Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What are the signs that ISO 27001:2022 controls…
Governance, Ownership & Risk

What are the signs that ISO 27001:2022 controls are being implemented superficially rather than effectively?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 26, 2026 Domain: Governance, Ownership & Risk

Common warning signs include undocumented cloud security requirements, inconsistent branch approvals, ad hoc monitoring alerts that nobody owns, and readiness testing that exists only on paper. Another signal is when teams can describe the control in audit language but cannot show current evidence. Effective controls leave a repeatable trail of implementation, review, and response across the technology stack.

How superficial ISO 27001:2022 implementation shows up in practice

Superficial implementation usually looks complete in audit packs but thin in operations. The control exists as a policy statement, spreadsheet entry, or ticket template, yet there is no consistent evidence that people, systems, and exceptions are being handled the same way every time. The gap is usually visible in ownership, records, and follow-through rather than in the wording of the control itself.

One of the clearest signs is that teams can recite the control language but cannot show the current state of implementation. That often means the organisation has documented intent, but not embedded the control into routine work, monitoring, or exception handling.

Where effective ISO 27001 controls leave a trace

Effective controls produce repeatable evidence across the full lifecycle: who approved it, how it was applied, what changed, when it was reviewed, and how issues were closed. If the evidence trail only appears during certification preparation, the control is likely serving the audit rather than the business.

That trail should also be consistent across environments and teams. If one branch, product group, or cloud platform follows a different process without a documented reason, the control is probably being interpreted locally rather than managed centrally.

For cloud and platform controls in particular, superficial implementation often shows up as undocumented requirements, inherited defaults, or a mismatch between policy and actual configuration. ISO/IEC 27001:2022 expects the ISMS to be operational, so a control that cannot be demonstrated in configuration, logging, review, or response is not mature enough to be trusted.

Signs the control is only paper-deep

  • Approvals are inconsistent, delayed, or reversible without clear criteria.
  • Monitoring exists, but alerts do not have an owner, a response path, or a closure record.
  • Testing is scheduled, but the results are not used to correct the control.
  • Control descriptions are detailed, yet staff cannot show current evidence from live systems.
  • Exceptions are frequent, but there is no trend analysis or root-cause follow-up.
  • The control passes audit review, but the underlying process still depends on manual memory or one-off effort.

These are not just documentation problems. They usually indicate that implementation is not embedded in normal operations, which means the control may fail exactly when the organisation needs it most.

Risk and Threat Considerations

Superficial controls create false assurance. The organisation may believe it has reduced exposure, while the real process remains inconsistent, unmonitored, or easy to bypass, especially where approvals, logging, or exception handling are loosely owned.

Failure mechanism: The control is written into policy or audit evidence, but not enforced in day-to-day workflows, so exceptions, misconfigurations, and weak approvals persist unnoticed until an incident or assessment exposes them.

Impact: This can lead to control failure, audit findings, slow incident response, and a larger blast radius when the control is needed to prevent or contain a security event.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
ISO/IEC 27001:2022A.5.37 — Documented operating proceduresSuperficial controls often lack operating discipline and repeatable execution evidence.
A.5.36 — Compliance with policies, rules and standards for information securityThe question is about whether controls are actually followed, not merely written down.
A.5.35 — Independent review of information securityIndependent review helps detect controls that exist on paper but fail in practice.
Recommendation — Require live operating records that show the control is executed consistently, not just documented. Verify that implementation evidence matches policy requirements and current operating practice. Use independent review to test whether the control works as designed in real operations.
NIST CSF 2.0GV.OV-01 — Oversight of cybersecurity risk management strategy is established and implementedSuperficial controls signal weak oversight over whether risk treatments are actually working.
Recommendation — Check that oversight routines verify control operation, not just control documentation.

Practitioner Guidance

What to verify: Ask for a live example, not a policy excerpt. A well-implemented control should be traceable from requirement to approval, execution, monitoring, and closure in current operational records.

What to measure: Look for repeatability, not just presence. If the same control produces different results across teams or environments, the implementation is probably inconsistent even if the documentation is polished.

Common mistake: Treating audit readiness as proof of control effectiveness. A control that can be described well but not demonstrated in live evidence should be treated as immature until proven otherwise.

Practitioner takeaway: The real test is whether the control changes operational behaviour in a measurable, repeatable way, not whether it reads well in a policy or audit file.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 26, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org