Auditing the Implementation of Annex A Controls
Auditing the implementation of Annex A controls is a core part of a Stage 2 certification audit and of surveillance audits. It verifies that the controls an organization selected to treat its information security risks are actually in place and operating effectively. In ISO/IEC 27001:2022, Annex A … Auditing the implementation of Annex A controls is a core part of a Stage 2 certification audit and of surveillance audits. It verifies that the controls an organization selected to treat its information security risks are actually in place and operating effectively. In ISO/IEC 27001:2022, Annex A lists 93 reference controls grouped into four themes: organizational (37), people (8), physical (14) and technological (34). Annex A is not a mandatory checklist. Under clause 6.1.3, the organization determines the controls it needs through risk treatment, compares them against Annex A, and documents the result in the Statement of Applicability (SoA). The SoA states which controls are included, why they are justified, whether they are implemented, and why any controls are excluded. The Lead Auditor therefore starts with the SoA and the risk treatment plan. The auditor checks that exclusions are justified and that included controls trace back to identified risks. Audit sampling is then planned around the controls most significant to the organization's risk profile, scope and context, since examining all controls in equal depth is rarely practical. Evidence is gathered in three main ways. Auditors interview personnel to confirm awareness and understanding. They review documentation and records such as policies, access reviews, incident logs, training records and supplier agreements. They also observe practices directly, for example physical entry controls, clear desk behaviour, backup processes or system configurations. The auditor assesses both design adequacy and operational effectiveness, asking whether the control exists, whether it is consistently applied, and whether it achieves its intended risk reduction. Findings are graded as major or minor nonconformities, observations or opportunities for improvement, each supported by objective evidence and linked to a specific requirement. A control that is claimed in the SoA but not implemented is a typical nonconformity. The Lead Auditor must stay impartial, apply professional judgment, and recognise that how a control is implemented may legitimately vary with the organization's size, complexity and risk appetite.
Auditing the Implementation of Annex A Controls: A Complete Guide for ISO/IEC 27001 Lead Auditors
Introduction
Auditing the implementation of Annex A controls is one of the most practical and heavily examined parts of the ISO/IEC 27001 Lead Auditor body of knowledge. Annex A of ISO/IEC 27001:2022 lists 93 information security controls grouped into four themes: Organizational (37 controls, A.5), People (8 controls, A.6), Physical (14 controls, A.7) and Technological (34 controls, A.8). The earlier 2013 edition had 114 controls in 14 domains. A lead auditor must determine whether the controls the organization has selected are actually implemented, operating as intended and effective in treating the identified information security risks.
Why It Is Important
1. It shows whether the ISMS works in reality. Clauses 4 to 10 define the management system. Annex A controls are where risk treatment becomes concrete through firewalls, access reviews, backups, training and supplier agreements. An ISMS can look well documented on paper and still fail in practice. Auditing the controls exposes that gap.
2. It links risk treatment to evidence. Clause 6.1.3 requires the organization to compare its necessary controls against Annex A and produce a Statement of Applicability (SoA). Auditing controls confirms that the SoA, the risk treatment plan and actual practice are consistent.
3. It supports a credible certification decision. Certification bodies operating under ISO/IEC 17021-1 and ISO/IEC 27006 must gather enough objective evidence that the controls are effective. Weak control auditing undermines the integrity of the certificate.
4. It protects stakeholders. Customers, regulators and partners rely on certification as assurance that their information is protected.
5. It drives improvement. Nonconformities and opportunities for improvement found in controls feed corrective action under Clause 10.
What It Is
Auditing Annex A controls is the systematic, independent and documented process of obtaining objective evidence about the selected controls. The auditor evaluates that evidence against the audit criteria, which are:
- ISO/IEC 27001 requirements
- the organization's SoA, policies and procedures
- legal, regulatory and contractual obligations
The key concepts are:
- Statement of Applicability: lists the necessary controls, justifies their inclusion, states whether they are implemented, and justifies any exclusions. It is the auditor's primary roadmap for control auditing.
- Design vs. implementation vs. effectiveness:
- Design asks whether the control is suitable to treat the risk.
- Implementation asks whether it is in place as described.
- Effectiveness asks whether it achieves its intended outcome consistently over time.
- ISO/IEC 27002: gives implementation guidance for each control. Its attributes are control type, information security properties, cybersecurity concepts, operational capabilities and security domains. It is guidance, not a set of auditable requirements. Auditors may use it to understand intent, but they must not raise nonconformities against 27002 itself.
- Audit evidence: records, statements of fact and other verifiable information. Examples are logs, configurations, signed agreements, interview responses and observed practices.
How It Works
Step 1: Preparation (Stage 1 and audit planning)
- Review the scope, risk assessment methodology, risk treatment plan and SoA.
- Check that every Annex A control has been considered and that each exclusion is justified, for example 'no outsourced development' as the reason for excluding A.8.30.
- Identify high-risk areas so audit effort can be prioritized (a risk-based audit approach).
- Build an audit plan and checklists or work documents that map controls to auditees, locations and evidence sources.
- Define a sampling strategy. Not every control instance can be verified, so representative samples are selected using judgment-based or statistical methods.
Step 2: Collecting evidence (Stage 2 and on-site or remote audit)
Auditors use the main evidence-gathering techniques described in ISO 19011:
- Interviews: ask staff how they perform the control. For example: 'How do you request access to the finance system?'
- Observation: watch the control in operation. Examples are visitor sign-in (A.7.2), clear desk (A.7.7) and screen locking.
- Document review: examine policies, procedures and contracts. Examples are supplier agreements (A.5.20) and the information security policy (A.5.1).
- Record review: check that the control actually ran. Examples are access review records (A.5.18), backup logs and restore tests (A.8.13), and training attendance (A.6.3).
- Technical verification: look at system configurations, log settings (A.8.15), patch status (A.8.8) and encryption settings (A.8.24), with the auditee's assistance.
The audit trail technique is especially powerful because it follows one item end to end. For example, the auditor can take a new joiner and trace:
- screening (A.6.1)
- terms of employment (A.6.2)
- awareness training (A.6.3)
- access provisioning (A.5.15, A.5.18, A.8.2)
The auditor can also trace backwards from a leaver to confirm that access was removed on time (A.6.5, A.5.18).
Step 3: Evaluating controls by theme (examples)
Organizational (A.5)
- Check the policies are approved and communicated.
- Check roles are defined and segregation of duties is applied.
- Check threat intelligence (A.5.7) is collected and used.
- Check the asset inventory (A.5.9) is complete.
- Check incident management (A.5.24 to A.5.28) works, including evidence collection.
- Check ICT readiness for business continuity (A.5.30) has been tested.
- Check the cloud services control (A.5.23) is addressed.
People (A.6)
- Check screening is proportionate to risk.
- Check confidentiality agreements are signed.
- Check training records exist.
- Check the disciplinary process is defined.
- Check remote working rules (A.6.7) are in place.
- Check event reporting channels (A.6.8) are known to staff.
Physical (A.7)
- Walk the perimeter.
- Test entry controls.
- Check physical security monitoring (A.7.4).
- Check equipment siting, cabling and maintenance.
- Check secure disposal of media and equipment (A.7.10, A.7.14).
Technological (A.8)
- Check endpoint protection and privileged access (A.8.2).
- Check malware protection (A.8.7).
- Check vulnerability management (A.8.8).
- Check configuration management (A.8.9).
- Check data masking and data leakage prevention (A.8.11, A.8.12).
- Check logging and monitoring (A.8.15, A.8.16).
- Check web filtering (A.8.23).
- Check secure coding (A.8.28).
- Check change management (A.8.32).
Step 4: Determining findings
- Conformity: the evidence shows the control is implemented and effective.
- Major nonconformity: a requirement is absent or there is a total breakdown that raises significant doubt about the ISMS achieving its outcomes. An example is no access control process at all.
- Minor nonconformity: an isolated lapse that does not undermine the system. An example is one leaver out of 25 sampled whose account was disabled late.
- Opportunity for improvement (OFI): no requirement is breached, but the practice could be better.
Each nonconformity statement should include three parts:
- the requirement (for example SoA, A.5.18 and the access control procedure)
- the evidence (objective, specific and traceable)
- the nature of the nonconformity
Note that a control failure is often raised against the relevant clause, typically 6.1.3 or 8.3 (implementing the risk treatment plan), referencing the Annex A control. Annex A controls become requirements because the organization declares them applicable in its SoA.
Step 5: Reporting and follow-up
- Present findings at the closing meeting.
- Document them in the audit report.
- Agree the timeline for corrections and corrective actions.
- Verify effectiveness, either at a follow-up audit or at the next surveillance audit.
Common Pitfalls Auditors Must Avoid
- Accepting a policy as proof that the control operates. A document shows intent, not implementation.
- Auditing controls that the SoA justifiably excludes, or failing to challenge unjustified exclusions.
- Raising nonconformities against ISO/IEC 27002 recommendations.
- Giving consultancy advice on how to fix a problem. This compromises impartiality.
- Relying only on interviews without corroborating evidence.
- Using samples that are too small or biased.
- Performing hands-on technical testing such as penetration testing without authorization. The auditor should observe and review, not attack systems.
Exam Tips: Answering Questions on Auditing the Implementation of Annex A Controls
1. Always start with the SoA. If a question asks what the auditor should check first or what defines which controls to audit, the answer is usually the Statement of Applicability, linked to the risk assessment and risk treatment plan.
2. Distinguish documentation from implementation. In scenario questions, a procedure that exists but has no records of execution indicates the control is not proven to be implemented. Choose answers that seek records or observation over answers that merely read the policy.
3. Know the 2022 structure. Memorize the four themes, the 93 controls and the 11 new controls:
- threat intelligence (5.7)
- information security for cloud services (5.23)
- ICT readiness for business continuity (5.30)
- physical security monitoring (7.4)
- configuration management (8.9)
- information deletion (8.10)
- data masking (8.11)
- data leakage prevention (8.12)
- monitoring activities (8.16)
- web filtering (8.23)
- secure coding (8.28)
4. Map the scenario to the right control. Examples:
- An unescorted visitor points to A.7.2.
- Shared admin passwords point to A.5.17 and A.8.2.
- No restore testing points to A.8.13.
- A missing supplier security clause points to A.5.20.
- An unpatched server points to A.8.8.
Precise mapping earns marks in essay-style exams such as PECB.
5. Grade nonconformities correctly. Ask yourself two questions:
- Is the failure systemic or isolated?
- Does it threaten the ISMS's ability to achieve its intended results?
Systemic or total absence suggests a major nonconformity. A single lapse with the process otherwise working suggests a minor one. If no requirement is breached, it is an OFI or no finding.
6. Write well-structured nonconformity statements. In open-answer exams, include three elements:
- the requirement reference (clause, control and the organization's own document)
- the objective evidence (who, what, when and where, plus the sample size)
- the statement of nonconformity
Avoid opinions and words like 'poor' or 'bad'.
7. Remember 27002 is guidance. If an option suggests raising a nonconformity because the organization did not follow a 27002 implementation tip, it is usually wrong. The exception is where the organization has adopted that guidance into its own procedures.
8. Challenge exclusions logically. An exclusion is invalid if the risk exists. For example, the organization excludes teleworking controls but staff work from home.
9. Prefer evidence-triangulation answers. The best auditor action usually combines interview, observation and records. When a question asks for the 'most appropriate' or 'best' next step, choose the option that verifies claims with objective evidence.
10. Maintain auditor independence. Answers in which the auditor fixes configurations, recommends specific products or designs controls are incorrect. The auditor may state the finding but not prescribe the solution.
11. Use sampling wisely. Expect questions on selecting samples. They should be representative across the following, and justified by risk:
- locations
- time periods
- systems
- personnel
12. Consider effectiveness over time. A control that worked today but has no history, such as an access review performed only the day before the audit, may indicate an implementation issue. Look for records covering the full period since the last audit.
13. Read scenarios carefully for scope. Controls outside the certified scope are not audited for certification. Note, however, that interfaces and dependencies such as outsourced processes (Clause 8.1) still need to be controlled.
14. Time management in case-study exams. Underline the facts, identify the control and clause, judge severity, then write a concise, evidence-based answer. Do not restate the scenario.
Summary
Auditing Annex A controls means verifying, with objective evidence and a risk-based sampling approach, that the controls declared in the SoA are designed appropriately, implemented as described and operating effectively. Master the SoA linkage, the four control themes, evidence-gathering techniques, nonconformity grading and nonconformity writing, and you will be well equipped both for real audits and for the ISO/IEC 27001 Lead Auditor exam.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!