Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 27001 assessment questions infographic

ISO 27001 Assessment Questions: The Essential 2026 List to Test Your ISMS

The best ISO 27001 assessment questions are the ones an auditor would ask you, asked earlier, by someone who wants you to pass. A well-run internal assessment exposes missing records, unclear ownership and controls that exist on paper only, while there is still time to fix them.

This guide gives you a practical question set organized the way the standard is organized: the management system clauses 4 to 10 first, then the Annex A controls. For each group you get the questions, what a good answer looks like and the evidence to have ready. Use it for a readiness review, an internal audit, a supplier check or a board briefing. Scores and timelines are yours to set; nothing here is a prediction of an audit result.

Free gap assessment

Where do you actually stand against ISO 27001?

Score every management system clause and all 93 Annex A controls, free, and get a prioritised gap list back.

Run the free ISO 27001 gap assessment →  or  View premium report sample

How to use ISO 27001 assessment questions

An assessment is only useful if the answers are honest and the evidence is real. Ask each question, record the answer, then ask to see the record that proves it. Score each item on a simple scale, for example not started, partial, implemented and evidenced, then assign an owner and a date to every gap.

Keep three rules. Ask open questions that require an explanation, not yes or no. Ask the person who performs the task, not only the manager. And sample across time: a control that worked last week may not have worked last quarter. The same discipline applies whether you use a spreadsheet or the ISO 27001 self-assessment approach described on our site.

ISO 27001 assessment questions for clauses 4 and 5: context and leadership

Clause 4 asks you to understand your organization, its interested parties and its ISMS scope. Clause 5 covers leadership commitment, policy and roles. Ask the following.

  • What internal and external issues affect information security, and where are they recorded?
  • Which customers, regulators and contracts impose security requirements?
  • Is the ISMS scope written down, including boundaries and exclusions with reasons?
  • Who is the top management sponsor, and what decisions have they made about security?
  • Is the information security policy approved, communicated and reviewed?
  • Are roles and responsibilities for the ISMS assigned and known to the people holding them?

ISO 27001 assessment questions for clause 6: risk and the Statement of Applicability

Clause 6 is where many assessments find the largest gaps. The standard requires a defined risk assessment process, risk treatment and a Statement of Applicability under clause 6.1.3. Ask the questions below and look for dated, approved records.

Free ISO 27001 risk assessment

Which of your risks sit above your appetite line?

Set your own risk criteria, pick from 61 information security risk scenarios, rate likelihood and impact, and decide how to treat each one. You get a heat map, a process score and the findings an auditor would raise, free.

Run the free risk assessment →  or  View premium report sample

ClauseThemeSample questionEvidence to show
4ContextWhich interested parties and requirements shape the ISMS scope?Context register, scope statement
5LeadershipWho approved the policy and when?Signed policy, management minutes
6PlanningHow are risks assessed and treated?Risk methodology, register, treatment plan, SoA
7SupportAre people competent and aware?Training records, competence matrix
8OperationAre planned controls operating?Procedures, logs, tickets
9EvaluationHas the ISMS been audited and reviewed?Internal audit report, review minutes
10ImprovementHow are nonconformities fixed?Corrective action log
  • What criteria do you use to rate likelihood and impact, and who approved them?
  • Is there a current risk register, and when was the last review?
  • Are risk owners named, and did they accept residual risk?
  • Does the risk treatment plan have dates, owners and budgets?
  • Does the Statement of Applicability list every Annex A control, with inclusion status and justification?
  • Are information security objectives measurable, and is progress tracked?
  • How are changes to the ISMS planned?

Clauses 7 to 10: support, operation, evaluation and improvement

These clauses show whether the system lives. Support covers resources, competence, awareness, communication and documented information. Operation covers running the plans. Evaluation covers monitoring, internal audit and management review. Improvement covers nonconformity and corrective action.

Good questions include: How do you decide what resources the ISMS needs? How is competence verified for security-critical roles? Where is documented information controlled and who can change it? Which metrics do you monitor and who reads them? When was the last internal audit, and what did it find? Did the last management review cover all required inputs? Which corrective actions are still open and why? An auditor will probe each of these, so practice the answers with the people who will give them.

ISO 27001 assessment questions for Annex A controls

ISO 27001:2022 has 93 Annex A controls in four themes: 37 organizational, 8 people, 14 physical and 34 technological. You do not have to implement all of them, but you must consider each one and justify exclusions in the Statement of Applicability. For the full list see our guide on the ISO 27001 control assessment.

Choose questions that test operation, not just existence. Examples by theme:

  • Organizational: How do you classify information, and how is the supplier security requirement enforced in contracts?
  • People: Are background checks, security training and disciplinary processes applied consistently?
  • Physical: Who can enter secure areas, and when were access rights last reviewed?
  • Technological: Is multi-factor authentication enforced, how quickly are critical patches applied and where are logs reviewed?
  • Incident response: When was the plan last tested and what changed afterward?
  • Continuity: Have backups been restored in a test within the past year?

Scoring your ISO 27001 assessment questions

Use a scoring model you can explain. A common approach gives zero for not started, one for documented but not operating, two for operating with some evidence and three for operating with consistent, reviewed evidence. Average by clause or control theme, then chart the result so leadership can see where to invest. Scores are a management tool; they are not audit outcomes, and a certification body will draw its own conclusions.

Prioritize gaps by risk, not by count. One missing risk assessment method is more serious than five missing signatures. For the relationship between maturity scoring and readiness, read ISO 27001 maturity assessment and ISO 27001 gap assessment.

Using a tool to run the assessment

A structured tool saves time because it keeps the questions, the answers, the evidence links and the scores in one place. The ISO 27001 Assessment Tool gives you a ready question set and scoring, so you can spend your time on fixing gaps instead of building a spreadsheet. If you then need policies and procedures to close the gaps, the full documentation toolkit can follow.

For a supplier version of the exercise, see ISO 27001 supplier assessment. For the authoritative text of the standard and the current edition, consult the ISO/IEC 27001 standard page. Remember that the transition from the 2013 edition to 2022 closed on 31 October 2025, so any certificate in force should already reference the 2022 edition.

Turning assessment results into an action plan

Once the scores are in, sort the gaps into three groups: blockers that would cause a major nonconformity, such as a missing risk assessment or Statement of Applicability, quick wins that need only a document or an approval, and longer projects such as deploying a new control. Give every item an owner and a date, and put the blockers on the management review agenda. If you want a sense of how long the work takes, see our ISO 27001 timeline guide, and use the ISO 27001 readiness assessment article to decide when to book the certification audit.

Re-run the assessment after the fixes and compare scores. The change between rounds is the evidence of progress that leadership wants, and it is also the record that shows an auditor your ISMS is improving. Comparing tools is worth a short look too; our page on ISO 27001 tools explains what to expect from software. Keep each round of answers, scores and evidence links in a dated folder so you can reproduce the result later.

Sample evidence requests to pair with each question

A question without an evidence request invites a confident answer and nothing else. Pair each one with a specific request: for risk, ask to see the register export with its last review date; for access control, ask for the latest quarterly access review and the tickets that removed rights; for supplier security, ask for two recent supplier assessments and the contract clauses that flow requirements down; for incident management, ask for the last incident record and the lessons-learned note; for backups, ask for the log of the most recent restore test. Keep these requests in the same sheet as the questions so the reviewer can tick them off in one pass and nothing is lost between sessions.

Common mistakes when using ISO 27001 assessment questions

Teams tend to answer from memory, which produces optimistic scores. They forget to collect evidence. They assess only the technology and skip governance. And they do one assessment and never repeat it, so the scores age. Repeat the review at least before each audit, and after any major change in systems, people or suppliers.

Finally, do not let the person who built the controls score them alone. Independence improves accuracy, and an honest gap found today costs far less than a nonconformity found by an external auditor.

ISO 27001 Assessment Questions FAQ

How many ISO 27001 assessment questions should I ask?

Enough to cover every clause from 4 to 10 and each Annex A theme. Many teams use between 50 and 150 questions depending on scope and size.

Who should run the assessment?

A person independent of the control owners, such as an internal auditor or external consultant, using a consistent scoring method.

Is an assessment the same as an audit?

No. An internal assessment is a management tool. An internal audit under clause 9.2 is a formal, planned activity, and certification audits are performed by accredited bodies.

How often should I repeat it?

At least before each certification or surveillance audit, and after major changes to scope, systems or suppliers.

Do I need to assess all 93 Annex A controls?

You must consider all of them and record in the Statement of Applicability whether each is applicable and why, but you only implement the ones your risk treatment requires.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.