Free resource
A structured self-check across scope, risk, SoA, evidence, access, suppliers, incidents and governance - score each item Yes / Partly / No and see where an auditor will dig.
The actual structure of the file, straight from the template we use on live engagements.
Sheet: Start here
Read this tab first, then work through the checklist. Score honestly - a 'Partly' you can see is worth more than a 'Yes' you cannot evidence. This is a working tool, not a certificate: it shows where an assessor will push, before they do.
| Topic | Detail |
|---|---|
| What this is | A 15-point readiness self-check across scope, risk, access, suppliers, evidence and governance - the areas a Stage 1 and Stage 2 auditor open first. |
| How to score | Yes = in place and you can show the evidence today. Partly = it exists but is incomplete, informal or unevidenced. No = not in place. Only a clear Yes counts when it is audited. |
| The #1 mistake | Confusing a tool or a policy with evidence. 'We use Okta' or 'we have a policy' is not proof - the auditor wants the dated record showing the control actually ran. |
| A second pair of eyes | If you want someone who has sat on the other side of the audit table to sanity-check your scoring before it counts, that is what we do at kellwick.com. |
Sheet: Readiness Checklist
Score each item Yes / Partly / No. Anything that is not a clear Yes is where an auditor will dig. The two middle columns are done for you - what a pass looks like, and the way teams most often fail it.
| Section | Check item | What good looks like | Most common failure (the red flag) | Status (Yes / Partly / No) | Owner | Evidence / where it lives |
|---|---|---|---|---|---|---|
| Scope | The ISMS scope reflects the real product, teams, systems and locations | A scope statement that names the products, teams, cloud accounts and offices - and matches reality | Scope quietly excludes a system that clearly processes customer data, to dodge a control | - | - | - |
| Scope | The Statement of Applicability is finalised and maps to real controls | Every Annex A control marked applicable or excluded, each exclusion justified in one line | Applicability copied from a template - exclusions with no reason, or none at all | - | - | - |
| Risk | The risk register names real, specific risks (not a template) | Risks describe a real scenario, asset and consequence in your own words | Generic template risks ('malware', 'data breach') with no owner or context | - | - | - |
| Risk | Risk treatments trace to decisions in the SoA | Each treatment links to the control(s) that deliver it | Risks accepted or treated with no line to the SoA or to any evidence | - | - | - |
Preview only. The download is a fully editable .xlsx file.
Go deeper
See how this template fits the wider readiness work, and where we pick it up on a live engagement.
Explore the related serviceMore resources