AuditBird

ISO/IEC 27001:2022 for SaaS teams

ISO 27001 Checklist for SaaS Teams

A practical, interactive checklist for building an ISO/IEC 27001:2022 information security management system.

Track your progress across scope, risk management, controls, documentation, evidence, internal audit and certification preparation.

Free · Interactive · No account required

70 implementation tasks. This is a practical preparation resource, not an official ISO checklist or certification assessment.

Checklist progress

ISO 27001 preparation progress

Track ISMS implementation work on this device. This is preparation progress — not a compliance percentage and not a certification-readiness score.

0 / 70 completed

0%

  • Ownership0 / 4
  • Context0 / 4
  • Scope0 / 5
  • Leadership0 / 4
  • Risk assessment0 / 7
  • Risk treatment & SoA0 / 7
  • Policies0 / 5
  • People0 / 4
  • Operations0 / 6
  • Suppliers0 / 4
  • Monitoring0 / 3
  • Internal audit0 / 4
  • Management review0 / 4
  • Corrective action0 / 4
  • Certification prep0 / 5

Checking boxes is only the beginning.

ISO 27001 depends on how your ISMS operates in practice — including risks, controls, evidence, internal audit and continual improvement.

ISO 27001 support is coming to AuditBird.

Smaller teams often benefit from defining a realistic scope instead of automatically including everything the company touches. That is not an invitation to hide systems a customer would reasonably expect to be protected.

ISO 27001 is risk-based. You need a repeatable approach your team can explain — not a branded methodology mandated by AuditBird.

The Statement of Applicability connects the organization's risk treatment decisions with control applicability. Not every Annex A control must be implemented. Statement of Applicability — dedicated page coming soon.

Documentation should reflect how the company actually operates. This is not a universal mandatory policy list. Many security policy concepts overlap across frameworks. Browse SOC 2 policy templates and adapt them to your actual ISMS and organization.

The exact control set should follow the organization's risk treatment decisions and applicable requirements. This section does not reproduce all 93 Annex A controls. ISO 27001 controls — dedicated page coming soon.

Internal audit is not the same as the certification audit. AuditBird is not your internal auditor.

Prepare for certification assessment. Completing this list does not mean you will “pass the audit.”

What is an ISO 27001 checklist?

An ISO 27001 checklist is a way to see the work of building an ISMS: who owns it, what is in scope, how risks are assessed and treated, which controls apply, what is documented, and how the system is evaluated. It organizes preparation. It does not replace the standard, a certification body, or evidence that the system operates.

How to use this ISO 27001 checklist

Work in implementation order. Check an item when the practice exists and you could show it — not when you intend to start next quarter. Progress is stored in this browser so you can return without creating an account.

Start with ownership and scope

If nobody owns the ISMS and the boundary is vague, later categories will sprawl.

Assess risk before picking controls

Annex A is a reference set. Treatment decisions come first.

Write what you actually do

Documents that describe an enterprise GRC program you do not run will not help Stage 2.

Evaluate the system, then prepare for assessment

Internal audit and management review are part of the ISMS — not optional extras after you hire a certification body.

ISO 27001 requirements vs Annex A controls

Clauses 4–10 contain the management system requirements: context, leadership, planning, support, operation, performance evaluation and improvement. Annex A provides 93 reference controls in four themes. You implement an ISMS against the clauses. You select and justify controls through risk treatment and the Statement of Applicability — you do not tick all 93 by default.

Why risk assessment comes before controls

ISO 27001 is risk-based. A control catalogue copied from a blog will not explain why a backup test or a vendor review exists in your environment. Identify risks in scope, decide treatment, then map controls — including Annex A as a completeness check. AuditBird does not mandate one risk methodology.

Related reading on the ISO 27001 guide. A dedicated risk assessment page is planned.

What is a Statement of Applicability?

The SoA records which Annex A controls apply, their implementation status, and why inclusions or exclusions are justified. It is the bridge between risk treatment and the control set a certification body will discuss. A copied SoA that ignores your systems will not hold up.

Statement of Applicability — dedicated guide coming soon. Until then, use the SoA category in this checklist and the ISO 27001 overview.

What evidence should SaaS teams prepare?

Think in dated samples: access reviews, awareness records, risk register updates, vendor reviews, change and vulnerability follow-up, backup tests, incident notes, internal audit reports, management review minutes, and closed corrective actions. Having a process is different from demonstrating that it operated.

Internal audit vs certification audit

Internal audit is how the organization checks its own ISMS. The certification audit is an independent assessment by a certification body, typically in Stage 1 and Stage 2. They are not the same event, and AuditBird is neither your internal auditor nor a certification body.

What happens after completing the checklist?

Use remaining gaps as a work queue: finish the SoA, run internal audit, hold management review, and only then engage a certification body. Completing every box is a preparation milestone. It does not mean the ISMS conforms to ISO/IEC 27001.

Continue with the ISO 27001 guide or see planned pricing. ISO 27001 support is coming to AuditBird — buying a plan today does not unlock a complete ISO 27001 product module.

Already working on SOC 2?

Many underlying security practices can support multiple frameworks — access reviews, vendor reviews, incident management, risk management, security awareness and evidence. There is no exact overlap percentage. SOC 2 is an attestation against Trust Services Criteria; ISO 27001 is a certifiable ISMS standard. Neither replaces the other universally.

AuditBird is being built around reusable controls, evidence and ownership across multiple frameworks. Cross-framework automation is not presented as a live ISO 27001 product feature today.

Questions

It is a practical list of implementation tasks for building an information security management system — scope, risk, controls, documentation, evidence, internal audit, management review and certification preparation. It helps a team see remaining work. It is not an official ISO document and not a certification assessment.

Build an ISMS without an enterprise GRC department.

ISO 27001 support is coming to AuditBird. Join early access for updates — and for the multi-framework program being built around reusable controls and evidence.

Read the ISO 27001 guide

SOC 2 · ISO 27001 · GDPR · and more