Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 27001 audit preparation covering documentation, evidence, internal audit and common findings

How to Prepare for an ISO 27001 Audit

The ISO 27001 audit is the moment your Information Security Management System is put to the test. Whether it is your internal audit or the certification body’s assessment, good preparation is the difference between a smooth result and a scramble to close findings. This guide explains what the audit checks, the types of audit, and exactly how to prepare.

ISO 27001 audit preparation covering documentation, evidence, internal audit and common findings

For the full context, see our complete ISO 27001 guide.

What an ISO 27001 audit checks

An ISO 27001 audit assesses whether your ISMS both conforms to the standard and is genuinely implemented. Auditors examine your mandatory documentation — scope, policy, risk assessment, Statement of Applicability — and then look for evidence that your selected controls are operating. They interview staff, sample records, and check that you monitor, review, and improve the system. In short, the audit tests not just that the ISMS exists on paper, but that it works in practice.

Internal audit vs certification audit

ISO 27001 requires you to run your own internal audits before certification — a self-assessment that surfaces gaps while you still have time to fix them. The certification audit, carried out by an accredited body, comes in two stages: Stage 1 reviews your documentation and readiness, and Stage 2 tests implementation in depth. Treating the internal audit seriously is the single best way to walk into Stage 2 with confidence.

How to prepare for your ISO 27001 audit

  • Confirm your documentation is complete — scope, policy, risk assessment, risk treatment plan, and Statement of Applicability all present and current.
  • Gather evidence that each selected control is operating — logs, tickets, training records, review minutes.
  • Run a thorough internal audit and close any nonconformities before the certification body arrives.
  • Hold a management review so leadership has formally assessed the ISMS.
  • Brief your team — auditors will interview staff, so people should understand their security responsibilities.
  • Prepare your evidence to be easy to find — a well-organised evidence pack speeds the audit and builds auditor confidence.

Common audit findings to avoid

The most frequent nonconformities are a Statement of Applicability that does not match reality, controls that are documented but not operating, missing or out-of-date records, an internal audit that was never completed, and no evidence of management review. Addressing these five areas before your audit removes the majority of typical findings and gives you the best chance of a clean result.

Walk into your audit prepared.

Our ISO 27001 Toolkit includes internal audit checklists, management-review templates, and every policy and record an auditor expects — mapped to ISO 27001:2022 and editable in Word and Excel.

Explore the ISO 27001 Toolkit →

Frequently asked questions

What happens in an ISO 27001 audit?

Auditors review your ISMS documentation and then test implementation — interviewing staff, sampling records, and checking that your selected controls operate and that you monitor and improve the system.

What is the difference between Stage 1 and Stage 2 audits?

Stage 1 reviews your documentation and readiness; Stage 2 tests how well the ISMS is implemented in practice. Both are carried out by the certification body.

How do I prepare for an ISO 27001 audit?

Complete your documentation, gather evidence that controls operate, run an internal audit and management review to close gaps, and brief your team on their security responsibilities.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.