Skip to content

Evidence request lists

ISO/IEC 27007:2020

Evidence request list. 28 controls, 28 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Annex A

27007-A.1
Generic Competence

Auditors demonstrate generic competence in ISMS principles, ISO 27001 requirements and audit methods.

Artefacts an auditor will ask for
  • Certification records
  • Knowledge assessments
  • Audit experience logs
Where this commonly fails
  • Outdated training
  • Limited experience evidence
27007-A.2
Discipline Specific Competence

Auditors demonstrate ISMS discipline competence including risk assessment, controls and metrics.

Artefacts an auditor will ask for
  • Control specific training
  • Risk methodology evidence
  • Metrics interpretation tests
Where this commonly fails
  • Control depth shallow
  • Risk methodology weak

Annex A: ISMS Auditing Practice Guidance

27007-A.4
Auditing context of the organization (Clause 4)

ISMS-specific audit guidance for ISO/IEC 27001 Clause 4 requirements

Artefacts an auditor will ask for
  • ISMS audit checklist
  • Clause-specific guidance
  • Practice notes
  • Audit programme
Where this commonly fails
  • Checklist superficial
  • Clauses skipped
  • Practice inconsistent
  • Programme not risk-based
27007-A.5
Auditing leadership (Clause 5)

ISMS-specific audit guidance for ISO/IEC 27001 Clause 5 requirements

Artefacts an auditor will ask for
  • ISMS audit checklist
  • Clause-specific guidance
  • Practice notes
  • Audit programme
Where this commonly fails
  • Checklist superficial
  • Clauses skipped
  • Practice inconsistent
  • Programme not risk-based
27007-A.6
Auditing planning (Clause 6)

ISMS-specific audit guidance for ISO/IEC 27001 Clause 6 requirements

Artefacts an auditor will ask for
  • ISMS audit checklist
  • Clause-specific guidance
  • Practice notes
  • Audit programme
Where this commonly fails
  • Checklist superficial
  • Clauses skipped
  • Practice inconsistent
  • Programme not risk-based
27007-A.7-10
Auditing support through improvement (Clauses 7-10)

ISMS-specific audit guidance for ISO/IEC 27001 Clauses 7 through 10 requirements and associated security controls

Artefacts an auditor will ask for
  • ISMS audit checklist
  • Clause-specific guidance
  • Practice notes
  • Audit programme
Where this commonly fails
  • Checklist superficial
  • Clauses skipped
  • Practice inconsistent
  • Programme not risk-based

Annex B

27007-B.1
Practical Guidance Examples

Apply practical guidance examples from Annex B when auditing ISO 27001 clauses 4 to 10.

Artefacts an auditor will ask for
  • Audit checklists per Annex B
  • Example based working papers
  • Cross references
Where this commonly fails
  • Generic checklists used
  • No mapping to Annex B

Audit Activities

27007-6.1
Initiating the Audit

Establish contact with auditee and determine feasibility before conducting ISMS audit.

Artefacts an auditor will ask for
  • Audit notification
  • Feasibility assessment
  • Initial contact records
Where this commonly fails
  • No feasibility check
  • Late notification
27007-6.2
Preparing Audit Activities

Plan ISMS audit, prepare documents and verify objectives, scope, criteria and risks.

Artefacts an auditor will ask for
  • Audit plan
  • Working documents
  • Checklists
Where this commonly fails
  • Inadequate planning
  • Checklists out of date
27007-6.3
Conducting Audit Activities

Execute ISMS audit including opening meeting, evidence collection and findings generation.

Artefacts an auditor will ask for
  • Audit logs
  • Evidence records
  • Findings register
Where this commonly fails
  • Evidence not retained
  • Sampling weak
27007-6.4
Preparing and Distributing the Audit Report

Issue ISMS audit report including findings, conclusions and recommendations to management.

Artefacts an auditor will ask for
  • Audit report
  • Distribution list
  • Acknowledgement records
Where this commonly fails
  • Reports delayed
  • Findings unclear
27007-6.5
Completing the Audit

Close ISMS audit including record retention and confidentiality controls.

Artefacts an auditor will ask for
  • Closure record
  • Retention log
  • Confidentiality declarations
Where this commonly fails
  • Records lost
  • Confidentiality breached
27007-6.6
Audit Follow Up

Follow up on ISMS audit findings and verify effective corrective actions.

Artefacts an auditor will ask for
  • Corrective action records
  • Verification evidence
  • Trend analysis
Where this commonly fails
  • Open findings not tracked
  • No verification testing

Clause 4: Principles of Auditing

27007-4.1
Auditing principles overview

Principles for conducting effective ISMS audits based on ISO 19011:2018 extended with ISMS-specific guidance

Artefacts an auditor will ask for
  • Audit charter
  • Auditor code of conduct
  • Evidence collection procedure
  • Independence declaration
Where this commonly fails
  • Independence compromised
  • Evidence sampling weak
  • Code not signed
  • Charter outdated
27007-4.2
Integrity and ethical conduct

Principles of integrity, fair presentation, and professional care in ISMS auditing

Artefacts an auditor will ask for
  • Audit charter
  • Auditor code of conduct
  • Evidence collection procedure
  • Independence declaration
Where this commonly fails
  • Independence compromised
  • Evidence sampling weak
  • Code not signed
  • Charter outdated
27007-4.3
Evidence-based approach

Principles of systematic, independent, and evidence-based auditing for ISMS

Artefacts an auditor will ask for
  • Audit charter
  • Auditor code of conduct
  • Evidence collection procedure
  • Independence declaration
Where this commonly fails
  • Independence compromised
  • Evidence sampling weak
  • Code not signed
  • Charter outdated

Clause 5: Managing an ISMS Audit Programme

27007-5.4
Establishing the Programme Resources

Determine and provide resources including competent auditors, time, tools and budget for audit programme.

Artefacts an auditor will ask for
  • Resource plan
  • Budget approvals
  • Tool inventory
Where this commonly fails
  • Insufficient auditor pool
  • Tooling not maintained

Competence

27007-7.1
Determining Auditor Competence

Define ISMS auditor competence requirements including knowledge of information security, risk and controls.

Artefacts an auditor will ask for
  • Competence criteria
  • Knowledge tests
  • Training records
Where this commonly fails
  • Criteria too generic
  • Sector knowledge missing
27007-7.2
Auditor Evaluation Criteria

Establish criteria for evaluating ISMS auditors at selection and during programme execution.

Artefacts an auditor will ask for
  • Evaluation forms
  • Selection records
  • Performance reviews
Where this commonly fails
  • No periodic re-evaluation
  • Selection undocumented
27007-7.3
Selection of Auditor Evaluation Method

Choose evaluation methods such as interviews, witnessed audits and reviews of reports.

Artefacts an auditor will ask for
  • Witness audit reports
  • Interview records
  • Report reviews
Where this commonly fails
  • Witness audits rare
  • Only paper review used
27007-7.4
Conducting Auditor Evaluation

Perform initial and ongoing evaluation of auditors against ISMS audit competence criteria.

Artefacts an auditor will ask for
  • Evaluation outcomes
  • Improvement plans
  • Reauthorisation records
Where this commonly fails
  • Outcomes not actioned
  • Plans not tracked
27007-7.5
Maintaining and Improving Auditor Competence

Maintain auditor competence through continuing professional development and lessons learned.

Artefacts an auditor will ask for
  • CPD logs
  • Training plans
  • Lessons learned notes
Where this commonly fails
  • No CPD tracking
  • Lessons not shared

Improvement

27007-5.7
Reviewing and Improving the Programme

Review the audit programme at planned intervals and act on improvements identified.

Artefacts an auditor will ask for
  • Programme review minutes
  • Improvement actions
  • Lessons learned
Where this commonly fails
  • Reviews missed
  • Improvements not implemented

Programme Management

27007-5.1
Establishing the Audit Programme

Establish an ISMS audit programme aligned with organisational objectives, risks, and ISO 19011 framework.

Artefacts an auditor will ask for
  • Audit programme charter
  • Annual audit plan
  • Risk based scope
Where this commonly fails
  • No risk based scope
  • Programme not approved
27007-5.2
Audit Programme Objectives

Define measurable audit programme objectives covering conformity, effectiveness and improvement of ISMS.

Artefacts an auditor will ask for
  • Documented objectives
  • KPIs
  • Programme review minutes
Where this commonly fails
  • Objectives vague
  • No measurement of effectiveness
27007-5.3
Audit Programme Risks

Identify and treat risks and opportunities that affect achievement of the audit programme.

Artefacts an auditor will ask for
  • Programme risk register
  • Treatment plans
  • Review records
Where this commonly fails
  • Risk register absent
  • No opportunity tracking
27007-5.5
Implementing the Audit Programme

Schedule, assign and monitor ISMS audits per programme including coordination with stakeholders.

Artefacts an auditor will ask for
  • Audit schedule
  • Assignment records
  • Stakeholder communications
Where this commonly fails
  • Audits postponed without rationale
  • No stakeholder coordination
27007-5.6
Monitoring the Audit Programme

Monitor execution and effectiveness of the audit programme through metrics, feedback and reviews.

Artefacts an auditor will ask for
  • KPI dashboard
  • Feedback surveys
  • Programme review records
Where this commonly fails
  • No KPI reporting
  • Auditee feedback ignored
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.