ISO 27001 maintenance without hiring a full-time GRC manager
Most small and mid-size organisations cannot justify a full-time GRC hire. A well-designed monthly and quarterly rhythm keeps your ISMS alive between audit cycles without the overhead.
By Kellwick Team · September 23, 2026 · 6 min read
A question that comes up repeatedly after certification is how to keep the ISMS running when there is no dedicated GRC function. The person who led the certification project has gone back to their day job. The consultants have left. The auditors have stamped the certificate. And in three to twelve months, a surveillance auditor will arrive and expect to see evidence that the ISMS has been operating continuously.
The good news is that an ISO 27001 ISMS does not require a full-time GRC manager to stay alive. It requires a structured rhythm and clear ownership distributed across a small group of people. This article describes a monthly and quarterly calendar that works for organisations with ten to two hundred employees and a scope that covers the core business.
The core principle: spread ownership, not load
The mistake many organisations make after certification is assuming that "whoever owned the project" must own ongoing maintenance. This person - often a technical lead, a head of IT, or a quality manager - becomes the single point of failure. When they leave, the ISMS often drifts within months.
A more resilient model distributes ownership of specific controls and records across the people who actually operate them. The security awareness training programme is owned by whoever runs HR onboarding. The backup test records are owned by whoever runs infrastructure. The supplier register is owned by whoever manages procurement. The ISMS coordinator role then becomes one of scheduling reviews, collecting evidence, and running the management review process - not doing everything themselves.
Across a team of three to five people with partial ISMS responsibilities, the total monthly overhead per person rarely exceeds one to two hours when the rhythm is well-designed.
The monthly checklist
Monthly activities should be short, specific, and tied to people who already own the underlying operational processes.
Access and accounts review (IT owner, approximately 30 minutes): Review the joiners, movers, and leavers log for the past month. Confirm that access was granted, modified, or revoked in line with role changes. Check for any stale accounts - people who left but whose accounts have not been disabled. Log the review with the date and reviewer name. This does not need to be exhaustive; it needs to be dated, evidenced, and recurring.
Patch and vulnerability status (IT owner, approximately 20 minutes): Note the current patching status against the agreed patching SLA. Flag any overdue critical patches and confirm that they have a tracked remediation. This is not a patch management project; it is a quick evidence check that the patching process is operating.
Incident log review (ISMS coordinator, approximately 15 minutes): Check the incident register. Were any incidents logged since the last review? Were they classified, investigated, and closed, or are any still open? Are there trends worth noting for the management review? Even if there are no incidents, the review should be logged - "no incidents recorded this month" is evidence that the log is being monitored.
Supplier register check (procurement or operations owner, quarterly flag): Once per quarter (flag this in the monthly review), confirm that no new in-scope suppliers have been onboarded without an information security assessment. Add any new suppliers and note their assessment status.
The quarterly deep-check
Quarterly reviews are where you look across a broader evidence horizon and catch drift before it accumulates into something an auditor would flag.
Risk register review (ISMS coordinator plus risk owners, 60-90 minutes): Review the risk register for relevance. Have any new risks emerged - new systems, new threats, changes to the regulatory environment, or incidents that suggest a gap? Have any existing risks changed in likelihood or impact? Record who reviewed the register and what conclusions were reached, even if no material changes were made. The dated record is the evidence.
Internal control spot-checks (rotated across control areas, 60 minutes): Pick three to five controls from the SoA each quarter and test whether the evidence of their operation is current. For example: is the business continuity plan still the right version and has it been tested? Are the backup test records from the past three months available? Did the last phishing simulation run on schedule? Rotate the control areas across quarters so that the full SoA is covered over the year. Document the check and any gaps found.
Training completion check (HR or ISMS coordinator, 20 minutes): Run a completion report for security awareness training. Identify anyone who has not completed training and set a chase deadline. Flag the completion rate to the management review. Training completions are one of the most commonly sampled evidence items in surveillance audits, and a single missing record for a key employee will be noted.
Document review log (ISMS coordinator, 20 minutes): Check whether any ISMS documents - policies, procedures, the scope statement - have a review date that is approaching or past. Assign reviews to named owners with a deadline. A policy that says "last reviewed 2024" in a 2026 surveillance audit is a flag, even if the content is still appropriate.
The annual calendar anchors
Beyond monthly and quarterly activities, two annual events anchor the ISMS and are required by the standard.
Internal audit: Plan, conduct, and document an internal audit of the ISMS against the requirements of ISO 27001. This can be conducted by a competent person who is independent of the areas being audited - which in smaller organisations often means using a cross-functional team or engaging an external advisor to support the audit. The output must include findings, any nonconformities raised, and a corrective action log.
Management review: Bring the ISMS inputs together - the results of the internal audit, the risk register review status, incident trends, training completion data, performance metrics, corrective action status, and any changes to the external and internal context - and produce a formal management review record. This is not a long meeting. In many organisations it is a one-hour session attended by the relevant owners, producing a documented output with actions and owners. The documented output is what the auditor will read; the meeting quality matters less than the record quality.
A simple annual calendar structure
A practical way to organise the above:
- January, April, July, October: Monthly checks plus quarterly deep-check.
- February, March, May, June, August, September, November: Monthly checks only.
- October or November: Internal audit (timed to allow actions to be closed before the annual management review).
- December: Annual management review, using the internal audit output and full year's data as inputs.
- Month before surveillance audit: Evidence collection check - pull everything an auditor is likely to sample and verify it is complete and accessible.
This structure means that by the time a surveillance auditor arrives, you have twelve months of documented monthly reviews, four quarterly deep-checks, an internal audit, and a management review on record. That is the evidence trail they are looking for.
What to avoid
The most common failure modes for small-team ISMS maintenance:
- Batching everything before the audit. Doing three months of "monthly" access reviews in the week before the surveillance visit is obvious and will be noted.
- Evidence that only one person can find. If the backup test records live in one engineer's inbox and they are on holiday when the auditor asks, you have an avoidable problem.
- Review records that are undated or unsigned. A dated, named record is evidence. An undated spreadsheet row is not.
- Skipping the incident log in quiet periods. "We had no incidents" needs to be recorded. An empty, unreviewed log looks like an abandoned process.
Where Kellwick fits
If you would like help designing a maintenance calendar that fits your team structure, or want an independent check that your rhythm is producing audit-quality evidence, Kellwick provides ongoing advisory support tailored to smaller teams. See /ongoing-support for how we work with organisations to keep their ISMS audit-ready between certification cycles without the overhead of a full-time GRC hire.
Where this fits
ISO 27001
Pass the audit. We find what blocks Stage 1 before the certification body does.
Read the ISO 27001 hubNeed a second pair of eyes before the auditor does?
A readiness review shows exactly where your ISMS stands - and what to fix first - while there is still time to act on it.
Stay audit-ready
Occasional, practical notes on ISO 27001 readiness and ISMS maintenance. No noise.