Guide · Information security

ISO 27001 evidence: what auditors actually want

Most of the anxiety around an ISO 27001 audit isn't about the controls themselves — it's about proving they're real. Certification hinges on evidence: records that show your information security management system is running, not just written down. Here's what assessors actually look for, and how much of it a Microsoft 365 estate can produce on its own.

What an auditor is really checking

An ISO 27001 assessment isn't a quiz on the standard. The assessor is testing one thing: does the information security management system (ISMS) you documented actually operate the way you say it does? They confirm that by sampling evidence — asking to see specific records and checking they're current, dated, owned and consistent with your policies.

That means the failure mode is rarely a missing control. It's a control that exists on paper but whose trail has gone cold — a policy last reviewed under last year's ownership, an access list that no longer matches the estate, a risk assessment that hasn't been revisited because the day job filled the calendar. Evidence is the difference between "we do this" and "we can show we do this" without a pre-assessment scramble.

The two halves of the standard

ISO 27001 has two parts, and both generate evidence:

The records assessors ask for most

Every audit is scoped to your organisation, but a recognisable core comes up almost every time:

Freshness beats volume. Assessors would rather see a lean set of current, owned, consistent records than a mountain of documents that contradict each other. A risk assessment dated this cycle and matching your SoA is worth more than a large policy set that nobody has had time to keep current — not for lack of care, but for lack of hours.

How much Microsoft 365 already produces

If your organisation runs on Microsoft 365, a large share of the operational evidence already exists — it's just scattered across admin centres. The estate can speak to a meaningful set of Annex A controls without anyone writing a document, for example:

The catch is that a live tenant setting is not, by itself, audit evidence. It has to be captured as a dated record, tied to the relevant control, and kept — so that six months later you can show the state as it was, not just as it is today. That capture step is where most teams lose time.

Where Kavorly fits

Kavorly runs ISO 27001 as a live ISMS and reads your Microsoft 365 estate to collect much of that operational evidence automatically — mapped to the controls it supports, dated and retained — so the audit trail builds as people do the day job — so assessment is a review, not hours of manual checking the month before. The management-system records (SoA, risk, audits, reviews, actions) live in the same place, so the whole picture is in one system.

See how Kavorly runs ISO 27001 →


This guide is a general introduction, not certification advice or a substitute for the standard itself. For the authoritative requirements, refer to the published text of ISO/IEC 27001 or speak to a certification body.

Next step

See how much evidence your estate already holds.

Check your ISO 27001 readiness free, or book a walkthrough to see Kavorly pull evidence from your own Microsoft 365.