Skip to content

Evidence request lists

ISO/IEC 27006:2024

Evidence request list. 33 controls, 33 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Annex A

27006-A.1
Auditor Competence Areas

Demonstrate auditor competence across ISMS, risk, controls, sector and audit techniques per Annex A table.

Artefacts an auditor will ask for
  • Competence matrix vs Annex A
  • Evidence of training per area
  • Witness audit records
Where this commonly fails
  • Risk management competence weak
  • Sector specifics missing

Annex B

27006-B.1
Audit Time Determination

Apply Annex B base audit time table and documented modifiers for ISMS audit duration.

Artefacts an auditor will ask for
  • Time calculation per Annex B
  • Modifier justifications
  • Comparison with previous cycles
Where this commonly fails
  • Modifiers misapplied
  • Reductions not justified

Annex C-E: Audit Time and Controls

27006-C
Audit time guidance

Guidance on determining audit time based on effective number of personnel concept

Artefacts an auditor will ask for
  • Audit plan
  • Audit report
  • Certification decision record
  • Surveillance schedule
Where this commonly fails
  • Plan deviates from scope
  • Findings unsubstantiated
  • Decision criteria unclear
  • Surveillance gaps
27006-D
Audit time calculation methods

Methods for calculating audit time including multi-site and scope extension calculations

Artefacts an auditor will ask for
  • Audit plan
  • Audit report
  • Certification decision record
  • Surveillance schedule
Where this commonly fails
  • Plan deviates from scope
  • Findings unsubstantiated
  • Decision criteria unclear
  • Surveillance gaps
27006-E
Controls alignment

Alignment of audit requirements with ISO/IEC 27001:2022, Annex A controls

Artefacts an auditor will ask for
  • Audit plan
  • Audit report
  • Certification decision record
  • Surveillance schedule
Where this commonly fails
  • Plan deviates from scope
  • Findings unsubstantiated
  • Decision criteria unclear
  • Surveillance gaps

Audit

27006-7.2
Audit Programme

Plan a three year ISMS audit programme covering full scope including surveillance and recertification.

Artefacts an auditor will ask for
  • Three year audit plan
  • Surveillance schedule
  • Recertification plan
Where this commonly fails
  • Incomplete coverage
  • Missing surveillance audits
27006-7.3
Stage 1 Audit

Conduct Stage 1 readiness audit covering documentation, scope and risk assessment review.

Artefacts an auditor will ask for
  • Stage 1 report
  • Document review notes
  • Readiness checklist
Where this commonly fails
  • Stage 1 skipped
  • Findings not addressed before Stage 2
27006-7.4
Stage 2 Audit

Conduct Stage 2 implementation audit on site covering Annex A controls and management system effectiveness.

Artefacts an auditor will ask for
  • Stage 2 audit report
  • Sampling evidence
  • Control test records
Where this commonly fails
  • Insufficient sampling
  • Annex A coverage gaps
27006-7.5
Surveillance Audits

Perform annual surveillance covering changes, incidents, internal audit, and selected controls.

Artefacts an auditor will ask for
  • Surveillance audit reports
  • Change review notes
  • Incident review records
Where this commonly fails
  • Surveillance superficial
  • Critical controls untested
27006-7.6
Recertification Audit

Perform recertification audit confirming ongoing effectiveness across full ISMS scope before certificate expiry.

Artefacts an auditor will ask for
  • Recertification audit report
  • Performance review
  • Three year trend analysis
Where this commonly fails
  • Late recertification
  • Limited scope coverage
27006-7.7
Special Audits

Conduct short notice or extension audits when significant changes or complaints affect ISMS.

Artefacts an auditor will ask for
  • Special audit reports
  • Trigger justification
  • Change notifications
Where this commonly fails
  • No process for short notice
  • Triggers not monitored
27006-7.8
Reporting

Issue audit reports including findings, nonconformities, opportunities, and certification recommendation.

Artefacts an auditor will ask for
  • Audit reports
  • Nonconformity records
  • Closure evidence
Where this commonly fails
  • Vague findings
  • No closure evidence retained

Clause 5: Structural Requirements

27006-5.1
General Requirements for Certification Bodies

Certification bodies must be legal entities accountable for ISMS certification decisions and impartiality.

Artefacts an auditor will ask for
  • Legal entity registration
  • Certification body charter
  • Liability insurance certificate
Where this commonly fails
  • Unclear legal accountability
  • Missing insurance coverage
27006-5.2
Management of Impartiality

Identify, analyse, and treat threats to impartiality in ISMS audit and certification activities.

Artefacts an auditor will ask for
  • Impartiality risk register
  • Impartiality committee minutes
  • Conflict of interest declarations
Where this commonly fails
  • Stale impartiality assessments
  • No oversight committee

Clause 6: Resource Requirements

27006-6.1
Competence of personnel

Competence requirements for personnel involved in the certification process

Artefacts an auditor will ask for
  • Competence matrix for laboratory personnel
  • Training and qualification records
  • Authorization records for examination activities
  • Continuing professional development log
Where this commonly fails
  • Competence reassessment intervals not defined
  • Authorization tied to job title rather than verified competence
  • No evidence of practical assessment for new methods
  • Training records missing for locum or agency staff

Clause 7: Process Requirements - Competence

27006-7.1
General competence requirements

General requirements for competence of various roles involved in providing a certification service

Artefacts an auditor will ask for
  • Competence matrix
  • Auditor qualification records
  • Training records
  • Knowledge assessment
Where this commonly fails
  • Competence not maintained
  • Technical depth shallow
  • Training records incomplete
  • Assessment irregular
27006-7.1.2
Multi-Site Sampling

Apply documented sampling for multi-site ISMS audits including site selection rationale.

Artefacts an auditor will ask for
  • Site list
  • Sampling plan
  • Justification records
Where this commonly fails
  • Same sites every cycle
  • No high risk weighting
27006-7.1.3
Technical knowledge requirements

Requirements for technical knowledge of information security specific to the client organization's sector

Artefacts an auditor will ask for
  • Competence matrix
  • Auditor qualification records
  • Training records
  • Knowledge assessment
Where this commonly fails
  • Competence not maintained
  • Technical depth shallow
  • Training records incomplete
  • Assessment irregular

Clause 8: Certification Documents and Information Requirements

27006-8.1
Certification Decision

Independent personnel make certification decisions based on audit evidence and competence review.

Artefacts an auditor will ask for
  • Decision records
  • Reviewer competence evidence
  • Decision rationale
Where this commonly fails
  • Auditor also decides
  • No documented rationale
27006-8.2
Suspension, Withdrawal, Reduction

Apply documented criteria for suspending, withdrawing or reducing ISMS certification scope.

Artefacts an auditor will ask for
  • Suspension records
  • Withdrawal notifications
  • Scope reduction letters
Where this commonly fails
  • No timely action on major nonconformities
  • Criteria not documented
27006-8.2.3
Referencing other standards

Refined requirements for referencing other standards in the ISMS certification documents

Artefacts an auditor will ask for
  • Certification document template
  • Reference standard list
  • Information package
  • Stakeholder communications
Where this commonly fails
  • Documents inconsistent
  • References stale
  • Information incomplete
  • Communications delayed

Clause 9: Audit and Certification Process Requirements

27006-9.1
Complaints and Appeals

Operate documented process for complaints and appeals with impartial review.

Artefacts an auditor will ask for
  • Complaints register
  • Appeals process
  • Independent review records
Where this commonly fails
  • No independent review
  • Appeals not tracked to closure
27006-9.1.3.3
Remote audit provisions

New requirements for deploying remote audit techniques including documentation of extent and effectiveness

Artefacts an auditor will ask for
  • Audit plan
  • Audit report
  • Certification decision record
  • Surveillance schedule
Where this commonly fails
  • Plan deviates from scope
  • Findings unsubstantiated
  • Decision criteria unclear
  • Surveillance gaps
27006-9.3
Initial certification

Requirements for the initial ISMS certification audit process

Artefacts an auditor will ask for
  • Audit plan
  • Audit report
  • Certification decision record
  • Surveillance schedule
Where this commonly fails
  • Plan deviates from scope
  • Findings unsubstantiated
  • Decision criteria unclear
  • Surveillance gaps
27006-9.3.2.2
Certification decision process

Requirements for the certification decision-making process and criteria

Artefacts an auditor will ask for
  • Audit plan
  • Audit report
  • Certification decision record
  • Surveillance schedule
Where this commonly fails
  • Plan deviates from scope
  • Findings unsubstantiated
  • Decision criteria unclear
  • Surveillance gaps
27006-9.4
Surveillance and recertification

Requirements for surveillance audit activities and recertification of ISMS

Artefacts an auditor will ask for
  • Audit plan
  • Audit report
  • Certification decision record
  • Surveillance schedule
Where this commonly fails
  • Plan deviates from scope
  • Findings unsubstantiated
  • Decision criteria unclear
  • Surveillance gaps

Financial Stability

27006-5.3
Liability and Financing

Demonstrate adequate finance and liability arrangements for certification operations.

Artefacts an auditor will ask for
  • Audited financial statements
  • Liability insurance policy
  • Financial risk assessment
Where this commonly fails
  • Insufficient liability limits
  • No financial contingency plan

Management

27006-9.2
Management System Requirements

Operate the certification body management system covering documents, records, internal audits and review.

Artefacts an auditor will ask for
  • Internal audit reports
  • Management review minutes
  • Document control records
Where this commonly fails
  • Management review missed
  • Internal audit shallow

Process

27006-7.1.1
Determining Audit Time

Calculate ISMS audit duration using documented method including risk and scope factors.

Artefacts an auditor will ask for
  • Audit time calculation worksheet
  • Scope definition
  • Justifications for reductions
Where this commonly fails
  • Time understated
  • No justification recorded

Resources

27006-6.1.1
Competence of Personnel

Define and maintain competence criteria for ISMS audit personnel and decision makers.

Artefacts an auditor will ask for
  • Competence matrix
  • Auditor CVs and certifications
  • Training records
Where this commonly fails
  • Missing sector competence
  • No witnessed audit records
27006-6.1.2
Personnel Involved in Certification

Manage internal and external personnel covering ISMS audit team roles and responsibilities.

Artefacts an auditor will ask for
  • Auditor agreements
  • Confidentiality undertakings
  • Role descriptions
Where this commonly fails
  • No signed impartiality declarations
  • Subcontractor controls weak
27006-6.1.3
Use of Individual External Auditors and Technical Experts

Control engagement of external auditors and technical experts including independence checks.

Artefacts an auditor will ask for
  • External auditor contracts
  • Technical expert qualification records
  • Independence checks
Where this commonly fails
  • No periodic re-qualification
  • Expert scope unclear
27006-6.2
Personnel Records

Maintain up to date records of qualifications, training, experience and performance for ISMS personnel.

Artefacts an auditor will ask for
  • Personnel files
  • Performance evaluations
  • CPD records
Where this commonly fails
  • Out of date records
  • No performance evidence
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.