ISO 27001 Annex A control audit
Internal audit across the ISO 27001:2022 Annex A control themes, structured the way a certification auditor will sample them.
Typically run by ISMS Manager / Internal Auditor
Loading AuditFlow…
Tech
Software companies, IT services, cloud providers and digital platforms.
The job you're hiring this for
Getting through a SOC 2 or ISO 27001 audit without derailing engineering for a month, and keeping evidence fresh between annual surveillance audits.
Every one carries weighted questions, auditor guidance and clause references — ready to run, or to edit into your own house standard.
Internal audit across the ISO 27001:2022 Annex A control themes, structured the way a certification auditor will sample them.
Typically run by ISMS Manager / Internal Auditor
Trust Services Criteria readiness check focused on whether controls will survive an operating-effectiveness test over the observation period.
Typically run by Compliance Lead / vCISO
Entitlement recertification across in-scope systems, with evidence of reviewer challenge and remediation of revoked access.
Typically run by IT Security / Application Owner
Samples production changes end-to-end from ticket to deployment, testing approval, testing evidence and separation of duties.
Typically run by IT Audit / Engineering Manager
Dual-framework privacy audit covering lawful basis, consent, data subject rights, retention and breach readiness under both GDPR and India's DPDP Act.
Typically run by DPO / Privacy Lead
Risk-tiered vendor assessment covering security posture, contractual protections, data flows and offboarding.
Typically run by Security / Procurement
Structured tabletop testing detection, escalation, decision-making and communication under a realistic scenario.
Typically run by Security Lead / BCM Coordinator
Proves recoverability by actually restoring — the control that is universally claimed and rarely tested.
Typically run by Infrastructure Lead
Tests the identity lifecycle end to end — access provisioned on approval, adjusted on transfer, removed on exit, and assets returned.
Typically run by IT Security / HR Systems Owner
Reviews who holds administrative rights across every layer, whether that access is time-bound, vaulted, monitored and recertified.
Typically run by IT Security Manager
Audits whether security is built into development — peer review enforcement, pipeline scanning, dependency hygiene and environment separation.
Typically run by Application Security Lead
Tests scan coverage against the real asset estate and whether remediation actually lands inside the stated SLA.
Typically run by Infrastructure Security Lead
Reviews a penetration test from scope through to verified closure, with particular attention to findings that repeat across reports.
Typically run by Security Manager / Internal Audit
Checks what is actually being logged and detected against what the estate contains — the gap between the two is the blind spot.
Typically run by SOC Lead / Security Engineer
Reviews the live configuration of cloud accounts against a hardening baseline, covering exposure, identity, encryption and audit logging.
Typically run by Cloud Security Engineer
Endpoint-level review of authentication, authorisation, data exposure and logging across public, partner and internal APIs.
Typically run by Application Security Engineer
Verifies that every corporate device is enrolled, encrypted, patched, monitored and recoverable through to secure disposal.
Typically run by IT Operations / Security
Reviews cryptographic policy against live practice — where keys live, who can reach them, whether rotation actually happens.
Typically run by Security Architect
Hunts for credentials in source control, pipelines and configuration, and tests whether discovered secrets are rotated rather than deleted.
Typically run by Platform Engineering / Security
Tests whether the retention schedule is executed in live systems, backups and processors — not merely written down.
Typically run by DPO / Data Governance Lead
Each of these has a real control library in the product — questions map to specific clauses, so gap analysis shows you what is genuinely unevidenced.
The international standard for information security management systems.
23 controls mapped
Business continuity management — impact analysis, strategies and tested plans.
12 controls mapped
Card-brand mandated controls for anyone storing, processing or transmitting card data.
12 controls mapped
AICPA trust services criteria attestation, expected by US enterprise buyers.
16 controls mapped
EU privacy regulation applying to any organisation processing EU residents' data.
16 controls mapped
India's personal data protection law, with consent and breach-notice obligations.
19 controls mapped
Not hypotheticals. These are the findings that recur in technology & saas, and every one of them is a question in at least one of the 20 templates above.
Templates, findings and AI prompts use your sector's terms, not generic audit language.
Pick one of the 20 templates above, walk the site with your phone, and see the finished report before you get back to your desk.