Hunting for evidence in audit week is the most expensive form of compliance work. This guide covers the practical way to manage evidence continuously, as part of the work, rather than just before the audit.
What does the auditor look at?
ISO/IEC 27001:2022 has two layers. The first is the management system requirements: context, leadership, planning, support, operation, performance evaluation and improvement (clauses 4–10). The second is the Annex A controls; the 2022 edition has 93 controls grouped under four themes: organisational, people, physical and technological.
An auditor is not satisfied that a control exists on paper. They want to see that it operates as designed, through records produced over a period. Evidence therefore comes in two kinds: design evidence (policy, procedure) and operating evidence (records, minutes, logs).
Start from the Statement of Applicability
The Statement of Applicability (SoA) shows which Annex A controls apply, which are excluded and why. Your evidence plan should derive from it: every control the SoA says is applied needs at least one defined piece of operating evidence.
Define the evidence for each control up front
Define evidence when the control is designed, not on audit day. For each control these five things should be clear:
- Design evidence: the policy or procedure that defines the control
- Operating evidence: the kind of record that shows it working
- Owner: the person who produces the evidence and keeps it current
- Frequency: how often the record must be renewed
- Validity: the date after which the evidence counts as stale
Track currency through evidence, not the calendar
If access reviews are quarterly, the auditor will want last quarter's record. Stale evidence becomes a finding on audit day. Tracking when each item was last produced and when the next one is due turns "are we ready?" from a guess into a fact.
Internal audit, management review and corrective action
Clauses 9 and 10 of the standard require the management system to audit itself and close its findings. Every nonconformity raised in an internal audit should be recorded with its root cause, corrective action, owner and closure evidence. A finding closed without evidence reopens at the next audit.
Common mistakes
The four mistakes we see most often in the field:
- Trying to produce all evidence at once just before the audit
- Different versions of the same document circulating in different folders
- Controls without a defined owner
- Counting a finding as closed without closure evidence
Audit readiness is not a last-minute project but an operation where control, evidence and ownership are managed together every day.
This guide is for general information and does not replace the assessment of your certification body or consultant.
All resources