QG Professional Services
- Cybersecurity
- Auditing
- Certification
ISO 27001 has a peculiar failure profile. The organisations that struggle with it are often the technically strongest ones — security teams with excellent controls, solid tooling, genuine expertise — who treat the certification as a technology audit and are blindsided when the findings land almost entirely on the management-system clauses they dismissed as paperwork. ISO 27001 certifies an Information Security Management System. The controls in Annex A matter, but the audit is won or lost on clauses 4 to 10: the system that decides, documents and improves.
Drawing on both sides of the table — implementing ISMSs and having audited management systems for certification bodies — here are the findings that recur.
1. A risk assessment that is a one-time artefact
The most common finding, across every version of the standard. A thorough risk assessment was produced during implementation, the Statement of Applicability was built from it, and then it fossilised — untouched through a cloud migration, a major new product, an acquisition. ISO 27001 requires risk assessment to be ongoing, tied to change. The fix: a defined risk-review cadence plus event triggers (new systems, incidents, significant change), with records proving the reviews happened and changed something.
2. Statement of Applicability that doesn't match reality
The SoA declares controls applicable, but the evidence shows they are not implemented as stated — or Annex A controls were excluded with justifications that do not survive scrutiny. In the 2022 revision, the reorganised Annex A (93 controls in four themes, including newcomers like threat intelligence, information security for cloud services, and data leakage prevention) has caught out organisations that transitioned their SoA mechanically without re-examining applicability. The fix: reconcile the SoA against actual implementation before the auditor does it for you.
3. Internal audits that skip the management system
Security teams audit firewalls and access reviews enthusiastically and never audit the ISMS processes — the risk process, management review, corrective action, competence. The internal-audit-coverage gap is as common in ISO 27001 as in any standard, and just as damaging: the internal audit programme must cover the whole system over the cycle, management clauses included, by auditors independent of what they audit.
4. Management review as a formality
A recurring pattern in tech-led organisations: security is "handled by the security team", and leadership engagement is thin. ISO 27001 clause 9.3 forces top-management involvement through management review, with defined inputs — audit results, risk status, incidents, the performance of controls, improvement opportunities. Ten-minute reviews with recycled minutes signal to the auditor that leadership is disengaged from information security, which is itself the finding.
5. Competence and awareness without evidence
Everyone "knows security", but the records proving competence for security-affecting roles are missing, and awareness activity is asserted rather than evidenced. The fix is unglamorous: define competence requirements for the roles that matter, keep the evidence, and retain proof that awareness actually reached people.
6. Corrective actions that don't reach root cause
Incidents and audit findings closed with the immediate fix and no root-cause analysis — the universal weakness, and in an ISMS a particularly telling one, because an information security management system that does not demonstrably learn from its incidents has failed at its core purpose. Auditors read the corrective-action log as the clearest single signal of whether the system is alive.
7. Supplier and cloud-service control gaps
The 2022 revision sharpened focus on information security in supplier relationships and cloud services. Findings cluster where critical SaaS and cloud providers are used with no security assessment, no defined requirements in contracts, and no ongoing monitoring — increasingly hard to defend when the organisation's crown jewels live in exactly those services.
8. Climate change missing from the context analysis
New since February 2024 and now appearing routinely. Amendment 1:2024 added climate-change wording to clauses 4.1 and 4.2 of ISO/IEC 27001 along with more than thirty other management system standards, effective immediately and with no transition period. For an ISMS the relevance is real rather than notional: extreme-weather impact on data-centre and office availability, energy-supply disruption affecting continuity, and climate-driven changes to supplier and hosting risk all belong in a security context analysis. The requirement is only to determine whether climate change is a relevant issue and record that determination — but an untouched 2023 context document cannot evidence it.
Why the pattern exists — and the fix
The root cause is treating ISO 27001 as a security-team project rather than a management-system project. The strongest technical organisations have the least patience for clauses 4–10, and it costs them at audit. The fix is a mindset shift plus, often, a genuine internal audit against the management clauses before certification. An independent internal audit or pre-certification review run by someone who knows what certification bodies actually examine finds these gaps while they are cheap — a major nonconformity on the management system blocks the certificate until closed and re-verified, which can cost months.
Practical steps
Read your last internal audit and check whether it examined the risk process, management review and corrective action — or only technical controls. Reconcile your Statement of Applicability against what is actually implemented. Count how many corrective actions in the last year reached a genuine root cause. If you are also moving toward AI governance, note that these same findings surface in ISO 42001, so fixing them now pays twice. QG bridges security engineering and management-systems discipline — exactly the combination ISO 27001 rewards and pure-technical teams tend to miss.