TL;DR: ISO 27001 audits depend on documented controls, repeatable evidence, and independent review, and StrongDM’s guide shows why stage 1 design review, stage 2 field testing, surveillance audits, and recertification all hinge on proving controls work in practice, not just on paper. For IAM teams, the lesson is that auditability becomes an operational requirement across human, NHI, and privileged access programmes.
At a glance
What this is: StrongDM’s audit guide argues that ISO 27001 readiness depends on demonstrating operating controls with evidence, not just documenting policies.
Why it matters: This matters because IAM and PAM teams have to prove access governance in practice, including for NHI and privileged access flows, or audit findings will expose a control gap.
Context
ISO 27001 audits are evidence exercises, not paperwork reviews. The core problem is the gap between documented controls and what auditors can actually verify in the field, especially where privileged access spans many systems, teams, and identity types.
For IAM, PAM, and NHI programmes, that means the question is not whether a control exists on paper. The question is whether the organisation can produce repeatable evidence that access, review, and remediation processes operate consistently enough to satisfy stage 1, stage 2, surveillance, and recertification demands.
Key questions
Q: What breaks when ISO 27001 user access reviews do not produce audit evidence?
A: The review stops being defensible. Auditors need to see who reviewed access, what changed, when it changed, and why the decision was made. If that trail is missing, the organisation may have performed the task but cannot prove control, which is enough to create certification and governance risk.
Q: Why does access governance matter during ISO 27001 audits?
A: Access governance matters because auditors are testing whether privilege decisions are documented, justified, and still accurate when the environment changes. If entitlements, exceptions, or supplier access are not traceable, the organisation may have controls on paper but not in practice. The result is weaker evidence for certification and a higher chance of remediation findings.
Q: What are the signs that audit evidence for access controls is weak?
A: Common signs include inconsistent logs, missing review artefacts, unclear control ownership, remediation records that stop at the last audit, and teams that assemble evidence manually only when a review is due. Those symptoms usually indicate that the control exists on paper but has not been turned into a repeatable operating process.
Q: How should security teams prepare privileged access evidence for ISO 27001 audits?
A: Security teams should ensure privileged access decisions, session logs, approvals, and remediation records are centralized and tied to named control owners. Auditors want a clean chain from policy to execution, so fragmented evidence creates avoidable friction. The best preparation is to test the audit trail before external review and fix ownership gaps early.
Technical breakdown
Stage 1 design review and the evidence baseline
Stage 1 in ISO 27001 is the ISMS design review, where auditors check whether the documented scope, policies, risk treatment, and Statement of Applicability are complete and internally consistent. The auditor is not yet proving that every control works in live production, but they are testing whether the control design is specific enough to be audited later. That makes the documentation baseline critical: if policies, procedures, and control ownership are vague, stage 2 has nothing stable to verify. In identity programmes, this is where access governance, logging, and review responsibilities must be written clearly enough to survive sampling.
Practical implication: lock down the written control design before asking auditors to test operational evidence.
Stage 2 field review and control effectiveness
Stage 2 is where the audit shifts from design to operating reality. Auditors sample records, interview stakeholders, and compare actual evidence with the approved procedures from stage 1. In privileged access environments, that means session records, query logs, command history, remediation proof, and prior audit responses have to line up with documented process. A control that exists but cannot be evidenced consistently will fail here, even if teams believe it is functioning. For NHI and PAM programmes, stage 2 exposes whether governance is happening continuously or only when an audit is imminent.
Practical implication: maintain field-ready evidence for privileged access, not just policy documents and screenshots.
Surveillance audits and recertification as lifecycle proof
ISO 27001 does not end at certification. Surveillance audits and the three-year recertification cycle test whether the ISMS remains effective as the organisation changes. That creates a lifecycle requirement: controls must keep producing evidence after the initial audit, not just during the certification sprint. For identity teams, this is the point where access reviews, log retention, control ownership, and remediation tracking become recurring governance functions rather than one-time projects. The audit model therefore measures operational continuity, not static compliance. Organisations that treat certification as a finish line usually discover their evidence quality degrades before the next audit window.
Practical implication: treat evidence generation as a recurring control process across the full certification lifecycle.
NHI Mgmt Group analysis
Auditability is the control, not a by-product of the control. ISO 27001 turns evidence into an operational requirement because auditors do not certify intent, they certify demonstrated practice. That changes how identity and access programmes should be run: logs, approvals, session records, and review artefacts must be designed as primary control outputs. The practitioner conclusion is simple: if a privileged access control cannot produce reliable evidence, it is not audit-ready.
Privileged access creates an evidence gap when teams cannot reconstruct who did what, when, and under which approval. The article’s emphasis on centralized logs is really about reconstructability, not convenience. In PAM and NHI contexts, access often spans ephemeral sessions, multiple systems, and high-risk commands, so the audit problem is whether the organisation can prove control operation at the level of individual activity. The practitioner conclusion is that evidence architecture belongs inside the access model itself.
Stage 1 and stage 2 expose different governance failures, and teams often confuse them. Stage 1 failures are usually design failures: unclear scope, incomplete documentation, weak accountability, or missing risk treatment. Stage 2 failures are execution failures: controls that were written down but not actually followed or recorded. The named concept here is the evidence gap, which is the distance between a stated control and a verifiable control. The practitioner conclusion is to separate design assurance from operating assurance.
Surveillance and recertification make audit readiness a lifecycle problem, not a certification event. The article shows that ongoing compliance depends on continuous internal audit cadence, not one-off preparation before the external visit. That matters across human IAM, NHI governance, and privileged access because the evidence burden resets as environments change. Organisations that do not govern evidence retention, review cycles, and remediation closure as lifecycle activities will accumulate audit debt. The practitioner conclusion is to manage evidence as a governed asset.
ISO 27001 rewards programmes that can prove repeatability under sampling conditions. The audit model is built around random field review, stakeholder interviews, and evidence from prior remediations, which means fragile or manual processes are easy to expose. In practice, this favours identity programmes that centralise logging, preserve review trails, and make control ownership explicit across teams. The practitioner conclusion is that repeatable evidence generation is now part of identity governance maturity, not a separate compliance exercise.
What this signals
Evidence gap: ISO 27001 audits expose the gap between having a documented control and being able to prove it operated in the field. For privileged access programmes, that means evidence design must sit alongside access design, because auditors will sample what actually happened, not what the policy promised.
Audit readiness becomes a lifecycle discipline when surveillance and recertification are part of the certification model. Teams that only prepare evidence at the point of review end up with brittle controls, weak remediation traceability, and a compliance posture that degrades between audits.
For practitioners
- Document control ownership for every privileged access process Map who owns approvals, session logging, review, remediation, and audit evidence for each privileged access workflow so stage 1 documentation matches real operating responsibility.
- Centralize audit evidence for sessions and commands Keep session records, queries, commands, and remediation artefacts in one evidence source so auditors can sample operating controls without chasing records across teams.
- Separate design evidence from operating evidence Use one evidence set for policies, scope, risk treatment, and control descriptions, then maintain a second set that proves those controls worked during production use.
- Run surveillance-ready internal audits on a fixed cadence Treat internal audits as recurring checks that validate whether logs, approvals, and remediations are still current before the external surveillance review arrives.
- Retain remediation proof through recertification Preserve evidence of findings, corrective actions, and closure decisions for the full certification cycle so the three-year recertification audit can trace continuous improvement.
Key takeaways
- ISO 27001 certification depends on proving that privileged access controls work in practice, not just showing that they are documented.
- The audit model rewards repeatable evidence across design review, field testing, surveillance, and recertification, which turns auditability into an operating requirement.
- IAM, PAM, and NHI teams should manage logs, reviews, and remediation proof as governed assets if they want to survive external scrutiny.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, CIS Controls v8 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| ISO/IEC 27001:2022 | A.5.37 — Documented Operating Procedures | The article centres on documenting and proving ISMS procedures during audit. |
| A.5.36 — Compliance with Policies, Rules and Standards for Information Security | The guide is about maintaining ongoing conformity with ISO 27001 requirements. | |
| Recommendation — Document and maintain operating procedures so auditors can verify control execution during review. Map privileged access evidence to the policies and standards your ISMS claims to follow. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | Privileged access evidence depends on proving entitlements and authorizations are controlled. |
| Recommendation — Verify that access permissions and authorizations are evidenced, reviewed, and traceable. | ||
| CIS Controls v8 | CIS-5 — Account Management | Audit evidence for privileged access is inseparable from account and access lifecycle governance. |
| Recommendation — Track account lifecycle records and retain proof of approvals, reviews, and removals. | ||
| NIST SP 800-53 Rev 5 | AU-6 — Audit Record Review, Analysis, and Reporting | The article depends on logs and evidence that can be reviewed during audits. |
| Recommendation — Review audit records regularly and retain analysis that shows controls worked as intended. | ||
Key terms
- Evidence Gap: The difference between having a control in policy and being able to prove it was applied in practice. In identity programmes, evidence gaps appear when access changes, reviews, and revocations must be reconstructed from emails, screenshots, or spreadsheets rather than generated continuously.
- Stage 1 Audit: The initial ISO 27001 review of documentation, scope, risk treatment, and control design before field testing begins. It checks whether the ISMS is defined clearly enough for later verification, which is especially important when access governance spans multiple teams and systems.
- Stage 2 Audit: Stage 2 is the evidential audit where the organisation must prove its documented controls are actually operating. Auditors sample records, interview stakeholders, and compare live evidence with the approved design, making this the decisive test of operational compliance.
- Surveillance Audit: A surveillance audit is a recurring review used to confirm that certification controls remain effective between renewal cycles. It is not a one-time checklist. Organisations must show continued control operation, corrective action, and evidence quality, or they risk non-conformance and loss of certification.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org