ISO 27001 checklist: implementation, documents and audit readiness
Written by Harry Sidhu, Director and Principal Consultant, Aegentra. Last reviewed .
A working ISO 27001 implementation checklist for Australian organisations: documented information, Clauses 4–10, risk-selected Annex A controls, internal audit, management review, Stage 1 and Stage 2. This is a planning aid, not a substitute for the organisation’s risk assessment or the standard.
How to use this checklist
Risks come first; Annex A is the cross-check, not the starting point.
There is no official ISO 27001 checklist, and there cannot be one. Which controls you need depends on your scope and your risk assessment, so any list that claims to be definitive is selling something. What is fixed: the clause structure (4 to 10 are mandatory and cannot be excluded), the mandatory documented information listed in the standard, the requirement to compare your controls against all 93 Annex A controls, and the requirement to run an internal audit and a management review before certification.
Use this as a planning aid alongside your risk assessment. For the control catalogue itself, see the full Annex A control list. For costs and the wider certification picture, see the ISO 27001 certification guide for Australia.
The mandatory documents checklist
ISO/IEC 27001:2022 names the documented information you must hold. Everything beyond this list is required only where you need it to control your processes — which is why a 200-page policy set is usually a sign of over-engineering, not diligence.
| Clause | Document | What the auditor is checking |
|---|---|---|
| 4.3 | ISMS scope | What is in and out, and why. The first thing every auditor reads. |
| 5.2 | Information security policy | Short, approved by top management, communicated to staff. |
| 6.1.2 | Risk assessment process | The method, not the output. Must be repeatable and produce consistent results. |
| 6.1.3 | Risk treatment process | How you decide to modify, retain, avoid or share each risk. |
| 6.1.3d | Statement of Applicability | All 93 Annex A controls with justification either way. The most-examined document. |
| 6.1.3e | Risk treatment plan | What is being done about each unacceptable risk, by whom, by when. |
| 6.2 | Information security objectives | Measurable, with plans to achieve them. |
| 7.2 | Evidence of competence | Training records, certifications, role descriptions. |
| 8.1 | Operational planning records | Evidence that planned processes are being carried out as planned. |
| 8.2 / 8.3 | Risk assessment and treatment results | The risk register, kept current, with review dates. |
| 9.1 | Monitoring and measurement results | What you measure, how often, who reviews it, and the numbers. |
| 9.2 | Internal audit programme and results | A programme covering the whole ISMS, plus reports from audits performed. |
| 9.3 | Management review results | Minutes showing decisions. Must predate Stage 2. |
| 10.2 | Nonconformities and corrective actions | A log with root cause and verification of effectiveness. |
Clause 4–10 readiness checklist
Clauses 4–10 cover the management-system requirements. Review both the documented arrangements and the evidence that those arrangements operate in practice.
If you are learning before applying the checklist, start with the PECB ISO 27001 Foundation course and use the free Clauses 4–10 study map as a plain-English companion.
Clause 4 — Context. Internal and external issues documented; interested parties and their requirements identified; ISMS scope defined, justified and documented.
Clause 5 — Leadership. Top management demonstrably supports the ISMS through minutes, budget and sign-off; the information security policy is approved and communicated; roles, responsibilities and authorities are assigned and understood.
Clause 6 — Planning. Risks and opportunities to the ISMS itself are addressed; the risk assessment has been performed using the documented method; the Statement of Applicability covers all 93 controls; measurable objectives exist with plans to achieve them.
Clause 7 — Support. Resources allocated; competence evidenced through training records; staff aware of the policy and their contribution; documented information version-controlled and access-controlled.
Clause 8 — Operation. Planned processes carried out with records; risk assessments performed at planned intervals and on significant change; the risk treatment plan being executed.
Clause 9 — Performance evaluation. What is monitored, when, by whom, and the results; internal audits performed to a programme with reports; management review held covering every required input.
Clause 10 — Improvement. Nonconformities logged with root cause analysis; corrective actions taken and verified as effective; evidence the ISMS is continually improved.
Internal audit and management review
Both activities must be completed before Stage 2, with dated records. Missing or incomplete records can delay readiness because the organisation cannot show that it checked the ISMS before certification. Evidence cannot be backdated.
The internal audit needs a programme showing the whole ISMS gets covered over time, auditors selected so competence, objectivity and impartiality are protected, without auditing their own work, documented criteria and scope, a report with findings and nonconformities raised where found, and corrective actions with root cause and verified effectiveness. The management review must cover every clause 9.3 input and the minutes must show decisions, not attendance. If a separately appointed audit is the clearest way to protect objectivity and impartiality, review Aegentra’s independent ISO 27001 internal-audit service.
Stage 1 audit checklist
Stage 1 asks whether the system exists and is coherent. It is a documentation and readiness review and may produce findings that need to be addressed before Stage 2.
- ISMS scope is documented and defensible
- Information security policy is approved and communicated
- Risk assessment method is documented and has been applied
- Statement of Applicability covers all 93 controls with justifications
- Risk treatment plan exists with owners and target dates
- Information security objectives are measurable
- Internal audit has been performed and reported
- Management review has been held and minuted
- Mandatory documented information is complete and version-controlled
Stage 2 audit checklist
Stage 2 asks whether the system runs. The auditor samples evidence and interviews people — documents alone will not carry it.
- Access reviews have actually been performed, with records
- Logs are being generated, retained and reviewed — not just enabled
- Backups have been restored and tested, not merely scheduled
- Vulnerabilities are remediated inside your stated timeframes
- Staff can describe how to report a security incident
- Supplier agreements contain the security clauses you claim
- Onboarding and offboarding evidence matches your procedure
- Corrective actions from the internal audit are closed and verified
- Control owners can explain their controls without reading the policy
An illustrative readiness sequence
Aegentra may target an approximately 12-week implementation programme for an appropriately scoped, Microsoft 365-first organisation with sufficient leadership availability and no major remediation blockers. This is a planning assumption, not a guarantee. Timing depends on the ISMS boundary, starting maturity, technical complexity, evidence availability, client decisions, remediation, internal-audit arrangements and the certification body’s schedule. The written proposal records the actual delivery plan and dependencies.
Practical readiness pitfalls
These six avoidable failure modes can delay certification readiness. Most concern ownership, planning and evidence rather than technology. Booking the audit too late — contact prospective certification bodies early and confirm their availability, readiness requirements and proposed Stage 1 and Stage 2 dates. Treating the Statement of Applicability as paperwork — record and review the reasons for your applicability decisions, including the justification for excluded Annex A controls. Skipping the internal audit — clause 9.2 is not optional and must precede Stage 2. Running it entirely out of IT — only 34 of 93 controls are technical; HR owns screening and offboarding, legal owns supplier clauses, management owns the review. Writing policies nobody follows — Stage 2 samples reality, and a policy promising quarterly access reviews with no evidence of one is worse than no policy. A risk register written once — auditors check revision dates.
The common thread is ownership. Programmes succeed when one named person owns the ISMS and has the authority to get evidence out of other teams. Training that person as a PECB ISO 27001 Lead Implementer is a practical way to buy that capability; the Lead Auditor course teaches the other side — how each of these checks gets tested. To have it done for you, see our ISO 27001 consulting and implementation service.
Frequently asked questions
What documents are mandatory for ISO 27001 certification?
ISO/IEC 27001:2022 requires specific documented information: the ISMS scope (4.3), information security policy (5.2), risk assessment and risk treatment processes (6.1.2, 6.1.3), the Statement of Applicability (6.1.3d), the risk treatment plan (6.1.3e), information security objectives (6.2), evidence of competence (7.2), results of risk assessment and treatment (8.2, 8.3), monitoring and measurement results (9.1), the internal audit programme and its results (9.2), management review results (9.3), and records of nonconformities and corrective actions (10.2). Everything else — individual policies and procedures — is required only where you need it to control your processes.
How long does ISO 27001 readiness take for an Australian SMB?
Aegentra may target an approximately 12-week implementation programme for an appropriately scoped, Microsoft 365-first organisation with sufficient leadership availability and no major remediation blockers. This is a planning assumption, not a guarantee. Timing depends on the ISMS boundary, starting maturity, technical complexity, evidence availability, client decisions, remediation, internal-audit arrangements and the certification body’s schedule. The written proposal records the actual delivery plan and dependencies.
What is the difference between a Stage 1 and Stage 2 audit?
Stage 1 is a documentation and readiness review — the auditor checks whether the scope, policy, risk assessment, Statement of Applicability, internal audit and management review are present and coherent, and records findings where relevant. Stage 2 tests whether the ISMS operates: the auditor samples evidence, interviews staff and checks implementation and effectiveness. Stage 1 asks whether the system is ready for Stage 2; Stage 2 examines how it operates in practice.
Can we get certified without an internal audit?
No. Clause 9.2 requires internal audits at planned intervals, and clause 9.3 requires a management review. Before certification, complete the applicable internal-audit programme and management review, retain dated records and address relevant corrective actions. The schedule should allow enough time to respond to findings before Stage 1 and Stage 2.
Do we need a consultant, or can we do this ourselves?
An organisation may run readiness internally if it assigns a competent owner with enough authority to coordinate decisions, evidence and control owners. Training can support competence, but no particular personal credential is mandatory for organisational certification. External consulting is optional; internal-audit and certification responsibilities must still be assigned separately.
How much does ISO 27001 certification cost in Australia?
Implementation, internal audit and certification-body fees are separate. Aegentra confirms an implementation fee after discovery, and the certification body should provide a current written quote based on scope, headcount, sites and audit duration. Use the ISO 27001 certification guide for the full cost structure.
Is there an official ISO 27001 checklist?
No. ISO does not publish a certification checklist, and no checklist can be authoritative because required controls depend on your scope and risk assessment. What is fixed is the clause structure (4 to 10), the mandatory documented information, and the requirement to compare your controls against Annex A. Any checklist — including this one — is a planning aid, not a substitute for your risk assessment.
ISO 27001 services
Put your checklist into practice
Get help building your ISMS, or arrange a separately scoped internal audit of the system you already operate.
Build your ISMS
ISO 27001 implementation
Turn identified gaps into an implementation plan. Aegentra helps you define scope, assess risks, prepare the Statement of Applicability and put the agreed controls, documentation and operating evidence in place.
Check your ISMS
ISO 27001 internal audit
Assess your ISMS against the agreed audit criteria. Aegentra plans the audit, samples evidence and reports findings to help you identify gaps and prioritise corrective actions before certification or your next surveillance audit.
Implementation and internal audit are separately scoped. Auditors do not audit their own work. An independent certification body makes the certification decision.