Guide · Information security
ISO 27001 evidence: what auditors actually want
Most of the anxiety around an ISO 27001 audit isn't about the controls themselves — it's about proving they're real. Certification hinges on evidence: records that show your information security management system is running, not just written down. Here's what assessors actually look for, and how much of it a Microsoft 365 estate can produce on its own.
What an auditor is really checking
An ISO 27001 assessment isn't a quiz on the standard. The assessor is testing one thing: does the information security management system (ISMS) you documented actually operate the way you say it does? They confirm that by sampling evidence — asking to see specific records and checking they're current, dated, owned and consistent with your policies.
That means the failure mode is rarely a missing control. It's a control that exists on paper but whose trail has gone cold — a policy last reviewed under last year's ownership, an access list that no longer matches the estate, a risk assessment that hasn't been revisited because the day job filled the calendar. Evidence is the difference between "we do this" and "we can show we do this" without a pre-assessment scramble.
The two halves of the standard
ISO 27001 has two parts, and both generate evidence:
- The management-system clauses (the numbered requirements) — context, leadership, planning, support, operation, performance evaluation and improvement. These produce records like your risk assessment and treatment plan, the Statement of Applicability, internal audit reports, management review minutes, and corrective actions.
- The Annex A controls — the reference set of information security controls you select from based on your risks. Each control you apply should have evidence it's operating.
The records assessors ask for most
Every audit is scoped to your organisation, but a recognisable core comes up almost every time:
- Statement of Applicability (SoA) — which controls you apply, which you don't, and why.
- Risk assessment and risk treatment plan — current, owned, and clearly linked to the controls you selected.
- Information security policy and supporting policies — approved, version-controlled, and reviewed on a defined cycle.
- Internal audit programme and reports — evidence you audit yourself, not just wait for the external assessor.
- Management review records — minutes showing leadership actually reviewed the ISMS and made decisions.
- Corrective actions — findings raised, root cause understood, actions closed out.
- Access control records — who has access to what, and evidence of periodic review and of joiners/movers/leavers being handled.
- Awareness and training records — that people know their responsibilities.
- Operational evidence — logging, backups, vulnerability and patch management, supplier assurance, and incident records.
Freshness beats volume. Assessors would rather see a lean set of current, owned, consistent records than a mountain of documents that contradict each other. A risk assessment dated this cycle and matching your SoA is worth more than a large policy set that nobody has had time to keep current — not for lack of care, but for lack of hours.
How much Microsoft 365 already produces
If your organisation runs on Microsoft 365, a large share of the operational evidence already exists — it's just scattered across admin centres. The estate can speak to a meaningful set of Annex A controls without anyone writing a document, for example:
- Access control — Entra ID users, groups, conditional access and access reviews.
- Authentication — multi-factor authentication coverage and sign-in activity.
- Malware and threat protection — Defender configuration and detections.
- Information handling — data loss prevention, retention and labelling in Purview.
- Logging and monitoring — audit logs across the tenant.
- Device management — Intune compliance and configuration.
The catch is that a live tenant setting is not, by itself, audit evidence. It has to be captured as a dated record, tied to the relevant control, and kept — so that six months later you can show the state as it was, not just as it is today. That capture step is where most teams lose time.
Where Kavorly fits
Kavorly runs ISO 27001 as a live ISMS and reads your Microsoft 365 estate to collect much of that operational evidence automatically — mapped to the controls it supports, dated and retained — so the audit trail builds as people do the day job — so assessment is a review, not hours of manual checking the month before. The management-system records (SoA, risk, audits, reviews, actions) live in the same place, so the whole picture is in one system.
See how Kavorly runs ISO 27001 →
This guide is a general introduction, not certification advice or a substitute for the standard itself. For the authoritative requirements, refer to the published text of ISO/IEC 27001 or speak to a certification body.