ISO/IEC 27007:2020
Evidence request list. 28 controls, 28 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Annex A
Auditors demonstrate generic competence in ISMS principles, ISO 27001 requirements and audit methods.
- Certification records
- Knowledge assessments
- Audit experience logs
- Outdated training
- Limited experience evidence
Auditors demonstrate ISMS discipline competence including risk assessment, controls and metrics.
- Control specific training
- Risk methodology evidence
- Metrics interpretation tests
- Control depth shallow
- Risk methodology weak
Annex A: ISMS Auditing Practice Guidance
ISMS-specific audit guidance for ISO/IEC 27001 Clause 4 requirements
- ISMS audit checklist
- Clause-specific guidance
- Practice notes
- Audit programme
- Checklist superficial
- Clauses skipped
- Practice inconsistent
- Programme not risk-based
ISMS-specific audit guidance for ISO/IEC 27001 Clause 5 requirements
- ISMS audit checklist
- Clause-specific guidance
- Practice notes
- Audit programme
- Checklist superficial
- Clauses skipped
- Practice inconsistent
- Programme not risk-based
ISMS-specific audit guidance for ISO/IEC 27001 Clause 6 requirements
- ISMS audit checklist
- Clause-specific guidance
- Practice notes
- Audit programme
- Checklist superficial
- Clauses skipped
- Practice inconsistent
- Programme not risk-based
ISMS-specific audit guidance for ISO/IEC 27001 Clauses 7 through 10 requirements and associated security controls
- ISMS audit checklist
- Clause-specific guidance
- Practice notes
- Audit programme
- Checklist superficial
- Clauses skipped
- Practice inconsistent
- Programme not risk-based
Annex B
Apply practical guidance examples from Annex B when auditing ISO 27001 clauses 4 to 10.
- Audit checklists per Annex B
- Example based working papers
- Cross references
- Generic checklists used
- No mapping to Annex B
Audit Activities
Establish contact with auditee and determine feasibility before conducting ISMS audit.
- Audit notification
- Feasibility assessment
- Initial contact records
- No feasibility check
- Late notification
Plan ISMS audit, prepare documents and verify objectives, scope, criteria and risks.
- Audit plan
- Working documents
- Checklists
- Inadequate planning
- Checklists out of date
Execute ISMS audit including opening meeting, evidence collection and findings generation.
- Audit logs
- Evidence records
- Findings register
- Evidence not retained
- Sampling weak
Issue ISMS audit report including findings, conclusions and recommendations to management.
- Audit report
- Distribution list
- Acknowledgement records
- Reports delayed
- Findings unclear
Close ISMS audit including record retention and confidentiality controls.
- Closure record
- Retention log
- Confidentiality declarations
- Records lost
- Confidentiality breached
Follow up on ISMS audit findings and verify effective corrective actions.
- Corrective action records
- Verification evidence
- Trend analysis
- Open findings not tracked
- No verification testing
Clause 4: Principles of Auditing
Principles for conducting effective ISMS audits based on ISO 19011:2018 extended with ISMS-specific guidance
- Audit charter
- Auditor code of conduct
- Evidence collection procedure
- Independence declaration
- Independence compromised
- Evidence sampling weak
- Code not signed
- Charter outdated
Principles of integrity, fair presentation, and professional care in ISMS auditing
- Audit charter
- Auditor code of conduct
- Evidence collection procedure
- Independence declaration
- Independence compromised
- Evidence sampling weak
- Code not signed
- Charter outdated
Principles of systematic, independent, and evidence-based auditing for ISMS
- Audit charter
- Auditor code of conduct
- Evidence collection procedure
- Independence declaration
- Independence compromised
- Evidence sampling weak
- Code not signed
- Charter outdated
Clause 5: Managing an ISMS Audit Programme
Determine and provide resources including competent auditors, time, tools and budget for audit programme.
- Resource plan
- Budget approvals
- Tool inventory
- Insufficient auditor pool
- Tooling not maintained
Competence
Define ISMS auditor competence requirements including knowledge of information security, risk and controls.
- Competence criteria
- Knowledge tests
- Training records
- Criteria too generic
- Sector knowledge missing
Establish criteria for evaluating ISMS auditors at selection and during programme execution.
- Evaluation forms
- Selection records
- Performance reviews
- No periodic re-evaluation
- Selection undocumented
Choose evaluation methods such as interviews, witnessed audits and reviews of reports.
- Witness audit reports
- Interview records
- Report reviews
- Witness audits rare
- Only paper review used
Perform initial and ongoing evaluation of auditors against ISMS audit competence criteria.
- Evaluation outcomes
- Improvement plans
- Reauthorisation records
- Outcomes not actioned
- Plans not tracked
Maintain auditor competence through continuing professional development and lessons learned.
- CPD logs
- Training plans
- Lessons learned notes
- No CPD tracking
- Lessons not shared
Improvement
Review the audit programme at planned intervals and act on improvements identified.
- Programme review minutes
- Improvement actions
- Lessons learned
- Reviews missed
- Improvements not implemented
Programme Management
Establish an ISMS audit programme aligned with organisational objectives, risks, and ISO 19011 framework.
- Audit programme charter
- Annual audit plan
- Risk based scope
- No risk based scope
- Programme not approved
Define measurable audit programme objectives covering conformity, effectiveness and improvement of ISMS.
- Documented objectives
- KPIs
- Programme review minutes
- Objectives vague
- No measurement of effectiveness
Identify and treat risks and opportunities that affect achievement of the audit programme.
- Programme risk register
- Treatment plans
- Review records
- Risk register absent
- No opportunity tracking
Schedule, assign and monitor ISMS audits per programme including coordination with stakeholders.
- Audit schedule
- Assignment records
- Stakeholder communications
- Audits postponed without rationale
- No stakeholder coordination
Monitor execution and effectiveness of the audit programme through metrics, feedback and reviews.
- KPI dashboard
- Feedback surveys
- Programme review records
- No KPI reporting
- Auditee feedback ignored
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.