Audit day: how to order your ISO 27001 evidence so Stage 2 goes fast
A disorganised evidence folder slows Stage 2 down and signals weak governance. Learn how to build an evidence index the auditor can follow, sequenced by clause and control.
By Kellwick Team · September 2, 2026 · 5 min read
Stage 2 audit day is not the moment to be searching for files. An auditor who has to wait while the auditee hunts through folders, Slack threads, and email archives is an auditor who is noting that the organisation does not have a firm grip on its own evidence. That impression colours the rest of the day - even if every control is genuinely in place.
Ordering evidence well before Stage 2 is not administrative box-ticking. It is a demonstration of the kind of organised, managed approach that ISO 27001 is actually asking for.
Why ordering matters independently of content
ISO 27001 auditors are assessing two things simultaneously: whether the controls exist and are operating, and whether the management system is being actively managed. An evidence folder that requires forty-five minutes of explanation to navigate suggests the second part is weak.
Conversely, an organisation that hands the auditor a structured index, where every document reference corresponds to a clearly labelled file and every control has one named location, is showing - through the evidence itself - that the ISMS is under control. It is not about impressing the auditor. It is about letting them do their job efficiently, which means they spend time assessing substance rather than logistics.
Disorganised evidence also increases the risk that relevant records get missed. If the access review results are in three different places and the auditor only sees one of them, the evidence appears weaker than it is.
The structure: clause-first, then control
The most practical ordering for Stage 2 evidence follows the ISO 27001 structure itself: main clauses first, then Annex A controls. This matches the order in which an auditor is likely to work through your ISMS.
A practical top-level index structure:
Section 1: ISMS scope and context
- Scope statement (clause 4.3)
- Context analysis - internal and external issues (clause 4.1)
- Interested parties register (clause 4.2)
- Climate-change relevance determination - the documented decision on whether climate change is a relevant issue (clause 4.1, as amended by Amendment 1:2024). Note this is a consider-and-document duty: recording a reasoned "not relevant" satisfies it. Clause 4.2 adds only a non-normative note.
Section 2: Leadership and commitment
- Information security policy - current version, signed, dated (clause 5.2)
- Management review records - last two meetings (clause 9.3)
- ISMS roles and responsibilities - named individuals (clause 5.3)
Section 3: Planning
- Risk assessment methodology (clause 6.1.2)
- Risk register - current version with treatment decisions (clause 6.1.2)
- Risk treatment plan with status (clause 6.1.3)
- Statement of Applicability - signed, with justifications (clause 6.1.3)
- Information security objectives (clause 6.2)
Section 4: Support
- Competence records - training logs, certificates (clause 7.2)
- Awareness programme evidence (clause 7.3)
- Document control procedure and version history (clause 7.5)
Section 5: Operation
- Operational procedures - key ones that auditors sample
- Change management records
- Supplier assessment records (Annex A 5.19-5.22)
- Incident log and management records (Annex A 5.24-5.28)
Section 6: Performance evaluation
- Internal audit programme, plan, and last audit report (clause 9.2)
- Nonconformity and corrective action register (clause 10.1)
- Key performance indicators or ISMS metrics (clause 9.1)
Section 7: Annex A controls
- Organised by control number, one subfolder or section per control area sampled in the audit
This structure means that when an auditor asks for a specific document, the auditee knows exactly where it is. More usefully, it means the auditee can prepare each section in advance and confirm it is complete rather than making that discovery during the audit itself.
Building the evidence index
The evidence index is the document that maps clause and control references to specific file names and locations. It is the first thing you hand the auditor, and it serves as the navigation layer for everything that follows.
A minimal index entry looks like this:
- Clause/Control: 9.2 - Internal audit
- Document name: Internal Audit Report Q2 2026 - ISMS
- File location: ISMS Evidence Pack / 6 Performance Evaluation / Internal Audit
- Version / date: v1.0 - 2026-06-14
- Notes: Includes audit programme, schedule, and corrective action register reference
One row per document. Every document in the evidence pack has a row. The index makes every reference resolvable in under thirty seconds.
Sequencing Annex A evidence
Within the Annex A section, the most efficient approach is to organise by the controls your auditor is most likely to sample. You will not know in advance exactly which controls they will focus on, but certain areas are consistently examined in Stage 2:
- Access control and access reviews
- Vulnerability management
- Backup and restore
- Change management
- Incident management
- Supplier security
- Physical security (for relevant organisations)
- Cryptography (especially where personal data is in scope)
For each of these, gather the evidence into a single named location before audit day. Do not leave any of them dependent on live system access that might be unavailable during the remote session, or on someone who is not in the room.
What not to put in the evidence pack
An evidence pack is not a document archive. Including every version of every policy ever written, every email thread tangentially related to security, and every tool screenshot the team could find does not strengthen the audit position - it weakens it by burying the useful evidence in noise.
Include only:
- Current versions of controlled documents.
- Records from the last operational cycle (typically the last twelve months for recurring activities).
- Supporting records only where they are explicitly referenced by a control or by a document already in the pack.
If a document needs an explanation before it can be understood as evidence, write a one-sentence label on the index entry, not a supplementary note inside the document itself.
The day before Stage 2
The day before Stage 2, run through the index against the actual files. Confirm every reference resolves. Check that date-sensitive records - management review minutes, internal audit reports, supplier assessments - are from within the operational period under review.
Prepare a short verbal briefing for the opening meeting: what the index covers, how it is structured, and who the right person is to access each section. An auditor who enters the audit knowing that a named person owns each section of evidence can work efficiently through their sampling plan.
A well-ordered evidence pack does not guarantee certification - that depends on whether the controls are genuinely operating. But it removes friction and demonstrates the kind of governance that is itself part of what the standard is assessing.
Where Kellwick fits
Building a complete, auditor-ready evidence pack and index is one of the specific services Kellwick provides as part of pre-Stage-2 advisory work. Kellwick operates independently of any certification body, as an independent advisory that has reviewed evidence packs from both sides of the audit table. See how the evidence pack service works to understand what a structured, audit-sequenced pack looks like for your programme.
Where this fits
ISO 27001
Pass the audit. We find what blocks Stage 1 before the certification body does.
Read the ISO 27001 hubNeed a second pair of eyes before the auditor does?
A readiness review shows exactly where your ISMS stands - and what to fix first - while there is still time to act on it.
Stay audit-ready
Occasional, practical notes on ISO 27001 readiness and ISMS maintenance. No noise.