1. Define scope and criteria
The review begins with ISMS boundaries: services, locations, processes, information assets, suppliers, and applicable requirements. Without a clear scope, even good documentation can fail to reflect the actual environment.
2. Review evidence
The review covers more than policies and procedures. It considers evidence of operation, such as risk assessments, the Statement of Applicability, training records, access records, logs, management reviews, and corrective actions.
3. Compare against requirements
Observations are compared with relevant ISO/IEC 27001:2022 clauses and selected controls. The aim is not to complete a checklist mechanically, but to understand whether controls work in the organisation’s business and technology context.
4. Sequence the priorities
Gaps are not equal. A useful assessment distinguishes critical risks, dependencies, and quick improvements so the team can plan realistically instead of working through an arbitrary list.
5. Create a practical plan
A useful outcome identifies next steps, responsible roles, and required evidence. This enables leadership to decide on the resources and timeline for readiness.
What to prepare in advance
- ISMS scope and key service description
- current risk assessment and treatment plan
- Statement of Applicability, if available
- policies, procedures, and registers
- sample records showing controls in operation
- your objective and preferred timeline
A gap assessment is a consulting review, not a certification audit. It does not replace a planned internal audit, but provides a strong basis for one.
View the gap assessment service