Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What are the signs that an ISO-based information…
Governance, Ownership & Risk

What are the signs that an ISO-based information security programme is not working well?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 27, 2026 Domain: Governance, Ownership & Risk

A weak programme usually shows up as inconsistent controls, unclear ownership, and security work that happens only after incidents. If risk assessments are irregular, policies are not enforced, and incident response is ad hoc, the ISMS is not operating as intended. Another warning sign is when controls exist on paper but do not change day-to-day behaviour.

How to tell when ISO controls exist on paper but are not operating as a real management system

An ISO-based information security programme is failing when it produces documents, not control. The clearest signs are uneven implementation, weak accountability, and evidence that decisions are being made case by case rather than through a repeatable system. In practice, the programme stops shaping behaviour, so the organisation cannot show that risk is being managed consistently.

A healthy ISMS turns policy into routine action. When that link breaks, the programme becomes reactive, audit-driven, or dependent on a few individuals who know the process informally. That is why the most useful signal is not whether policies exist, but whether they are followed, reviewed, and improved in a way that changes how teams actually work.

What operational symptoms usually show the ISMS is weak?

The most common symptom is inconsistency. One team applies access reviews, incident handling, or change approval carefully, while another treats the same control as optional. Another warning sign is unclear ownership: if no one can say who approves exceptions, who tracks remediation, or who challenges overdue actions, the programme is already losing control of its own obligations.

Weak programmes also show poor feedback loops. Risk assessments are completed irregularly, control exceptions linger without expiry, and lessons from incidents do not feed back into the control set. When security activity spikes only after an audit, a breach, or a customer complaint, the programme is functioning as a response mechanism, not as a management system.

For an ISMS, ISO/IEC 27001:2022 Information Security Management is strongest when the organisation can demonstrate that controls are embedded into normal operations rather than maintained as a compliance artefact. Companion guidance in ISO/IEC 27002:2022 Information Security Controls helps because it translates the management intent into implementable control behaviour.

Why does “paper compliance” matter to security outcomes?

Paper compliance matters because it creates false confidence. If controls only exist in the policy set, the organisation may believe it has reduced risk when the actual attack surface has not changed. That gap is especially damaging in access control, incident response, supplier oversight, and corrective action tracking, where a procedure that is not exercised is effectively absent.

The practical failure mode is drift. Teams keep referencing the standard while actual behaviour moves away from it, often through shortcuts, exceptions, or undocumented workarounds. Over time, the ISMS no longer provides a reliable picture of control effectiveness, so management cannot make informed decisions about risk acceptance, prioritisation, or remediation.

This is where implementation guidance becomes valuable: ISO/IEC 27002:2022 Information Security Controls is useful not because it adds paperwork, but because it helps leaders and control owners test whether the control is actually being operated. If the answer is “only when someone remembers,” the system is weak even if the audit file looks complete.

Risk and Threat Considerations

A weak ISO-based programme creates exposure because attackers and operational failures benefit from the same gaps: inconsistent enforcement, slow remediation, and controls that are easy to bypass in exceptional cases. If the organisation cannot prove that controls are monitored and corrected, then hidden exceptions can become persistent entry points or recurring failure patterns.

Failure mechanism: The ISMS loses its control loop, so exceptions, incidents, and nonconformities are not reliably corrected, and the same weakness keeps reappearing in operations.

Impact: Risk accumulates silently, audit evidence stops reflecting reality, and the organisation may discover that its apparent compliance posture does not match its real security posture.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

ISO/IEC 27001:2022 provides the primary governance reference for this topic.

FrameworkControl / ReferenceRelevance
ISO/IEC 27001:2022A.5.15 — Access controlWeak ISMS programmes often fail first in access enforcement and exception handling.
A.5.35 — Independent review of information securityProgramme weakness is often exposed when review findings do not change operations.
A.5.36 — Compliance with policies, rules and standards for information securityA failing programme shows policies on paper but inconsistent operational adherence.
Recommendation — Verify that access rules are enforced consistently and reviewed as part of the ISMS. Use independent review evidence to test whether security controls are actually operating. Measure whether teams comply with security policies in daily work, not just during audits.

Practitioner Guidance

What to verify: Check whether the same control failure shows up in multiple places, because repeated exceptions, overdue actions, or manual workarounds are stronger evidence of a failing ISMS than a single missed task. Verify that ownership, escalation, and review cadence are explicit enough that a control can survive staff turnover.

What good looks like: A functioning programme shows consistent execution, documented exception handling with expiry, and evidence that incidents or audit findings lead to sustained control changes. If teams can describe the control but cannot produce operational proof that it is used, the programme is not yet mature.

Practitioner takeaway: Treat the ISMS as a living operating model, not a document set, and judge it by whether it changes day-to-day behaviour, not by whether the latest policy pack looks complete.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 27, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org