Skip to content

Evidence request lists

ISO/IEC 27014:2020

Evidence request list. 39 controls, 39 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Assure

27014-6.5
Assure Process

Governing body commissions independent assurance activities to verify that information security governance is operating as directed.

Artefacts an auditor will ask for
  • internal audit plan covering security governance
  • external assurance reports
  • management responses with remediation tracking
Where this commonly fails
  • assurance scope limited to operational controls
  • no follow-up on assurance findings at board level

Clause 1-4: Introduction and Context

27014-1
Scope

Defines the scope of guidance on concepts, objectives, and processes for governance of information security

Artefacts an auditor will ask for
  • Scope statement
  • Concept reference
  • Definitions glossary
  • Governance charter
Where this commonly fails
  • Scope unclear
  • Concepts not adopted
  • Glossary outdated
  • Charter inactive
27014-3
Terms and definitions

Key terms including governance, governing body, information security, and management

Artefacts an auditor will ask for
  • Scope statement
  • Concept reference
  • Definitions glossary
  • Governance charter
Where this commonly fails
  • Scope unclear
  • Concepts not adopted
  • Glossary outdated
  • Charter inactive
27014-4
Concepts

Fundamental concepts of information security governance and its relationship to organizational governance

Artefacts an auditor will ask for
  • Scope statement
  • Concept reference
  • Definitions glossary
  • Governance charter
Where this commonly fails
  • Scope unclear
  • Concepts not adopted
  • Glossary outdated
  • Charter inactive
29134-1
Scope

Guidelines for a process on privacy impact assessments and structure and content of a PIA report

Artefacts an auditor will ask for
  • PIA template
  • DPIA report
  • Privacy risk register
  • Mitigation plan
Where this commonly fails
  • PIA skipped at design
  • DPIA shallow
  • Risk catalogue incomplete
  • Mitigations not tracked
29134-3
Terms and definitions

Privacy impact assessment terminology including PII, privacy risk, and PIA report

Artefacts an auditor will ask for
  • PIA template
  • DPIA report
  • Privacy risk register
  • Mitigation plan
Where this commonly fails
  • PIA skipped at design
  • DPIA shallow
  • Risk catalogue incomplete
  • Mitigations not tracked
29134-4
General overview

General overview of PIA process, its purpose, and relationship to other privacy management activities

Artefacts an auditor will ask for
  • PIA template
  • DPIA report
  • Privacy risk register
  • Mitigation plan
Where this commonly fails
  • PIA skipped at design
  • DPIA shallow
  • Risk catalogue incomplete
  • Mitigations not tracked

Clause 5: Guiding Principles

27014-5.1
Governance Objectives

Define and document objectives for the governance of information security aligned with organisational strategy and stakeholder expectations.

Artefacts an auditor will ask for
  • board-approved information security governance charter
  • alignment matrix linking security objectives to business strategy
  • stakeholder register with expectation logs
Where this commonly fails
  • security objectives drafted by IT without board ratification
  • no traceability from corporate strategy to security goals
27014-5.2
Governance Principles

Apply the six principles of information security governance covering organisation-wide approach, risk-based decisions, investment, conformance, human behaviour and value delivery.

Artefacts an auditor will ask for
  • written governance principles statement endorsed by governing body
  • policy cross-reference to each of the six principles
  • minutes showing principles applied in decisions
Where this commonly fails
  • principles copy-pasted without contextualisation
  • no evidence of principles influencing actual decisions
27014-5.3
Effectiveness

Ensuring information security governance produces effective outcomes

Artefacts an auditor will ask for
  • Principles statement
  • Effectiveness metrics
  • Efficiency review
  • Improvement plan
Where this commonly fails
  • Principles aspirational
  • Metrics absent
  • Efficiency not tracked
  • Improvement abandoned
27014-5.4
Efficiency

Delivering information security governance in a resource-efficient manner

Artefacts an auditor will ask for
  • Principles statement
  • Effectiveness metrics
  • Efficiency review
  • Improvement plan
Where this commonly fails
  • Principles aspirational
  • Metrics absent
  • Efficiency not tracked
  • Improvement abandoned
27014-5.5
Alignment

Aligning information security governance with business strategy and objectives

Artefacts an auditor will ask for
  • Principles statement
  • Effectiveness metrics
  • Efficiency review
  • Improvement plan
Where this commonly fails
  • Principles aspirational
  • Metrics absent
  • Efficiency not tracked
  • Improvement abandoned
27014-5.6
Continuous improvement

Continually improving information security governance based on changing business needs

Artefacts an auditor will ask for
  • Principles statement
  • Effectiveness metrics
  • Efficiency review
  • Improvement plan
Where this commonly fails
  • Principles aspirational
  • Metrics absent
  • Efficiency not tracked
  • Improvement abandoned

Clause 6: Governance Relationships

27014-6.1
Evaluate Process

Governing body evaluates the current and forecast performance of information security against objectives, risk appetite and external context.

Artefacts an auditor will ask for
  • quarterly board security performance dashboards
  • horizon scan reports
  • risk appetite versus current exposure analysis
Where this commonly fails
  • evaluation limited to backward-looking metrics
  • no forecast or forward-looking indicators
27014-6.2
Direct Process

Governing body provides direction by approving the information security strategy, policy, resourcing and risk treatment priorities.

Artefacts an auditor will ask for
  • signed information security strategy document
  • approved annual security budget with board minutes
  • directives issued to executive management
Where this commonly fails
  • strategy never refreshed after initial approval
  • budget approved without linkage to risk priorities
27014-6.3
Monitor Process

Governing body monitors achievement of strategic security objectives, conformance with policy and effectiveness of risk treatments through defined indicators.

Artefacts an auditor will ask for
  • KPI catalogue with thresholds
  • monthly monitoring reports to executive committee
  • exception reports for breached thresholds
Where this commonly fails
  • KPIs measure activity not outcomes
  • no escalation path when thresholds breached

Clause 7.3: Governance Processes

27014-7.3.1
Evaluate

Governance process that considers current and forecast achievement of objectives based on current processes and planned changes

Artefacts an auditor will ask for
  • Governance process map
  • Direction setting record
  • Monitoring dashboard
  • Assurance report
Where this commonly fails
  • EDM cycle broken
  • Direction not cascaded
  • Monitoring lagging
  • Assurance unreliable
27014-7.3.2
Direct

Governance process by which the governing body provides direction on objectives, strategy, resource allocation, and policy approvals

Artefacts an auditor will ask for
  • Governance process map
  • Direction setting record
  • Monitoring dashboard
  • Assurance report
Where this commonly fails
  • EDM cycle broken
  • Direction not cascaded
  • Monitoring lagging
  • Assurance unreliable
27014-7.3.3
Monitor

Governance process that enables the governing body to assess the achievement of its strategic objectives

Artefacts an auditor will ask for
  • Governance process map
  • Direction setting record
  • Monitoring dashboard
  • Assurance report
Where this commonly fails
  • EDM cycle broken
  • Direction not cascaded
  • Monitoring lagging
  • Assurance unreliable
27014-7.3.4
Communicate

Governance process ensuring clear messaging on security priorities throughout the organization

Artefacts an auditor will ask for
  • Governance process map
  • Direction setting record
  • Monitoring dashboard
  • Assurance report
Where this commonly fails
  • EDM cycle broken
  • Direction not cascaded
  • Monitoring lagging
  • Assurance unreliable
27014-7.3.5
Assure

Governance process confirming that security efforts deliver value and remain aligned with business needs

Artefacts an auditor will ask for
  • Governance process map
  • Direction setting record
  • Monitoring dashboard
  • Assurance report
Where this commonly fails
  • EDM cycle broken
  • Direction not cascaded
  • Monitoring lagging
  • Assurance unreliable

Clause 7: Governance Objectives and Processes

27014-7.2.1
Objective 1: Establish comprehensive information security

Establish integrated comprehensive entity-wide information security

Artefacts an auditor will ask for
  • Governance objectives
  • Decision register
  • Conformance report
  • Culture survey
Where this commonly fails
  • Objectives not cascaded
  • Decisions undocumented
  • Conformance gaps
  • Culture not measured
27014-7.2.2
Objective 2: Risk-based decision making

Make decisions using a risk-based approach to information security

Artefacts an auditor will ask for
  • Governance objectives
  • Decision register
  • Conformance report
  • Culture survey
Where this commonly fails
  • Objectives not cascaded
  • Decisions undocumented
  • Conformance gaps
  • Culture not measured
27014-7.2.3
Objective 3: Set direction of acquisition

Set the direction for investment in information security

Artefacts an auditor will ask for
  • Governance objectives
  • Decision register
  • Conformance report
  • Culture survey
Where this commonly fails
  • Objectives not cascaded
  • Decisions undocumented
  • Conformance gaps
  • Culture not measured
27014-7.2.4
Objective 4: Ensure conformance

Ensure conformance with internal and external requirements

Artefacts an auditor will ask for
  • Governance objectives
  • Decision register
  • Conformance report
  • Culture survey
Where this commonly fails
  • Objectives not cascaded
  • Decisions undocumented
  • Conformance gaps
  • Culture not measured
27014-7.2.5
Objective 5: Foster security-positive culture

Foster a security-positive environment across the organization

Artefacts an auditor will ask for
  • Governance objectives
  • Decision register
  • Conformance report
  • Culture survey
Where this commonly fails
  • Objectives not cascaded
  • Decisions undocumented
  • Conformance gaps
  • Culture not measured
27014-7.2.6
Objective 6: Performance relative to business outcomes

Ensure information security performance is related to business outcomes

Artefacts an auditor will ask for
  • Governance objectives
  • Decision register
  • Conformance report
  • Culture survey
Where this commonly fails
  • Objectives not cascaded
  • Decisions undocumented
  • Conformance gaps
  • Culture not measured

Communicate

27014-6.4
Communicate Process

Bi-directional communication between governing body, executive management, internal and external stakeholders on security posture, expectations and obligations.

Artefacts an auditor will ask for
  • stakeholder communication plan
  • samples of internal security updates and external disclosures
  • feedback logs from stakeholders
Where this commonly fails
  • one-way communication only top-down
  • external stakeholders excluded from communications plan
27014-9.1
Stakeholder Engagement

Identify, classify and engage internal and external stakeholders with interest in or influence on information security governance.

Artefacts an auditor will ask for
  • stakeholder register with classification
  • engagement plan with cadence and channels
  • records of engagement activities
Where this commonly fails
  • stakeholder list limited to internal parties
  • no review of engagement effectiveness
27014-9.2
Reporting to External Parties

Provide accurate and timely information security disclosures to regulators, customers, investors and the public as required.

Artefacts an auditor will ask for
  • disclosure policy
  • samples of regulatory filings and customer-facing security statements
  • review and approval workflow for disclosures
Where this commonly fails
  • disclosures released without board review
  • inconsistent statements across audiences

Conformance

27014-8.5
Conformance and Compliance

Ensure information security governance demonstrates conformance with internal policy and compliance with external legal and regulatory obligations.

Artefacts an auditor will ask for
  • legal and regulatory register
  • compliance attestations
  • conformance review reports to board
Where this commonly fails
  • regulatory register out of date
  • no board-level visibility of compliance status

Improvement

27014-10.1
Continual Improvement of Governance

Continually improve information security governance through review of effectiveness, lessons learned and adaptation to changing context.

Artefacts an auditor will ask for
  • annual governance review report
  • improvement action register
  • lessons learned from incidents fed into governance
Where this commonly fails
  • no formal governance review cycle
  • improvements stop at operational level

Integration

27014-8.1
Alignment with Enterprise Governance

Information security governance integrates with broader enterprise governance frameworks and risk management.

Artefacts an auditor will ask for
  • mapping of security governance to enterprise risk framework
  • shared committee structures
  • integrated reporting
Where this commonly fails
  • security governance operates in silo from enterprise risk
  • duplicate or contradictory reporting lines

Monitor

27014-8.4
Performance Measurement

Define and use measurements that demonstrate whether information security governance objectives are being achieved.

Artefacts an auditor will ask for
  • governance measurement framework
  • balanced scorecard for security
  • trend analysis over multiple reporting periods
Where this commonly fails
  • metrics drawn only from operational layer
  • no governance-level outcome metrics

Resources

27014-8.3
Resource Optimisation

Allocate resources to information security in proportion to risk and strategic priority, with periodic review of return on investment.

Artefacts an auditor will ask for
  • security investment portfolio
  • annual ROI or benefits realisation review
  • resource reallocation decisions tied to risk changes
Where this commonly fails
  • security funded by historic baseline not risk
  • no benefits tracking after project closure

Risk

27014-8.2
Risk Appetite and Tolerance

Governing body defines and communicates information security risk appetite and tolerance levels that guide all downstream decisions.

Artefacts an auditor will ask for
  • approved risk appetite statement for information security
  • tolerance thresholds by risk category
  • evidence of decisions referencing appetite
Where this commonly fails
  • risk appetite expressed in vague qualitative terms only
  • no review cadence for appetite statement

Roles

27014-7.1
Roles and Responsibilities of Governing Body

Define explicit responsibilities of the governing body for setting direction, accountability and oversight of information security.

Artefacts an auditor will ask for
  • board terms of reference covering security
  • RACI matrix for governance activities
  • induction materials for new board members
Where this commonly fails
  • security oversight assumed under audit committee with no explicit charter
  • no induction on security accountability for new directors
27014-7.2
Roles of Executive Management

Executive management implements direction from the governing body, operates the information security management system and reports performance upward.

Artefacts an auditor will ask for
  • executive committee charter referencing security
  • ISMS operating model showing executive sponsors
  • executive performance objectives linked to security
Where this commonly fails
  • CISO reports only to CIO with no executive committee visibility
  • executives lack security accountability in their objectives
27014-7.3
Relationship Between Governing Body and Management

Establish a clear separation and working relationship between governance (direction setting) and management (execution) for information security.

Artefacts an auditor will ask for
  • documented interface between board and executive on security matters
  • escalation procedures
  • joint planning calendars
Where this commonly fails
  • board members involved in operational security decisions
  • no defined escalation triggers from management to board
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.