Reviewed by the Aegentra Security Team — NV1-cleared ISO 27001 practitioners · Updated May 2026
A working ISO 27001 implementation checklist for Australian businesses — every mandatory document, the clause-by-clause readiness checks, what Stage 1 and Stage 2 auditors actually ask for, and a 12-week timeline that reflects how long certification bodies really take to book.
There is no official ISO 27001 checklist, and there cannot be one. Which controls you need depends on your scope and your risk assessment, so any list that claims to be definitive is selling something. What is fixed: the clause structure (4 to 10 are mandatory and cannot be excluded), the mandatory documented information listed in the standard, the requirement to compare your controls against all 93 Annex A controls, and the requirement to run an internal audit and a management review before certification.
Use this as a planning aid alongside your risk assessment. For the control catalogue itself, see the full Annex A control list. For costs and the wider certification picture, see the ISO 27001 certification guide for Australia.
ISO/IEC 27001:2022 names the documented information you must hold. Everything beyond this list is required only where you need it to control your processes — which is why a 200-page policy set is usually a sign of over-engineering, not diligence.
| Clause | Document | What the auditor is checking |
|---|---|---|
| 4.3 | ISMS scope | What is in and out, and why. The first thing every auditor reads. |
| 5.2 | Information security policy | Short, approved by top management, communicated to staff. |
| 6.1.2 | Risk assessment process | The method, not the output. Must be repeatable and produce consistent results. |
| 6.1.3 | Risk treatment process | How you decide to modify, retain, avoid or share each risk. |
| 6.1.3d | Statement of Applicability | All 93 Annex A controls with justification either way. The most-examined document. |
| 6.1.3e | Risk treatment plan | What is being done about each unacceptable risk, by whom, by when. |
| 6.2 | Information security objectives | Measurable, with plans to achieve them. |
| 7.2 | Evidence of competence | Training records, certifications, role descriptions. |
| 8.1 | Operational planning records | Evidence that planned processes are being carried out as planned. |
| 8.2 / 8.3 | Risk assessment and treatment results | The risk register, kept current, with review dates. |
| 9.1 | Monitoring and measurement results | What you measure, how often, who reviews it, and the numbers. |
| 9.2 | Internal audit programme and results | A programme covering the whole ISMS, plus reports from audits performed. |
| 9.3 | Management review results | Minutes showing decisions. Must predate Stage 2. |
| 10.2 | Nonconformities and corrective actions | A log with root cause and verification of effectiveness. |
Auditors fail more organisations on the clauses than on Annex A, because the clauses are where the management system either runs or does not.
Clause 4 — Context. Internal and external issues documented; interested parties and their requirements identified; ISMS scope defined, justified and documented.
Clause 5 — Leadership. Top management demonstrably supports the ISMS through minutes, budget and sign-off; the information security policy is approved and communicated; roles, responsibilities and authorities are assigned and understood.
Clause 6 — Planning. Risks and opportunities to the ISMS itself are addressed; the risk assessment has been performed using the documented method; the Statement of Applicability covers all 93 controls; measurable objectives exist with plans to achieve them.
Clause 7 — Support. Resources allocated; competence evidenced through training records; staff aware of the policy and their contribution; documented information version-controlled and access-controlled.
Clause 8 — Operation. Planned processes carried out with records; risk assessments performed at planned intervals and on significant change; the risk treatment plan being executed.
Clause 9 — Performance evaluation. What is monitored, when, by whom, and the results; internal audits performed to a programme with reports; management review held covering every required input.
Clause 10 — Improvement. Nonconformities logged with root cause analysis; corrective actions taken and verified as effective; evidence the ISMS is continually improved.
Both must have happened before your Stage 2 audit, with dated records. This is the single most common reason a certification slips — the work is done, but there is no evidence the organisation checked itself first. Evidence cannot be backdated.
The internal audit needs a programme showing the whole ISMS gets covered over time, auditors independent of the area being audited, documented criteria and scope, a report with findings and nonconformities raised where found, and corrective actions with root cause and verified effectiveness. The management review must cover every clause 9.3 input and the minutes must show decisions, not attendance. If you want the internal audit run independently, that is what our ISO 27001 internal audit service does.
Stage 1 asks whether the system exists and is coherent. It is a documentation review and normally produces findings you must close before Stage 2.
Stage 2 asks whether the system runs. The auditor samples evidence and interviews people — documents alone will not carry it.
For an Australian SMB of 10–50 staff on Microsoft 365. Stage 1 follows immediately; Stage 2 lands roughly four weeks later, so kickoff to certificate is typically 16–20 weeks.
Weeks 1–2 — Scope, gap analysis, audit booking. Define and document the ISMS scope; run a gap analysis against clauses 4–10 and Annex A; appoint the ISMS owner and confirm management commitment; book the certification body, which is the long-lead item.
Weeks 3–4 — Risk assessment. Build the asset and information inventory; document the risk assessment method and risk criteria; run the assessment and produce the risk register; get risk owners to accept residual risk in writing.
Weeks 5–6 — Statement of Applicability and treatment plan. Work through all 93 Annex A controls justifying each inclusion and exclusion; write the risk treatment plan with owners and dates; draft the information security policy and set measurable objectives.
Weeks 7–9 — Control implementation. Implement technical controls covering access, logging, monitoring, backup and patching; publish supporting policies and operating procedures; run staff awareness training and record attendance; update supplier agreements with security clauses.
Weeks 10–11 — Internal audit and management review. Run the internal audit against the full ISMS; log nonconformities and complete corrective actions with root cause; hold the management review with all clause 9.3 inputs.
Week 12 — Stage 1 readiness. Assemble the evidence pack against the mandatory documents list; dry-run the auditor interviews with control owners; confirm every record predates the audit date.
Six failure modes account for most slipped certifications, and none of them are technical. Booking the audit too late — certification bodies need 6–10 weeks, so book in week 1. Treating the Statement of Applicability as paperwork — exclusions with no justification are the most common Stage 1 finding. Skipping the internal audit — clause 9.2 is not optional and must precede Stage 2. Running it entirely out of IT — only 34 of 93 controls are technical; HR owns screening and offboarding, legal owns supplier clauses, management owns the review. Writing policies nobody follows — Stage 2 samples reality, and a policy promising quarterly access reviews with no evidence of one is worse than no policy. A risk register written once — auditors check revision dates.
The common thread is ownership. Programmes succeed when one named person owns the ISMS and has the authority to get evidence out of other teams. Training that person as a PECB ISO 27001 Lead Implementer is the cheapest way to buy that capability; the Lead Auditor course teaches the other side — how each of these checks gets tested. To have it done for you, see our ISO 27001 consulting and implementation service.