Disconnected ISMS documents put certification at risk

Disconnected ISMS documents put certification at risk

Firms chasing ISO 27001 certification often hit the same wall. They go looking for practical ISMS examples and find vague templates built around fictional firms and empty phrases such as “implements strong controls”.

According to Copla, the gap between generic guidance and what assessors actually read is where many information security management systems begin to fail.

The RegTech firm has set out illustrative wording for each core document required under clauses 4 to 9 of ISO 27001:2022. These are the scope statement, the information security policy, the risk register entry, the Statement of Applicability (SoA), the ISMS objective and the internal audit finding.

The examples are deliberately linked. A single risk, a departing employee whose SaaS access is not revoked in time, runs through every document and ties back to Annex A control A.5.18 on access rights.

That connection is the central point. Copla argues that a folder of six documents that are each correct on their own, but never reference one another, is still fragile when the auditor arrives.

Assessors check whether the SoA’s justification matches a real entry in the risk register, and whether audit findings trace back to current policy wording. Where those links break, the gap comes to light during the audit rather than before it.

Build order matters too. The scope must come first, because nothing else can be sized until the boundary is set. The SoA should follow the risk register, since an SoA drafted earlier cites controls nobody has justified.

The objective comes last and should tie to a business goal rather than a metric only IT tracks. Risk treatment follows four recognised strategies: modify, share, avoid or retain.

The 2022 revision adds urgency. Annex A shrank from 114 controls to 93, grouped into four themes: organisational (37), people (8), physical (14) and technological (34). Eleven controls are new, covering areas such as threat intelligence, cloud service security and ICT readiness for business continuity. Any SoA still citing 2013 numbering, or leaving out the new controls, will not match the standard auditors now use.

Implementation, Copla stresses, is more than paperwork. Each document needs an owner who can explain what has changed since it was last updated, and reviews should not be tied to the audit calendar. Internal audits under clause 9.2 must run at planned intervals, be carried out by someone without a conflict of interest, and feed into corrective action under clause 10.

Certification then applies an external test to these same connections. Stage 1 examines the documentation and Stage 2 checks whether the controls actually operate. Annual surveillance audits look for drift between documents, and full recertification follows every three years. The firms that pass comfortably are the ones that built the consistency before anyone asked for it.

Read the full Copla post here. 

Read the daily RegTech news

Copyright © 2026 RegTech Analyst

Enjoyed the story? 

Subscribe to our weekly RegTech newsletter and get the latest industry news & research

Copyright © 2026 RegTech Analyst

Investors

The following investor(s) were tagged in this article.