Skip to content
Talk to a Security Expert
ISO/IEC 27001:2022ISMS / GRCSAMPLE REPORT

ISO/IEC 27001:2022 ISMS Audit & Readiness Assessment — Sample Report

ISO/IEC 27001:2022 / ISMS Audit & Readiness Assessment — Illustrative Sample Report. A fictional ISMS audit-readiness engagement for NorthBridge Digital Services, Inc., a cloud software and SaaS organization, showing how TMG Security evaluates ISMS context, governance, risk management, the Statement of Applicability, Annex A controls, evidence, findings, and remediation planning ahead of a formal ISO/IEC 27001:2022 certification audit.

Illustrative Sample Fictional Organization Not an Actual ISO/IEC 27001 Certification Audit

NorthBridge Digital Services, Inc. is a fictional entity. No actual ISO/IEC 27001 certification audit was performed, no certification decision was made, and no ISO/IEC 27001 certificate was issued in connection with this document.

01 · OVERVIEW

Overview

An ISO/IEC 27001 audit is a structured review of an organization's Information Security Management System (ISMS) against the requirements of ISO/IEC 27001:2022 — the internationally recognized standard for establishing, implementing, maintaining, and continually improving an ISMS. A formal certification audit is performed by an accredited independent certification body and results in a certification decision; TMG Security is not an accredited ISO/IEC 27001 certification body and this document is not a certification audit of any kind.

An ISO/IEC 27001 readiness assessment — the type of engagement this sample illustrates — is a gap-analysis-style review performed ahead of a formal certification audit. It evaluates ISMS context, governance, risk management, the Statement of Applicability, and Annex A control implementation to identify gaps and produce prioritized remediation guidance, so an organization can strengthen its ISMS before engaging an accredited certification body. A readiness assessment does not itself produce a certification decision or a certificate, and it is not a substitute for one.

This sample report shows how TMG Security structures that deliverable. It is built around NorthBridge Digital Services, Inc., a fictional cloud software / SaaS / enterprise technology organization headquartered in Denver, Colorado, and covers a simulated assessment period of 01 January – 31 August 2026, evaluated against ISO/IEC 27001:2022 together with Amendment 1:2024.

Assessment TypeISO/IEC 27001:2022 ISMS Audit & Readiness Assessment (Illustrative)
Standard BasisISO/IEC 27001:2022 + Amendment 1:2024
Assessment Period01 January – 31 August 2026 (Fictional)
Report Date15 September 2026 (Fictional)
OrganizationNorthBridge Digital Services, Inc. (Fictional Entity)
Industry / HQCloud Software / SaaS / Enterprise Technology · Denver, CO, USA
Illustrative Scale~900 employees · ~2,700 enterprise/mid-market customers
Overall Illustrative StatusPartially Ready for Formal Certification Audit
Performed ByTMG Security
02 · WHAT THIS SAMPLE DEMONSTRATES

What this sample demonstrates

NorthBridge Digital Services, Inc. does not exist. Every finding, control status, and figure in this sample is fictional and constructed to show TMG's methodology and reporting standard for an ISO/IEC 27001:2022 ISMS audit-readiness engagement — not to describe any real organization's ISMS posture, and not to represent the difference between a readiness assessment and a certification audit as anything other than illustrative.

  • How TMG defines ISMS context, interested parties, and scope before testing begins (Clauses 4.1–4.3)
  • How ISMS governance, leadership commitment, and the policy framework are reviewed (Clause 5)
  • How risk assessment and risk treatment are performed and tracked against the ISMS risk register (Clause 6.1)
  • How a Statement of Applicability (SoA) is built and justified across all 93 Annex A:2022 controls
  • How an Annex A control assessment is structured — applicability, implementation status, and illustrative testing
  • How findings are rated for severity, root-caused with a 5-Whys approach, and mapped to specific clauses and Annex A controls
  • How a 30/60/90-day remediation roadmap and management action plan are built from findings ahead of a real certification audit
  • The full appendix structure — evidence register, interview register, control testing register, finding register, and assessment limitations — that supports a real engagement
03 · ASSESSMENT SCOPE

Assessment scope

The illustrative scope below reflects the ISMS boundary TMG Security would define and document under Clause 4.3 ahead of an ISO/IEC 27001:2022 readiness engagement, covering the fictional information systems, cloud infrastructure, and critical third-party services in scope for NorthBridge's ISMS.

In scope

  • Corporate information systems and end-user computing environment
  • Production SaaS platform serving enterprise and mid-market customers
  • Cloud infrastructure (compute, storage, and networking) supporting production services
  • Identity & access management systems, including SSO and privileged access tiers
  • CI/CD environment and source control supporting secure development
  • Customer support platform handling in-scope customer data
  • Security operations tooling — centralized SIEM and endpoint detection & response (EDR)
  • Backup and disaster recovery infrastructure for business-critical services
  • Critical third-party and subprocessor services supporting the production environment

Out of scope

  • Legacy subsidiary systems not integrated with the production environment
  • Isolated experimental / research environments with no customer data access
  • Unrelated marketing technology with no connectivity to in-scope systems
  • Unmanaged personal devices outside the corporate device-management program

NorthBridge's fictional environment operates on a shared-responsibility cloud model (AWS, Kubernetes, and managed data services), which is why several facility-level Annex A physical controls (A.7.11, A.7.12) are assessed as Not Applicable — those responsibilities sit with the underlying cloud infrastructure provider rather than NorthBridge directly.

04 · ISMS CONTEXT & INTERESTED PARTIES

ISMS context & interested parties

ISMS context (Clause 4.1) is the set of external and internal issues that can affect an organization's ability to achieve its ISMS objectives. This fictional assessment reviewed five illustrative external issues — enterprise SaaS market competition, the evolving cloud threat landscape, customer contractual security requirements, regulatory and privacy expectations, and climate-related operational disruption — alongside five illustrative internal issues: rapid engineering headcount growth, multi-team ownership of cloud infrastructure, maturing GRC platform adoption, a distributed/remote workforce model, and multiple critical third-party dependencies.

Interested parties (Clause 4.2) are the people and organizations whose requirements are relevant to the ISMS. NorthBridge's fictional interested-party analysis covers customers, employees and contractors, executive leadership and the board, regulators, contractual partners and channel resellers, suppliers and subprocessors, cloud infrastructure providers, independent auditors, cyber insurers, and shareholders/investors — each mapped to its expectations, security relevance, and an accountable ISMS owner.

05 · ISMS GOVERNANCE & LEADERSHIP

ISMS governance & leadership

Clause 5 requires top management to demonstrate leadership and commitment to the ISMS. NorthBridge's fictional governance structure runs from the Board and Executive Leadership through the CISO, down to the GRC Manager, Security Operations Lead, and Internal Audit Lead, with further accountability distributed to the IAM Program Manager, Engineering Director, IT Director, and HR Manager. Governance and leadership commitment were assessed as Effective for this fictional sample, and no findings were raised against this section.

NorthBridge's fictional information security policy framework spans twelve reviewed policy areas — including access control, asset management, cryptography, incident response, business continuity, supplier security, vulnerability management, secure development, acceptable use, data classification, backup, and logging & monitoring — each on an annual review cycle. Roles, responsibilities, and authorities (Clause 5.3) were reviewed through a full RACI matrix spanning ten ISMS activities across ten accountable roles, from the CEO and CISO down to functional leads.

06 · RISK ASSESSMENT & RISK TREATMENT

Risk assessment & risk treatment

Clause 6.1.2 requires a defined, repeatable risk assessment methodology. NorthBridge's fictional methodology rates each risk on a five-level likelihood scale (Rare, Unlikely, Possible, Likely, Almost Certain) and a five-level impact scale (Insignificant, Minor, Moderate, Major, Severe), then applies risk treatment (Clause 6.1.3) — reduce, avoid, transfer, or accept — with an owner and target date recorded for every open action. The full illustrative risk register covers twelve enterprise risks; representative examples are shown below.

Representative entries from the illustrative 12-risk enterprise risk register — fictional sample data.
RiskInherent → ResidualTreatmentOwnerFinding
Unauthorized Access to Customer SystemsHigh → MediumReduceIAM Program ManagerISMS-H-002
Compromised Privileged AccountHigh → MediumReduceSecurity Operations LeadISMS-H-002
Third-Party Security FailureHigh → MediumReduceProcurement LeadISMS-H-003
Insufficient Vulnerability RemediationHigh → MediumReduceSecurity Operations LeadISMS-M-005
Inadequate Backup RecoveryMedium → LowReduceEngineering Director, PlatformISMS-M-006
Insufficient Employee Security AwarenessMedium → LowReduceHR ManagerISMS-M-007
07 · STATEMENT OF APPLICABILITY

Statement of Applicability

A Statement of Applicability (SoA) is the documented list of Annex A controls, together with their applicability, justification, and implementation status, required by Clause 6.1.3(d) of ISO/IEC 27001:2022. It is one of the central deliverables of an ISMS and a mandatory input to a formal certification audit. This fictional sample includes a comprehensive illustrative SoA covering all 93 Annex A:2022 controls for NorthBridge's environment, each with a TMG-authored plain-language applicability justification — the full SoA is presented in the complete sample PDF.

Of the 93 controls considered, 90 were determined applicable to NorthBridge's fictional environment and 3 were determined not applicable — reflecting NorthBridge's shared-responsibility cloud model and the fact that no in-house software development was outsourced during the assessment period.

Illustrative Statement of Applicability summary — fictional sample data.
MetricCount
Total Controls Considered93
Applicable90
Not Applicable3
Implemented (Effective)79
Partially Implemented (Partially Effective)7
Improvement Required4
08 · ANNEX A CONTROL ASSESSMENT

Annex A control assessment

An Annex A control assessment evaluates the 93 information security controls listed in Annex A of ISO/IEC 27001:2022, organized across four themes — A.5 Organizational, A.6 People, A.7 Physical, and A.8 Technological — determining applicability, implementation status, and, where applicable, illustrative testing results. TMG's control descriptions below are original plain-language summaries of each control's intent; no copyrighted ISO/IEC control text is reproduced, and no controls beyond those defined in Annex A:2022 are introduced.

Illustrative Annex A theme summary — fictional sample data.
ThemeTotalApplicableEffectivePartialImprove
A.5 Organizational37373322
A.6 People88710
A.7 Physical14121110
A.8 Technological34332832

Representative illustrative testing examples

Representative Annex A testing examples — fictional sample data, Section 38 of the full PDF.
Ref.Control Theme (TMG Summary)StatusFinding
A.5.9Maintaining an inventory of information and other associated assets, with ownersPartially EffectiveISMS-M-008
A.5.22Monitoring, reviewing, and managing change in supplier service deliveryRequires ImprovementISMS-H-003
A.6.3Providing personnel with appropriate security awareness, education, and trainingPartially EffectiveISMS-M-007
A.7.2Controlling physical entry to secure areas through appropriate entry controlsPartially EffectiveISMS-L-011
A.8.2Restricting and managing the allocation and use of privileged access rightsRequires ImprovementISMS-H-002
A.8.8Obtaining information about technical vulnerabilities and evaluating exposurePartially EffectiveISMS-M-005
09 · EVIDENCE & SAMPLING METHODOLOGY

Evidence & sampling methodology

TMG Security's fictional assessment methodology combines multiple evidence-gathering techniques — document review, simulated interviews, observation, technical evidence, sampling, walkthroughs, configuration review, testing, and management-record review — to form an evidence-based, illustrative view of ISMS design and operation. The full sample references thirty illustrative evidence entries (policies, registers, review artifacts, technical configurations, and test records), ten simulated role-holder interviews, and fourteen illustrative control-testing procedures with documented populations, samples, results, and finding references. Every evidence reference, interview, and test result in this sample is illustrative — no actual client evidence was collected or reviewed, and no actual interviews were conducted.

10 · FINDINGS & RISK REPORTING

Findings & risk reporting

This fictional sample identified 14 total findings and observations across 96 illustrative ISMS areas assessed: 0 rated Critical, 3 High, 6 Medium, 3 Low, and 2 forward-looking Observations. Every finding, evidence reference, and management response below is fictional.

0
Critical
3
High
6
Medium
3
Low
2
Observations
ISMS-H-001 · HIGH · Clause 6.1.3 / 8.3 Risk Treatment

Enterprise Risk Treatment Tracking Not Consistently Updated

A fictional sample review of 24 open risk-treatment actions found that 9 had not been updated within the required 10-business-day window, because tracking depends on manual entry into a spreadsheet-based tracker with no integration to the underlying remediation systems. Recommendation: migrate risk treatment tracking into the centralized GRC platform, with automated status pulls where feasible.

Illustrative Assessment Status: Requires Improvement · Owner: GRC Manager · Target: 15 Nov 2026

ISMS-M-006 · MEDIUM · A.8.13 Information Backup

Backup Restoration Evidence Not Consistently Retained

Of 10 sampled backup restoration test records across business-critical databases, 3 records for a secondary reporting database could not be located, because that database is tested by a separate engineering sub-team using a different, less mature tracking practice. Recommendation: consolidate restoration test scheduling and evidence retention for all business-critical databases under a single, centrally tracked calendar and repository.

Illustrative Assessment Status: Partially Effective · Owner: Engineering Director, Platform · Target: 15 Dec 2026

ISMS-O-013 · OBSERVATION · Clause 9.1 Performance Evaluation

Opportunity to Improve ISMS Metrics Automation

ISMS performance metrics are currently compiled through a partially manual export-and-consolidate process rather than being pulled automatically from source systems. This is not a control exception but a forward-looking opportunity to reduce manual effort and improve metric timeliness as the ISMS programme matures. Recommendation: evaluate automated metrics-collection tooling that can pull ISMS performance data directly from source systems.

Illustrative Assessment Status: Effective · Owner: GRC Manager · Target: 30 Jun 2027

Full illustrative finding register — Section 54 of the sample PDF.
IDTitleSeverityClause / Annex A
ISMS-H-001Enterprise Risk Treatment Tracking Not Consistently UpdatedHighClause 6.1.3
ISMS-H-002Privileged Access Recertification Evidence IncompleteHighA.8.2
ISMS-H-003Supplier Security Reassessment Evidence IncompleteHighA.5.22
ISMS-M-004Internal Audit Follow-Up Tracking InconsistentMediumClause 9.2
ISMS-M-005Vulnerability Remediation Exception Documentation IncompleteMediumA.8.8
ISMS-M-006Backup Restoration Evidence Not Consistently RetainedMediumA.8.13
ISMS-M-007Security Awareness Completion Exceptions Not Centrally TrackedMediumA.6.3
ISMS-M-008Asset Inventory Reconciliation Requires ImprovementMediumA.5.9
ISMS-M-009Change Management Security Review Evidence InconsistentMediumA.8.32
ISMS-L-010Document Version Metadata InconsistencyLowClause 7.5
ISMS-L-011Physical Visitor Record Review Documentation GapLowA.7.2
ISMS-L-012Supplier Review Evidence Formatting InconsistencyLowA.5.20
ISMS-O-013Opportunity to Improve ISMS Metrics AutomationObservationClause 9.1
ISMS-O-014Opportunity to Improve Management Dashboard StandardizationObservationClause 9.3
11 · CORRECTIVE ACTION & REMEDIATION

Corrective action & remediation

Clause 10 requires continual improvement, including corrective action on nonconformities. Every High-severity finding, and a representative Medium-severity finding, was carried through a fictional 5-Whys root-cause analysis to move from the immediate condition to an underlying, addressable root cause — for example, ISMS-H-001's tracking lapse traced back to the risk-treatment process never having been re-engineered to take advantage of current GRC tooling. Corrective actions are logged in a centralized register with owner, priority, target date, and an independent retest validation method for every finding, consolidating root cause, action, and ownership into a single fictional Corrective Action Plan and Management Action Plan.

NorthBridge's fictional management team reviewed and formally accepted each finding, assigning Priority 1 to the three High-severity findings, Priority 2 to the six Medium-severity findings, Priority 3 to the three Low-severity findings, and Priority 4 to the two forward-looking Observations — each with a documented target date and an independent retest sample planned for the subsequent assessment cycle.

12 · MANAGEMENT REVIEW

Management review

Clause 9.3 requires top management to review the ISMS at planned intervals to ensure its continuing suitability, adequacy, and effectiveness. NorthBridge's fictional Q3 2026 management review considered the status of previous actions, changes in context, risk status, security objectives, audit results, incidents, supplier performance, and resourcing — producing six illustrative action items, including migrating risk-treatment tracking to the centralized GRC platform and extending the IAM governance platform to privileged account tiers.

Clause 9.1 performance evaluation reviewed trend data across the ISMS objectives dashboard. Selected illustrative KPIs: MFA coverage 100% (on target), vulnerability SLA compliance 88% against a 95% target, security training completion 94% against a 98% target, and supplier reassessment coverage 58% against a 100% target — each reconciling to the findings above. Performance evaluation and continual improvement practices were themselves assessed as Partially Effective for this fictional sample, reflecting the internal audit follow-up and metrics-automation observations rather than a control design deficiency.

13 · ISMS MATURITY ASSESSMENT

ISMS maturity assessment

The fictional maturity model below rates twelve ISMS domains on a five-level scale (1 Initial, 2 Developing, 3 Defined, 4 Managed, 5 Optimized), reflecting the fictional findings identified throughout this sample.

Illustrative ISMS maturity model — fictional scores by domain.
DomainLevel
Governance4 — Managed
Risk Management3 — Defined
Policy Framework4 — Managed
Asset Management3 — Defined
Access Control3 — Defined
Supplier Security3 — Defined
Incident Management4 — Managed
Business Continuity4 — Managed
Internal Audit3 — Defined
Management Review4 — Managed
Continual Improvement3 — Defined
Technical Controls4 — Managed
14 · 30/60/90 DAY REMEDIATION ROADMAP

30/60/90-day remediation roadmap

The fictional 90-day remediation roadmap sequences remediation activity ahead of an actual, independent ISO/IEC 27001:2022 certification audit, prioritizing the three High-severity findings for early closure. All dates and timelines shown are illustrative.

0–30 days

  • Begin migration of enterprise risk-treatment tracking into the centralized GRC platform (ISMS-H-001)
  • Extend the IAM governance platform to cover privileged account tiers with system-enforced attestation (ISMS-H-002)
  • Complete overdue reassessments for the High/Medium risk-tier suppliers identified in this sample and implement reassessment-due alerting (ISMS-H-003)

31–60 days

  • Automate vulnerability exception-record generation with mandatory Security leadership sign-off for SLA-exceeding findings (ISMS-M-005)
  • Consolidate backup restoration testing scheduling and evidence retention under a single centrally tracked calendar (ISMS-M-006)
  • Introduce a mandatory independent verification step prior to closing internal audit findings (ISMS-M-004)
  • Add a system-enforced security-review gate to the change-management workflow for Medium-risk-or-higher changes (ISMS-M-009)

61–90 days

  • Implement automated asset-inventory registration for auto-scaled analytics resources and complete a full inventory reconciliation (ISMS-M-008)
  • Integrate LMS overdue-training data into the centralized GRC reporting dashboard (ISMS-M-007)
  • Configure automated version-metadata population within the document management platform; add the visitor-log review to the physical security checklist; retrofit supplier evidence files to the standard template (ISMS-L-010, ISMS-L-011, ISMS-L-012)
  • Evaluate automated ISMS metrics tooling and adopt a standardized management review template (ISMS-O-013, ISMS-O-014)
  • Complete a full retest cycle across all 2026 findings ahead of engaging an accredited independent certification body for an actual ISO/IEC 27001:2022 certification audit
15 · READINESS CONCLUSION

Readiness conclusion

Illustrative readiness conclusion: Partially Ready for Formal Certification Audit. This conclusion is illustrative only — it is not an ISO/IEC 27001 certification decision, and a formal certification decision must be made by an appropriately accredited independent certification body following an actual certification audit.

This fictional assessment demonstrates that NorthBridge has established an ISMS foundation with major governance processes in place: leadership commitment is visible, risk management is operational, the Statement of Applicability is comprehensive, and a substantial majority of Annex A:2022 controls — 79 of 90 applicable controls — were assessed as Effective in this sample. The difference between this readiness assessment and a certification audit is that a readiness assessment identifies and helps remediate gaps like these in advance; a certification audit, performed by an accredited body, tests whether the ISMS conforms to ISO/IEC 27001:2022 and results in a formal certification decision. None of the fictional findings in this sample indicate an absent control programme — they reflect documentation, consistency, and evidence-retention gaps within an otherwise well-designed ISMS, the pattern TMG Security would expect to identify and help remediate during a readiness engagement conducted ahead of an organization's first, or a subsequent, certification audit.

Strengths (Fictional)

  • Visible executive leadership commitment and a well-structured governance and reporting model
  • Comprehensive, current information security policy framework reviewed on a defined annual cycle
  • Mature technical control baseline: enforced MFA/SSO, centralized SIEM/EDR, strong cryptography and key management practices
  • Documented, exercised incident management and business continuity/disaster recovery programmes
  • A comprehensive, well-justified Statement of Applicability covering all 93 Annex A:2022 controls

Improvement Areas (Fictional)

  • Enterprise risk treatment tracking evidence and cross-system status reconciliation
  • Privileged access recertification evidence retention across cloud, container, and database administrative tiers
  • Supplier security reassessment cadence enforcement for High/Medium risk-tier suppliers
  • Internal audit finding closure — independent verification prior to marking findings resolved
  • Vulnerability remediation exception governance, backup restoration evidence, and change-management security-review consistency

This conclusion, and every figure, finding, and status referenced throughout this sample, is entirely fictional and constructed for demonstration purposes only. It does not describe the security, availability, or ISMS posture of any real organization, and does not constitute an ISO/IEC 27001 certificate, certification decision, or independent certification audit report.

16 · IMPORTANT DISCLAIMER
Illustrative Sample — Not an Actual ISO/IEC 27001 Certification Audit

NorthBridge Digital Services, Inc. is a fictional entity. It does not correspond to any real business, and any resemblance to an actual organization is purely coincidental.

No actual ISO/IEC 27001 certification audit, readiness assessment, or gap analysis was performed against any real environment, system, or organization. No production environment, system, or network of any kind was accessed in the creation of this report, and no actual evidence — including policies, configuration exports, screenshots, logs, or records — was collected, reviewed, or relied upon. No actual interviews or control walkthroughs were conducted with any personnel.

All findings, risk ratings, evidence references, control statuses, dates, metrics, and management responses in this report are illustrative and fictional. They were constructed to demonstrate realistic reporting conventions and do not describe any actual security or ISMS condition.

This document is not an official ISO/IEC 27001 certification output. No formal ISO/IEC 27001 certification audit — of any type, by any certification body — was undertaken in connection with this document. No certification decision was made, and no ISO/IEC 27001 certificate was issued as a result of, or in connection with, this document. This document is not evidence of ISO/IEC 27001 certification for any organization, and it is not legal, regulatory, or compliance advice.

TMG Security is not an accredited ISO/IEC 27001 certification body. A formal certification decision, if pursued, must be made by an appropriately accredited independent certification body following an actual certification audit.

17 · VIEW FULL SAMPLE PDF

View the full sample PDF

The complete 51-page illustrative report, including the full ISMS context and governance review, risk assessment and treatment, the complete Statement of Applicability, the Annex A control matrix, detailed findings, remediation roadmap, and every appendix.

NorthBridge Digital Services, Inc. ISO/IEC 27001:2022 ISMS Audit & Readiness Assessment — Sample Report.pdf
ISO/IEC 27001:2022 · ISMS Audit & Readiness Assessment · 51 Pages · Illustrative Sample
18 · REQUEST A SIMILAR ASSESSMENT

Request a similar assessment

Preparing for a first, or a subsequent, ISO/IEC 27001:2022 certification audit? TMG Security's GRC & Compliance team can scope a real ISMS audit-readiness assessment built with the same structure, methodology, and reporting depth shown in this sample — ISMS context and scope definition, governance and risk review, a comprehensive Statement of Applicability, Annex A control testing, a finding register, and a remediation roadmap your team can execute against before engaging an accredited certification body. Not sure which framework applies to your organization? See how ISO/IEC 27001 compares to other frameworks in TMG's ISO 27001 vs SOC 2 vs PCI DSS comparison guide.