ISO 27001: getting certified and running the system are different jobs
Passing the certification audit is a project; operating an information security management system is a habit. Confusing the two produces a bill at the first surveillance audit.
- ISO 27001
- Compliance
- Audit
There are two distinct goals in an ISO 27001 project, and they are often conflated. The first is getting the certificate: showing a document set on audit day and closing the nonconformities. The second is operating the system: the controls becoming part of the organisation's daily work.
Implementations that aim only at the first usually do get the certificate. The problem appears a year later, at the first surveillance audit.
Why it appears
A certification audit can capture a snapshot; a surveillance audit looks at continuity. The concrete questions are these:
- Did you update the risk assessment this year? What happened to the items in the risk treatment plan?
- How many times did you review access rights? When were leavers' accounts closed?
- Did you test a restore from backup? Is there a record of the test?
- Did you run an internal audit, and were the findings closed?
- Did the management review meeting take place, and what did it decide?
All of these are things that should be happening. None can be produced during audit week, because every one of them carries a timestamp.
Tying a control to the work
The practical test for whether a control works: does it still run when nobody is thinking about the audit?
- Access review as a calendar meeting whose output is an email gets skipped in the first busy period. The system has to put the list in front of the manager for approval.
- Restore testing as a "we'll get to it" task never happens. It needs a quarterly calendar item and a record where the outcome is written down.
- Supplier assessment that is not inside the procurement process means nobody ever looks back after the contract is signed.
Embedding a control in a process is more work than writing a document. In exchange, it carries itself once it is done.
Narrowing the scope is not an escape hatch
Narrowing the scope is a legitimate decision — you do not have to bring the whole organisation in at once. But if what you left outside connects to systems inside the scope, that connection will be asked about in the audit. The scope boundary has to be technically defensible too.
What to expect on timing
For a mid-sized organisation starting from scratch, the span from scope definition to the certification audit is measured in months; what determines it is not documentation but getting the controls actually operating and running for a while. An auditor cannot treat a control with no record as operating.
In our ISO 27001 service we work in this order: scope and asset inventory, risk assessment, putting controls into operation, internal audit, then certification. Changing the order raises the cost.
This article is for information and does not constitute legal advice.

