On this page
- Quick Reference: A.5.35 in 60 Seconds
- What the Standard Actually Requires
- Why Independent Review Matters
- Scope and Applicability
- Key Definitions and Terminology
- Relationship to Other Controls
- The Internal Audit vs. Independent Review Distinction
- Building the Independent Review Function
- Audit Charter and Governance
- Audit Planning and Risk Assessment
- Competence and Independence Requirements
- Conducting the Independent Review
- Audit Evidence Collection Techniques
- Reporting and Management Review
- Corrective Action and Continuous Improvement
- Tools, Technologies, and Solutions
- Policy and Procedure Templates
- Risk Assessment and Treatment
- Audit and Compliance Checklist
- Metrics and KPIs
- Common Pitfalls / Audit Failures & How to Avoid Them
- Illustrative Scenarios
- Multi-Framework Mapping
- Implementation Roadmap
- FAQ
- References and Further Reading
Quick Reference: A.5.35 in 60 Seconds
| Attribute | Details |
|---|---|
| Control ID | A.5.35 |
| Title | Independent review of information security |
| Objective | Obtain independent assurance that the ISMS and its controls are suitable, adequate, effective, and continuously improving. |
| Domain | Organizational controls (A.5), Governance, assurance, and compliance |
| What You Must Do | Plan and conduct independent reviews of the organization's information security approach and implementation (people, processes, technologies) at planned intervals and when significant changes occur. |
| Typical Owner | Chief Information Security Officer (CISO) sponsors; Internal Audit Head / Information Security Audit Manager executes. |
| Maturity Level 1 | Ad-hoc reviews performed only before external audit. No documented plan or independence. |
| Maturity Level 2 | Annual internal audit plan exists, but reviewers may report to the CISO and lack objectivity. |
| Maturity Level 3 | Independent internal audit function with approved charter, risk-based plan, competent auditors, and management-reviewed reports. |
| Maturity Level 4 | Integrated assurance: internal audit, technical testing, management review, and external audit findings drive a continuous improvement cycle with KPIs. |
| Maturity Level 5 | Predictive, data-driven assurance using GRC automation, continuous controls monitoring, and AI-assisted anomaly detection; audit findings correlate with risk appetite and board strategy. |
| Audit Red Flag | Internal audit reports to the CISO, audit plan not risk-based, findings not tracked to closure, auditors lack competence, no evidence of independence. |
| Quick Win | Create an Internal Audit Charter, approve a 12-month risk-based audit plan, and establish a findings-tracking register with escalation to top management. |
| Time to Implement | 4–8 weeks for initial program; ongoing execution forever. |
| Related Controls | A.5.1 (Policies), A.5.2 (Roles), A.5.36 (Compliance with policies), A.5.37 (Documented operating procedures), A.6.1 (Screening), A.6.2 (Terms and conditions), A.8.15 (Logging), A.8.16 (Monitoring activities), A.9.2 (Access to networks), A.9.4 (System access control). |
What the Standard Actually Requires
Figure · Process
What A.5.35 asks you to do

ISO 27001:2022 A.5.35 Control Text
ISO 27001:2022 Annex A 5.35 asks organizations to review the organization's approach to managing information security independently, at planned intervals and after significant changes.
This single sentence contains five mandatory elements:
| Element | Requirement | Auditor Interpretation |
|---|---|---|
| "organization's approach to managing information security" | The ISMS as a whole: governance, risk management, policy framework, roles, processes, culture. | Auditors expect to see the ISMS scope, context, leadership commitment, and management system mechanics reviewed. |
| "and its implementation" | How the ISMS is executed day-to-day: are controls actually implemented, operating, and effective? | Auditors will sample controls across departments, systems, and sites. |
| "including people, processes and technologies" | The review must cover all three dimensions, not just technology or documentation. | A purely paper-based audit or purely vulnerability scan is insufficient. |
| "reviewed independently" | The reviewer must be free from operational responsibility for the area being reviewed. | The CISO cannot audit their own function; IT cannot audit IT without safeguards. |
| "at planned intervals, or when significant changes occur" | Reviews must be scheduled (typically at least annually) and triggered by material change. | Annual audit plan + change-triggered reviews (M&A, cloud migration, major breach, new regulation). |
ISO 27002:2022 Implementation Guidance (Section 5.35)
ISO 27002:2022 provides the following implementation guidance for A.5.35:
- Independence of reviewers, Reviewers should be independent of the activities being reviewed. Where full independence is not feasible due to organization size, independence should be maximized through reporting lines, scope separation, or external support.
- Competence, Reviewers should be competent in information security management, auditing principles, and the technologies/processes under review.
- Risk-based planning, Reviews should be planned based on risk, previous findings, regulatory requirements, and changes.
- Scope coverage, Reviews should assess whether the ISMS conforms to the organization's own policies and procedures and to ISO 27001, and whether it is effectively implemented and maintained.
- Reporting, Results should be documented and reported to relevant management, including top management where appropriate.
- Follow-up, Findings should be tracked to closure with evidence of corrective action.
Shall / Should / May Analysis
| Word | Frequency in A.5.35 Text | Interpretation |
|---|---|---|
| shall | 1 | The organization must conduct independent reviews at planned intervals or on significant change. This is mandatory. |
| should | 0 (in the control text) | ISO 27002 uses "should" for guidance; the control itself is prescriptive. |
| may | 0 | No optional elements in the control. |
What Auditors Actually Check
| Auditor Action | What They Want to See | Common Finding |
|---|---|---|
| Review audit charter | Documented independence, authority, scope, reporting line to top management or audit committee | Charter missing or audit reports to CISO |
| Review annual audit plan | Risk-based, covers all Annex A controls over a reasonable cycle, includes people/process/technology | Plan is generic, not risk-based, or only covers IT |
| Check auditor competence | CVs, certifications (CISA, qualified lead auditor), training records | Auditors lack security audit qualifications |
| Sample audit working papers | Evidence of planning, execution, sampling, testing, conclusions | No working papers or inadequate evidence |
| Review audit reports | Clear findings, risk ratings, recommendations, management responses | Findings are observations without risk ratings |
| Check findings register | All findings tracked to closure with evidence and target dates | Open findings beyond target dates, no escalation |
| Interview process owners | Confirm audit occurred and was independent | Process owners unaware of audit or findings |
| Verify change-triggered reviews | Evidence of audits after major changes | No reviews after cloud migration / M&A / breach |
| Review management review inputs | Audit results feed into management review | Audit findings not discussed by top management |
| Check independence safeguards | Auditors do not audit their own work; rotation or oversight exists | IT manager performs "self-audit" |
Why Independent Review Matters
The Business Risk Narrative
Independent review is the immune system of the ISMS. Without it, organizations operate on assumptions: "Our policies are followed," "Our controls work," "Our risks are managed." These assumptions are dangerous. An independent review tests reality against intention. It discovers whether the security program is performative or operational, whether risk treatment is effective or decorative, and whether management has the information it needs to govern.
The consequences of weak independent review include:
- Undetected control failures that persist for months or years.
- External audit nonconformities and certification suspension.
- Regulatory penalties for failing to demonstrate assurance.
- Breaches that exploit known but unremediated weaknesses.
- Loss of customer trust and enterprise revenue.
Indian Regulatory Context
Indian organizations face a layered assurance environment. A.5.35 is not an abstract ISO checkbox; it aligns directly with Indian legal and supervisory expectations.
Digital Personal Data Protection Act, 2023 (DPDP Act)
Section 8 of the DPDP Act requires data fiduciaries to implement "reasonable security safeguards" to prevent personal data breaches. Section 9 imposes additional duties on significant data fiduciaries, including the appointment of a Data Protection Officer and the conduct of periodic independent audits. While the DPDP Rules are still under finalization, the statutory intent is clear: independent review of security controls will be a compliance obligation for many organizations. A.5.35 implementation prepares organizations for this requirement.
Reserve Bank of India (RBI)
- Cyber Security Framework in Banks (2016): Banks must conduct periodic independent assurance audits of their cyber security posture. The board must review assurance reports.
- Master Direction on Information Technology Framework for NBFCs: Requires NBFCs to establish an internal audit function for IT and cyber security, with reporting to the board or audit committee.
- Cyber Security Information Technology (CSIT) directions: Regulated entities must report incidents within six hours and maintain strong assurance mechanisms.
Securities and Exchange Board of India (SEBI)
SEBI's cybersecurity circulars for market infrastructure institutions (MIIs), stock brokers, depository participants, and mutual funds mandate:
- Half-yearly cybersecurity audits by empaneled auditors.
- Submission of audit reports to SEBI.
- Remediation timelines and evidence of closure.
- Board-level review of cybersecurity posture.
Insurance Regulatory and Development Authority of India (IRDAI)
IRDAI's cybersecurity guidelines for insurers require:
- An information security governance framework.
- Periodic internal and external audits.
- Reporting of cyber incidents.
- Maintenance of audit trails.
CERT-In Directions, 2022
CERT-In's directions under the IT Act, 2000 require:
- Reporting of specified cyber incidents within six hours.
- Maintenance of ICT asset inventory and user logs.
- Synchronization of ICT system clocks. Independent reviews validate whether these operational requirements are actually met.
Information Technology Act, 2000
Section 43A imposes liability on body corporates for negligence in implementing and maintaining reasonable security practices. The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 recognize ISO 27001 as a valid security standard. An effective A.5.35 program provides evidence of due diligence in court or regulatory proceedings.
Industry-Specific Consequences
| Industry | Consequence of Weak Independent Review |
|---|---|
| BFSI | RBI/SEBI enforcement, penalty, restriction on business expansion, loss of banking license eligibility. |
| SaaS / IT / ITeS | Enterprise customers demand SOC 2 / ISO 27001 reports; failed audits terminate deals. |
| Healthcare | Patient data breaches, NABH accreditation issues, DPDP Act penalties, reputational damage. |
| Manufacturing | OT/IT security gaps, IP theft, ransomware shutdowns, supply chain disruption. |
| Government | CERT-In/MeitY sanctions, public accountability, national security implications. |
| E-commerce / Consumer Tech | Customer data breaches, DPDP Act fines, loss of consumer trust, regulatory investigations. |
impact of Non-Compliance: Statistics and Research
| Study / Source | Finding |
|---|---|
| IBM impact of a Data Breach Report 2024 | Global average breach overhead: USD 4.88 million; India average: approximately USD 1.78 million (s). |
| Ponemon Institute | Organizations with mature internal audit and security testing functions reduce breach overhead by 30-40%. |
| ISO Survey 2024 | Over 85,000 ISO 27001 certificates worldwide; India is among the fastest-growing markets. |
| SEBI enforcement actions | Multiple brokers and MIIs have faced restrictions for inadequate cybersecurity audits and reporting. |
| RBI penalties | Banks and NBFCs have been fined for deficiencies in cyber security governance and internal audit. |
A single major nonconformity on A.5.35, for example, an internal audit function that lacks independence, can lead to a corrective action request, suspension of certification, and cascading customer and regulatory consequences.
Scope and Applicability
What A.5.35 Covers
A.5.35 applies to the review of the entire ISMS implementation, not just technical controls. The scope includes:
| Dimension | Examples of Review Scope |
|---|---|
| People | Roles and responsibilities, competence, awareness training, screening, terms and conditions, segregation of duties, security culture. |
| Processes | Risk assessment, incident management, access management, change management, vendor management, business continuity, policy management, management review. |
| Technologies | Networks, systems, applications, cloud services, endpoints, encryption, logging, monitoring, backups, identity and access management. |
| Governance | Leadership commitment, policy framework, risk appetite, resource allocation, performance evaluation, continual improvement. |
| Documentation | Policies, procedures, records, risk assessments, asset inventories, audit reports, management review minutes, corrective action records. |
Who It Applies To
A.5.35 applies to all organizations seeking or maintaining ISO 27001 certification, regardless of size or sector. The implementation approach varies:
| Organization Profile | Implementation Approach |
|---|---|
| Small organization (1-50 employees) | Outsourced internal audit to an external firm; audit committee or CEO provides oversight. |
| Medium organization (50-500 employees) | Dedicated internal auditor or audit function; may outsource specialized technical testing. |
| Large organization (500+ employees) | Full internal audit department; risk-based multi-year audit plan; co-sourced technical specialists. |
| Enterprise (5000+ employees) | Enterprise audit function with regional teams; continuous auditing; integrated assurance model. |
| Regulated entity (BFSI, SEBI, IRDAI) | Mandatory audits beyond ISO: RBI/SEBI/IRDAI-specific audit programs and empaneled auditors. |
| SaaS / multi-tenant | Audit must cover tenant isolation, shared responsibility, customer data protection, and change control. |
Role Categories Covered by Review
| Role Category | Why Reviewed |
|---|---|
| Top management / Board | Governance, resource allocation, risk appetite, management review participation. |
| CISO / Security team | Security program design and execution; however, must not audit themselves. |
| IT / Engineering | Implementation and operation of technical controls; must not perform unsupervised self-review. |
| HR | Screening, awareness training, terms and conditions, termination procedures. |
| Legal / Compliance | Regulatory mapping, contracts, data protection, breach notification. |
| Procurement / Vendor management | Supplier risk assessment, contract security clauses, monitoring. |
| Operations / Facilities | Physical security, business continuity, environmental controls. |
| Third parties / Suppliers | Where suppliers operate controls on the organization's behalf. |
Key Definitions and Terminology
| Term | Definition | ISO 27001 / 27002 Context |
|---|---|---|
| Independent review | A systematic, documented, and objective evaluation of the ISMS conducted by a person or team free from operational responsibility for the area reviewed. | A.5.35 implementation mechanism. |
| Internal audit | A formal, independent assurance activity designed to add value and improve an organization's operations. Often the delivery mechanism for A.5.35. | Closely aligned with ISO 19011 and IIA standards. |
| Auditor independence | Freedom from conditions that threaten objectivity or the appearance of objectivity. Includes organizational independence and personal independence. | Core requirement of A.5.35. |
| Competence | Demonstrated ability to apply knowledge and skills to achieve intended results. | Auditors must be competent in ISMS, security, and auditing. |
| Audit criteria | Set of policies, procedures, or requirements used as a reference against which audit evidence is compared. | ISO 27001, organization policies, legal requirements. |
| Audit evidence | Records, statements of fact, or other information relevant to audit criteria and capable of being verified. | Sampling, interviews, observations, document review. |
| Audit finding | Result of evaluating audit evidence against audit criteria. Can be conformity, nonconformity, or opportunity for improvement. | Must be risk-rated and tracked. |
| Nonconformity | Non-fulfillment of a requirement. In ISO 27001, can be major or minor. | Requires corrective action. |
| Corrective action | Action to eliminate the cause of a nonconformity and prevent recurrence. | Closes audit findings. |
| Management review | Formal review by top management of the ISMS at planned intervals to ensure continuing suitability, adequacy, and effectiveness. | Receives audit results as input. |
| Risk-based audit planning | Prioritizing audits based on risk, regulatory requirements, past findings, and changes. | Required for effective A.5.35. |
| Integrated assurance | Coordination of internal audit, external audit, compliance, risk management, and control self-assessment to provide unified assurance. | Maturity Level 4-5 approach. |
| Three Lines Model | Governance model: first line (management owns risk), second line (risk/compliance oversight), third line (internal audit provides independent assurance). | Helps structure independence. |
| Audit trail | Chronological record of system activities that enables the reconstruction and examination of events. | Evidence source for A.5.35. |
| Significant change | Change that could materially affect information security risk, such as M&A, cloud migration, new product launch, major incident, new regulation, or reorganization. | Triggers review under A.5.35. |
Relationship to Other Controls
A.5.35 does not operate in isolation. It provides assurance over the implementation of many other controls.
Upstream Controls (Inputs to A.5.35)
| Control | Relationship |
|---|---|
| A.5.1, Policies for information security | Policies are audit criteria. A.5.35 verifies that policies exist, are approved, communicated, acknowledged, and reviewed. |
| A.5.2, Information security roles and responsibilities | A.5.35 verifies that roles are defined, filled, and segregation of duties is maintained (including for audit itself). |
| A.5.4, Management responsibilities | A.5.35 provides evidence that management is actively governing information security. |
| A.5.5, Contact with special interest groups | A.5.35 may assess whether threat intelligence inputs are incorporated into risk and audit planning. |
| A.5.9, Inventory of information and other associated assets | Asset inventory is a prerequisite for scoped audits. |
| A.6.3, Information security awareness, education and training | A.5.35 tests whether staff understand and apply security requirements. |
| A.8.15, Logging | Logs are primary audit evidence for A.5.35 reviews of technical controls. |
| A.8.16, Monitoring activities | A.5.35 evaluates whether monitoring is effective and acted upon. |
Downstream Controls (Assured by A.5.35)
| Control | Relationship |
|---|---|
| A.5.36, Compliance with policies, rules and standards for information security | A.5.35 audits compliance; A.5.36 establishes the compliance monitoring mechanism. |
| A.5.37, Documented operating procedures | A.5.35 verifies that procedures are followed in practice. |
| A.8.1, User endpoint devices | A.5.35 audits endpoint security implementation. |
| A.8.2, Privileged access rights | A.5.35 tests privileged access controls through sampling. |
| A.8.9, Management of removable media | A.5.35 verifies media handling practices. |
| A.8.24, Use of cryptography | A.5.35 assesses cryptographic implementation against policy. |
| A.8.32, Change management | A.5.35 audits change control effectiveness. |
Parallel Controls (Complementary Assurance)
| Control | Relationship |
|---|---|
| A.5.24, Information security incident management planning and preparation | A.5.35 may review incident response capability as part of the audit plan. |
| A.5.25, Assessment and decision on information security events | A.5.35 evaluates whether incidents are correctly classified and escalated. |
| A.5.31, Legal, statutory, regulatory and contractual requirements | A.5.35 verifies compliance with legal and contractual obligations. |
| A.6.8, Information security event reporting | A.5.35 tests whether reporting channels work and staff use them. |
The Internal Audit vs. Independent Review Distinction
Is A.5.35 the Same as Internal Audit?
Not exactly. A.5.35 requires an independent review of information security. Internal audit is the most common and strong way to satisfy this requirement, but other models are possible if they preserve independence and competence.
| Model | Description | Best For |
|---|---|---|
| Internal audit function | Dedicated internal audit department or auditor reports to Audit Committee / CEO / Board. | Medium to large organizations. |
| Co-sourced audit | Internal staff plus external audit firm; external party provides independence and specialized skills. | Organizations building audit capability. |
| Fully outsourced audit | External firm conducts all internal audit activities under an approved charter. | Small organizations, startups, SMEs. |
| Independent management review | A peer manager from an unrelated function reviews security (less strong; requires safeguards). | Very small organizations with documented independence. |
| External certification audit only | Relying solely on the external ISO 27001 surveillance audit does not satisfy A.5.35, because the organization must perform its own independent reviews between external audits. | Not acceptable as the sole mechanism. |
Independence Continuum
LEAST INDEPENDENT MOST INDEPENDENT
─────────────────────────────────────────────────────────────────────►
Self-review by CISO Peer review by Internal audit Co-sourced Fully outsourced
or IT manager unrelated manager reporting to internal internal audit
board/CEO audit by Big 4 /
specialist
The Three Lines Model Applied to A.5.35
┌─────────────────────────────────────────────────────────────────┐
│ LINE 1: OPERATIONS (Owns Risk) │
│ • IT, Engineering, HR, Facilities, Procurement │
│ • Implement and operate controls │
│ • Perform control self-assessments │
└─────────────────────────────────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────────────────────┐
│ LINE 2: RISK & COMPLIANCE OVERSIGHT │
│ • CISO, Risk Manager, Compliance Officer, DPO │
│ • Establish policies, monitor compliance, report to management │
│ • NOT independent of management; provides oversight │
└─────────────────────────────────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────────────────────┐
│ LINE 3: INDEPENDENT ASSURANCE (A.5.35) │
│ • Internal Audit / Independent Review Function │
│ • Reports to Board / Audit Committee / CEO │
│ • Independent of operations and security management │
└─────────────────────────────────────────────────────────────────┘
Critical point: If the CISO or security team also performs the internal audit, the organization has violated the independence requirement of A.5.35, regardless of how competent the individuals are.
Building the Independent Review Function
Organizational Options by Size
| Organization Size | Recommended Structure | Reporting Line | Rationale |
|---|---|---|---|
| 1-50 employees | Outsourced internal audit to a specialist firm (e.g., Singahi, Big 4, boutique ISO 27001 auditor) | Reports to CEO / Founder | No internal capacity; external independence satisfies requirement. |
| 50-200 employees | Part-time internal auditor + annual co-sourced technical audits | Reports to CEO or Audit Committee | Balance of overhead and independence. |
| 200-1000 employees | Full-time Internal Audit Manager + 1-2 auditors; co-source specialized areas | Reports to Audit Committee / Board with administrative link to CEO | Sufficient scale for dedicated function. |
| 1000-5000 employees | Internal Audit Department with IT/security audit specialization | Reports functionally to Audit Committee; administratively to CEO | Complex environment needs specialization. |
| 5000+ employees / Group | Group Internal Audit with regional/center-of-excellence model; Chief Audit Executive | Reports to Group Audit Committee / Board | Enterprise-wide assurance and consistency. |
Independence Safeguards Checklist
- The audit function has a formal charter approved by top management or the board.
- The audit function has unrestricted access to people, records, systems, and premises.
- The head of audit has direct access to the CEO / Board / Audit Committee without management filtering.
- Auditors do not audit operations for which they are responsible.
- Auditors are not incentivized based on the performance of the areas they audit.
- Audit scope and plan cannot be unilaterally overridden by operational management.
- Auditors have a documented conflict-of-interest declaration process.
- Where the same person must perform security operations and audit (very small orgs), a record of mitigating controls exists (e.g., external review, management review, board oversight).
Audit Charter Template (Key Clauses)
INTERNAL AUDIT / INDEPENDENT REVIEW CHARTER
[Organization Name]
Version: 1.0
Approved by: [Board / Audit Committee / CEO]
Date: [Date]
Review Date: [Date + 12 months]
1. PURPOSE
This charter establishes the authority, independence, responsibility, and scope
of the independent review of information security at [Organization Name].
2. AUTHORITY
The independent review function is authorized to:
• Access all information, records, systems, personnel, and premises relevant
to information security.
• Request assistance from any employee or third party.
• Report findings directly to the Audit Committee / Board / CEO.
• Escalate unresolved high-risk findings without management interference.
3. INDEPENDENCE
The independent review function shall be independent of the activities reviewed.
The Head of Internal Audit reports functionally to the [Audit Committee / Board]
and administratively to the [CEO].
4. SCOPE
The scope includes the ISMS, information security policies, procedures, controls,
people, processes, and technologies, including outsourced operations.
5. RESPONSIBILITIES
• Develop and maintain a risk-based audit plan.
• Conduct audits in accordance with ISO 19011 principles.
• Issue clear, risk-rated findings and recommendations.
• Track findings to closure.
• Provide input to management review.
• Maintain auditor competence.
6. QUALITY ASSURANCE
The audit function shall undergo periodic internal and external quality assessments.
7. APPROVAL
This charter is approved by:
[Chairperson, Audit Committee] Date: __________
[CEO] Date: __________
[Head of Internal Audit] Date: __________
Audit Charter and Governance
Governance Structure
┌─────────────────────────────────────────────────────────────┐
│ BOARD OF DIRECTORS / GOVERNING BODY │
│ • Ultimate oversight of information security │
│ • Approves audit charter and risk appetite │
│ • Receives summary audit reports │
└─────────────────────────────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────────────────┐
│ AUDIT COMMITTEE (or equivalent) │
│ • Oversees internal audit function │
│ • Approves annual audit plan │
│ • Reviews significant findings and remediation │
│ • Hires / fires Head of Internal Audit │
└─────────────────────────────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────────────────┐
│ HEAD OF INTERNAL AUDIT / INDEPENDENT REVIEW │
│ • Develops audit plan │
│ • Ensures independence and competence │
│ • Signs off on audit reports │
│ • Escalates unresolved issues │
└─────────────────────────────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────────────────┐
│ AUDIT TEAM(S) │
│ • Execute audit engagements │
│ • Document working papers │
│ • Test controls and sample evidence │
│ • Draft findings and reports │
└─────────────────────────────────────────────────────────────┘
Audit Committee Agenda (Quarterly)
| Agenda Item | Owner | Time | Output |
|---|---|---|---|
| Approval of annual audit plan | Head of Internal Audit | 15 min | Approved plan |
| Review of audit reports since last meeting | Audit Team | 30 min | Management actions agreed |
| Status of open findings | Audit Team | 20 min | Escalation list |
| Independence and resource update | Head of Internal Audit | 10 min | Resource / independence confirmation |
| Regulatory audit updates | Compliance Officer | 10 min | Regulatory compliance status |
| External audit coordination | CISO / Audit Head | 10 min | Certification audit plan |
| Fraud / whistleblower updates | Audit Committee Chair | 10 min | Action items |
Audit Planning and Risk Assessment
Risk-Based Audit Planning Process
┌─────────────────────────────────────────────────────────────┐
│ STEP 1: UNDERSTAND CONTEXT │
│ • ISMS scope, assets, processes, locations │
│ • Risk register and risk treatment plan │
│ • Legal / regulatory requirements │
│ • Previous audit findings │
│ • External audit / certification history │
└─────────────────────────────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────────────────┐
│ STEP 2: RISK ASSESSMENT FOR AUDIT PLANNING │
│ • Inherent risk by process / system / location │
│ • Control effectiveness from prior reviews │
│ • Regulatory and customer priority │
│ • Recent changes and incidents │
└─────────────────────────────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────────────────┐
│ STEP 3: PRIORITIZE AND SCHEDULE │
│ • High-risk areas audited more frequently │
│ • All Annex A controls covered over audit cycle │
│ • Resource allocation and timing │
└─────────────────────────────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────────────────┐
│ STEP 4: APPROVE PLAN │
│ • Audit Committee / top management approval │
│ • Communicate plan to stakeholders │
└─────────────────────────────────────────────────────────────┘
Risk Scoring for Audit Planning
| Factor | Weight | Score 1 (Low) | Score 3 (Medium) | Score 5 (High) |
|---|---|---|---|---|
| Regulatory / legal exposure | 25% | No specific regulation | Industry guidance applies | RBI/SEBI/IRDAI/CERT-In mandated |
| Likelihood of incident | 20% | Rare, no history | Occasional, some history | Frequent or recent incidents |
| Potential business impact | 25% | Limited operational impact | Significant financial/reputational | Business-critical or existential |
| Control maturity | 15% | Mature controls, clean history | Partial controls, minor findings | Weak controls, repeated findings |
| Change / complexity | 15% | Stable, well-understood | Moderate change | Major change, new technology, M&A |
Audit Priority Score = Σ (Factor Weight × Score)
| Priority Score | Frequency |
|---|---|
| 4.0 – 5.0 | Audit annually or more frequently |
| 2.5 – 3.9 | Audit every 12-24 months |
| 1.0 – 2.4 | Audit every 24-36 months or by exception |
Sample Three-Year Audit Plan
| Year | Focus Areas | Rationale |
|---|---|---|
| Year 1 | Governance (A.5.1, A.5.2, A.5.35), Risk assessment (A.5.36, A.6.1), Access control (A.5.15-A.5.18), Incident management (A.5.24-A.5.28) | Foundational controls; high risk; external certification readiness. |
| Year 2 | Asset management (A.5.9-A.5.14), Cryptography (A.8.24), Operations security (A.8.1-A.8.16), Change management (A.8.32) | Technical controls; regulatory focus on encryption and operations. |
| Year 3 | Supplier relationships (A.5.19-A.5.23), Physical security (A.7.1-A.7.14), Business continuity (A.5.29-A.5.30, A.8.13-A.8.14), Secure development (A.8.25-A.8.31) | Third-party and resilience; complete Annex A coverage. |
Note: High-risk areas should be audited every year regardless of the cycle.
Competence and Independence Requirements
Auditor Competence Framework
| Competency Area | Required Knowledge / Skills | Evidence |
|---|---|---|
| ISO 27001 and ISMS | Annex A controls, ISO 27001 clauses 4-10, audit lifecycle | qualified lead auditor certification, training records |
| Information security | Access control, cryptography, network security, incident response, cloud security | CISA, certified, or equivalent experience |
| Auditing principles | ISO 19011, sampling, evidence, interviewing, report writing | Internal audit training, previous audit records |
| Industry / regulatory | DPDP Act, RBI, SEBI, IRDAI, CERT-In, GDPR as applicable | Domain training, legal updates |
| Technology | Cloud, SaaS, OS, databases, networks, identity platforms | Hands-on experience, certifications |
| Soft skills | Interviewing, communication, objectivity, conflict management | Training, performance reviews |
Independence Threats and Mitigations
| Threat | Example | Mitigation |
|---|---|---|
| Self-review | IT manager audits their own patch management process | Assign auditor from different function or external firm. |
| Familiarity | Long-term internal auditor becomes too close to operations | Rotate auditors, use external co-source, cooling-off periods. |
| Intimidation | Auditor fears retaliation from senior operations manager | Reporting line to board/audit committee, whistleblower protection. |
| Personal conflict of interest | Auditor has financial interest in a vendor being audited | Conflict-of-interest declaration and recusal process. |
| Management pressure | Audit scope reduced to avoid findings | Charter protects scope; escalation path to audit committee. |
| Reporting compromise | CISO reviews and edits audit report before board sees it | Direct reporting to audit committee; unfiltered findings. |
Conflict-of-Interest Declaration Template
CONFLICT-OF-INTEREST DECLARATION
Audit Engagement: ________________________________
Auditor Name: ________________________________
Date: ________________________________
I declare that:
☐ I have no financial or personal interest in the area or personnel being audited.
☐ I have not been involved in designing, implementing, or operating the controls
being audited in the past 12 months.
☐ I have no close family relationship with any manager in the audited area.
☐ I am not aware of any other circumstance that could impair my objectivity.
If any of the above is NOT true, describe below:
________________________________________________
Mitigation agreed:
________________________________________________
Auditor Signature: __________________ Date: __________
Audit Manager Signature: ____________ Date: __________
Conducting the Independent Review
Audit Engagement Lifecycle
┌─────────────────────────────────────────────────────────────┐
│ 1. ENGAGEMENT PLANNING │
│ • Define objectives, scope, criteria │
│ • Identify auditee, resources, timing │
│ • Prepare audit program and checklists │
└─────────────────────────────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────────────────┐
│ 2. OPENING MEETING │
│ • Confirm scope and schedule │
│ • Introduce audit team │
│ • Explain methodology and independence │
└─────────────────────────────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────────────────┐
│ 3. FIELDWORK / EVIDENCE GATHERING │
│ • Interviews, document review, observation, testing │
│ • Sample selection and testing │
│ • Working paper documentation │
└─────────────────────────────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────────────────┐
│ 4. ANALYSIS AND FINDING FORMULATION │
│ • Evaluate evidence against criteria │
│ • Rate risk and formulate findings │
│ • Validate with auditee (no surprises) │
└─────────────────────────────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────────────────┐
│ 5. REPORTING │
│ • Draft audit report │
│ • Management response and action plan │
│ • Finalize and distribute │
└─────────────────────────────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────────────────┐
│ 6. FOLLOW-UP AND CLOSURE │
│ • Track corrective actions │
│ • Verify closure evidence │
│ • Escalate overdue items │
└─────────────────────────────────────────────────────────────┘
Audit Program Template: A.5.35 Review of Information Security
| Step | Activity | Evidence Sought | Sample Size |
|---|---|---|---|
| 1 | Review ISMS scope and context | Scope statement, interested parties, applicability statement | All |
| 2 | Review risk assessment and treatment | Risk register, risk treatment plan, residual risk acceptance | All |
| 3 | Test policy framework | Master policy, topic-specific policies, approvals, reviews, acknowledgments | Sample of 5-10 policies |
| 4 | Test access control | User access lists, MFA evidence, privileged access reviews, termination records | 25 user accounts per system |
| 5 | Test asset management | Asset inventory, classification, ownership, disposal records | 25 assets |
| 6 | Test incident management | Incident register, response records, post-incident reviews | All incidents in period |
| 7 | Test supplier security | Vendor assessments, contracts, monitoring records | Top 10 critical vendors |
| 8 | Test logging and monitoring | Log samples, SIEM alerts, review records | 1 week of logs per critical system |
| 9 | Test backup and recovery | Backup logs, restore test records | Last 3 restore tests |
| 10 | Test business continuity | BIA, plans, test records | All critical plans |
| 11 | Test HR security | Screening records, training records, termination checklists | 10 hires, 10 terminations |
| 12 | Test management review | Minutes, action tracking, resource decisions | Last 2 management reviews |
| 13 | Test corrective action | Nonconformity register, root cause analysis, closure evidence | All open and recently closed |
| 14 | Test awareness | Training records, phishing test results | 10% of staff or sample |
Audit Sampling Guidance
| Population Size | Recommended Sample | Rationale |
|---|---|---|
| < 25 | 100% (census) | Small populations; every item matters. |
| 25 – 100 | 15-25 items | Statistically reasonable for assurance. |
| 100 – 1000 | 25-50 items | Balance of coverage and efficiency. |
| 1000+ | 50-100 items + risk-stratified sampling | Focus on high-risk / privileged / changed items. |
Sample selection must be risk-based and representative, not convenience-based. Document the sampling method in working papers.
Audit Evidence Collection Techniques
Evidence Types and Reliability
| Evidence Type | Reliability | Examples |
|---|---|---|
| Documentary evidence | High if original and controlled | Approved policies, signed contracts, management review minutes |
| System-generated records | High if logs are tamper-protected | SIEM logs, backup logs, access control system reports |
| Interviews | Medium (subjective) | Staff explaining how they handle incidents |
| Observation | Medium (snapshot in time) | Watching a clearance process at a reception |
| Reperformance | High | Auditor independently verifies a control (e.g., attempts unauthorized access in test environment) |
| Analytical procedures | Medium-High | Trend analysis of incidents, access reviews, patching metrics |
| External confirmations | High | Vendor SOC 2 reports, penetration test reports, certification body communications |
Interview Techniques for Auditors
| Technique | Purpose | Example Question |
|---|---|---|
| Open-ended | Understand process and mindset | "Walk me through how you handle a reported phishing email." |
| Closed | Verify specific facts | "Do you have MFA enabled on your email account?" |
| Probing | Explore inconsistencies | "You said access is reviewed quarterly. Can you show me the last review?" |
| Scenario-based | Test practical knowledge | "If you discovered a laptop with customer data was stolen, what would you do first?" |
| Document-linked | Tie testimony to evidence | "This policy says incidents are reported within 1 hour. When did you last report an incident, and how?" |
Working Paper Requirements
Every audit finding must be supported by working papers containing:
- Audit objective and criteria.
- Population and sampling method.
- Evidence collected (with references to documents, logs, screenshots).
- Auditor analysis and conclusion.
- Finding classification (conformity / nonconformity / OFI).
- Risk rating and rationale.
- Cross-reference to final report.
Reporting and Management Review
Audit Report Structure
INDEPENDENT REVIEW REPORT — INFORMATION SECURITY
[Organization Name]
Audit Engagement: ________________________________
Audit Period: ________________________________
Report Date: ________________________________
Distribution: Audit Committee, CEO, CISO, [relevant management]
1. EXECUTIVE SUMMARY
• Overall opinion on ISMS effectiveness
• Number and severity of findings
• Key themes and trends
2. AUDIT SCOPE AND OBJECTIVES
• What was reviewed and why
• Audit criteria (ISO 27001, policies, regulations)
3. METHODOLOGY
• Sampling approach, evidence types, interviews conducted
4. FINDINGS
For each finding:
• Finding ID and title
• Risk rating (Critical / High / Medium / Low)
• ISO 27001 / policy clause reference
• Condition (what was found)
• Criterion (what should be)
• Cause (root cause)
• Effect (risk / impact)
• Recommendation
5. MANAGEMENT RESPONSE AND ACTION PLAN
• Agreed actions, owners, target dates
6. OVERALL OPINION
• Effective / Partially Effective / Ineffective
7. APPENDICES
• Detailed test results, sample lists, evidence references
Risk Rating Matrix for Findings
| Rating | Definition | Typical Escalation |
|---|---|---|
| Critical | Control failure could lead to severe breach, regulatory action, or business disruption; immediate action required. | CEO / Board within 24 hours |
| High | Significant weakness with material risk; action required within 30 days. | Audit Committee / CISO |
| Medium | Control deficiency with moderate risk; action required within 90 days. | Department head / CISO |
| Low | Minor gap; best practice improvement; action within 180 days or by next review. | Process owner |
| Observation / OFI | No nonconformity, but opportunity for improvement. | Process owner |
Management Review Input
A.5.35 outputs must feed into ISO 27001 Clause 9.3 Management Review. Inputs include:
- Summary of audit results (internal and external).
- Status of open findings and corrective actions.
- Trends in incidents and control failures.
- Resource adequacy of the audit function.
- Changes affecting the ISMS.
- Recommendations for improvement.
Corrective Action and Continuous Improvement
Findings Register
| Finding ID | Description | Risk Rating | ISO Clause / Policy | Owner | Target Date | Status | Closure Evidence |
|---|---|---|---|---|---|---|---|
| A.5.35-001 | Privileged access reviews not performed quarterly | High | A.5.18 / Access Control Policy | IT Director | 2026-07-31 | Open | Quarterly review records |
| A.5.35-002 | Incident response plan not tested in past 12 months | Medium | A.5.24 / IR Policy | CISO | 2026-08-15 | Open | Tabletop exercise report |
| A.5.35-003 | Two terminated employees retained VPN access for 5 days | High | A.6.6 / HR Security Policy | HR Manager | 2026-07-15 | Closed | Termination checklist + system log |
Corrective Action Process
FINDING IDENTIFIED
│
▼
ROOT CAUSE ANALYSIS
(5 Whys / Fishbone / Fault Tree)
│
▼
CORRECTIVE ACTION PLAN
(Who, What, When, Evidence)
│
▼
MANAGEMENT APPROVAL
│
▼
ACTION IMPLEMENTATION
│
▼
VERIFICATION BY AUDITOR
(Evidence review, retest)
│
▼
FINDING CLOSED
Escalation Protocol for Overdue Findings
| Days Overdue | Action | Owner |
|---|---|---|
| 7 days | Reminder to finding owner | Internal Audit |
| 14 days | Copy to owner + 1 (manager) | Internal Audit |
| 21 days | Escalate to CISO / functional head | Internal Audit |
| 30 days | Escalate to CEO / Audit Committee | Head of Internal Audit |
| 45 days | Board / Audit Committee formal notification | Head of Internal Audit |
Tools, Technologies, and Solutions
GRC and Audit Management Platforms
| Platform | Best For | Key Features | licensing Indication (India) |
|---|---|---|---|
| ServiceNow GRC / IRM | Enterprises | Integrated risk, audit, compliance, vendor management | + annually |
| MetricStream | Large banks, NBFCs, regulated entities | Audit management, regulatory compliance, BCM | + annually |
| RSA Archer | Enterprise GRC | Highly configurable risk and audit workflows | + annually |
| SAP GRC | SAP-centric organizations | Access control, process control, audit management | + annually |
| Qualys Policy Compliance | Technical control assessment | Continuous scanning against CIS benchmarks, policies | + annually |
| Tenable.sc / Nessus | Vulnerability and configuration audit | VA scans, configuration audits, dashboards | + annually |
| Zoho Creator (custom) | SMEs | Low-code audit workflow and register |
Technical Testing Tools for Audit Evidence
| Category | Tool Examples | Use in A.5.35 |
|---|---|---|
| Vulnerability assessment | Nessus, Qualys, OpenVAS, Rapid7 | Verify patch and configuration controls. |
| Penetration testing | Burp Suite, Metasploit, Cobalt Strike, Kali Linux | Validate effectiveness of technical defenses. |
| SIEM / log analysis | Splunk, ELK, QRadar, Sentinel, Wazuh | Verify logging, monitoring, and alerting. |
| IAM audit | Okta, Entra ID, SailPoint, Saviynt | Verify access reviews, MFA, provisioning. |
| Cloud security posture | Prisma Cloud, Wiz, Orca, Lacework | Verify cloud control effectiveness. |
| Code security | SonarQube, Snyk, Checkmarx, Semgrep | Verify secure development controls. |
| Data discovery / DLP | Symantec DLP, Forcepoint, Microsoft Purview | Verify data classification and protection. |
| GRC / audit workflow | AuditBoard, Workiva, TeamMate+ | Manage audit engagements and findings. |
Build vs. Buy vs. Outsource
| Approach | Best For | Pros | Cons |
|---|---|---|---|
| Spreadsheets + documents | Very small orgs, first audit | Cheap, fast | Not scalable, weak evidence integrity |
| Low-code / Zoho Creator | SMEs | Affordable, customizable | Requires maintenance |
| Enterprise GRC (ServiceNow, MetricStream) | Large regulated entities | Scalable, integrated | premium-tier, long implementation |
| Outsourced internal audit | All sizes | Immediate independence and expertise | Recurring overhead, less institutional knowledge |
Policy and Procedure Templates
Independent Review / Internal Audit Policy (Extract)
INDEPENDENT REVIEW OF INFORMATION SECURITY POLICY
[Organization Name]
Version: 1.0
Owner: Head of Internal Audit
Approved by: [CEO / Audit Committee Chair]
Date: [Date]
Review Date: [Date + 12 months]
1. PURPOSE
This policy defines the requirements for independent review of the organization's
information security management system (ISMS) and its implementation.
2. SCOPE
This policy applies to all ISMS processes, controls, personnel, technologies,
locations, and third-party operations within the defined ISMS scope.
3. POLICY STATEMENTS
3.1 The organization shall conduct independent reviews of information security
at planned intervals and when significant changes occur.
3.2 Reviews shall be conducted by competent reviewers who are independent of
the activities being reviewed.
3.3 Reviews shall assess conformance to ISO 27001, organization policies, and
applicable legal/regulatory requirements.
3.4 Review findings shall be documented, risk-rated, reported to management,
and tracked to closure.
3.5 Results of independent reviews shall be input to management review.
3.6 The review function shall have an approved charter, unrestricted access,
and a reporting line to top management or the audit committee.
4. ROLES AND RESPONSIBILITIES
4.1 Board / Audit Committee: Approve charter, approve plan, oversee findings.
4.2 Head of Internal Audit: Plan, execute, and report independent reviews.
4.3 Process Owners: Provide access, implement corrective actions.
4.4 CISO: Support audits, remediate security findings (but does not audit own function).
5. INDEPENDENCE AND CONFLICTS
5.1 Auditors shall not audit their own work.
5.2 Auditors shall declare conflicts of interest before each engagement.
5.3 Where full independence is not achievable, mitigation shall be documented
and approved by top management.
6. COMPETENCE
6.1 Auditors shall maintain relevant qualifications (CISA, qualified lead auditor,
certified, or equivalent).
6.2 Auditors shall complete at least 20 hours of continuing professional
development annually.
7. PLANNING AND EXECUTION
7.1 A risk-based audit plan shall be prepared annually and approved by the
Audit Committee / top management.
7.2 Audit engagements shall follow the documented audit methodology aligned
with ISO 19011.
7.3 Audit working papers shall be maintained securely and retained for at
least [X] years.
8. REPORTING AND FOLLOW-UP
8.1 Audit reports shall be issued within [15/30] days of engagement completion.
8.2 Management shall provide responses and action plans within [15] days.
8.3 Findings shall be tracked in a central register until closure.
8.4 Overdue findings shall be escalated per the escalation matrix.
9. REVIEW
This policy is reviewed annually and on significant change.
Audit Procedure Template (Extract)
PROCEDURE: CONDUCTING INDEPENDENT INFORMATION SECURITY REVIEWS
1. PURPOSE
To define the steps for planning, conducting, reporting, and following up on
independent reviews of information security.
2. SCOPE
All ISMS audits, reviews, and assurance engagements.
3. PROCEDURE STEPS
Step 1 — Annual Planning
a. Review risk register, previous findings, incident trends, regulatory changes.
b. Develop risk-based audit plan covering all Annex A controls over [3-year] cycle.
c. Obtain Audit Committee / top management approval.
Step 2 — Engagement Planning
a. Define objectives, scope, and criteria.
b. Assign competent, independent auditors.
c. Issue engagement letter / notification to auditee at least 2 weeks in advance.
d. Prepare audit program and checklists.
Step 3 — Opening Meeting
a. Confirm scope, schedule, and contacts.
b. Explain independence and confidentiality obligations.
c. Document attendance and agreements.
Step 4 — Fieldwork
a. Conduct interviews, document reviews, observations, and testing.
b. Maintain working papers with evidence references.
c. Hold daily debriefs to discuss emerging issues.
Step 5 — Findings Validation
a. Draft findings and share with auditee for factual accuracy.
b. Allow auditee to provide additional evidence.
c. Finalize risk ratings.
Step 6 — Reporting
a. Draft audit report within [15] days.
b. Obtain management responses and action plans.
c. Finalize and distribute to approved recipients.
Step 7 — Follow-Up
a. Track corrective actions to target dates.
b. Verify closure evidence.
c. Report status to Audit Committee / management review.
4. RECORDS
• Annual audit plan
• Engagement planning documents
• Working papers
• Audit reports
• Findings register
• Closure evidence
Risk Assessment and Treatment
A.5.35-Specific Risk Table
| Risk ID | Threat / Vulnerability | Likelihood | Impact | Risk Level | Treatment | Owner |
|---|---|---|---|---|---|---|
| R-001 | Internal audit lacks independence; CISO audits own team | High | Critical | Critical | Establish audit function reporting to board/CEO; implement charter; use external co-source | CEO / Audit Committee |
| R-002 | Auditors lack competence in ISO 27001 / information security | Medium | High | High | Require CISA/qualified lead auditor; provide training; outsource complex audits | Head of Internal Audit |
| R-003 | Audit plan not risk-based; high-risk areas missed | Medium | High | High | Implement risk-based planning methodology; align with risk register | Head of Internal Audit |
| R-004 | Findings not tracked; corrective actions overdue | Medium | High | High | Implement findings register with escalation; verify closure | Head of Internal Audit |
| R-005 | External certification audit identifies major nonconformity before internal audit does | Medium | High | High | Increase audit frequency; improve technical testing; pre-audit internal review | CISO |
| R-006 | Significant change (cloud migration, M&A) not reviewed | Medium | Critical | High | Define change-triggered review policy; include in change management | CISO |
| R-007 | Audit evidence insufficient or unreliable | Medium | Medium | Medium | Train auditors in evidence techniques; use system-generated logs | Head of Internal Audit |
| R-008 | Management ignores audit findings | Low | High | Medium | Report to board/audit committee; link to incentives and risk appetite | Board |
| R-009 | Third-party controls not included in review scope | Medium | Medium | Medium | Extend scope to critical suppliers; include supplier audits in plan | Procurement / CISO |
| R-010 | Audit reports leaked or mishandled | Low | Medium | Low | Classification, access controls, secure distribution | Head of Internal Audit |
Risk Treatment Summary
| Treatment Type | Count | Risk IDs |
|---|---|---|
| Mitigate | 9 | R-001 to R-009 |
| Transfer | 0 | - |
| Accept | 1 | R-010 (residual risk managed through confidentiality controls) |
| Avoid | 0 | - |
Audit and Compliance Checklist
A.5.35 Audit Checklist (for Internal / External Auditors)
| # | Audit Question | Expected Evidence | Red Flag |
|---|---|---|---|
| 1 | Is there an approved internal audit / independent review charter? | Signed charter, board/audit committee minutes | No charter; charter lacks independence language |
| 2 | Does the audit function report to a level that ensures independence? | Organization chart, reporting line documentation | Reports to CISO or IT Director |
| 3 | Is there an annual, risk-based audit plan approved by top management? | Approved plan, planning methodology | No plan; plan not risk-based |
| 4 | Does the plan cover people, processes, and technologies? | Plan scope statement | Plan only covers documents or IT systems |
| 5 | Are audits conducted at planned intervals? | Audit reports with dates | Audits only before certification audit |
| 6 | Are audits triggered by significant changes? | Change-triggered review records | No reviews after M&A / cloud migration / major incident |
| 7 | Are auditors competent and qualified? | CVs, certifications, training records | Auditors without security audit qualifications |
| 8 | Do auditors declare conflicts of interest? | Conflict declarations | No conflict management process |
| 9 | Are audit working papers maintained? | Working paper files | No evidence of how conclusions were reached |
| 10 | Are audit reports clear, risk-rated, and actionable? | Sample reports | Reports are vague "observations" only |
| 11 | Are findings tracked to closure? | Findings register, closure evidence | Open findings beyond target dates |
| 12 | Are overdue findings escalated? | Escalation records, board minutes | No escalation process |
| 13 | Are audit results input to management review? | Management review minutes | Audit results never discussed by top management |
| 14 | Is there evidence that the CISO does not audit their own function? | Scope allocation, independence matrix | CISO signs their own audit report |
| 15 | Are third-party / outsourced operations included in scope? | Supplier audit records | No supplier reviews |
| 16 | Are corrective actions verified before closure? | Closure evidence, retest records | Findings closed without evidence |
| 17 | Does the organization use external audit support where needed? | Contracts, co-source reports | Refuses external support despite gaps |
| 18 | Are audit plans updated based on risk and incident trends? | Plan updates, risk register linkage | Static plan unchanged for years |
| 19 | Is there a quality assurance process for the audit function? | QA review records | No self-assessment or external QA |
| 20 | Do auditors have unrestricted access to information and personnel? | Charter, access logs | Management restricts access during audit |
Compliance Evidence Mapping
| Requirement Source | Evidence Required | Where to Find |
|---|---|---|
| ISO 27001 A.5.35 | Audit charter, plan, reports, findings register | Internal audit file repository |
| ISO 27001 Clause 9.2 (internal audit) | Internal audit program, audit criteria, results | ISO 27001 implementation records |
| ISO 27001 Clause 9.3 (management review) | Minutes referencing audit results | Management review minutes |
| DPDP Act 2023 (anticipated) | Independent audit reports for significant data fiduciaries | Legal/compliance files |
| RBI Cyber Security Framework | Board-reviewed cyber assurance reports | Board/audit committee records |
| SEBI cybersecurity circulars | Empaneled auditor reports, remediation evidence | Compliance/regulatory files |
| CERT-In directions | Incident and log review records | SOC/CERT-In files |
Metrics and KPIs
Figure · Measures
The measures that show A.5.35 is working
- Audit plan completion≥ 95%Quarterly
- Finding closure rate≥ 95%Monthly
- Critical finding aging< 15 daysWeekly
- High finding aging< 45 daysMonthly
- Audit report timeliness≥ 95%Per audit
Audit Function KPIs
| KPI | Formula | Target | Frequency |
|---|---|---|---|
| Audit plan completion | (Audits completed / Audits planned) × 100 | ≥ 95% | Quarterly |
| Finding closure rate | (Findings closed on time / Total due findings) × 100 | ≥ 95% | Monthly |
| Critical finding aging | Average days critical findings remain open | < 15 days | Weekly |
| High finding aging | Average days high findings remain open | < 45 days | Monthly |
| Audit report timeliness | (Reports issued within SLA / Total reports) × 100 | ≥ 95% | Per audit |
| Management review coverage | (Audit topics discussed in management review / Required topics) × 100 | 100% | Per management review |
| Auditor competence compliance | (Auditors meeting qualification requirements / Total auditors) × 100 | 100% | Annually |
| Independence compliance | (Audits with no conflict / Total audits) × 100 | 100% | Per audit |
| Repeat finding rate | (Repeat findings / Total findings) × 100 | < 10% | Annually |
| Audit satisfaction (auditee) | Survey score from auditees | ≥ 4.0 / 5 | Per audit |
| overhead per audit day | Total audit overhead / Audit days | Benchmark internally | Annually |
| External audit finding correlation | (External findings not previously identified internally / Total external findings) × 100 | < 20% | Per certification audit |
| Change-triggered review coverage | (Significant changes reviewed / Significant changes) × 100 | 100% | Per change |
| Supplier audit coverage | (Critical suppliers audited / Critical suppliers) × 100 | ≥ 90% | Annually |
| Training hours per auditor | Total CPD hours / Number of auditors | ≥ 20 hours/year | Annually |
KPI Dashboard Template
INDEPENDENT REVIEW KPI DASHBOARD — Q2 2026
[Organization Name]
AUDIT PLAN
Planned audits: 12
Completed: 11
Completion rate: 91.7% ⚠️ (target 95%)
FINDINGS
Open: 23
Critical: 1 (age 8 days)
High: 5 (avg age 22 days)
Medium: 10
Low: 7
Closed on time: 94% ✅
COMPETENCE & INDEPENDENCE
Auditor qualification compliance: 100% ✅
Independence compliance: 100% ✅
CPD hours per auditor: 24 ✅
EXTERNAL AUDIT ALIGNMENT
External certification findings: 2
Previously identified internally: 2
Internal coverage: 100% ✅
TOP RISKS
1. Delayed closure of privileged access review finding
2. One supplier audit postponed due to resource constraints
Common Pitfalls / Audit Failures & How to Avoid Them
| # | Pitfall / Finding | Cause | How to Avoid | Timeline |
|---|---|---|---|---|
| 1 | CISO audits their own function | Misunderstanding of independence; resource constraints | Charter must require audit function independence; use external co-source if needed | 2 weeks |
| 2 | No annual audit plan | Ad-hoc approach; no governance | Develop risk-based plan; get Audit Committee approval | 2 weeks |
| 3 | Audit plan is a generic checklist | Copied from internet without customization | Link plan to risk register, assets, regulatory requirements | 1 week |
| 4 | Auditors lack security competence | HR hired generic internal auditor | Require CISA/certified/qualified lead auditor; train or outsource | 1 month |
| 5 | Findings are vague observations | Inexperienced auditors; fear of conflict | Train auditors on finding format: condition, criterion, cause, effect, risk | 2 weeks |
| 6 | No follow-up on findings | Weak governance; no tracking tool | Implement findings register with escalation | 1 week |
| 7 | Management review ignores audit results | Results not packaged for management | Provide executive summary; link findings to risk and business impact | 1 week |
| 8 | Significant changes not reviewed | Change management and audit not integrated | Add "security review required" gate in change management | 2 weeks |
| 9 | Audit evidence is unreliable | Spreadsheets, manual screenshots, no log integrity | Use system-generated, tamper-protected evidence where possible | Ongoing |
| 10 | Third-party controls excluded | Narrow scope definition | Include critical suppliers and cloud services in audit universe | 2 weeks |
| 11 | Audit reports not distributed | Political sensitivity | Charter mandates distribution to Audit Committee/CEO | 1 week |
| 12 | No quality assurance of audit function | Audit function not reviewed | Perform annual self-assessment and periodic external QA | Annually |
Illustrative Scenarios
Illustrative scenario, a composite example for guidance, not a specific Singahi engagement or a verified outcome.
Illustrative Scenario 1: Bengaluru Fintech, Major Nonconformity on Independence
Background A 300-employee fintech startup in Bengaluru processed payments and lending data for over 1 million customers. The company had achieved ISO 27001 certification two years earlier and was preparing for recertification.
The Incident During the Stage 1 recertification audit, the external auditor reviewed the internal audit function. The findings were severe:
- The "Internal Audit Manager" reported directly to the CISO.
- The internal audit plan was drafted by the CISO and approved by the CISO.
- Two of three internal auditors were former members of the IT security team.
- The internal audit report for the previous year had been edited by the CISO before submission to management.
- The audit had not reviewed any area owned by the CISO (risk assessment, incident management, security operations).
The external auditor issued a major nonconformity against A.5.35 and suspended the certification process.
Impact
- ISO 27001 recertification delayed by 6 months.
- Two enterprise customers (a bank and an NBFC) put partnership agreements on hold, citing loss of certification.
- Estimated revenue impact: s in delayed deals.
- Regulatory scrutiny increased because the company was also preparing for RBI NBFC cyber security compliance.
Root Cause Analysis
- Structural independence failure: The audit function was structurally subordinate to the function it was supposed to review.
- Conflict of interest: Former IT security staff auditing their old colleagues created familiarity and intimidation threats.
- Lack of board oversight: No audit committee existed; the board received only summarized, sanitized reports.
- overhead-driven design: The company had combined the CISO and internal audit roles to save headcount.
- Weak understanding of A.5.35: The team treated internal audit as a compliance checkbox rather than a governance control.
Remediation The company engaged Singahi to redesign the independent review function:
Phase 1, Restructure (Week 1-2):
- Created an Internal Audit Charter approved by the Board.
- Appointed a Head of Internal Audit reporting functionally to the Board and administratively to the CEO.
- Removed internal audit from the CISO's organization.
- Implemented conflict-of-interest declarations and auditor rotation.
Phase 2, Re-audit (Week 3-8):
- Re-performed the prior year's internal audit with the new independent team.
- Added external co-source for technical security testing.
- Audited the CISO function directly for the first time.
- Identified 18 findings, including 3 high-risk gaps in incident response and privileged access.
Phase 3, Close and Certify (Month 3-6):
- Tracked all findings to closure with verified evidence.
- Updated management review process to include unfiltered audit inputs.
- Passed follow-up external audit with no A.5.35 nonconformity.
Results
- Recertification achieved 6 months after initial suspension.
- Regained enterprise customer trust; both partnerships signed.
- Board established a quarterly Audit Committee agenda item for information security.
- Investment: Revenue protected/added: + crores.
Key Lessons
- Independence is non-negotiable. A CISO cannot audit their own function.
- Organizational design matters more than individual integrity.
- Board/audit committee oversight is essential for credible assurance.
- The impact of remediation far exceeds the impact of designing independence correctly from the start.
- A.5.35 is a governance control, not a documentation exercise.
Illustrative Scenario 2: Mumbai NBFC, From Regulatory Warning to RBI-Ready Assurance
Background A mid-sized non-banking financial company (NBFC) in Mumbai with 800 employees and s in assets under management had grown rapidly through digital lending. The RBI Master Direction on IT Framework for NBFCs required periodic independent audits of IT and cyber security.
The Incident During an RBI thematic inspection, the regulator observed:
- No documented independent review of cyber security in the past 24 months.
- IT audit was performed by the IT department itself.
- Findings from previous external audits were not tracked to closure.
- No evidence that the board reviewed cyber security assurance.
RBI issued a warning letter requiring corrective action within 90 days and a follow-up submission.
Impact
- Board and senior management reputation risk.
- Potential restriction on onboarding new digital borrowers.
- Increased impact of compliance and external audit support.
- Customer and investor confidence shaken.
Root Cause Analysis
- Compliance silos: The compliance team managed RBI reporting, the IT team managed controls, and internal audit focused on financial audits. Cyber security assurance fell through the gaps.
- No risk-based IT audit plan: The annual internal audit plan did not include cyber security as a priority.
- Inadequate board reporting: Cyber security was a single slide in the annual board presentation, with no assurance opinion.
- Resource constraints: The internal audit team had financial audit expertise but no cyber security competence.
Remediation Singahi designed an integrated assurance program aligned with RBI and ISO 27001:
Phase 1, Setup (Week 1-3):
- Drafted Information Security Independent Review Policy and Charter.
- Appointed a Head of IT Audit with CISA and qualified lead auditor credentials.
- Established an IT Audit Sub-Committee of the Board.
- Created a 3-year risk-based audit plan covering RBI cyber security domains and ISO 27001 Annex A.
Phase 2, Execution (Week 4-10):
- Conducted complete independent review of cyber security governance, access control, incident management, vendor management, data protection, and business continuity.
- Used co-sourced technical testing (penetration testing, configuration review, log analysis).
- Identified 32 findings, including critical gaps in data localization logging and privileged access.
Phase 3, Closure and Reporting (Week 11-13):
- Management action plans approved by the Board.
- Follow-up testing verified closure of all critical and high findings.
- Submitted detailed assurance report to RBI within the deadline.
Results
- RBI accepted the remediation; no further enforcement action.
- Board now receives quarterly cyber security assurance dashboards.
- ISO 27001 surveillance audit passed with zero findings on A.5.35.
- Customer due diligence improved; two new institutional investors completed security assessments successfully.
- Investment: Regulatory and reputational risk: substantially reduced.
Key Lessons
- Financial audit expertise does not equal information security audit expertise.
- Regulators expect board-level oversight and independent assurance, not self-certification.
- A risk-based audit plan must explicitly cover cyber security, data protection, and third parties.
- Co-sourcing technical expertise is a practical way to build credibility quickly.
- A.5.35 compliance directly supports regulatory compliance with RBI, SEBI, IRDAI, and DPDP Act expectations.
Multi-Framework Mapping
| ISO 27001:2022 A.5.35 | SOC 2 Type II | PCI DSS 4.0 | NIST 800-53 Rev 5 | CIS Controls v8 | COBIT 2019 | GDPR / DPDP Act 2023 |
|---|---|---|---|---|---|---|
| Independent review of information security | CC1.3 (Management establishes structures, reporting lines, authorities), CC4.1 (Management selects and develops controls), CC4.2 (Management evaluates controls) | 12.4.2 (Verify audit log reviews), 12.5 (Deploy change-detection mechanisms), 12.10.4 (Review logs for unauthorized changes) | CA-2 (Control assessments), CA-7 (Continuous monitoring), PM-30 (Authorization process), RA-3 (Risk assessment), SA-12 (Auditing policy / procedures) | Control 7 (Continuous vulnerability management), Control 8 (Audit log management), Control 19 (Incident response management) | APO14.02 (Managed assurance), MEA01.01 (Monitor and evaluate performance), MEA01.02 (Monitor and evaluate internal control), MEA01.04 (Obtain assurance) | GDPR Article 32 (Security of processing, including review), DPDP Act 2023 Section 8 (Reasonable security safeguards), anticipated DPDP Rules on periodic independent audits |
| A.5.1 (Policies) | CC1.1, CC1.2 | 12.4.1 | PL-1, PL-2, PL-4 | Control 3 (Data protection) | EDM01.01, EDM01.02 | DPDP Act notice/consent policies |
| A.5.36 (Compliance with policies) | CC1.4 | 12.4.2 | PM-4, PM-5 | Control 5 (Account management) | APO14.03 | DPDP Act Section 12 (grievance redressal) |
| A.5.37 (Documented operating procedures) | CC7.2 | 12.4.2 | SA-12 | Control 4 (Secure configuration) | DSS05.04 | - |
| A.8.15 (Logging) | CC7.2 | 10.3, 10.4 | AU-6, AU-12 | Control 8 | DSS05.07 | DPDP Act accountability |
| A.8.16 (Monitoring activities) | CC7.2 | 11.4.5 | CA-7, SI-4 | Control 13 (Network monitoring) | DSS05.07 | - |
Implementation Roadmap
Figure · Timeline
Rollout in order
- Phase 1: Foun…1-30
- Phase 2: Build31-60
- Phase 3: Oper…61-90
8-Week Implementation Roadmap
| Week | Focus | Key Activities | Deliverable |
|---|---|---|---|
| 1 | Governance & Charter | Establish reporting line, draft charter, identify Audit Committee sponsor | Draft Internal Audit Charter |
| 2 | Charter Approval & Planning | Approve charter, appoint Head of Audit, assess current audit maturity | Approved Charter; Maturity assessment |
| 3 | Risk-Based Plan | Map ISMS scope, risk register, assets; draft 12-month / 3-year plan | Risk-based audit plan draft |
| 4 | Competence & Tools | Confirm auditor qualifications; select audit management tool; develop templates | Competence matrix; tool selected |
| 5 | Methodology & Templates | Finalize audit program, checklists, finding format, report template | Audit methodology pack |
| 6 | Pilot Audit | Conduct pilot audit of 1-2 high-risk areas; test process end-to-end | Pilot audit report |
| 7 | Process Refinement | Address pilot issues; update templates; train process owners | Refined methodology |
| 8 | Launch Program | Execute first full audit cycle; establish findings register and KPI dashboard | Program launched |
90-Day Sprint for New ISMS
| Phase | Days | Activities |
|---|---|---|
| Phase 1: Foundation | 1-30 | Charter, reporting line, plan, competence assessment, tool selection |
| Phase 2: Build | 31-60 | Templates, methodology, pilot audit, process refinement |
| Phase 3: Operate | 61-90 | First full audits, findings register, management review input, KPIs |
FAQ
Is internal audit mandatory for ISO 27001?
Not explicitly. ISO 27001 requires an independent review of information security (A.5.35). Internal audit is the standard way to satisfy this, but other models are acceptable if they preserve independence and competence. For most organizations, a formal internal audit function or co-sourced/outsourced equivalent is expected by certification auditors.
Can the CISO perform the internal audit?
No. The CISO cannot independently review their own function. This is the most common A.5.35 failure. Independence requires separation. The CISO can support the audit by providing evidence and implementing corrective actions, but cannot be the auditor or approve the audit scope/report for their own area.
How often must the independent review be conducted?
At planned intervals, typically at least annually for the overall ISMS, and more frequently for high-risk areas. Additionally, reviews must be triggered by significant changes such as mergers, acquisitions, cloud migration, major incidents, new regulations, or major system launches.
What qualifications should an information security auditor have?
Ideal qualifications include:
- CISA (Certified Information Systems Auditor)
- qualified lead auditor
- certified or certified
- Relevant technical certifications (cloud, networking, etc.)
- Training in ISO 19011 auditing principles
For specialized technical testing, the auditor may be supported by penetration testers, cloud security engineers, or forensics experts.
What if we are too small to have a dedicated internal auditor?
Small organizations can:
- Outsource internal audit to a qualified firm.
- Use a part-time external auditor.
- Engage a virtual CISO / audit service.
- Document independence safeguards in the charter.
The key is that the reviewer is independent of the operations reviewed, not that they are a full-time employee.
Does A.5.35 require us to audit every Annex A control every year?
No. A.5.35 requires reviews at planned intervals. A risk-based audit plan typically covers all Annex A controls over a 2-3 year cycle, with high-risk controls audited annually. The plan must be justified by risk and approved by top management.
What is the difference between A.5.35 and ISO 27001 Clause 9.2 (internal audit)?
- Clause 9.2 is a management system requirement to conduct internal audits of the ISMS at planned intervals.
- A.5.35 is an Annex A control specifically requiring independent review of the information security approach and implementation, including people, processes, and technologies.
In practice, a well-designed internal audit program satisfies both requirements simultaneously.
How does A.5.35 relate to DPDP Act 2023 independent audits?
The DPDP Act 2023 requires significant data fiduciaries to conduct periodic independent audits. While the detailed rules are pending, A.5.35 implementation provides the foundation: an independent audit function, risk-based plan, competent auditors, and documented findings. Organizations should align their A.5.35 program with anticipated DPDP audit requirements.
What should be in an A.5.35 audit report?
An effective report includes:
- Executive summary and overall opinion.
- Scope, objectives, and criteria.
- Methodology and sampling.
- Risk-rated findings with condition, criterion, cause, effect, and recommendation.
- Management response and action plan.
- Appendices with detailed evidence references.
How do we demonstrate independence if we use an outsourced auditor?
Demonstrate that:
- The outsourced firm has no conflict of interest (e.g., did not design the controls being audited).
- The contract specifies independence and reporting lines.
- The firm reports directly to your board/audit committee/CEO.
- You maintain oversight and quality review of their work.
Can IT perform vulnerability assessments and still be independent?
IT can perform operational vulnerability management (first line). However, independent validation of whether vulnerability management is effective should be performed by someone independent of IT, such as internal audit or an external firm. This distinction is critical for A.5.35.
What triggers a change-driven review under A.5.35?
Examples include:
- Merger, acquisition, or divestiture.
- Major cloud migration or infrastructure change.
- Launch of a new product or service handling sensitive data.
- New regulation (e.g., DPDP Act, RBI update).
- Major security incident or breach.
- Significant organizational restructuring.
- New critical supplier or outsourcing arrangement.
The organization should define "significant change" in its audit policy.
What are the most common external audit findings on A.5.35?
- Internal audit reports to the CISO or IT manager.
- No annual risk-based audit plan.
- Auditors lack competence or qualifications.
- Findings not tracked to closure.
- No evidence of change-triggered reviews.
- Audit reports are only observations without risk ratings.
- Working papers are missing or inadequate.
How much does it overhead to implement A.5.35 properly?
| Approach | overhead Range | Best For |
|---|---|---|
| Spreadsheet-based + outsourced annual audit | Small organizations | |
| GRC tool + co-sourced audit | Growing companies | |
| Enterprise GRC + dedicated internal audit team | Large enterprises |
The impact of non-compliance, certification suspension, customer loss, regulatory penalties, typically far exceeds the investment.
References and Further Reading
Standards and Frameworks
| Reference | Relevance |
|---|---|
| ISO/IEC 27001:2022 | Annex A 5.35; Clause 9.2 (internal audit); Clause 9.3 (management review) |
| ISO/IEC 27002:2022 | Section 5.35 implementation guidance |
| ISO 19011:2018 | Guidelines for auditing management systems |
| IIA International Standards for the Professional Practice of Internal Auditing | Internal audit independence, competence, quality |
| COSO Internal Control, Integrated Framework | Governance and internal control assurance |
| NIST SP 800-53 Rev 5 | CA (Security Assessment) control family |
| NIST Cybersecurity Framework 2.0 | Govern function (GV.RR-01 to GV.RR-06) |
| COBIT 2019 | MEA01 (Monitor, Evaluate and Assess) domain |
Indian Regulations and Guidelines
| Reference | Relevance |
|---|---|
| Digital Personal Data Protection Act, 2023 | Reasonable security safeguards; anticipated independent audit obligations for significant data fiduciaries |
| Information Technology Act, 2000 (as amended) | Section 43A, CERT-In directions, reasonable security practices |
| CERT-In Directions, 2022 | Incident reporting, log retention, asset inventory |
| RBI Cyber Security Framework in Banks, 2016 | Periodic independent assurance, board review |
| RBI Master Direction, Information Technology Framework for NBFCs | IT internal audit, cyber security governance |
| SEBI Cyber Security and Cyber Resilience Framework | Half-yearly audits for market infrastructure institutions |
| SEBI Circulars on Cyber Security for Stock Brokers / Depository Participants | Empaneled auditor reports, remediation |
| IRDAI Guidelines on Information and Cyber Security for Insurers | Governance, audit, incident reporting |
Additional Reading
| Resource | Topic |
|---|---|
| ISACA CISA Review Manual | Information systems auditing standards and practices |
| qualified lead auditor Course Materials | ISMS audit methodology |
| ICAI Guidance Note on Internal Audit of IT | Indian chartered accountants' guidance on IT audit |
| RBI Annual Reports and FAQs on Cyber Security | Regulatory expectations for banks and NBFCs |