Governance and policy · question family
Independent audit and certification: the clause the question tests
Whether someone independent has examined the controls, against what, and when.
How the customer usually asks it
example"Is your organisation independently audited against a recognised security standard?"
Anchor clauses
2 frameworks| Framework | Anchor clause |
|---|---|
| ISO/IEC 27001:2022 | 5.35 Independent review of information security · clause 9.2 Internal audit (named, not quoted) |
| SOC 2 (Trust Services Criteria) | CC4.1 COSO principle 16: Selects and develops ongoing and separate evaluations |
Every framework that anchors this family is listed here; a register shows the ones ticked for the customer.
Evidence expected
The current certificate or attestation report with its scope statement and period, and the latest internal audit summary.
The clauses, with what an assessor asks for
ISO 27001 5.35 Independent review of information securityHave the security approach and its implementation reviewed independently on a cadence and after significant change.
Evidence an assessor expects: Review schedule; Review reports; Reviewer independence; Change trigger log
Where answers usually fall short: Reviews performed by internal staff only; Infrequent or ad-hoc review cadence
Source: ISO/IEC 27001:2022
Where answers usually fall short: Reviews performed by internal staff only; Infrequent or ad-hoc review cadence
Source: ISO/IEC 27001:2022
SOC 2 CC4.1 COSO principle 16: Selects and develops ongoing and separate evaluationsNamed, not quoted: the criteria text is not held in full here.
Evidence an assessor expects: The plan for ongoing and separate evaluations, showing scope, type, frequency and who performs them; Results of evaluations performed in the period, such as internal audit reports, control self assessments, vulnerability assessments and penetration tests; Evidence evaluators are objective and knowledgeable, and independent of the activity evaluated; Evidence a baseline understanding of the control system exists and is used to scope evaluations; Evidence of the mix and rate of change, showing evaluations are adjusted as risk changes
Where answers usually fall short: Only one annual assessment performed, with no ongoing evaluation between times; Evaluations performed by the people who operate the controls, so objectivity fails
Source: SOC 2 (Trust Services Criteria)
Where answers usually fall short: Only one annual assessment performed, with no ongoing evaluation between times; Evaluations performed by the people who operate the controls, so objectivity fails
Source: SOC 2 (Trust Services Criteria)