Compliance
What actually gets audited: ISO 27001 in practice
14 August 2026
Most organisations we work with already have the policy documents - an information security policy, an access control policy, an incident response plan. What an ISO 27001 auditor actually spends their time on is different: tracing a specific control from the policy statement through to live evidence that it's operating, right now, in the actual environment.
That's where the gap usually lives. A policy might say access is reviewed quarterly; the evidence an auditor wants is the actual review record from the last quarter, with names, and proof that access flagged for removal was actually removed within a stated timeframe. A policy might say cloud resources are encrypted at rest; the evidence is a current scan showing every resource, not a snapshot from the policy's approval date two years ago.
Third-party and vendor risk is where this gap shows up most consistently. Internal technical controls are usually reasonably well evidenced; the vendor register, contract terms and ongoing risk reassessment for critical suppliers is where documentation most often lags reality, because it depends on someone remembering to update a spreadsheet rather than a system that flags it automatically.
The organisations that handle this well treat compliance evidence as a continuous by-product of how the environment actually runs, not a separate exercise assembled before an audit window. That's the same principle behind our Cloud & Kubernetes Performance & Compliance platform - continuous scanning against the frameworks you've opted into, so the evidence exists before anyone asks for it.
For the vendor side specifically, that's also where structured vendor governance earns its keep - a live register beats a spreadsheet nobody's updated since onboarding.
Frequently asked questions
How far in advance should we prepare for an ISO 27001 audit?
Ideally, you shouldn't be "preparing" in the traditional sense at all - if evidence is generated continuously as a by-product of normal operations, an audit becomes a matter of exporting existing records rather than a scramble beforehand.
What's the biggest gap you typically find in ISO 27001 audits?
Third-party and vendor risk evidence, consistently. Internal technical controls are usually reasonably well evidenced; the vendor register, contract terms and ongoing risk reassessment for critical suppliers is where documentation most often lags reality.
Does continuous scanning replace the need for an external auditor?
No - it doesn't replace certification, but it means the evidence an auditor asks for already exists and is current, rather than being assembled specially for the audit window.
Want to talk this through?
Happy to go into more detail, or look at how it applies to your own setup.
Speak with us