ISO/IEC 27006:2024
Evidence request list. 33 controls, 33 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Annex A
Demonstrate auditor competence across ISMS, risk, controls, sector and audit techniques per Annex A table.
- Competence matrix vs Annex A
- Evidence of training per area
- Witness audit records
- Risk management competence weak
- Sector specifics missing
Annex B
Apply Annex B base audit time table and documented modifiers for ISMS audit duration.
- Time calculation per Annex B
- Modifier justifications
- Comparison with previous cycles
- Modifiers misapplied
- Reductions not justified
Annex C-E: Audit Time and Controls
Guidance on determining audit time based on effective number of personnel concept
- Audit plan
- Audit report
- Certification decision record
- Surveillance schedule
- Plan deviates from scope
- Findings unsubstantiated
- Decision criteria unclear
- Surveillance gaps
Methods for calculating audit time including multi-site and scope extension calculations
- Audit plan
- Audit report
- Certification decision record
- Surveillance schedule
- Plan deviates from scope
- Findings unsubstantiated
- Decision criteria unclear
- Surveillance gaps
Alignment of audit requirements with ISO/IEC 27001:2022, Annex A controls
- Audit plan
- Audit report
- Certification decision record
- Surveillance schedule
- Plan deviates from scope
- Findings unsubstantiated
- Decision criteria unclear
- Surveillance gaps
Audit
Plan a three year ISMS audit programme covering full scope including surveillance and recertification.
- Three year audit plan
- Surveillance schedule
- Recertification plan
- Incomplete coverage
- Missing surveillance audits
Conduct Stage 1 readiness audit covering documentation, scope and risk assessment review.
- Stage 1 report
- Document review notes
- Readiness checklist
- Stage 1 skipped
- Findings not addressed before Stage 2
Conduct Stage 2 implementation audit on site covering Annex A controls and management system effectiveness.
- Stage 2 audit report
- Sampling evidence
- Control test records
- Insufficient sampling
- Annex A coverage gaps
Perform annual surveillance covering changes, incidents, internal audit, and selected controls.
- Surveillance audit reports
- Change review notes
- Incident review records
- Surveillance superficial
- Critical controls untested
Perform recertification audit confirming ongoing effectiveness across full ISMS scope before certificate expiry.
- Recertification audit report
- Performance review
- Three year trend analysis
- Late recertification
- Limited scope coverage
Conduct short notice or extension audits when significant changes or complaints affect ISMS.
- Special audit reports
- Trigger justification
- Change notifications
- No process for short notice
- Triggers not monitored
Issue audit reports including findings, nonconformities, opportunities, and certification recommendation.
- Audit reports
- Nonconformity records
- Closure evidence
- Vague findings
- No closure evidence retained
Clause 5: Structural Requirements
Certification bodies must be legal entities accountable for ISMS certification decisions and impartiality.
- Legal entity registration
- Certification body charter
- Liability insurance certificate
- Unclear legal accountability
- Missing insurance coverage
Identify, analyse, and treat threats to impartiality in ISMS audit and certification activities.
- Impartiality risk register
- Impartiality committee minutes
- Conflict of interest declarations
- Stale impartiality assessments
- No oversight committee
Clause 6: Resource Requirements
Competence requirements for personnel involved in the certification process
- Competence matrix for laboratory personnel
- Training and qualification records
- Authorization records for examination activities
- Continuing professional development log
- Competence reassessment intervals not defined
- Authorization tied to job title rather than verified competence
- No evidence of practical assessment for new methods
- Training records missing for locum or agency staff
Clause 7: Process Requirements - Competence
General requirements for competence of various roles involved in providing a certification service
- Competence matrix
- Auditor qualification records
- Training records
- Knowledge assessment
- Competence not maintained
- Technical depth shallow
- Training records incomplete
- Assessment irregular
Apply documented sampling for multi-site ISMS audits including site selection rationale.
- Site list
- Sampling plan
- Justification records
- Same sites every cycle
- No high risk weighting
Requirements for technical knowledge of information security specific to the client organization's sector
- Competence matrix
- Auditor qualification records
- Training records
- Knowledge assessment
- Competence not maintained
- Technical depth shallow
- Training records incomplete
- Assessment irregular
Clause 8: Certification Documents and Information Requirements
Independent personnel make certification decisions based on audit evidence and competence review.
- Decision records
- Reviewer competence evidence
- Decision rationale
- Auditor also decides
- No documented rationale
Apply documented criteria for suspending, withdrawing or reducing ISMS certification scope.
- Suspension records
- Withdrawal notifications
- Scope reduction letters
- No timely action on major nonconformities
- Criteria not documented
Refined requirements for referencing other standards in the ISMS certification documents
- Certification document template
- Reference standard list
- Information package
- Stakeholder communications
- Documents inconsistent
- References stale
- Information incomplete
- Communications delayed
Clause 9: Audit and Certification Process Requirements
Operate documented process for complaints and appeals with impartial review.
- Complaints register
- Appeals process
- Independent review records
- No independent review
- Appeals not tracked to closure
New requirements for deploying remote audit techniques including documentation of extent and effectiveness
- Audit plan
- Audit report
- Certification decision record
- Surveillance schedule
- Plan deviates from scope
- Findings unsubstantiated
- Decision criteria unclear
- Surveillance gaps
Requirements for the initial ISMS certification audit process
- Audit plan
- Audit report
- Certification decision record
- Surveillance schedule
- Plan deviates from scope
- Findings unsubstantiated
- Decision criteria unclear
- Surveillance gaps
Requirements for the certification decision-making process and criteria
- Audit plan
- Audit report
- Certification decision record
- Surveillance schedule
- Plan deviates from scope
- Findings unsubstantiated
- Decision criteria unclear
- Surveillance gaps
Requirements for surveillance audit activities and recertification of ISMS
- Audit plan
- Audit report
- Certification decision record
- Surveillance schedule
- Plan deviates from scope
- Findings unsubstantiated
- Decision criteria unclear
- Surveillance gaps
Financial Stability
Demonstrate adequate finance and liability arrangements for certification operations.
- Audited financial statements
- Liability insurance policy
- Financial risk assessment
- Insufficient liability limits
- No financial contingency plan
Management
Operate the certification body management system covering documents, records, internal audits and review.
- Internal audit reports
- Management review minutes
- Document control records
- Management review missed
- Internal audit shallow
Process
Calculate ISMS audit duration using documented method including risk and scope factors.
- Audit time calculation worksheet
- Scope definition
- Justifications for reductions
- Time understated
- No justification recorded
Resources
Define and maintain competence criteria for ISMS audit personnel and decision makers.
- Competence matrix
- Auditor CVs and certifications
- Training records
- Missing sector competence
- No witnessed audit records
Manage internal and external personnel covering ISMS audit team roles and responsibilities.
- Auditor agreements
- Confidentiality undertakings
- Role descriptions
- No signed impartiality declarations
- Subcontractor controls weak
Control engagement of external auditors and technical experts including independence checks.
- External auditor contracts
- Technical expert qualification records
- Independence checks
- No periodic re-qualification
- Expert scope unclear
Maintain up to date records of qualifications, training, experience and performance for ISMS personnel.
- Personnel files
- Performance evaluations
- CPD records
- Out of date records
- No performance evidence
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.