COMPLIANCE

ISO 27001 Auditing: Why Passing Certification Doesn't Mean Your Controls Actually Work

C

CovaCtrl

4 min read

Every organisation with an ISO 27001 certificate can produce the certificate itself. Far fewer can show that the certification reflects how information security actually operates day to day. An ISO 27001 audit tests a sample of a management system at a single point in time, and the space between that sample and daily operations is where most control failures at certified organisations actually live.

What Does an ISO 27001 Certification Audit Actually Verify?

A certification audit checks whether an information security management system conforms to the requirements in clauses four through ten of the standard, and whether the controls listed in the organisation's Statement of Applicability are implemented as described. Under the 2022 revision, that Statement of Applicability draws from 93 Annex A controls grouped into four themes: organisational, people, physical and technological.

The auditor's job is conformity assessment, not penetration testing. They confirm a control exists, is documented and produces evidence consistent with its stated design. Whether that control would actually stop a capable attacker is a separate question, and one the audit is not designed to answer.

Why Can an Organisation Pass Its Audit and Still Have Weak Security?

Conformity and effectiveness are not the same thing, and the distance between them is where most of the false confidence sits. A quarterly access review can be performed on schedule, documented with a signed spreadsheet and shown to the auditor as evidence, while the reviewer simply confirms the same list every quarter without checking whether any of those permissions should have been revoked months earlier.

The control exists. It produces evidence. It satisfies the audit. It does not do the thing it was designed to do, which is remove access that no longer belongs to someone. Auditors sampling that evidence trail have no practical way to distinguish a genuine review from a rubber stamp unless they interview the reviewer directly and press on specifics, which rarely happens within the time allotted to a single control.

Why Does Audit Sampling Leave So Much Unchecked?

Certification bodies do not test every instance of every control every year. Annual surveillance audits examine a subset of the management system, chosen on a risk basis, with the full Annex A scope revisited only across the three-year certification cycle. A large organisation with dozens of business units and hundreds of control instances can go through an entire audit cycle without a given control ever being pulled for detailed testing, particularly if it sits in a part of the business the auditor rated as lower risk two cycles earlier.

This is a reasonable and necessary constraint on audit scope. It also means that a control quietly degrading, an owner who left the company, a process that was simplified informally after the last audit, can persist for years without anyone independent looking at it closely.

What Happens When the Statement of Applicability Drifts From Reality?

The Statement of Applicability is approved once, then rarely revisited with the same rigour. New SaaS tools get adopted, infrastructure moves to a different cloud provider, a process that used to run through a controlled system now runs through email, and the document that defines what the ISMS actually covers does not move with any of it.

Auditors test what is documented. A control gap that never made it into the Statement of Applicability, because the system it should cover was never formally recognised as in scope, is invisible to the audit by construction. Those undocumented gaps are frequently the exact areas that get exploited, precisely because nobody, including the auditor, was looking at them.

Where Does the Confidence Gap Actually Sit?

What the certification audit tests What often goes unchecked between audits
Whether a control is documented and produces evidence Whether that evidence reflects genuine judgement or a rubber stamp
A risk-based sample of Annex A controls each year Controls outside the sample, sometimes for a full three-year cycle
Conformity to the current Statement of Applicability Systems and processes added since the Statement was last reviewed
A snapshot at the point of the surveillance visit Control performance in the eleven months either side of it

How Should Internal Audit Close the Gap Between Certification and Operating Security?

Closing this gap does not require a bigger audit programme, it requires a different rhythm. Internal audit or the information security function needs to test operating effectiveness on its own schedule, not only in the weeks before the external auditor arrives, and the Statement of Applicability needs an owner who reviews it against actual architecture changes at least twice a year rather than once at recertification.

Effort is better concentrated on the controls that genuinely carry risk than spread evenly across all 93 entries in Annex A. A control governing access to the production database deserves more frequent independent scrutiny than one governing visitor sign-in at reception, yet many ISMS programmes give both the same testing cadence because the standard does not tell them not to.

How Is CovaCtrl Different?

CovaCtrl maintains continuous evidence of control performance as work happens, rather than reconstructing a year of activity in the weeks before a surveillance audit. For controls mapped to Annex A, this means the evidence an auditor eventually samples reflects what actually happened throughout the certification period, not a version assembled to look consistent after the fact.

Teams managing an ISMS can see where a control's evidence trail is thin or repetitive long before an external auditor or a real incident finds the same gap.

Why This Matters Now

The transition deadline for ISO/IEC 27001:2022 passed on October 31, 2025. Every certified organisation is now moving through its first full surveillance cycle tested purely against the revised control set, and many Statements of Applicability were updated only enough to satisfy that transition audit rather than to reflect genuine architectural change. This is exactly the moment when documentation that was patched for a deadline meets the operational reality it was supposed to describe.

A certificate on the wall confirms that a management system was found to conform on the day it was tested. It says nothing about the days in between. Organisations that treat the audit as the finish line will keep passing it, right up until the gap it never tested is the one that gets exploited.

Related Articles

CONTROLS4 min read

The Remediation Gap: Why the Same Audit Findings Keep Coming Back

JUNE 26, 2026

CONTROLS4 min read

Outsourcing a Process Does Not Outsource the Control

JUNE 19, 2026

CONTROLS4 min read

IT General Controls and the SaaS Era: Why Coverage Has Become the New Control Failure

JUNE 13, 2026

CONTROLS4 min read

Control Rationalization: Why Fewer Controls Often Means Better Assurance

JUNE 05, 2026

COMPLIANCE4 min read

ESG Reporting Has a Controls Problem: Why Sustainability Data Needs the Same Rigour as Financial Data

MAY 29, 2026

COMPLIANCE4 min read

SOX Under Two Watchdogs: What the SEC's New Enforcement Group and Revised PCAOB Standards Mean for Internal Controls

MAY 22, 2026

CONTROLS4 min read

When the Tool Becomes the Risk: Governing AI in Your Control Framework

MAY 18, 2026

RISK5 min read

Why Your GRC Platform Is Just a Documentation System in Disguise

APRIL 13, 2026

RISK4 min read

The Role of Dependencies in Operational Risk: Why One Weak Link Can Break the Chain

APRIL 9, 2026

RISK4 min read

Why Most Incidents Start Small and Go Unnoticed

APRIL 7, 2026

CONTROLS3 min read

What Makes an Internal Control Effective? Key Principles Explained

MARCH 24, 2026

RISK3 min read

The Danger of Periodic Monitoring: Why Risks Are Often Detected Too Late

MARCH 5, 2026

COMPLIANCE3 min read

Internal Control in the UK Corporate Governance Code: What Boards Need to Know

FEBRUARY 24, 2026

COMPLIANCE3 min read

Internal Control Maturity: How to Strengthen and Scale Your Control Framework

FEBRUARY 19, 2026

RISK4 min read

Why Traditional GRC Systems Are Outdated, And What Modern Risk Management Requires

FEBRUARY 13, 2026

RISK3 min read

Risk Management Without Spreadsheets: What Changes?

FEBRUARY 9, 2026

COMPLIANCE3 min read

5 Internal Controls Every Scaling Company Needs (and Why)

FEBRUARY 2, 2026

RISK3 min read

Operational Risks in Supply Chains: What They Are and How to Manage Them

JANUARY 29, 2026

COMPLIANCE4 min read

SOX Compliance Explained: What It Is, Why It Matters and Why It's Still Hard

JANUARY 20, 2026

RISK3 min read

Risk Appetite vs. Risk Tolerance: What's the Difference and Why It Matters

JANUARY 12, 2026

RISK2 min read

The Future of Risk Management: From Static Control to Living System

JANUARY 8, 2026

RISK3 min read

Making the Three Lines of Defence Work in Practice

DECEMBER 9, 2025

QUALITY4 min read

Quality Control in Modern Operations

NOVEMBER 20, 2025