ISO 27001 Auditing: Why Passing Certification Doesn't Mean Your Controls Actually Work
CovaCtrl
4 min read
Every organisation with an ISO 27001 certificate can produce the certificate itself. Far fewer can show that the certification reflects how information security actually operates day to day. An ISO 27001 audit tests a sample of a management system at a single point in time, and the space between that sample and daily operations is where most control failures at certified organisations actually live.
What Does an ISO 27001 Certification Audit Actually Verify?
A certification audit checks whether an information security management system conforms to the requirements in clauses four through ten of the standard, and whether the controls listed in the organisation's Statement of Applicability are implemented as described. Under the 2022 revision, that Statement of Applicability draws from 93 Annex A controls grouped into four themes: organisational, people, physical and technological.
The auditor's job is conformity assessment, not penetration testing. They confirm a control exists, is documented and produces evidence consistent with its stated design. Whether that control would actually stop a capable attacker is a separate question, and one the audit is not designed to answer.
Why Can an Organisation Pass Its Audit and Still Have Weak Security?
Conformity and effectiveness are not the same thing, and the distance between them is where most of the false confidence sits. A quarterly access review can be performed on schedule, documented with a signed spreadsheet and shown to the auditor as evidence, while the reviewer simply confirms the same list every quarter without checking whether any of those permissions should have been revoked months earlier.
The control exists. It produces evidence. It satisfies the audit. It does not do the thing it was designed to do, which is remove access that no longer belongs to someone. Auditors sampling that evidence trail have no practical way to distinguish a genuine review from a rubber stamp unless they interview the reviewer directly and press on specifics, which rarely happens within the time allotted to a single control.
Why Does Audit Sampling Leave So Much Unchecked?
Certification bodies do not test every instance of every control every year. Annual surveillance audits examine a subset of the management system, chosen on a risk basis, with the full Annex A scope revisited only across the three-year certification cycle. A large organisation with dozens of business units and hundreds of control instances can go through an entire audit cycle without a given control ever being pulled for detailed testing, particularly if it sits in a part of the business the auditor rated as lower risk two cycles earlier.
This is a reasonable and necessary constraint on audit scope. It also means that a control quietly degrading, an owner who left the company, a process that was simplified informally after the last audit, can persist for years without anyone independent looking at it closely.
What Happens When the Statement of Applicability Drifts From Reality?
The Statement of Applicability is approved once, then rarely revisited with the same rigour. New SaaS tools get adopted, infrastructure moves to a different cloud provider, a process that used to run through a controlled system now runs through email, and the document that defines what the ISMS actually covers does not move with any of it.
Auditors test what is documented. A control gap that never made it into the Statement of Applicability, because the system it should cover was never formally recognised as in scope, is invisible to the audit by construction. Those undocumented gaps are frequently the exact areas that get exploited, precisely because nobody, including the auditor, was looking at them.
Where Does the Confidence Gap Actually Sit?
How Should Internal Audit Close the Gap Between Certification and Operating Security?
Closing this gap does not require a bigger audit programme, it requires a different rhythm. Internal audit or the information security function needs to test operating effectiveness on its own schedule, not only in the weeks before the external auditor arrives, and the Statement of Applicability needs an owner who reviews it against actual architecture changes at least twice a year rather than once at recertification.
Effort is better concentrated on the controls that genuinely carry risk than spread evenly across all 93 entries in Annex A. A control governing access to the production database deserves more frequent independent scrutiny than one governing visitor sign-in at reception, yet many ISMS programmes give both the same testing cadence because the standard does not tell them not to.
How Is CovaCtrl Different?
CovaCtrl maintains continuous evidence of control performance as work happens, rather than reconstructing a year of activity in the weeks before a surveillance audit. For controls mapped to Annex A, this means the evidence an auditor eventually samples reflects what actually happened throughout the certification period, not a version assembled to look consistent after the fact.
Teams managing an ISMS can see where a control's evidence trail is thin or repetitive long before an external auditor or a real incident finds the same gap.
Why This Matters Now
The transition deadline for ISO/IEC 27001:2022 passed on October 31, 2025. Every certified organisation is now moving through its first full surveillance cycle tested purely against the revised control set, and many Statements of Applicability were updated only enough to satisfy that transition audit rather than to reflect genuine architectural change. This is exactly the moment when documentation that was patched for a deadline meets the operational reality it was supposed to describe.
A certificate on the wall confirms that a management system was found to conform on the day it was tested. It says nothing about the days in between. Organisations that treat the audit as the finish line will keep passing it, right up until the gap it never tested is the one that gets exploited.

