Internal Audit
Certification Readiness
ISO 27001 Clause 7 Internal Audit: Competence, Awareness, Communication, and Document Control
A practical guide to auditing ISO 27001 Clause 7 evidence for resources, competence, awareness, communication, documented information, training records, policy approvals, SharePoint document control, and certification readiness.
Quick Answer
What should an ISO 27001 Clause 7 internal audit review?
An ISO 27001 Clause 7 internal audit should check whether the organization has enough support to run the ISMS.
That support includes resources, competence, awareness, communication, and controlled documented information.
Strong evidence includes training records, role descriptions, competence matrices, policy acknowledgments, communication logs, document registers, approval workflows, version history, review dates, and controlled SharePoint libraries.
Clause 7 Is About ISMS Support
Clause 7 is not only about training.
It asks whether the organization can support the ISMS in daily work.
For example, policies may exist. Training may be assigned. SharePoint may contain many documents.
However, the audit may still find unclear owners, missing approvals, outdated versions, weak communication, and poor awareness.
Practical rule: Clause 7 proves whether people, communication, and documented information can support the ISMS.
The Main Audit Question
The best audit question is not, “Did employees finish training?”
A stronger question is:
Can the organization prove that the right people are competent, aware, informed, and using controlled ISMS information?
ISO 27001 Clause 7 Audit Snapshot
| Clause 7 Area | What Internal Audit Should Test |
|---|---|
| 7.1 Resources | People, tools, time, budget, and ISMS support. |
| 7.2 Competence | Role competence for ISMS tasks and control responsibilities. |
| 7.3 Awareness | Employee understanding of policies, duties, and consequences. |
| 7.4 Communication | Planned, delivered, retained, and understood security communication. |
| 7.5 Documented Information | Policies, procedures, approvals, versions, records, and evidence control. |
Why Clause 7 Matters
Clause 7 supports every part of the ISMS.
Even strong controls can fail when people do not understand them.
Also, evidence becomes weak when documents are outdated or uncontrolled.
1. Audit Clause 7.1 Resources
Start with resources.
The organization must provide enough support to maintain the ISMS.
Audit Questions
- Are enough people assigned to maintain the ISMS?
- Do control owners have time to complete evidence tasks?
- Are tools available for risk, audit, evidence, and corrective action tracking?
- Are resource gaps discussed in management review?
- Does leadership review ISMS support needs?
Common finding: control owners must maintain ISO 27001 evidence, but they do not have enough time, reminders, tools, or structure.
2. Audit Clause 7.2 Competence
Competence means people can perform their ISMS duties.
This may come from training, experience, education, or certification.
Evidence to Review
- Competence matrix.
- Role descriptions.
- Training records.
- Internal auditor qualification records.
- Control owner onboarding records.
Practical rule: a name in a control owner matrix is not enough. Competence must be shown.
Need Clause 7 Evidence Ready Before Audit?
Canadian Cyber helps organizations audit ISO 27001 Clause 7 evidence for competence, awareness, communication, document control, training records, and SharePoint libraries.
We help clean up evidence before the certification auditor finds gaps.
3. Audit Clause 7.3 Awareness
Awareness is different from competence.
Competence is about ability.
Awareness is about understanding responsibilities and consequences.
Awareness Topics to Test
- Information Security Policy.
- Acceptable use.
- Incident reporting.
- Data handling.
- Remote work and device security.
- AI tool usage rules.
Common finding: awareness training is assigned to employees, but contractors, temporary workers, privileged users, or new hires are missed.
4. Test Awareness Through Interviews
Training completion alone does not prove awareness.
Therefore, internal audit should ask simple interview questions.
Employee Questions
- Where can you find the Information Security Policy?
- How do you report a security incident?
- What should you do after a suspicious email?
- Can you enter client data into public AI tools?
Control Owner Questions
- Which control do you own?
- What evidence do you produce?
- How often does the control operate?
- What happens if the control fails?
Practical rule: awareness is proven when people can explain what they are expected to do.
5. Audit Clause 7.4 Communication
Clause 7 requires planned communication.
The organization should know what to communicate, when, to whom, how, and by whom.
Also, important communication should be retained as evidence.
| Communication Area | Evidence to Review |
|---|---|
| Policy updates | Email, Teams post, acknowledgment, or communication log. |
| Training reminders | Reminder records, overdue lists, and follow-up actions. |
| Audit findings | Audit report, action tracker, assignment email, and owner response. |
| AI usage rules | Acceptable use guidance, policy update, or training record. |
Common finding: security messages are sent through email or Teams, but no record shows what was sent, to whom, and when.
6. Audit Clause 7.5 Documented Information
Documented information includes policies, procedures, records, forms, logs, approvals, reports, and evidence.
When this information is not controlled, audit evidence becomes unreliable.
Document Control Questions
- Is there a document register?
- Are documents approved before release?
- Are documents version-controlled?
- Are review dates defined?
- Are obsolete documents archived?
- Are draft and approved documents separated?
Practical rule: document control should make the current approved version obvious.
7. Test Policy Approval Evidence
Policy approval is a common weak point.
A current policy should have current approval evidence.
Audit Questions
- Who approves each policy?
- Is approval recorded?
- Is the current version clear?
- Are old versions archived?
- Was the policy communicated after approval?
Common finding: a policy is published as current, but approval for that exact version is missing.
8. Test Version Control
Version control is not a formatting issue.
It affects trust in evidence.
Common finding: multiple versions of the same policy are available in different folders.
9. Test External Documents
Some external documents affect the ISMS.
Therefore, they should be controlled when they influence risks, controls, obligations, or evidence.
Examples to Review
- Client security requirements.
- Contracts and vendor reports.
- Cloud shared responsibility documents.
- Insurance requirements.
- AI vendor terms and supplier policies.
Practical rule: external documents that affect the ISMS need ownership and review control.
Clause 7 Evidence Matrix
| Area | Strong Evidence | Weak Evidence |
|---|---|---|
| Resources | Resource plan and management review decisions. | Verbal support only. |
| Competence | Role requirements, training, and owner interviews. | Names assigned with no proof. |
| Awareness | Training, acknowledgments, and interview confirmation. | Training assigned but incomplete. |
| Communication | Communication matrix, emails, Teams posts, and logs. | Informal messages not retained. |
| Document Control | Document register, approvals, versions, and review dates. | Uncontrolled folders. |
Sample Clause 7 Finding
Weak Finding
Document control needs improvement.
Stronger Finding
The Information Security Policy, Access Control Procedure, and Supplier Security Procedure are stored in SharePoint. However, approved versions are mixed with draft and older versions in the same library. The document register does not identify the current approved version, approval date, owner, or next review date for all sampled documents. As a result, employees and auditors may use outdated requirements during ISMS operation and certification evidence review.
How SharePoint Can Support Clause 7
A SharePoint ISMS workspace can make Clause 7 easier to audit.
It can connect policy approvals, version history, owners, training records, communication logs, and corrective actions.
Store only approved ISMS documents.
Separate drafts from approved versions.
Track completion and overdue users.
Track what was communicated and when.
Track owners, approvers, and review dates.
Show missing approvals and overdue reviews.
Practical rule: SharePoint should help prove control, not become another uncontrolled folder system.
When Clause 7 Needs Support
Professional support may help when these problems appear:
How Canadian Cyber Helps
Canadian Cyber helps organizations audit ISO 27001 Clause 7 evidence for resources, competence, awareness, communication, and documented information.
We help teams move from scattered training records and uncontrolled folders to clear, audit-ready evidence.
Our support includes competence evidence review, awareness evidence review, policy acknowledgment review, communication matrix development, document control review, SharePoint ISMS library setup, version control cleanup, evidence owner mapping, corrective action tracking, and certification readiness reporting.
Senior Advisory Support
Canadian Cyber also provides senior advisory support for ISO 27001 internal audits, Clause 7 reviews, SharePoint ISMS dashboards, corrective action tracking, management review preparation, and vCISO guidance.
Frequently Asked Questions
What is ISO 27001 Clause 7?
ISO 27001 Clause 7 covers support for the ISMS. It includes resources, competence, awareness, communication, and documented information.
What evidence is needed for Clause 7?
Evidence may include training records, competence matrices, role descriptions, policy acknowledgments, communication logs, document registers, approval workflows, version history, review dates, and controlled evidence libraries.
What is the difference between competence and awareness?
Competence means a person can perform a specific ISMS role. Awareness means employees understand security expectations, responsibilities, policies, and consequences.
What is a common Clause 7 finding?
A common finding is that policies exist but are not version-controlled, approved, reviewed, communicated, or separated from obsolete drafts.
Can SharePoint help manage Clause 7 evidence?
Yes. SharePoint can manage policy approvals, version history, document registers, training evidence, policy acknowledgments, communications, corrective actions, and readiness dashboards.
Can Canadian Cyber help audit ISO 27001 Clause 7?
Yes. Canadian Cyber helps organizations audit Clause 7, review competence and awareness evidence, improve document control, build SharePoint ISMS libraries, and prepare for certification readiness.
Takeaway
Clause 7 is not just about training.
It is about support.
A strong audit should test resources, competence, awareness, communication, document control, records, and evidence ownership.
When Clause 7 is strong, the ISMS is easier to operate. When Clause 7 is weak, the organization may have policies but no proof that people know them, use them, or work from the correct versions.
Make ISO 27001 Clause 7 Audit-Ready
Canadian Cyber can help your organization review Clause 7 competence, awareness, communication, and document control evidence before internal audit or certification audit.
We support ISO 27001 internal audits, training evidence reviews, competence assessments, communication matrices, document control reviews, SharePoint ISMS dashboards, corrective action tracking, management review preparation, vCISO support, SOC 2 readiness, ISO 42001, ISO 27017, ISO 27018, and cybersecurity assessments.
Stay Connected With Canadian Cyber
Follow Canadian Cyber for practical guidance on ISO 27001 internal audits, Clause 7, competence, awareness, communication, document control, certification readiness, SharePoint ISMS, SOC 2 readiness, AI governance, and vCISO services.
