fails
  • Scope boundaries unclear for cloud services
  • Stakeholder needs not refreshed annually
  • Evidence is point in time rather than ongoing
  • Control owner unclear or vacant
  • No metric tracks control effectiveness
ISO27003-6.2
Information Security Objectives and Planning to Achieve Them

Guidance on setting measurable information security objectives at relevant functions and levels, and planning actions, resources, responsibilities, and timeframes.

Artefacts an auditor will ask for
  • Consent capture and withdrawal logs
  • Data subject request workflow and SLA tracker
  • Scope statement signed by management
  • Stakeholder and interested party register
  • Process owner attestation
  • Tooling configuration export
Where this commonly fails
  • Consent records lack timestamp or version
  • DSR responses miss statutory deadline
  • Scope boundaries unclear for cloud services
  • Stakeholder needs not refreshed annually
  • Evidence is point in time rather than ongoing

Policy

27003-5.2
Information Security Policy

Establish information security policy aligned to strategic context, with commitments and continual improvement.

Artefacts an auditor will ask for
  • ISMS policy document
  • Approval record
  • Distribution evidence
Where this commonly fails
  • Not communicated
  • No review cadence

Risk Management

27003-6.1.2
Information Security Risk Assessment

Define and apply a risk assessment process with criteria, repeatability, and documented results.

Artefacts an auditor will ask for
  • Risk methodology
  • Risk register
  • Assessment reports
Where this commonly fails
  • Methodology informal
  • Results not retained
27003-6.1.3
Information Security Risk Treatment

Select treatment options, determine controls, produce Statement of Applicability, and gain risk owner approval.

Artefacts an auditor will ask for
  • Risk treatment plan
  • Statement of Applicability
  • Risk owner approvals
Where this commonly fails
  • SoA outdated
  • Residual risk unsigned

Scope

27003-4.3
Determining ISMS Scope

Determine boundaries and applicability of the ISMS considering external and internal issues, interested parties, and interfaces with other organizations.

Artefacts an auditor will ask for
  • Scope statement
  • Boundary diagram
  • Interface and dependency map
Where this commonly fails
  • Scope ambiguous
  • Interfaces undocumented

Support

27003-7.1
Resources

Determine and provide resources needed for the establishment, implementation, maintenance, and continual improvement of the ISMS.

Artefacts an auditor will ask for
  • Budget allocation
  • Staffing plan
  • Tooling inventory
Where this commonly fails
  • Underfunded
  • No staffing plan
27003-7.2
Competence

Determine necessary competence, ensure persons are competent, and retain evidence of competence.

Artefacts an auditor will ask for
  • Competence matrix
  • Training records
  • Certification copies
Where this commonly fails
  • No competence matrix
  • Training informal
27003-7.3
Awareness

Persons under the organization's control are aware of policy, their contribution, and implications of non-conformance.

Artefacts an auditor will ask for
  • Awareness programme content
  • Completion metrics
  • Reinforcement campaigns
Where this commonly fails
  • One-time training only
  • No completion tracking
27003-7.4
Communication

Determine internal and external communications relevant to the ISMS including what, when, with whom, and how.

Artefacts an auditor will ask for
  • Communication plan
  • Distribution logs
  • External notice templates
Where this commonly fails
  • No plan
  • External comms ad hoc
27003-7.5
Documented Information

Create, update, and control documented information required by the ISMS with appropriate identification and protection.

Artefacts an auditor will ask for
  • Document register
  • Version control evidence
  • Retention schedule
Where this commonly fails
  • No version control
  • Retention undefined

Support (Clause 7)

ISO27003-7.1
Resources

Guidance on determining and providing resources needed for establishment, implementation, maintenance, and continual improvement of the ISMS.

Artefacts an auditor will ask for
  • Control narrative tied to evidence
  • Sample of operating evidence over the period
  • Process owner attestation
  • Tooling configuration export
  • Meeting minutes referencing the control
  • Training material referencing the control
Where this commonly fails
  • Evidence sampling not representative
  • Operating effectiveness not demonstrated
  • Evidence is point in time rather than ongoing
  • Control owner unclear or vacant
  • No metric tracks control effectiveness
ISO27003-7.2
Competence

Guidance on determining necessary competence of persons, ensuring they are competent through education, training, or experience, and retaining evidence.

Artefacts an auditor will ask for
  • Training completion records by role
  • Phishing simulation results
  • Process owner attestation
  • Tooling configuration export
  • Meeting minutes referencing the control
  • Training material referencing the control
Where this commonly fails
  • Role based training not delivered to high risk teams
  • Training metrics not reported to leadership
  • Evidence is point in time rather than ongoing
  • Control owner unclear or vacant
  • No metric tracks control effectiveness
ISO27003-7.3
Awareness

Guidance on ensuring all persons doing work under the organisation's control are aware of the information security policy, their contribution, and implications of non-conformance.

Artefacts an auditor will ask for
  • Training completion records by role
  • Phishing simulation results
  • Process owner attestation
  • Tooling configuration export
  • Meeting minutes referencing the control
  • Training material referencing the control
Where this commonly fails
  • Role based training not delivered to high risk teams
  • Training metrics not reported to leadership
  • Evidence is point in time rather than ongoing
  • Control owner unclear or vacant
  • No metric tracks control effectiveness
ISO27003-7.4
Communication

Guidance on determining the need for internal and external communications relevant to the ISMS: what, when, with whom, who communicates, and the processes.

Artefacts an auditor will ask for
  • Control narrative tied to evidence
  • Sample of operating evidence over the period
  • Process owner attestation
  • Tooling configuration export
  • Meeting minutes referencing the control
  • Training material referencing the control
Where this commonly fails
  • Evidence sampling not representative
  • Operating effectiveness not demonstrated
  • Evidence is point in time rather than ongoing
  • Control owner unclear or vacant
  • No metric tracks control effectiveness
ISO27003-7.5
Documented Information

Guidance on creating, updating, and controlling documented information required by the ISMS, including access, storage, retention, and disposition.

Artefacts an auditor will ask for
  • Signed and dated policy set with version history
  • Annual review and approval records
  • Process owner attestation
  • Tooling configuration export
  • Meeting minutes referencing the control
  • Training material referencing the control
Where this commonly fails
  • Policies past their review date
  • No evidence policies were communicated to staff
  • Evidence is point in time rather than ongoing
  • Control owner unclear or vacant
  • No metric tracks control effectiveness
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.