ClausePass27001 Toolkit 2.0 is available
See what is included in the current toolkit release.
View pricingLoading page…
Assurance and improvement
You have policies and audit dates, but weak evidence, repeated findings, or management-review minutes that never change the work.
The short answer
Internal audit is an independent, documented evaluation of evidence against defined criteria. Management review is top management's decision process about the ISMS's suitability, adequacy, effectiveness, resources, risks, and required changes. Connect them through corrective action, but do not treat them as the same activity.
Published by ClausePass2700116 minute readUpdated 2026-09-04Part of the free 134-page implementation manual
Instant PDF. No email or account required.
Operating an ISMS creates many records. Performance evaluation begins when the organization decides which question a record can answer, how the result will be examined, who receives it, and what response follows. Counting what is easy can hide the condition management actually needs to see.
Monitoring, measurement, control testing, management reporting, and internal audit may inspect some of the same sources, but they do different jobs. Monitoring determines status through observation or critical review. Measurement determines a value under a defined method. Internal audit is the organization's systematic, independent, documented evaluation of evidence against audit criteria. Management review uses current inputs to decide whether the ISMS and its direction need to change.
Keep those activities distinguishable and connect their outputs. A weak result may produce a correction, a nonconformity, a risk update, or a management decision. The route should depend on the facts and applicable criterion, not on the title of the meeting where the issue appeared.
An objective should name the result that matters; a measure should retain the method needed to reproduce and interpret it.
| Element | Question to answer |
|---|---|
| Intended result | What condition should change, for whom or what, and why? |
| Population and boundary | Which services, roles, systems, suppliers, locations, or cases are included? |
| Baseline | Which current result is supported, over what period, and by which source? |
| Indicator | Which value or observed condition reveals progress or deterioration? |
| Method | How are data collected, validated, calculated, analysed, and reported? |
| Criterion | Which value, range, trend, deadline, or condition requires a response? |
| Ownership | Who owns the result, supplies the data, checks quality, and acts? |
| Resources and timing | Which capacity, system, budget, or dependency is needed, and when? |
| Limitations | Which exclusions, latency, uncertainty, or quality issue affects interpretation? |
| Action route | What happens when the result misses the criterion or the measure becomes misleading? |
For a percentage, retain its numerator, denominator, period, extraction time, exclusions, treatment of missing and disputed records, validation checks, and source query. A strong-looking percentage can be unreliable when its population is incomplete.
Send proof of access control is not a usable request. State the proposition, control or process, population, period, expected source, required fields, handling restrictions, and whether review needs a sample or the full population.
| Quality test | Question |
|---|---|
| Relevance | Does the source address the stated criterion, control, population, and period? |
| Authority | Who or what produced it, and is that source authoritative for the fact? |
| Completeness | Is the population complete, or are the sample and exclusions known? |
| Timing | Was it created during the activity, reconstructed later, or extracted for review? |
| Integrity | Can inappropriate alteration be detected or reasonably controlled for this use? |
| Consistency | Does it agree with linked systems and maintained records? |
| Accessibility | Can an authorized reviewer retrieve it without a private account or expired link? |
| Interpretability | Are fields, states, calculations, time zones, and limitations understood? |
A screenshot may establish a setting at one moment; it rarely proves coverage across a population or period. A procedure establishes intended design, not operation. When evidence is weak, seek corroboration or narrow the conclusion. Do not make the wording stronger.
The program coordinates audits across a defined period. It should cover the full approved ISMS scope and applicable criteria over time, but it does not need to give every clause, control, process, or department equal attention.
At the guide's source-check date, ISO 19011:2026 was the current general guideline for management-system audit programs and audits, including remote auditing and virtual locations. ISO/IEC 27007:2020 remained the published information-security-specific audit guidance while revision work was underway. Use the editions adopted by the organization and recheck their status. Neither guidance document replaces the internal-audit requirements in ISO/IEC 27001.
Objectives state what the audit is intended to accomplish. Scope sets its organizational, process, technology, place, and time boundaries. Criteria are the controlled requirements against which evidence will be compared.
| Plan area | What to establish |
|---|---|
| Objectives | The conformity, implementation, maintenance, effectiveness, or finding-follow-up question assigned to the engagement. |
| Scope | Functions, activities, processes, systems, services, physical or virtual locations, and the period examined. |
| Criteria | The relevant management-system requirement, controlled internal direction, applicable external obligation, or approved control specification. |
| Process route | The event that starts the process, its input and authority, operation, maintained result, owner review, and failed route. |
| Evidence plan | The population, source, method, sample rationale, confidentiality controls, and expected limitations. |
| Reporting | Finding categories, factual-review route, authorized recipients, escalation, and follow-up. |
Do not list the entire standard as criteria for a narrow engagement. Use the current controlled criteria relevant to the assigned scope. A checklist is a memory aid, not a barrier to following relevant evidence within scope.
Determine competence across audit practice, information security subject matter, organizational context, evidence evaluation, communication, and any sector or legal knowledge the engagement requires. Retain how competence was established and evaluated.
Auditors should not audit their own work or make management decisions for the process under review. In a small organization, a cross-functional auditor, careful scope assignment, external specialist, or independent review can reduce a conflict. Record the actual conflict and safeguard rather than claiming structural independence the organization does not have.
An auditor can identify a gap and explain the evidence. Process management owns correction and corrective action. If an auditor designed or implemented the response, give later verification to someone able to challenge it objectively.
Preserve the population source and the auditor's selection. Include relevant variation rather than accepting only the process owner's strongest examples.
| Sampling decision | What to record |
|---|---|
| Frame | The population and the unit from which records are selected. |
| Method | Random, judgmental, or combined selection and the reason it fits the objective. |
| Extent | Sample size, period, locations, systems, roles, or other material coverage. |
| Variation | Normal and emergency routes, successful and failed outcomes, privilege, classification, supplier, time, or location contrasts. |
| Interpretation | Known limits and the boundary of conclusions supported by the sample. |
| Expansion | Why and how the sample changed when evidence suggested a wider issue. |
One record can establish a factual failure in that case. A broader conclusion must fit the criterion, population, corroborating evidence, process design, and stated sampling limits.
Use interviews, observation, controlled documents, data analysis, system inspection, and maintained records according to the proposition. Corroborate material statements and collect no more sensitive detail than the audit needs.
An audit conclusion answers the engagement objectives within its scope and the evidence obtained. A limited internal audit is not a declaration that the whole ISMS conforms or is ready for certification. Transfer accepted findings with stable references, and verify follow-up from evidence rather than a status email.
A nonconformity is the non-fulfilment of a requirement. An operational problem is not automatically a nonconformity, and one event may create several linked records.
| Response | Question it answers |
|---|---|
| Containment | How is immediate harm, unreliable information, or loss of control limited? |
| Correction | How is the detected error or nonconformity removed for the affected case? |
| Extent review | Which period, population, service, location, technology, or provider may share the condition? |
| Cause analysis | Why was the requirement not fulfilled, and why did the system not prevent or detect it earlier? |
| Corrective action | Which supported cause must be removed to prevent recurrence? |
| Implementation verification | Was the approved action delivered for the intended population and effective date? |
| Effectiveness review | Did the action address the cause and prevent recurrence under stated conditions? |
| Consequential change | Must risk, treatment, scope, a control, an objective, or a controlled document also change? |
The named technique matters less than the evidence and reasoning. Repeated why questions, a causal tree, barrier analysis, or technical fault analysis may help, but do not choose the explanation in advance.
Choose corrective action that addresses the supported cause and affected extent. Name an owner with delivery authority, specify resources and dependencies, set a completion condition, and identify the record that will prove implementation. Consider unintended effects before release: a stricter measure may delay recovery, create an unsafe workaround, or move activity into an unmonitored route.
Implementation verification and effectiveness review are separate. The first establishes that the approved change was delivered. The second asks whether it addressed the cause and prevented recurrence for a defined population and observation period. Decide the evidence, criterion, reviewer, and failure route before seeing the result.
Allow enough time in normal operation. A quarterly process cannot be judged from a next-day screenshot. Simulations and design inspections can test limited propositions for rare events, but they do not become evidence that the next real event operated successfully. If the effectiveness result fails or remains inconclusive, reopen the case or create a linked one; do not relax the criterion after seeing the result.
Management review is a top-management decision process, not a presentation ceremony. An existing governance meeting can perform it when the agenda, authority, inputs, decisions, and retained record are suitable.
For each subject, state the current condition, trend, evidence period and population, consequence, uncertainty, options, and decision required. Link to the authoritative source instead of copying every register onto slides.
| Decision field | Required record |
|---|---|
| Conclusion | What management approved, rejected, changed, postponed, or escalated and the relevant rationale. |
| Accountability | The owner of resulting work and the authority available to deliver it. |
| Commitment | Resource, timing, and due date. |
| Condition | Any assumption, limit, expiry, or prerequisite attached to the decision. |
| Follow-up | How and when completion or an adverse result returns to governance. |
If the group lacks authority, record the escalation destination and interim control. Management noted the report is not a substitute for a decision when change is required.
Measures retain their populations and calculation methods. Audit findings remain tied to criteria and evidence. Correction controls the immediate case; corrective action follows supported causes. Effectiveness is evaluated after enough time in normal operation. Management-review records contain decisions and owned actions rather than slide summaries. Improvement then returns to ordinary governance, and any certification-readiness decision receives the current scope, SoA, audit results, review decisions, open findings, and limits on the available evidence.
This chapter is ClausePass27001 implementation guidance. It does not reproduce the standard, decide conformity, or replace competent legal, technical, audit, or certification advice. Check the current authorized sources before relying on a version-sensitive point.