Skip to content
Singahi

Compliance · guide

ISO 27001 A.5.35: Independent Review of Information Security

48 min read

Share
On this page

Quick Reference: A.5.35 in 60 Seconds

AttributeDetails
Control IDA.5.35
TitleIndependent review of information security
ObjectiveObtain independent assurance that the ISMS and its controls are suitable, adequate, effective, and continuously improving.
DomainOrganizational controls (A.5), Governance, assurance, and compliance
What You Must DoPlan and conduct independent reviews of the organization's information security approach and implementation (people, processes, technologies) at planned intervals and when significant changes occur.
Typical OwnerChief Information Security Officer (CISO) sponsors; Internal Audit Head / Information Security Audit Manager executes.
Maturity Level 1Ad-hoc reviews performed only before external audit. No documented plan or independence.
Maturity Level 2Annual internal audit plan exists, but reviewers may report to the CISO and lack objectivity.
Maturity Level 3Independent internal audit function with approved charter, risk-based plan, competent auditors, and management-reviewed reports.
Maturity Level 4Integrated assurance: internal audit, technical testing, management review, and external audit findings drive a continuous improvement cycle with KPIs.
Maturity Level 5Predictive, data-driven assurance using GRC automation, continuous controls monitoring, and AI-assisted anomaly detection; audit findings correlate with risk appetite and board strategy.
Audit Red FlagInternal audit reports to the CISO, audit plan not risk-based, findings not tracked to closure, auditors lack competence, no evidence of independence.
Quick WinCreate an Internal Audit Charter, approve a 12-month risk-based audit plan, and establish a findings-tracking register with escalation to top management.
Time to Implement4–8 weeks for initial program; ongoing execution forever.
Related ControlsA.5.1 (Policies), A.5.2 (Roles), A.5.36 (Compliance with policies), A.5.37 (Documented operating procedures), A.6.1 (Screening), A.6.2 (Terms and conditions), A.8.15 (Logging), A.8.16 (Monitoring activities), A.9.2 (Access to networks), A.9.4 (System access control).

What the Standard Actually Requires

Figure · Process

What A.5.35 asks you to do

The 6 requirements of ISO 27001 A.5.35, independent review of information security, in order: independence of reviewers; competence; risk-based planning; scope coverage; reporting; follow-up.
The 6 things the control expects. Each is expanded in the section below.

ISO 27001:2022 A.5.35 Control Text

ISO 27001:2022 Annex A 5.35 asks organizations to review the organization's approach to managing information security independently, at planned intervals and after significant changes.

This single sentence contains five mandatory elements:

ElementRequirementAuditor Interpretation
"organization's approach to managing information security"The ISMS as a whole: governance, risk management, policy framework, roles, processes, culture.Auditors expect to see the ISMS scope, context, leadership commitment, and management system mechanics reviewed.
"and its implementation"How the ISMS is executed day-to-day: are controls actually implemented, operating, and effective?Auditors will sample controls across departments, systems, and sites.
"including people, processes and technologies"The review must cover all three dimensions, not just technology or documentation.A purely paper-based audit or purely vulnerability scan is insufficient.
"reviewed independently"The reviewer must be free from operational responsibility for the area being reviewed.The CISO cannot audit their own function; IT cannot audit IT without safeguards.
"at planned intervals, or when significant changes occur"Reviews must be scheduled (typically at least annually) and triggered by material change.Annual audit plan + change-triggered reviews (M&A, cloud migration, major breach, new regulation).

ISO 27002:2022 Implementation Guidance (Section 5.35)

ISO 27002:2022 provides the following implementation guidance for A.5.35:

  1. Independence of reviewers, Reviewers should be independent of the activities being reviewed. Where full independence is not feasible due to organization size, independence should be maximized through reporting lines, scope separation, or external support.
  2. Competence, Reviewers should be competent in information security management, auditing principles, and the technologies/processes under review.
  3. Risk-based planning, Reviews should be planned based on risk, previous findings, regulatory requirements, and changes.
  4. Scope coverage, Reviews should assess whether the ISMS conforms to the organization's own policies and procedures and to ISO 27001, and whether it is effectively implemented and maintained.
  5. Reporting, Results should be documented and reported to relevant management, including top management where appropriate.
  6. Follow-up, Findings should be tracked to closure with evidence of corrective action.

Shall / Should / May Analysis

WordFrequency in A.5.35 TextInterpretation
shall1The organization must conduct independent reviews at planned intervals or on significant change. This is mandatory.
should0 (in the control text)ISO 27002 uses "should" for guidance; the control itself is prescriptive.
may0No optional elements in the control.

What Auditors Actually Check

Auditor ActionWhat They Want to SeeCommon Finding
Review audit charterDocumented independence, authority, scope, reporting line to top management or audit committeeCharter missing or audit reports to CISO
Review annual audit planRisk-based, covers all Annex A controls over a reasonable cycle, includes people/process/technologyPlan is generic, not risk-based, or only covers IT
Check auditor competenceCVs, certifications (CISA, qualified lead auditor), training recordsAuditors lack security audit qualifications
Sample audit working papersEvidence of planning, execution, sampling, testing, conclusionsNo working papers or inadequate evidence
Review audit reportsClear findings, risk ratings, recommendations, management responsesFindings are observations without risk ratings
Check findings registerAll findings tracked to closure with evidence and target datesOpen findings beyond target dates, no escalation
Interview process ownersConfirm audit occurred and was independentProcess owners unaware of audit or findings
Verify change-triggered reviewsEvidence of audits after major changesNo reviews after cloud migration / M&A / breach
Review management review inputsAudit results feed into management reviewAudit findings not discussed by top management
Check independence safeguardsAuditors do not audit their own work; rotation or oversight existsIT manager performs "self-audit"

Why Independent Review Matters

The Business Risk Narrative

Independent review is the immune system of the ISMS. Without it, organizations operate on assumptions: "Our policies are followed," "Our controls work," "Our risks are managed." These assumptions are dangerous. An independent review tests reality against intention. It discovers whether the security program is performative or operational, whether risk treatment is effective or decorative, and whether management has the information it needs to govern.

The consequences of weak independent review include:

  • Undetected control failures that persist for months or years.
  • External audit nonconformities and certification suspension.
  • Regulatory penalties for failing to demonstrate assurance.
  • Breaches that exploit known but unremediated weaknesses.
  • Loss of customer trust and enterprise revenue.

Indian Regulatory Context

Indian organizations face a layered assurance environment. A.5.35 is not an abstract ISO checkbox; it aligns directly with Indian legal and supervisory expectations.

Digital Personal Data Protection Act, 2023 (DPDP Act)

Section 8 of the DPDP Act requires data fiduciaries to implement "reasonable security safeguards" to prevent personal data breaches. Section 9 imposes additional duties on significant data fiduciaries, including the appointment of a Data Protection Officer and the conduct of periodic independent audits. While the DPDP Rules are still under finalization, the statutory intent is clear: independent review of security controls will be a compliance obligation for many organizations. A.5.35 implementation prepares organizations for this requirement.

Reserve Bank of India (RBI)

  • Cyber Security Framework in Banks (2016): Banks must conduct periodic independent assurance audits of their cyber security posture. The board must review assurance reports.
  • Master Direction on Information Technology Framework for NBFCs: Requires NBFCs to establish an internal audit function for IT and cyber security, with reporting to the board or audit committee.
  • Cyber Security Information Technology (CSIT) directions: Regulated entities must report incidents within six hours and maintain strong assurance mechanisms.

Securities and Exchange Board of India (SEBI)

SEBI's cybersecurity circulars for market infrastructure institutions (MIIs), stock brokers, depository participants, and mutual funds mandate:

  • Half-yearly cybersecurity audits by empaneled auditors.
  • Submission of audit reports to SEBI.
  • Remediation timelines and evidence of closure.
  • Board-level review of cybersecurity posture.

Insurance Regulatory and Development Authority of India (IRDAI)

IRDAI's cybersecurity guidelines for insurers require:

  • An information security governance framework.
  • Periodic internal and external audits.
  • Reporting of cyber incidents.
  • Maintenance of audit trails.

CERT-In Directions, 2022

CERT-In's directions under the IT Act, 2000 require:

  • Reporting of specified cyber incidents within six hours.
  • Maintenance of ICT asset inventory and user logs.
  • Synchronization of ICT system clocks. Independent reviews validate whether these operational requirements are actually met.

Information Technology Act, 2000

Section 43A imposes liability on body corporates for negligence in implementing and maintaining reasonable security practices. The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 recognize ISO 27001 as a valid security standard. An effective A.5.35 program provides evidence of due diligence in court or regulatory proceedings.

Industry-Specific Consequences

IndustryConsequence of Weak Independent Review
BFSIRBI/SEBI enforcement, penalty, restriction on business expansion, loss of banking license eligibility.
SaaS / IT / ITeSEnterprise customers demand SOC 2 / ISO 27001 reports; failed audits terminate deals.
HealthcarePatient data breaches, NABH accreditation issues, DPDP Act penalties, reputational damage.
ManufacturingOT/IT security gaps, IP theft, ransomware shutdowns, supply chain disruption.
GovernmentCERT-In/MeitY sanctions, public accountability, national security implications.
E-commerce / Consumer TechCustomer data breaches, DPDP Act fines, loss of consumer trust, regulatory investigations.

impact of Non-Compliance: Statistics and Research

Study / SourceFinding
IBM impact of a Data Breach Report 2024Global average breach overhead: USD 4.88 million; India average: approximately USD 1.78 million (s).
Ponemon InstituteOrganizations with mature internal audit and security testing functions reduce breach overhead by 30-40%.
ISO Survey 2024Over 85,000 ISO 27001 certificates worldwide; India is among the fastest-growing markets.
SEBI enforcement actionsMultiple brokers and MIIs have faced restrictions for inadequate cybersecurity audits and reporting.
RBI penaltiesBanks and NBFCs have been fined for deficiencies in cyber security governance and internal audit.

A single major nonconformity on A.5.35, for example, an internal audit function that lacks independence, can lead to a corrective action request, suspension of certification, and cascading customer and regulatory consequences.


Scope and Applicability

What A.5.35 Covers

A.5.35 applies to the review of the entire ISMS implementation, not just technical controls. The scope includes:

DimensionExamples of Review Scope
PeopleRoles and responsibilities, competence, awareness training, screening, terms and conditions, segregation of duties, security culture.
ProcessesRisk assessment, incident management, access management, change management, vendor management, business continuity, policy management, management review.
TechnologiesNetworks, systems, applications, cloud services, endpoints, encryption, logging, monitoring, backups, identity and access management.
GovernanceLeadership commitment, policy framework, risk appetite, resource allocation, performance evaluation, continual improvement.
DocumentationPolicies, procedures, records, risk assessments, asset inventories, audit reports, management review minutes, corrective action records.

Who It Applies To

A.5.35 applies to all organizations seeking or maintaining ISO 27001 certification, regardless of size or sector. The implementation approach varies:

Organization ProfileImplementation Approach
Small organization (1-50 employees)Outsourced internal audit to an external firm; audit committee or CEO provides oversight.
Medium organization (50-500 employees)Dedicated internal auditor or audit function; may outsource specialized technical testing.
Large organization (500+ employees)Full internal audit department; risk-based multi-year audit plan; co-sourced technical specialists.
Enterprise (5000+ employees)Enterprise audit function with regional teams; continuous auditing; integrated assurance model.
Regulated entity (BFSI, SEBI, IRDAI)Mandatory audits beyond ISO: RBI/SEBI/IRDAI-specific audit programs and empaneled auditors.
SaaS / multi-tenantAudit must cover tenant isolation, shared responsibility, customer data protection, and change control.

Role Categories Covered by Review

Role CategoryWhy Reviewed
Top management / BoardGovernance, resource allocation, risk appetite, management review participation.
CISO / Security teamSecurity program design and execution; however, must not audit themselves.
IT / EngineeringImplementation and operation of technical controls; must not perform unsupervised self-review.
HRScreening, awareness training, terms and conditions, termination procedures.
Legal / ComplianceRegulatory mapping, contracts, data protection, breach notification.
Procurement / Vendor managementSupplier risk assessment, contract security clauses, monitoring.
Operations / FacilitiesPhysical security, business continuity, environmental controls.
Third parties / SuppliersWhere suppliers operate controls on the organization's behalf.

Key Definitions and Terminology

TermDefinitionISO 27001 / 27002 Context
Independent reviewA systematic, documented, and objective evaluation of the ISMS conducted by a person or team free from operational responsibility for the area reviewed.A.5.35 implementation mechanism.
Internal auditA formal, independent assurance activity designed to add value and improve an organization's operations. Often the delivery mechanism for A.5.35.Closely aligned with ISO 19011 and IIA standards.
Auditor independenceFreedom from conditions that threaten objectivity or the appearance of objectivity. Includes organizational independence and personal independence.Core requirement of A.5.35.
CompetenceDemonstrated ability to apply knowledge and skills to achieve intended results.Auditors must be competent in ISMS, security, and auditing.
Audit criteriaSet of policies, procedures, or requirements used as a reference against which audit evidence is compared.ISO 27001, organization policies, legal requirements.
Audit evidenceRecords, statements of fact, or other information relevant to audit criteria and capable of being verified.Sampling, interviews, observations, document review.
Audit findingResult of evaluating audit evidence against audit criteria. Can be conformity, nonconformity, or opportunity for improvement.Must be risk-rated and tracked.
NonconformityNon-fulfillment of a requirement. In ISO 27001, can be major or minor.Requires corrective action.
Corrective actionAction to eliminate the cause of a nonconformity and prevent recurrence.Closes audit findings.
Management reviewFormal review by top management of the ISMS at planned intervals to ensure continuing suitability, adequacy, and effectiveness.Receives audit results as input.
Risk-based audit planningPrioritizing audits based on risk, regulatory requirements, past findings, and changes.Required for effective A.5.35.
Integrated assuranceCoordination of internal audit, external audit, compliance, risk management, and control self-assessment to provide unified assurance.Maturity Level 4-5 approach.
Three Lines ModelGovernance model: first line (management owns risk), second line (risk/compliance oversight), third line (internal audit provides independent assurance).Helps structure independence.
Audit trailChronological record of system activities that enables the reconstruction and examination of events.Evidence source for A.5.35.
Significant changeChange that could materially affect information security risk, such as M&A, cloud migration, new product launch, major incident, new regulation, or reorganization.Triggers review under A.5.35.

Relationship to Other Controls

A.5.35 does not operate in isolation. It provides assurance over the implementation of many other controls.

Upstream Controls (Inputs to A.5.35)

ControlRelationship
A.5.1, Policies for information securityPolicies are audit criteria. A.5.35 verifies that policies exist, are approved, communicated, acknowledged, and reviewed.
A.5.2, Information security roles and responsibilitiesA.5.35 verifies that roles are defined, filled, and segregation of duties is maintained (including for audit itself).
A.5.4, Management responsibilitiesA.5.35 provides evidence that management is actively governing information security.
A.5.5, Contact with special interest groupsA.5.35 may assess whether threat intelligence inputs are incorporated into risk and audit planning.
A.5.9, Inventory of information and other associated assetsAsset inventory is a prerequisite for scoped audits.
A.6.3, Information security awareness, education and trainingA.5.35 tests whether staff understand and apply security requirements.
A.8.15, LoggingLogs are primary audit evidence for A.5.35 reviews of technical controls.
A.8.16, Monitoring activitiesA.5.35 evaluates whether monitoring is effective and acted upon.

Downstream Controls (Assured by A.5.35)

ControlRelationship
A.5.36, Compliance with policies, rules and standards for information securityA.5.35 audits compliance; A.5.36 establishes the compliance monitoring mechanism.
A.5.37, Documented operating proceduresA.5.35 verifies that procedures are followed in practice.
A.8.1, User endpoint devicesA.5.35 audits endpoint security implementation.
A.8.2, Privileged access rightsA.5.35 tests privileged access controls through sampling.
A.8.9, Management of removable mediaA.5.35 verifies media handling practices.
A.8.24, Use of cryptographyA.5.35 assesses cryptographic implementation against policy.
A.8.32, Change managementA.5.35 audits change control effectiveness.

Parallel Controls (Complementary Assurance)

ControlRelationship
A.5.24, Information security incident management planning and preparationA.5.35 may review incident response capability as part of the audit plan.
A.5.25, Assessment and decision on information security eventsA.5.35 evaluates whether incidents are correctly classified and escalated.
A.5.31, Legal, statutory, regulatory and contractual requirementsA.5.35 verifies compliance with legal and contractual obligations.
A.6.8, Information security event reportingA.5.35 tests whether reporting channels work and staff use them.

The Internal Audit vs. Independent Review Distinction

Is A.5.35 the Same as Internal Audit?

Not exactly. A.5.35 requires an independent review of information security. Internal audit is the most common and strong way to satisfy this requirement, but other models are possible if they preserve independence and competence.

ModelDescriptionBest For
Internal audit functionDedicated internal audit department or auditor reports to Audit Committee / CEO / Board.Medium to large organizations.
Co-sourced auditInternal staff plus external audit firm; external party provides independence and specialized skills.Organizations building audit capability.
Fully outsourced auditExternal firm conducts all internal audit activities under an approved charter.Small organizations, startups, SMEs.
Independent management reviewA peer manager from an unrelated function reviews security (less strong; requires safeguards).Very small organizations with documented independence.
External certification audit onlyRelying solely on the external ISO 27001 surveillance audit does not satisfy A.5.35, because the organization must perform its own independent reviews between external audits.Not acceptable as the sole mechanism.

Independence Continuum

LEAST INDEPENDENT                                    MOST INDEPENDENT
─────────────────────────────────────────────────────────────────────►
Self-review by CISO    Peer review by    Internal audit    Co-sourced    Fully outsourced
or IT manager          unrelated manager reporting to      internal      internal audit
                                            board/CEO        audit        by Big 4 /
                                                                           specialist

The Three Lines Model Applied to A.5.35

┌─────────────────────────────────────────────────────────────────┐
│  LINE 1: OPERATIONS (Owns Risk)                                 │
│  • IT, Engineering, HR, Facilities, Procurement                 │
│  • Implement and operate controls                               │
│  • Perform control self-assessments                             │
└─────────────────────────────────────────────────────────────────┘
                              │
                              ▼
┌─────────────────────────────────────────────────────────────────┐
│  LINE 2: RISK & COMPLIANCE OVERSIGHT                            │
│  • CISO, Risk Manager, Compliance Officer, DPO                  │
│  • Establish policies, monitor compliance, report to management │
│  • NOT independent of management; provides oversight            │
└─────────────────────────────────────────────────────────────────┘
                              │
                              ▼
┌─────────────────────────────────────────────────────────────────┐
│  LINE 3: INDEPENDENT ASSURANCE (A.5.35)                         │
│  • Internal Audit / Independent Review Function                 │
│  • Reports to Board / Audit Committee / CEO                     │
│  • Independent of operations and security management            │
└─────────────────────────────────────────────────────────────────┘

Critical point: If the CISO or security team also performs the internal audit, the organization has violated the independence requirement of A.5.35, regardless of how competent the individuals are.


Building the Independent Review Function

Organizational Options by Size

Organization SizeRecommended StructureReporting LineRationale
1-50 employeesOutsourced internal audit to a specialist firm (e.g., Singahi, Big 4, boutique ISO 27001 auditor)Reports to CEO / FounderNo internal capacity; external independence satisfies requirement.
50-200 employeesPart-time internal auditor + annual co-sourced technical auditsReports to CEO or Audit CommitteeBalance of overhead and independence.
200-1000 employeesFull-time Internal Audit Manager + 1-2 auditors; co-source specialized areasReports to Audit Committee / Board with administrative link to CEOSufficient scale for dedicated function.
1000-5000 employeesInternal Audit Department with IT/security audit specializationReports functionally to Audit Committee; administratively to CEOComplex environment needs specialization.
5000+ employees / GroupGroup Internal Audit with regional/center-of-excellence model; Chief Audit ExecutiveReports to Group Audit Committee / BoardEnterprise-wide assurance and consistency.

Independence Safeguards Checklist

  • The audit function has a formal charter approved by top management or the board.
  • The audit function has unrestricted access to people, records, systems, and premises.
  • The head of audit has direct access to the CEO / Board / Audit Committee without management filtering.
  • Auditors do not audit operations for which they are responsible.
  • Auditors are not incentivized based on the performance of the areas they audit.
  • Audit scope and plan cannot be unilaterally overridden by operational management.
  • Auditors have a documented conflict-of-interest declaration process.
  • Where the same person must perform security operations and audit (very small orgs), a record of mitigating controls exists (e.g., external review, management review, board oversight).

Audit Charter Template (Key Clauses)

INTERNAL AUDIT / INDEPENDENT REVIEW CHARTER
[Organization Name]
Version: 1.0
Approved by: [Board / Audit Committee / CEO]
Date: [Date]
Review Date: [Date + 12 months]

1. PURPOSE
This charter establishes the authority, independence, responsibility, and scope
of the independent review of information security at [Organization Name].

2. AUTHORITY
The independent review function is authorized to:
   • Access all information, records, systems, personnel, and premises relevant
to information security.
   • Request assistance from any employee or third party.
   • Report findings directly to the Audit Committee / Board / CEO.
   • Escalate unresolved high-risk findings without management interference.

3. INDEPENDENCE
The independent review function shall be independent of the activities reviewed.
The Head of Internal Audit reports functionally to the [Audit Committee / Board]
and administratively to the [CEO].

4. SCOPE
The scope includes the ISMS, information security policies, procedures, controls,
people, processes, and technologies, including outsourced operations.

5. RESPONSIBILITIES
   • Develop and maintain a risk-based audit plan.
   • Conduct audits in accordance with ISO 19011 principles.
   • Issue clear, risk-rated findings and recommendations.
   • Track findings to closure.
   • Provide input to management review.
   • Maintain auditor competence.

6. QUALITY ASSURANCE
The audit function shall undergo periodic internal and external quality assessments.

7. APPROVAL
This charter is approved by:
   [Chairperson, Audit Committee]    Date: __________
   [CEO]                             Date: __________
   [Head of Internal Audit]          Date: __________

Audit Charter and Governance

Governance Structure

┌─────────────────────────────────────────────────────────────┐
│  BOARD OF DIRECTORS / GOVERNING BODY                        │
│  • Ultimate oversight of information security               │
│  • Approves audit charter and risk appetite                 │
│  • Receives summary audit reports                           │
└─────────────────────────────────────────────────────────────┘
                              │
                              ▼
┌─────────────────────────────────────────────────────────────┐
│  AUDIT COMMITTEE (or equivalent)                            │
│  • Oversees internal audit function                         │
│  • Approves annual audit plan                               │
│  • Reviews significant findings and remediation             │
│  • Hires / fires Head of Internal Audit                     │
└─────────────────────────────────────────────────────────────┘
                              │
                              ▼
┌─────────────────────────────────────────────────────────────┐
│  HEAD OF INTERNAL AUDIT / INDEPENDENT REVIEW                │
│  • Develops audit plan                                      │
│  • Ensures independence and competence                      │
│  • Signs off on audit reports                               │
│  • Escalates unresolved issues                              │
└─────────────────────────────────────────────────────────────┘
                              │
                              ▼
┌─────────────────────────────────────────────────────────────┐
│  AUDIT TEAM(S)                                              │
│  • Execute audit engagements                                │
│  • Document working papers                                  │
│  • Test controls and sample evidence                        │
│  • Draft findings and reports                               │
└─────────────────────────────────────────────────────────────┘

Audit Committee Agenda (Quarterly)

Agenda ItemOwnerTimeOutput
Approval of annual audit planHead of Internal Audit15 minApproved plan
Review of audit reports since last meetingAudit Team30 minManagement actions agreed
Status of open findingsAudit Team20 minEscalation list
Independence and resource updateHead of Internal Audit10 minResource / independence confirmation
Regulatory audit updatesCompliance Officer10 minRegulatory compliance status
External audit coordinationCISO / Audit Head10 minCertification audit plan
Fraud / whistleblower updatesAudit Committee Chair10 minAction items

Audit Planning and Risk Assessment

Risk-Based Audit Planning Process

┌─────────────────────────────────────────────────────────────┐
│  STEP 1: UNDERSTAND CONTEXT                                 │
│  • ISMS scope, assets, processes, locations                 │
│  • Risk register and risk treatment plan                    │
│  • Legal / regulatory requirements                          │
│  • Previous audit findings                                  │
│  • External audit / certification history                   │
└─────────────────────────────────────────────────────────────┘
                              │
                              ▼
┌─────────────────────────────────────────────────────────────┐
│  STEP 2: RISK ASSESSMENT FOR AUDIT PLANNING                 │
│  • Inherent risk by process / system / location             │
│  • Control effectiveness from prior reviews                 │
│  • Regulatory and customer priority                         │
│  • Recent changes and incidents                             │
└─────────────────────────────────────────────────────────────┘
                              │
                              ▼
┌─────────────────────────────────────────────────────────────┐
│  STEP 3: PRIORITIZE AND SCHEDULE                            │
│  • High-risk areas audited more frequently                  │
│  • All Annex A controls covered over audit cycle            │
│  • Resource allocation and timing                           │
└─────────────────────────────────────────────────────────────┘
                              │
                              ▼
┌─────────────────────────────────────────────────────────────┐
│  STEP 4: APPROVE PLAN                                       │
│  • Audit Committee / top management approval                │
│  • Communicate plan to stakeholders                         │
└─────────────────────────────────────────────────────────────┘

Risk Scoring for Audit Planning

FactorWeightScore 1 (Low)Score 3 (Medium)Score 5 (High)
Regulatory / legal exposure25%No specific regulationIndustry guidance appliesRBI/SEBI/IRDAI/CERT-In mandated
Likelihood of incident20%Rare, no historyOccasional, some historyFrequent or recent incidents
Potential business impact25%Limited operational impactSignificant financial/reputationalBusiness-critical or existential
Control maturity15%Mature controls, clean historyPartial controls, minor findingsWeak controls, repeated findings
Change / complexity15%Stable, well-understoodModerate changeMajor change, new technology, M&A

Audit Priority Score = Σ (Factor Weight × Score)

Priority ScoreFrequency
4.0 – 5.0Audit annually or more frequently
2.5 – 3.9Audit every 12-24 months
1.0 – 2.4Audit every 24-36 months or by exception

Sample Three-Year Audit Plan

YearFocus AreasRationale
Year 1Governance (A.5.1, A.5.2, A.5.35), Risk assessment (A.5.36, A.6.1), Access control (A.5.15-A.5.18), Incident management (A.5.24-A.5.28)Foundational controls; high risk; external certification readiness.
Year 2Asset management (A.5.9-A.5.14), Cryptography (A.8.24), Operations security (A.8.1-A.8.16), Change management (A.8.32)Technical controls; regulatory focus on encryption and operations.
Year 3Supplier relationships (A.5.19-A.5.23), Physical security (A.7.1-A.7.14), Business continuity (A.5.29-A.5.30, A.8.13-A.8.14), Secure development (A.8.25-A.8.31)Third-party and resilience; complete Annex A coverage.

Note: High-risk areas should be audited every year regardless of the cycle.


Competence and Independence Requirements

Auditor Competence Framework

Competency AreaRequired Knowledge / SkillsEvidence
ISO 27001 and ISMSAnnex A controls, ISO 27001 clauses 4-10, audit lifecyclequalified lead auditor certification, training records
Information securityAccess control, cryptography, network security, incident response, cloud securityCISA, certified, or equivalent experience
Auditing principlesISO 19011, sampling, evidence, interviewing, report writingInternal audit training, previous audit records
Industry / regulatoryDPDP Act, RBI, SEBI, IRDAI, CERT-In, GDPR as applicableDomain training, legal updates
TechnologyCloud, SaaS, OS, databases, networks, identity platformsHands-on experience, certifications
Soft skillsInterviewing, communication, objectivity, conflict managementTraining, performance reviews

Independence Threats and Mitigations

ThreatExampleMitigation
Self-reviewIT manager audits their own patch management processAssign auditor from different function or external firm.
FamiliarityLong-term internal auditor becomes too close to operationsRotate auditors, use external co-source, cooling-off periods.
IntimidationAuditor fears retaliation from senior operations managerReporting line to board/audit committee, whistleblower protection.
Personal conflict of interestAuditor has financial interest in a vendor being auditedConflict-of-interest declaration and recusal process.
Management pressureAudit scope reduced to avoid findingsCharter protects scope; escalation path to audit committee.
Reporting compromiseCISO reviews and edits audit report before board sees itDirect reporting to audit committee; unfiltered findings.

Conflict-of-Interest Declaration Template

CONFLICT-OF-INTEREST DECLARATION
Audit Engagement: ________________________________
Auditor Name: ________________________________
Date: ________________________________

I declare that:
   ☐ I have no financial or personal interest in the area or personnel being audited.
   ☐ I have not been involved in designing, implementing, or operating the controls
      being audited in the past 12 months.
   ☐ I have no close family relationship with any manager in the audited area.
   ☐ I am not aware of any other circumstance that could impair my objectivity.

If any of the above is NOT true, describe below:
________________________________________________

Mitigation agreed:
________________________________________________

Auditor Signature: __________________ Date: __________
Audit Manager Signature: ____________ Date: __________

Conducting the Independent Review

Audit Engagement Lifecycle

┌─────────────────────────────────────────────────────────────┐
│  1. ENGAGEMENT PLANNING                                     │
│  • Define objectives, scope, criteria                       │
│  • Identify auditee, resources, timing                      │
│  • Prepare audit program and checklists                     │
└─────────────────────────────────────────────────────────────┘
                              │
                              ▼
┌─────────────────────────────────────────────────────────────┐
│  2. OPENING MEETING                                         │
│  • Confirm scope and schedule                               │
│  • Introduce audit team                                     │
│  • Explain methodology and independence                     │
└─────────────────────────────────────────────────────────────┘
                              │
                              ▼
┌─────────────────────────────────────────────────────────────┐
│  3. FIELDWORK / EVIDENCE GATHERING                          │
│  • Interviews, document review, observation, testing        │
│  • Sample selection and testing                             │
│  • Working paper documentation                              │
└─────────────────────────────────────────────────────────────┘
                              │
                              ▼
┌─────────────────────────────────────────────────────────────┐
│  4. ANALYSIS AND FINDING FORMULATION                        │
│  • Evaluate evidence against criteria                       │
│  • Rate risk and formulate findings                         │
│  • Validate with auditee (no surprises)                     │
└─────────────────────────────────────────────────────────────┘
                              │
                              ▼
┌─────────────────────────────────────────────────────────────┐
│  5. REPORTING                                               │
│  • Draft audit report                                       │
│  • Management response and action plan                      │
│  • Finalize and distribute                                  │
└─────────────────────────────────────────────────────────────┘
                              │
                              ▼
┌─────────────────────────────────────────────────────────────┐
│  6. FOLLOW-UP AND CLOSURE                                   │
│  • Track corrective actions                                 │
│  • Verify closure evidence                                  │
│  • Escalate overdue items                                   │
└─────────────────────────────────────────────────────────────┘

Audit Program Template: A.5.35 Review of Information Security

StepActivityEvidence SoughtSample Size
1Review ISMS scope and contextScope statement, interested parties, applicability statementAll
2Review risk assessment and treatmentRisk register, risk treatment plan, residual risk acceptanceAll
3Test policy frameworkMaster policy, topic-specific policies, approvals, reviews, acknowledgmentsSample of 5-10 policies
4Test access controlUser access lists, MFA evidence, privileged access reviews, termination records25 user accounts per system
5Test asset managementAsset inventory, classification, ownership, disposal records25 assets
6Test incident managementIncident register, response records, post-incident reviewsAll incidents in period
7Test supplier securityVendor assessments, contracts, monitoring recordsTop 10 critical vendors
8Test logging and monitoringLog samples, SIEM alerts, review records1 week of logs per critical system
9Test backup and recoveryBackup logs, restore test recordsLast 3 restore tests
10Test business continuityBIA, plans, test recordsAll critical plans
11Test HR securityScreening records, training records, termination checklists10 hires, 10 terminations
12Test management reviewMinutes, action tracking, resource decisionsLast 2 management reviews
13Test corrective actionNonconformity register, root cause analysis, closure evidenceAll open and recently closed
14Test awarenessTraining records, phishing test results10% of staff or sample

Audit Sampling Guidance

Population SizeRecommended SampleRationale
< 25100% (census)Small populations; every item matters.
25 – 10015-25 itemsStatistically reasonable for assurance.
100 – 100025-50 itemsBalance of coverage and efficiency.
1000+50-100 items + risk-stratified samplingFocus on high-risk / privileged / changed items.

Sample selection must be risk-based and representative, not convenience-based. Document the sampling method in working papers.


Audit Evidence Collection Techniques

Evidence Types and Reliability

Evidence TypeReliabilityExamples
Documentary evidenceHigh if original and controlledApproved policies, signed contracts, management review minutes
System-generated recordsHigh if logs are tamper-protectedSIEM logs, backup logs, access control system reports
InterviewsMedium (subjective)Staff explaining how they handle incidents
ObservationMedium (snapshot in time)Watching a clearance process at a reception
ReperformanceHighAuditor independently verifies a control (e.g., attempts unauthorized access in test environment)
Analytical proceduresMedium-HighTrend analysis of incidents, access reviews, patching metrics
External confirmationsHighVendor SOC 2 reports, penetration test reports, certification body communications

Interview Techniques for Auditors

TechniquePurposeExample Question
Open-endedUnderstand process and mindset"Walk me through how you handle a reported phishing email."
ClosedVerify specific facts"Do you have MFA enabled on your email account?"
ProbingExplore inconsistencies"You said access is reviewed quarterly. Can you show me the last review?"
Scenario-basedTest practical knowledge"If you discovered a laptop with customer data was stolen, what would you do first?"
Document-linkedTie testimony to evidence"This policy says incidents are reported within 1 hour. When did you last report an incident, and how?"

Working Paper Requirements

Every audit finding must be supported by working papers containing:

  • Audit objective and criteria.
  • Population and sampling method.
  • Evidence collected (with references to documents, logs, screenshots).
  • Auditor analysis and conclusion.
  • Finding classification (conformity / nonconformity / OFI).
  • Risk rating and rationale.
  • Cross-reference to final report.

Reporting and Management Review

Audit Report Structure

INDEPENDENT REVIEW REPORT — INFORMATION SECURITY
[Organization Name]
Audit Engagement: ________________________________
Audit Period: ________________________________
Report Date: ________________________________
Distribution: Audit Committee, CEO, CISO, [relevant management]

1. EXECUTIVE SUMMARY
   • Overall opinion on ISMS effectiveness
   • Number and severity of findings
   • Key themes and trends

2. AUDIT SCOPE AND OBJECTIVES
   • What was reviewed and why
   • Audit criteria (ISO 27001, policies, regulations)

3. METHODOLOGY
   • Sampling approach, evidence types, interviews conducted

4. FINDINGS
   For each finding:
   • Finding ID and title
   • Risk rating (Critical / High / Medium / Low)
   • ISO 27001 / policy clause reference
   • Condition (what was found)
   • Criterion (what should be)
   • Cause (root cause)
   • Effect (risk / impact)
   • Recommendation

5. MANAGEMENT RESPONSE AND ACTION PLAN
   • Agreed actions, owners, target dates

6. OVERALL OPINION
   • Effective / Partially Effective / Ineffective

7. APPENDICES
   • Detailed test results, sample lists, evidence references

Risk Rating Matrix for Findings

RatingDefinitionTypical Escalation
CriticalControl failure could lead to severe breach, regulatory action, or business disruption; immediate action required.CEO / Board within 24 hours
HighSignificant weakness with material risk; action required within 30 days.Audit Committee / CISO
MediumControl deficiency with moderate risk; action required within 90 days.Department head / CISO
LowMinor gap; best practice improvement; action within 180 days or by next review.Process owner
Observation / OFINo nonconformity, but opportunity for improvement.Process owner

Management Review Input

A.5.35 outputs must feed into ISO 27001 Clause 9.3 Management Review. Inputs include:

  • Summary of audit results (internal and external).
  • Status of open findings and corrective actions.
  • Trends in incidents and control failures.
  • Resource adequacy of the audit function.
  • Changes affecting the ISMS.
  • Recommendations for improvement.

Corrective Action and Continuous Improvement

Findings Register

Finding IDDescriptionRisk RatingISO Clause / PolicyOwnerTarget DateStatusClosure Evidence
A.5.35-001Privileged access reviews not performed quarterlyHighA.5.18 / Access Control PolicyIT Director2026-07-31OpenQuarterly review records
A.5.35-002Incident response plan not tested in past 12 monthsMediumA.5.24 / IR PolicyCISO2026-08-15OpenTabletop exercise report
A.5.35-003Two terminated employees retained VPN access for 5 daysHighA.6.6 / HR Security PolicyHR Manager2026-07-15ClosedTermination checklist + system log

Corrective Action Process

FINDING IDENTIFIED
        │
        ▼
ROOT CAUSE ANALYSIS
(5 Whys / Fishbone / Fault Tree)
        │
        ▼
CORRECTIVE ACTION PLAN
(Who, What, When, Evidence)
        │
        ▼
MANAGEMENT APPROVAL
        │
        ▼
ACTION IMPLEMENTATION
        │
        ▼
VERIFICATION BY AUDITOR
(Evidence review, retest)
        │
        ▼
FINDING CLOSED

Escalation Protocol for Overdue Findings

Days OverdueActionOwner
7 daysReminder to finding ownerInternal Audit
14 daysCopy to owner + 1 (manager)Internal Audit
21 daysEscalate to CISO / functional headInternal Audit
30 daysEscalate to CEO / Audit CommitteeHead of Internal Audit
45 daysBoard / Audit Committee formal notificationHead of Internal Audit

Tools, Technologies, and Solutions

GRC and Audit Management Platforms

PlatformBest ForKey Featureslicensing Indication (India)
ServiceNow GRC / IRMEnterprisesIntegrated risk, audit, compliance, vendor management+ annually
MetricStreamLarge banks, NBFCs, regulated entitiesAudit management, regulatory compliance, BCM+ annually
RSA ArcherEnterprise GRCHighly configurable risk and audit workflows+ annually
SAP GRCSAP-centric organizationsAccess control, process control, audit management+ annually
Qualys Policy ComplianceTechnical control assessmentContinuous scanning against CIS benchmarks, policies+ annually
Tenable.sc / NessusVulnerability and configuration auditVA scans, configuration audits, dashboards+ annually
Zoho Creator (custom)SMEsLow-code audit workflow and register

Technical Testing Tools for Audit Evidence

CategoryTool ExamplesUse in A.5.35
Vulnerability assessmentNessus, Qualys, OpenVAS, Rapid7Verify patch and configuration controls.
Penetration testingBurp Suite, Metasploit, Cobalt Strike, Kali LinuxValidate effectiveness of technical defenses.
SIEM / log analysisSplunk, ELK, QRadar, Sentinel, WazuhVerify logging, monitoring, and alerting.
IAM auditOkta, Entra ID, SailPoint, SaviyntVerify access reviews, MFA, provisioning.
Cloud security posturePrisma Cloud, Wiz, Orca, LaceworkVerify cloud control effectiveness.
Code securitySonarQube, Snyk, Checkmarx, SemgrepVerify secure development controls.
Data discovery / DLPSymantec DLP, Forcepoint, Microsoft PurviewVerify data classification and protection.
GRC / audit workflowAuditBoard, Workiva, TeamMate+Manage audit engagements and findings.

Build vs. Buy vs. Outsource

ApproachBest ForProsCons
Spreadsheets + documentsVery small orgs, first auditCheap, fastNot scalable, weak evidence integrity
Low-code / Zoho CreatorSMEsAffordable, customizableRequires maintenance
Enterprise GRC (ServiceNow, MetricStream)Large regulated entitiesScalable, integratedpremium-tier, long implementation
Outsourced internal auditAll sizesImmediate independence and expertiseRecurring overhead, less institutional knowledge

Policy and Procedure Templates

Independent Review / Internal Audit Policy (Extract)

INDEPENDENT REVIEW OF INFORMATION SECURITY POLICY
[Organization Name]
Version: 1.0
Owner: Head of Internal Audit
Approved by: [CEO / Audit Committee Chair]
Date: [Date]
Review Date: [Date + 12 months]

1. PURPOSE
This policy defines the requirements for independent review of the organization's
information security management system (ISMS) and its implementation.

2. SCOPE
This policy applies to all ISMS processes, controls, personnel, technologies,
locations, and third-party operations within the defined ISMS scope.

3. POLICY STATEMENTS
3.1 The organization shall conduct independent reviews of information security
    at planned intervals and when significant changes occur.
3.2 Reviews shall be conducted by competent reviewers who are independent of
    the activities being reviewed.
3.3 Reviews shall assess conformance to ISO 27001, organization policies, and
    applicable legal/regulatory requirements.
3.4 Review findings shall be documented, risk-rated, reported to management,
    and tracked to closure.
3.5 Results of independent reviews shall be input to management review.
3.6 The review function shall have an approved charter, unrestricted access,
    and a reporting line to top management or the audit committee.

4. ROLES AND RESPONSIBILITIES
4.1 Board / Audit Committee: Approve charter, approve plan, oversee findings.
4.2 Head of Internal Audit: Plan, execute, and report independent reviews.
4.3 Process Owners: Provide access, implement corrective actions.
4.4 CISO: Support audits, remediate security findings (but does not audit own function).

5. INDEPENDENCE AND CONFLICTS
5.1 Auditors shall not audit their own work.
5.2 Auditors shall declare conflicts of interest before each engagement.
5.3 Where full independence is not achievable, mitigation shall be documented
    and approved by top management.

6. COMPETENCE
6.1 Auditors shall maintain relevant qualifications (CISA, qualified lead auditor,
    certified, or equivalent).
6.2 Auditors shall complete at least 20 hours of continuing professional
    development annually.

7. PLANNING AND EXECUTION
7.1 A risk-based audit plan shall be prepared annually and approved by the
    Audit Committee / top management.
7.2 Audit engagements shall follow the documented audit methodology aligned
    with ISO 19011.
7.3 Audit working papers shall be maintained securely and retained for at
    least [X] years.

8. REPORTING AND FOLLOW-UP
8.1 Audit reports shall be issued within [15/30] days of engagement completion.
8.2 Management shall provide responses and action plans within [15] days.
8.3 Findings shall be tracked in a central register until closure.
8.4 Overdue findings shall be escalated per the escalation matrix.

9. REVIEW
This policy is reviewed annually and on significant change.

Audit Procedure Template (Extract)

PROCEDURE: CONDUCTING INDEPENDENT INFORMATION SECURITY REVIEWS

1. PURPOSE
To define the steps for planning, conducting, reporting, and following up on
independent reviews of information security.

2. SCOPE
All ISMS audits, reviews, and assurance engagements.

3. PROCEDURE STEPS

Step 1 — Annual Planning
   a. Review risk register, previous findings, incident trends, regulatory changes.
   b. Develop risk-based audit plan covering all Annex A controls over [3-year] cycle.
   c. Obtain Audit Committee / top management approval.

Step 2 — Engagement Planning
   a. Define objectives, scope, and criteria.
   b. Assign competent, independent auditors.
   c. Issue engagement letter / notification to auditee at least 2 weeks in advance.
   d. Prepare audit program and checklists.

Step 3 — Opening Meeting
   a. Confirm scope, schedule, and contacts.
   b. Explain independence and confidentiality obligations.
   c. Document attendance and agreements.

Step 4 — Fieldwork
   a. Conduct interviews, document reviews, observations, and testing.
   b. Maintain working papers with evidence references.
   c. Hold daily debriefs to discuss emerging issues.

Step 5 — Findings Validation
   a. Draft findings and share with auditee for factual accuracy.
   b. Allow auditee to provide additional evidence.
   c. Finalize risk ratings.

Step 6 — Reporting
   a. Draft audit report within [15] days.
   b. Obtain management responses and action plans.
   c. Finalize and distribute to approved recipients.

Step 7 — Follow-Up
   a. Track corrective actions to target dates.
   b. Verify closure evidence.
   c. Report status to Audit Committee / management review.

4. RECORDS
   • Annual audit plan
   • Engagement planning documents
   • Working papers
   • Audit reports
   • Findings register
   • Closure evidence

Risk Assessment and Treatment

A.5.35-Specific Risk Table

Risk IDThreat / VulnerabilityLikelihoodImpactRisk LevelTreatmentOwner
R-001Internal audit lacks independence; CISO audits own teamHighCriticalCriticalEstablish audit function reporting to board/CEO; implement charter; use external co-sourceCEO / Audit Committee
R-002Auditors lack competence in ISO 27001 / information securityMediumHighHighRequire CISA/qualified lead auditor; provide training; outsource complex auditsHead of Internal Audit
R-003Audit plan not risk-based; high-risk areas missedMediumHighHighImplement risk-based planning methodology; align with risk registerHead of Internal Audit
R-004Findings not tracked; corrective actions overdueMediumHighHighImplement findings register with escalation; verify closureHead of Internal Audit
R-005External certification audit identifies major nonconformity before internal audit doesMediumHighHighIncrease audit frequency; improve technical testing; pre-audit internal reviewCISO
R-006Significant change (cloud migration, M&A) not reviewedMediumCriticalHighDefine change-triggered review policy; include in change managementCISO
R-007Audit evidence insufficient or unreliableMediumMediumMediumTrain auditors in evidence techniques; use system-generated logsHead of Internal Audit
R-008Management ignores audit findingsLowHighMediumReport to board/audit committee; link to incentives and risk appetiteBoard
R-009Third-party controls not included in review scopeMediumMediumMediumExtend scope to critical suppliers; include supplier audits in planProcurement / CISO
R-010Audit reports leaked or mishandledLowMediumLowClassification, access controls, secure distributionHead of Internal Audit

Risk Treatment Summary

Treatment TypeCountRisk IDs
Mitigate9R-001 to R-009
Transfer0-
Accept1R-010 (residual risk managed through confidentiality controls)
Avoid0-

Audit and Compliance Checklist

A.5.35 Audit Checklist (for Internal / External Auditors)

#Audit QuestionExpected EvidenceRed Flag
1Is there an approved internal audit / independent review charter?Signed charter, board/audit committee minutesNo charter; charter lacks independence language
2Does the audit function report to a level that ensures independence?Organization chart, reporting line documentationReports to CISO or IT Director
3Is there an annual, risk-based audit plan approved by top management?Approved plan, planning methodologyNo plan; plan not risk-based
4Does the plan cover people, processes, and technologies?Plan scope statementPlan only covers documents or IT systems
5Are audits conducted at planned intervals?Audit reports with datesAudits only before certification audit
6Are audits triggered by significant changes?Change-triggered review recordsNo reviews after M&A / cloud migration / major incident
7Are auditors competent and qualified?CVs, certifications, training recordsAuditors without security audit qualifications
8Do auditors declare conflicts of interest?Conflict declarationsNo conflict management process
9Are audit working papers maintained?Working paper filesNo evidence of how conclusions were reached
10Are audit reports clear, risk-rated, and actionable?Sample reportsReports are vague "observations" only
11Are findings tracked to closure?Findings register, closure evidenceOpen findings beyond target dates
12Are overdue findings escalated?Escalation records, board minutesNo escalation process
13Are audit results input to management review?Management review minutesAudit results never discussed by top management
14Is there evidence that the CISO does not audit their own function?Scope allocation, independence matrixCISO signs their own audit report
15Are third-party / outsourced operations included in scope?Supplier audit recordsNo supplier reviews
16Are corrective actions verified before closure?Closure evidence, retest recordsFindings closed without evidence
17Does the organization use external audit support where needed?Contracts, co-source reportsRefuses external support despite gaps
18Are audit plans updated based on risk and incident trends?Plan updates, risk register linkageStatic plan unchanged for years
19Is there a quality assurance process for the audit function?QA review recordsNo self-assessment or external QA
20Do auditors have unrestricted access to information and personnel?Charter, access logsManagement restricts access during audit

Compliance Evidence Mapping

Requirement SourceEvidence RequiredWhere to Find
ISO 27001 A.5.35Audit charter, plan, reports, findings registerInternal audit file repository
ISO 27001 Clause 9.2 (internal audit)Internal audit program, audit criteria, resultsISO 27001 implementation records
ISO 27001 Clause 9.3 (management review)Minutes referencing audit resultsManagement review minutes
DPDP Act 2023 (anticipated)Independent audit reports for significant data fiduciariesLegal/compliance files
RBI Cyber Security FrameworkBoard-reviewed cyber assurance reportsBoard/audit committee records
SEBI cybersecurity circularsEmpaneled auditor reports, remediation evidenceCompliance/regulatory files
CERT-In directionsIncident and log review recordsSOC/CERT-In files

Metrics and KPIs

Figure · Measures

The measures that show A.5.35 is working

  • Audit plan completion≥ 95%Quarterly
  • Finding closure rate≥ 95%Monthly
  • Critical finding aging< 15 daysWeekly
  • High finding aging< 45 daysMonthly
  • Audit report timeliness≥ 95%Per audit
Targets and reporting cadence as defined in the table below, where the formula for each is given.

Audit Function KPIs

KPIFormulaTargetFrequency
Audit plan completion(Audits completed / Audits planned) × 100≥ 95%Quarterly
Finding closure rate(Findings closed on time / Total due findings) × 100≥ 95%Monthly
Critical finding agingAverage days critical findings remain open< 15 daysWeekly
High finding agingAverage days high findings remain open< 45 daysMonthly
Audit report timeliness(Reports issued within SLA / Total reports) × 100≥ 95%Per audit
Management review coverage(Audit topics discussed in management review / Required topics) × 100100%Per management review
Auditor competence compliance(Auditors meeting qualification requirements / Total auditors) × 100100%Annually
Independence compliance(Audits with no conflict / Total audits) × 100100%Per audit
Repeat finding rate(Repeat findings / Total findings) × 100< 10%Annually
Audit satisfaction (auditee)Survey score from auditees≥ 4.0 / 5Per audit
overhead per audit dayTotal audit overhead / Audit daysBenchmark internallyAnnually
External audit finding correlation(External findings not previously identified internally / Total external findings) × 100< 20%Per certification audit
Change-triggered review coverage(Significant changes reviewed / Significant changes) × 100100%Per change
Supplier audit coverage(Critical suppliers audited / Critical suppliers) × 100≥ 90%Annually
Training hours per auditorTotal CPD hours / Number of auditors≥ 20 hours/yearAnnually

KPI Dashboard Template

INDEPENDENT REVIEW KPI DASHBOARD — Q2 2026
[Organization Name]

AUDIT PLAN
   Planned audits: 12
   Completed: 11
   Completion rate: 91.7% ⚠️ (target 95%)

FINDINGS
   Open: 23
   Critical: 1 (age 8 days)
   High: 5 (avg age 22 days)
   Medium: 10
   Low: 7
   Closed on time: 94% ✅

COMPETENCE & INDEPENDENCE
   Auditor qualification compliance: 100% ✅
   Independence compliance: 100% ✅
   CPD hours per auditor: 24 ✅

EXTERNAL AUDIT ALIGNMENT
   External certification findings: 2
   Previously identified internally: 2
   Internal coverage: 100% ✅

TOP RISKS
   1. Delayed closure of privileged access review finding
   2. One supplier audit postponed due to resource constraints

Common Pitfalls / Audit Failures & How to Avoid Them

#Pitfall / FindingCauseHow to AvoidTimeline
1CISO audits their own functionMisunderstanding of independence; resource constraintsCharter must require audit function independence; use external co-source if needed2 weeks
2No annual audit planAd-hoc approach; no governanceDevelop risk-based plan; get Audit Committee approval2 weeks
3Audit plan is a generic checklistCopied from internet without customizationLink plan to risk register, assets, regulatory requirements1 week
4Auditors lack security competenceHR hired generic internal auditorRequire CISA/certified/qualified lead auditor; train or outsource1 month
5Findings are vague observationsInexperienced auditors; fear of conflictTrain auditors on finding format: condition, criterion, cause, effect, risk2 weeks
6No follow-up on findingsWeak governance; no tracking toolImplement findings register with escalation1 week
7Management review ignores audit resultsResults not packaged for managementProvide executive summary; link findings to risk and business impact1 week
8Significant changes not reviewedChange management and audit not integratedAdd "security review required" gate in change management2 weeks
9Audit evidence is unreliableSpreadsheets, manual screenshots, no log integrityUse system-generated, tamper-protected evidence where possibleOngoing
10Third-party controls excludedNarrow scope definitionInclude critical suppliers and cloud services in audit universe2 weeks
11Audit reports not distributedPolitical sensitivityCharter mandates distribution to Audit Committee/CEO1 week
12No quality assurance of audit functionAudit function not reviewedPerform annual self-assessment and periodic external QAAnnually

Illustrative Scenarios

Illustrative scenario, a composite example for guidance, not a specific Singahi engagement or a verified outcome.

Illustrative Scenario 1: Bengaluru Fintech, Major Nonconformity on Independence

Background A 300-employee fintech startup in Bengaluru processed payments and lending data for over 1 million customers. The company had achieved ISO 27001 certification two years earlier and was preparing for recertification.

The Incident During the Stage 1 recertification audit, the external auditor reviewed the internal audit function. The findings were severe:

  • The "Internal Audit Manager" reported directly to the CISO.
  • The internal audit plan was drafted by the CISO and approved by the CISO.
  • Two of three internal auditors were former members of the IT security team.
  • The internal audit report for the previous year had been edited by the CISO before submission to management.
  • The audit had not reviewed any area owned by the CISO (risk assessment, incident management, security operations).

The external auditor issued a major nonconformity against A.5.35 and suspended the certification process.

Impact

  • ISO 27001 recertification delayed by 6 months.
  • Two enterprise customers (a bank and an NBFC) put partnership agreements on hold, citing loss of certification.
  • Estimated revenue impact: s in delayed deals.
  • Regulatory scrutiny increased because the company was also preparing for RBI NBFC cyber security compliance.

Root Cause Analysis

  1. Structural independence failure: The audit function was structurally subordinate to the function it was supposed to review.
  2. Conflict of interest: Former IT security staff auditing their old colleagues created familiarity and intimidation threats.
  3. Lack of board oversight: No audit committee existed; the board received only summarized, sanitized reports.
  4. overhead-driven design: The company had combined the CISO and internal audit roles to save headcount.
  5. Weak understanding of A.5.35: The team treated internal audit as a compliance checkbox rather than a governance control.

Remediation The company engaged Singahi to redesign the independent review function:

Phase 1, Restructure (Week 1-2):

  • Created an Internal Audit Charter approved by the Board.
  • Appointed a Head of Internal Audit reporting functionally to the Board and administratively to the CEO.
  • Removed internal audit from the CISO's organization.
  • Implemented conflict-of-interest declarations and auditor rotation.

Phase 2, Re-audit (Week 3-8):

  • Re-performed the prior year's internal audit with the new independent team.
  • Added external co-source for technical security testing.
  • Audited the CISO function directly for the first time.
  • Identified 18 findings, including 3 high-risk gaps in incident response and privileged access.

Phase 3, Close and Certify (Month 3-6):

  • Tracked all findings to closure with verified evidence.
  • Updated management review process to include unfiltered audit inputs.
  • Passed follow-up external audit with no A.5.35 nonconformity.

Results

  • Recertification achieved 6 months after initial suspension.
  • Regained enterprise customer trust; both partnerships signed.
  • Board established a quarterly Audit Committee agenda item for information security.
  • Investment: Revenue protected/added: + crores.

Key Lessons

  1. Independence is non-negotiable. A CISO cannot audit their own function.
  2. Organizational design matters more than individual integrity.
  3. Board/audit committee oversight is essential for credible assurance.
  4. The impact of remediation far exceeds the impact of designing independence correctly from the start.
  5. A.5.35 is a governance control, not a documentation exercise.

Illustrative Scenario 2: Mumbai NBFC, From Regulatory Warning to RBI-Ready Assurance

Background A mid-sized non-banking financial company (NBFC) in Mumbai with 800 employees and s in assets under management had grown rapidly through digital lending. The RBI Master Direction on IT Framework for NBFCs required periodic independent audits of IT and cyber security.

The Incident During an RBI thematic inspection, the regulator observed:

  • No documented independent review of cyber security in the past 24 months.
  • IT audit was performed by the IT department itself.
  • Findings from previous external audits were not tracked to closure.
  • No evidence that the board reviewed cyber security assurance.

RBI issued a warning letter requiring corrective action within 90 days and a follow-up submission.

Impact

  • Board and senior management reputation risk.
  • Potential restriction on onboarding new digital borrowers.
  • Increased impact of compliance and external audit support.
  • Customer and investor confidence shaken.

Root Cause Analysis

  1. Compliance silos: The compliance team managed RBI reporting, the IT team managed controls, and internal audit focused on financial audits. Cyber security assurance fell through the gaps.
  2. No risk-based IT audit plan: The annual internal audit plan did not include cyber security as a priority.
  3. Inadequate board reporting: Cyber security was a single slide in the annual board presentation, with no assurance opinion.
  4. Resource constraints: The internal audit team had financial audit expertise but no cyber security competence.

Remediation Singahi designed an integrated assurance program aligned with RBI and ISO 27001:

Phase 1, Setup (Week 1-3):

  • Drafted Information Security Independent Review Policy and Charter.
  • Appointed a Head of IT Audit with CISA and qualified lead auditor credentials.
  • Established an IT Audit Sub-Committee of the Board.
  • Created a 3-year risk-based audit plan covering RBI cyber security domains and ISO 27001 Annex A.

Phase 2, Execution (Week 4-10):

  • Conducted complete independent review of cyber security governance, access control, incident management, vendor management, data protection, and business continuity.
  • Used co-sourced technical testing (penetration testing, configuration review, log analysis).
  • Identified 32 findings, including critical gaps in data localization logging and privileged access.

Phase 3, Closure and Reporting (Week 11-13):

  • Management action plans approved by the Board.
  • Follow-up testing verified closure of all critical and high findings.
  • Submitted detailed assurance report to RBI within the deadline.

Results

  • RBI accepted the remediation; no further enforcement action.
  • Board now receives quarterly cyber security assurance dashboards.
  • ISO 27001 surveillance audit passed with zero findings on A.5.35.
  • Customer due diligence improved; two new institutional investors completed security assessments successfully.
  • Investment: Regulatory and reputational risk: substantially reduced.

Key Lessons

  1. Financial audit expertise does not equal information security audit expertise.
  2. Regulators expect board-level oversight and independent assurance, not self-certification.
  3. A risk-based audit plan must explicitly cover cyber security, data protection, and third parties.
  4. Co-sourcing technical expertise is a practical way to build credibility quickly.
  5. A.5.35 compliance directly supports regulatory compliance with RBI, SEBI, IRDAI, and DPDP Act expectations.

Multi-Framework Mapping

ISO 27001:2022 A.5.35SOC 2 Type IIPCI DSS 4.0NIST 800-53 Rev 5CIS Controls v8COBIT 2019GDPR / DPDP Act 2023
Independent review of information securityCC1.3 (Management establishes structures, reporting lines, authorities), CC4.1 (Management selects and develops controls), CC4.2 (Management evaluates controls)12.4.2 (Verify audit log reviews), 12.5 (Deploy change-detection mechanisms), 12.10.4 (Review logs for unauthorized changes)CA-2 (Control assessments), CA-7 (Continuous monitoring), PM-30 (Authorization process), RA-3 (Risk assessment), SA-12 (Auditing policy / procedures)Control 7 (Continuous vulnerability management), Control 8 (Audit log management), Control 19 (Incident response management)APO14.02 (Managed assurance), MEA01.01 (Monitor and evaluate performance), MEA01.02 (Monitor and evaluate internal control), MEA01.04 (Obtain assurance)GDPR Article 32 (Security of processing, including review), DPDP Act 2023 Section 8 (Reasonable security safeguards), anticipated DPDP Rules on periodic independent audits
A.5.1 (Policies)CC1.1, CC1.212.4.1PL-1, PL-2, PL-4Control 3 (Data protection)EDM01.01, EDM01.02DPDP Act notice/consent policies
A.5.36 (Compliance with policies)CC1.412.4.2PM-4, PM-5Control 5 (Account management)APO14.03DPDP Act Section 12 (grievance redressal)
A.5.37 (Documented operating procedures)CC7.212.4.2SA-12Control 4 (Secure configuration)DSS05.04-
A.8.15 (Logging)CC7.210.3, 10.4AU-6, AU-12Control 8DSS05.07DPDP Act accountability
A.8.16 (Monitoring activities)CC7.211.4.5CA-7, SI-4Control 13 (Network monitoring)DSS05.07-

Implementation Roadmap

Figure · Timeline

Rollout in order

  1. Phase 1: Foun…1-30
  2. Phase 2: Build31-60
  3. Phase 3: Oper…61-90
Milestones in delivery order. Owners and the evidence each produces are in the table below.

8-Week Implementation Roadmap

WeekFocusKey ActivitiesDeliverable
1Governance & CharterEstablish reporting line, draft charter, identify Audit Committee sponsorDraft Internal Audit Charter
2Charter Approval & PlanningApprove charter, appoint Head of Audit, assess current audit maturityApproved Charter; Maturity assessment
3Risk-Based PlanMap ISMS scope, risk register, assets; draft 12-month / 3-year planRisk-based audit plan draft
4Competence & ToolsConfirm auditor qualifications; select audit management tool; develop templatesCompetence matrix; tool selected
5Methodology & TemplatesFinalize audit program, checklists, finding format, report templateAudit methodology pack
6Pilot AuditConduct pilot audit of 1-2 high-risk areas; test process end-to-endPilot audit report
7Process RefinementAddress pilot issues; update templates; train process ownersRefined methodology
8Launch ProgramExecute first full audit cycle; establish findings register and KPI dashboardProgram launched

90-Day Sprint for New ISMS

PhaseDaysActivities
Phase 1: Foundation1-30Charter, reporting line, plan, competence assessment, tool selection
Phase 2: Build31-60Templates, methodology, pilot audit, process refinement
Phase 3: Operate61-90First full audits, findings register, management review input, KPIs

FAQ

Is internal audit mandatory for ISO 27001?

Not explicitly. ISO 27001 requires an independent review of information security (A.5.35). Internal audit is the standard way to satisfy this, but other models are acceptable if they preserve independence and competence. For most organizations, a formal internal audit function or co-sourced/outsourced equivalent is expected by certification auditors.

Can the CISO perform the internal audit?

No. The CISO cannot independently review their own function. This is the most common A.5.35 failure. Independence requires separation. The CISO can support the audit by providing evidence and implementing corrective actions, but cannot be the auditor or approve the audit scope/report for their own area.

How often must the independent review be conducted?

At planned intervals, typically at least annually for the overall ISMS, and more frequently for high-risk areas. Additionally, reviews must be triggered by significant changes such as mergers, acquisitions, cloud migration, major incidents, new regulations, or major system launches.

What qualifications should an information security auditor have?

Ideal qualifications include:

  • CISA (Certified Information Systems Auditor)
  • qualified lead auditor
  • certified or certified
  • Relevant technical certifications (cloud, networking, etc.)
  • Training in ISO 19011 auditing principles

For specialized technical testing, the auditor may be supported by penetration testers, cloud security engineers, or forensics experts.

What if we are too small to have a dedicated internal auditor?

Small organizations can:

  • Outsource internal audit to a qualified firm.
  • Use a part-time external auditor.
  • Engage a virtual CISO / audit service.
  • Document independence safeguards in the charter.

The key is that the reviewer is independent of the operations reviewed, not that they are a full-time employee.

Does A.5.35 require us to audit every Annex A control every year?

No. A.5.35 requires reviews at planned intervals. A risk-based audit plan typically covers all Annex A controls over a 2-3 year cycle, with high-risk controls audited annually. The plan must be justified by risk and approved by top management.

What is the difference between A.5.35 and ISO 27001 Clause 9.2 (internal audit)?

  • Clause 9.2 is a management system requirement to conduct internal audits of the ISMS at planned intervals.
  • A.5.35 is an Annex A control specifically requiring independent review of the information security approach and implementation, including people, processes, and technologies.

In practice, a well-designed internal audit program satisfies both requirements simultaneously.

How does A.5.35 relate to DPDP Act 2023 independent audits?

The DPDP Act 2023 requires significant data fiduciaries to conduct periodic independent audits. While the detailed rules are pending, A.5.35 implementation provides the foundation: an independent audit function, risk-based plan, competent auditors, and documented findings. Organizations should align their A.5.35 program with anticipated DPDP audit requirements.

What should be in an A.5.35 audit report?

An effective report includes:

  • Executive summary and overall opinion.
  • Scope, objectives, and criteria.
  • Methodology and sampling.
  • Risk-rated findings with condition, criterion, cause, effect, and recommendation.
  • Management response and action plan.
  • Appendices with detailed evidence references.

How do we demonstrate independence if we use an outsourced auditor?

Demonstrate that:

  • The outsourced firm has no conflict of interest (e.g., did not design the controls being audited).
  • The contract specifies independence and reporting lines.
  • The firm reports directly to your board/audit committee/CEO.
  • You maintain oversight and quality review of their work.

Can IT perform vulnerability assessments and still be independent?

IT can perform operational vulnerability management (first line). However, independent validation of whether vulnerability management is effective should be performed by someone independent of IT, such as internal audit or an external firm. This distinction is critical for A.5.35.

What triggers a change-driven review under A.5.35?

Examples include:

  • Merger, acquisition, or divestiture.
  • Major cloud migration or infrastructure change.
  • Launch of a new product or service handling sensitive data.
  • New regulation (e.g., DPDP Act, RBI update).
  • Major security incident or breach.
  • Significant organizational restructuring.
  • New critical supplier or outsourcing arrangement.

The organization should define "significant change" in its audit policy.

What are the most common external audit findings on A.5.35?

  1. Internal audit reports to the CISO or IT manager.
  2. No annual risk-based audit plan.
  3. Auditors lack competence or qualifications.
  4. Findings not tracked to closure.
  5. No evidence of change-triggered reviews.
  6. Audit reports are only observations without risk ratings.
  7. Working papers are missing or inadequate.

How much does it overhead to implement A.5.35 properly?

Approachoverhead RangeBest For
Spreadsheet-based + outsourced annual auditSmall organizations
GRC tool + co-sourced auditGrowing companies
Enterprise GRC + dedicated internal audit teamLarge enterprises

The impact of non-compliance, certification suspension, customer loss, regulatory penalties, typically far exceeds the investment.


References and Further Reading

Standards and Frameworks

ReferenceRelevance
ISO/IEC 27001:2022Annex A 5.35; Clause 9.2 (internal audit); Clause 9.3 (management review)
ISO/IEC 27002:2022Section 5.35 implementation guidance
ISO 19011:2018Guidelines for auditing management systems
IIA International Standards for the Professional Practice of Internal AuditingInternal audit independence, competence, quality
COSO Internal Control, Integrated FrameworkGovernance and internal control assurance
NIST SP 800-53 Rev 5CA (Security Assessment) control family
NIST Cybersecurity Framework 2.0Govern function (GV.RR-01 to GV.RR-06)
COBIT 2019MEA01 (Monitor, Evaluate and Assess) domain

Indian Regulations and Guidelines

ReferenceRelevance
Digital Personal Data Protection Act, 2023Reasonable security safeguards; anticipated independent audit obligations for significant data fiduciaries
Information Technology Act, 2000 (as amended)Section 43A, CERT-In directions, reasonable security practices
CERT-In Directions, 2022Incident reporting, log retention, asset inventory
RBI Cyber Security Framework in Banks, 2016Periodic independent assurance, board review
RBI Master Direction, Information Technology Framework for NBFCsIT internal audit, cyber security governance
SEBI Cyber Security and Cyber Resilience FrameworkHalf-yearly audits for market infrastructure institutions
SEBI Circulars on Cyber Security for Stock Brokers / Depository ParticipantsEmpaneled auditor reports, remediation
IRDAI Guidelines on Information and Cyber Security for InsurersGovernance, audit, incident reporting

Additional Reading

ResourceTopic
ISACA CISA Review ManualInformation systems auditing standards and practices
qualified lead auditor Course MaterialsISMS audit methodology
ICAI Guidance Note on Internal Audit of ITIndian chartered accountants' guidance on IT audit
RBI Annual Reports and FAQs on Cyber SecurityRegulatory expectations for banks and NBFCs

How we can help

Working toward this?

If a certification or a customer's security questionnaire is what brought you here, tell us where you are. We'll give you an honest read on the work and the timeline, with no obligation.

What happens next

  1. Tell us the trigger

    A questionnaire, an audit date or an investor ask. The short form or a call both work.

  2. A practitioner replies

    A senior practitioner, not a bot, within four business hours.

  3. You get a scoped next step

    An honest view of what the work involves. No pressure, no theatre.