ISO 27001
Internal Audit
Documentation Review

Internal Audit Documentation Review: What to Check Before Starting Fieldwork

Prepare for ISO 27001 internal audit fieldwork by reviewing scope, policies, risks, SoA, evidence owners, access reviews, vendors, incidents, corrective actions, and SharePoint evidence readiness first.

Quick Answer

What is an ISO 27001 internal audit documentation review?

An ISO 27001 internal audit documentation review is the pre-fieldwork check of key ISMS documents and evidence.

The auditor reviews scope, policies, approvals, risk register, Statement of Applicability, access reviews, vendor files, incidents, management review, and corrective actions before interviews begin.

The goal is simple: confirm what exists, what is missing, what needs testing, and who should be interviewed during fieldwork.

Do Not Start Fieldwork in Confusion

Internal audit fieldwork should not begin with a document chase.

Before interviews start, the auditor should review the core documentation.

This step is often skipped.

That creates delays.

It also creates findings that could have been fixed earlier.

Practical rule: documentation review should tell the auditor where fieldwork should focus.

The Main Pre-Fieldwork Question

The strongest question is not only, “Do we have documents?”

The stronger question is:

Are the documents current, approved, mapped, owned, evidenced, and ready to be tested?

Quick Documentation Review Snapshot

Documentation Area What to Check Before Fieldwork
ISMS Scope Is the scope current, approved, and aligned with operations?
Policies Are policies approved, version-controlled, reviewed, and published?
Risk Register Are risks current, owned, rated, and linked to treatment?
Statement of Applicability Are applicable controls justified, mapped, and evidenced?
Access Reviews Are reviews complete, signed off, and linked to removals?
Corrective Actions Are findings assigned, evidenced, verified, and tracked?

Documentation Review vs Fieldwork

Documentation review and fieldwork are connected.

However, they are not the same step.

Stage Main Purpose Output
Documentation Review Understand what exists before testing. Gap list, interview plan, and sampling focus.
Fieldwork Test whether controls are operating. Validated evidence, findings, and observations.
Reporting Communicate audit results. Internal audit report.

1. Review the ISMS Scope

Start with the ISMS scope.

If scope is unclear, the whole audit becomes unclear.

What to Check

  • Is the ISMS scope documented and approved?
  • Does it include the right business units?
  • Does it include cloud services and remote work?
  • Does it include vendors where relevant?
  • Does it include AI tools where relevant?

Fieldwork impact: if the scope is outdated, the auditor may interview the wrong teams or miss important systems.

2. Review Policies and Document Control

Policies are foundational.

But they must be approved, controlled, reviewed, and published.

Policy inventory.
Document register.
Approved policy library.
Version history.
Review tracker.
Policy owner matrix.

Common gap: policies exist, but approval evidence, version control, or review dates are missing.

3. Review the Risk Register

The risk register explains what the organization considers important.

It should reflect the current business, not last year’s audit preparation.

Risk Register Check Why It Matters
Risk owners assigned. Risks need accountability.
Treatments documented. The audit should see planned action.
Accepted risks approved. Leadership should approve acceptance.
Cloud, vendor, and AI risks included. The register should match current operations.

4. Review the Statement of Applicability

The Statement of Applicability should not be treated as a static compliance file.

Use it as an audit map.

What to Check

  • Is the SoA current?
  • Are applicable controls justified?
  • Are non-applicable controls justified?
  • Is each applicable control linked to evidence?
  • Does the SoA match the risk treatment plan?

Need a Pre-Fieldwork Documentation Review?

Canadian Cyber helps organizations review documentation, map evidence, check policy approvals, validate the SoA, and prepare SharePoint ISMS evidence before interviews begin.

A strong documentation review makes fieldwork faster, clearer, and more useful.

5. Review the Evidence Matrix

The evidence matrix shows whether each requirement has proof.

Before fieldwork, use it to identify gaps and testing priorities.

Clauses mapped to evidence.
Annex A controls mapped to evidence.
Control owners listed.
Evidence owners listed.
Evidence links working.
Missing items flagged.

6. Review Access Review Documentation

Access review evidence is often tested during fieldwork.

Review the documents before interviewing IT.

Evidence to Review

  • User access reviews.
  • Privileged access reviews.
  • MFA reports.
  • Offboarding tickets.
  • Vendor access reviews.
  • Access removal evidence.

Practical rule: an access export is not the same as an access review.

7. Review Vendor and Supplier Records

Vendor evidence should prove review and oversight.

It should not only prove that documents were collected.

Vendor Record What to Confirm
Vendor register. Is it current and complete?
Risk assessments. Are vendors risk-rated?
Contracts and DPAs. Are obligations stored and reviewed?
Security reports. Are review conclusions documented?

8. Review Incident, Backup, and Log Evidence

Incident response, backup, restore, logging, and monitoring evidence should be reviewed before technical interviews.

These areas often reveal readiness gaps.

Incident Response
Review incident register, tabletop reports, lessons learned, and action items.
Backup and Restore
Review backup reports, restore tests, RTO/RPO records, and failure tickets.
Logging and Monitoring
Review log sources, alerts, admin actions, triage tickets, and retention settings.

Practical rule: backups show data is copied. Restore tests show the organization can recover.

9. Review HR, Training, and Awareness Records

HR documentation supports people-related controls.

It should connect directly to access control and awareness.

Onboarding checklist.
Offboarding checklist.
Training completion report.
Policy acknowledgment report.
Role change records.
Contractor records.

10. Review Management Review and Corrective Actions

Management review and corrective actions show whether the ISMS is improving.

They should show decisions, owners, evidence, and verification.

Area What to Review
Management Review Agenda, minutes, risk decisions, objectives, resources, and action items.
Corrective Actions Owner, root cause, due date, closure evidence, verification, and repeat findings.

Practical rule: a corrective action is not closed until evidence is verified.

Pre-Fieldwork Documentation Review Checklist

  • ISMS scope is current and approved.
  • Policies are approved and version-controlled.
  • Policy review dates are tracked.
  • Risk register is current.
  • Risk owners are assigned.
  • Statement of Applicability is updated.
  • Evidence is mapped to controls.
  • Access reviews have sign-off.
  • Vendor reviews have conclusions.
  • Incidents and tabletop exercises are documented.
  • Backup restore testing is evidenced.
  • Corrective actions include closure evidence.
  • Management review includes decisions and action items.

Documentation Quality Red Flags

Red flags during documentation review should become fieldwork priorities.

Documents marked “final” but not approved.
Multiple versions with no current version identified.
Policies with no owner.
SoA not linked to evidence.
Vendor reports with no review notes.
Corrective actions closed without proof.

SharePoint Documentation Review for ISO 27001

Many organizations store ISO 27001 evidence in SharePoint.

That works well when the structure is controlled.

Evidence Missing Owner
Find items with no accountable person.
Evidence Due for Review
Find outdated records before fieldwork.
High-Risk Controls Missing Evidence
Focus fieldwork on real risk.
Corrective Actions Pending Verification
Track closure before reporting.

Practical rule: SharePoint should help the audit team see readiness, not force them to search through folders.

Senior Advisory Support

Canadian Cyber also provides senior advisory support for ISO 27001 documentation review, internal audit readiness, SharePoint ISMS dashboards, corrective action tracking, management review reporting, and vCISO guidance.

For senior cybersecurity, ISO 27001, audit readiness, and vCISO advisory support, you can review Waqar Mehboob’s profile.

View Waqar Mehboob’s Profile

How Canadian Cyber Helps

Canadian Cyber helps organizations review ISO 27001 documentation before internal audit fieldwork begins.

We help teams organize evidence, identify gaps, map controls, prepare interviews, and reduce audit delays.

ISO 27001 documentation review.
Pre-fieldwork readiness assessment.
ISMS scope review.
Policy approval evidence review.
Risk register and SoA review.
Evidence matrix development.
SharePoint ISMS evidence review.
Fieldwork planning.

Frequently Asked Questions

What is an internal audit documentation review?

An internal audit documentation review is the pre-fieldwork review of policies, registers, evidence records, approvals, risks, controls, findings, and management records before interviews and testing begin.

Why should documentation be reviewed before fieldwork?

Documentation review helps the auditor understand the ISMS, identify gaps, plan interviews, select samples, and focus fieldwork on higher-risk areas.

What documents should be reviewed before ISO 27001 fieldwork?

Key documents include ISMS scope, policies, risk register, risk treatment plan, Statement of Applicability, evidence matrix, access reviews, vendor records, incident records, training records, management review minutes, and corrective action tracker.

Is documentation review the same as fieldwork?

No. Documentation review checks readiness and identifies areas to test. Fieldwork validates whether controls are operating through interviews, sampling, and evidence testing.

Can SharePoint help with documentation review?

Yes. SharePoint can organize policies, evidence, owners, review dates, control mappings, findings, corrective actions, and dashboards when configured properly.

Can Canadian Cyber help before fieldwork starts?

Yes. Canadian Cyber helps organizations perform ISO 27001 documentation reviews, organize evidence, map controls, prepare fieldwork plans, and build SharePoint ISMS dashboards before fieldwork begins.

Takeaway

Internal audit fieldwork should not begin in confusion.

Before interviews, samples, and testing, the auditor should review the documentation.

A good review shows what is current, what is missing, what is weak, and what needs deeper testing.

Review the documents first. Then fieldwork becomes clearer, faster, and more useful.

Prepare Your ISO 27001 Documentation Before Fieldwork

Canadian Cyber can help you review documentation before internal audit fieldwork begins.

We support ISO 27001 documentation reviews, SharePoint ISMS readiness checks, risk register reviews, SoA reviews, policy approval evidence reviews, corrective action tracker reviews, vCISO services, SOC 2 readiness, ISO 42001, ISO 27017, ISO 27018, and cybersecurity assessments.

Stay Connected With Canadian Cyber

Follow Canadian Cyber for practical guidance on ISO 27001 internal audits, documentation review, certification readiness, SharePoint ISMS, corrective actions, SOC 2 readiness, AI governance, and vCISO services.