Based on real audit experience: the areas certification auditors prioritise and what they expect to find.
Updated 14 Mar 2026
What Auditors Prioritise
Experienced auditors follow a pattern. Knowing what they look for first helps you prepare effectively.
1. Management Commitment
Auditors want evidence that leadership is actively involved — not just a signature on a policy. They look for:
•Minutes from management reviews
•Resource allocation decisions
•Security objectives set by leadership
2. Risk Assessment & Treatment
This is the engine of your ISMS. Auditors check:
•Methodology documentation
•Completeness of risk identification
•Logical connection between risks and controls
•Evidence of regular review
3. Statement of Applicability (SoA)
Every Annex A control must be addressed. For each:
•Is it applicable? Why or why not?
•If applicable, what's the implementation status?
•What evidence supports implementation?
4. Internal Audit Results
Auditors want to see that you audit yourself honestly:
•Were nonconformities identified?
•Were they addressed with corrective actions?
•Is there a systematic audit programme?
5. Corrective Actions
How you handle problems reveals maturity:
•Are root causes identified (not just symptoms)?
•Are actions tracked to completion?
•Is there evidence of effectiveness review?
The Meta-Point
Auditors are looking for a *living system*, not a documentation exercise. Show them the ISMS is actively used and continuously improved.
Related Modules
Standard Controls
Documents
Corrective Actions
Related Controls / Clauses
5.1
6.1.2
9.2
10.1
26 practitioner guides — included free with your workspace
27 Launchpad generates your full compliance toolkit from a 10-minute setup: policies, risk register, legal register, controls, and AI-assisted document review.