Start with ownership and scope
If nobody owns the ISMS and the boundary is vague, later categories will sprawl.
ISO/IEC 27001:2022 for SaaS teams
A practical, interactive checklist for building an ISO/IEC 27001:2022 information security management system.
Track your progress across scope, risk management, controls, documentation, evidence, internal audit and certification preparation.
Free · Interactive · No account required
70 implementation tasks. This is a practical preparation resource, not an official ISO checklist or certification assessment.
Checklist progress
Track ISMS implementation work on this device. This is preparation progress — not a compliance percentage and not a certification-readiness score.
0 / 70 completed
0%
Checking boxes is only the beginning.
ISO 27001 depends on how your ISMS operates in practice — including risks, controls, evidence, internal audit and continual improvement.
ISO 27001 support is coming to AuditBird.
Smaller teams often benefit from defining a realistic scope instead of automatically including everything the company touches. That is not an invitation to hide systems a customer would reasonably expect to be protected.
ISO 27001 is risk-based. You need a repeatable approach your team can explain — not a branded methodology mandated by AuditBird.
The Statement of Applicability connects the organization's risk treatment decisions with control applicability. Not every Annex A control must be implemented. Statement of Applicability — dedicated page coming soon.
Documentation should reflect how the company actually operates. This is not a universal mandatory policy list. Many security policy concepts overlap across frameworks. Browse SOC 2 policy templates and adapt them to your actual ISMS and organization.
The exact control set should follow the organization's risk treatment decisions and applicable requirements. This section does not reproduce all 93 Annex A controls. ISO 27001 controls — dedicated page coming soon.
Internal audit is not the same as the certification audit. AuditBird is not your internal auditor.
Prepare for certification assessment. Completing this list does not mean you will “pass the audit.”
An ISO 27001 checklist is a way to see the work of building an ISMS: who owns it, what is in scope, how risks are assessed and treated, which controls apply, what is documented, and how the system is evaluated. It organizes preparation. It does not replace the standard, a certification body, or evidence that the system operates.
Work in implementation order. Check an item when the practice exists and you could show it — not when you intend to start next quarter. Progress is stored in this browser so you can return without creating an account.
If nobody owns the ISMS and the boundary is vague, later categories will sprawl.
Annex A is a reference set. Treatment decisions come first.
Documents that describe an enterprise GRC program you do not run will not help Stage 2.
Internal audit and management review are part of the ISMS — not optional extras after you hire a certification body.
Clauses 4–10 contain the management system requirements: context, leadership, planning, support, operation, performance evaluation and improvement. Annex A provides 93 reference controls in four themes. You implement an ISMS against the clauses. You select and justify controls through risk treatment and the Statement of Applicability — you do not tick all 93 by default.
ISO 27001 is risk-based. A control catalogue copied from a blog will not explain why a backup test or a vendor review exists in your environment. Identify risks in scope, decide treatment, then map controls — including Annex A as a completeness check. AuditBird does not mandate one risk methodology.
Related reading on the ISO 27001 guide. A dedicated risk assessment page is planned.
The SoA records which Annex A controls apply, their implementation status, and why inclusions or exclusions are justified. It is the bridge between risk treatment and the control set a certification body will discuss. A copied SoA that ignores your systems will not hold up.
Statement of Applicability — dedicated guide coming soon. Until then, use the SoA category in this checklist and the ISO 27001 overview.
Think in dated samples: access reviews, awareness records, risk register updates, vendor reviews, change and vulnerability follow-up, backup tests, incident notes, internal audit reports, management review minutes, and closed corrective actions. Having a process is different from demonstrating that it operated.
Internal audit is how the organization checks its own ISMS. The certification audit is an independent assessment by a certification body, typically in Stage 1 and Stage 2. They are not the same event, and AuditBird is neither your internal auditor nor a certification body.
Use remaining gaps as a work queue: finish the SoA, run internal audit, hold management review, and only then engage a certification body. Completing every box is a preparation milestone. It does not mean the ISMS conforms to ISO/IEC 27001.
Continue with the ISO 27001 guide or see planned pricing. ISO 27001 support is coming to AuditBird — buying a plan today does not unlock a complete ISO 27001 product module.
Many underlying security practices can support multiple frameworks — access reviews, vendor reviews, incident management, risk management, security awareness and evidence. There is no exact overlap percentage. SOC 2 is an attestation against Trust Services Criteria; ISO 27001 is a certifiable ISMS standard. Neither replaces the other universally.
AuditBird is being built around reusable controls, evidence and ownership across multiple frameworks. Cross-framework automation is not presented as a live ISO 27001 product feature today.
It is a practical list of implementation tasks for building an information security management system — scope, risk, controls, documentation, evidence, internal audit, management review and certification preparation. It helps a team see remaining work. It is not an official ISO document and not a certification assessment.
ISO 27001 support is coming to AuditBird. Join early access for updates — and for the multi-framework program being built around reusable controls and evidence.
SOC 2 · ISO 27001 · GDPR · and more