Why most ISMS templates fail when the auditor arrives

Why most ISMS templates fail when the auditor arrives

Anyone searching for ISMS examples will likely find generic templates, fictional firms and vague claims about “strong controls”.

According to compliance platform Copla, that approach leaves organisations badly exposed. Auditors do not judge whether a document reads well. They judge whether a set of documents hold together.

An information security management system (ISMS) built to ISO 27001:2022 rests on six core documents across clauses 4 to 9.

These are the scope statement (4.3), the information security policy (5.2), the risk register (6.1.2), the Statement of Applicability (6.1.3), the ISMS objectives (6.2) and the internal audit findings (9.2). A useful example of each should name specific actions and deadlines, fill in every field, and show clearly why a decision was made.

Copla illustrates this with a single thread. A risk register entry, RR-014, flags that a departing employee’s SaaS access might not be revoked in time.

The Statement of Applicability then cites RR-014 to justify including control A.5.18, access rights. An objective sets a target of revoking access within one business day by the end of Q3. An internal audit then tests it and finds that one leaver’s account stayed active for 11 days. That finding triggers corrective action, including automated alerts.

Order matters too. The scope must come first, because nothing can be sized until the boundary is set. A Statement of Applicability drafted before the risk register exists will cite controls nobody has justified. ISO 27001 lets organisations modify, share, avoid or retain risks, and it does not mandate a specific methodology, as long as scoring stays consistent.

The 2022 revision adds urgency. Annex A shrank from 114 controls to 93, grouped into four themes: organisational (37), people (8), physical (14) and technological (34). Eleven controls are new, covering areas such as threat intelligence, cloud security and ICT readiness for business continuity. Any Statement of Applicability still using 2013 numbering, or missing the new controls, will not match what the auditor is working from.

Ownership is the other weak point. Each document needs someone who can explain its latest change without looking it up. It also needs a review schedule that runs independently of the audit calendar. A register updated only before an audit is a snapshot, not a living record.

Certification raises the stakes further. Stage 1 reviews the documentation, while Stage 2 checks whether controls actually operate. Annual surveillance audits look for drift between documents, and full recertification follows every three years. Consistency cannot be created during the audit itself. It has to exist already.

Read the full Copla post here. 

Read the daily FinTech news

Copyright © 2026 FinTech Global

Enjoying the stories?

Subscribe to our daily FinTech newsletter and get the latest industry news & research

Investors

The following investor(s) were tagged in this article.