Syntic

Skills may execute instructions and code that could affect your environment. Marketplace scans reduce risk but do not guarantee safety. Always review files, run your own security checks, and use at your own risk.

ComplianceFree Safe

iso27001-audit-prep

Security Scan Summary

Status: Safe

Source: Syntic Skills registry

Automated security scan completed with no high-risk patterns detected. Manual review is still required.

About This Skill

Use when preparing an ISO 27001 ISMS audit: before annual Clause 9.2 review, stage 1/2 certification, surveillance audits, scope changes, or post-incident ISMS review.

Downloadable SKILL.md

Download SKILL.md and place it in your Syntic skills folder. For Syntic Code, install in your local skills directory, review contents, and run in a controlled environment first. Acknowledge the risk notice above to enable the download.

SKILL.md
---
name: iso27001-audit-prep
description: Use when preparing an ISO 27001 ISMS audit: before annual Clause 9.2 review, stage 1/2 certification, surveillance audits, scope changes, or post-incident ISMS review.
category: Compliance
version: 1.0.0
tools: []
---

# ISO 27001 ISMS Audit Prep — Six Forcing Questions

Pressure-test any ISMS work with six sample-driven questions before an internal audit, stage 1/2 certification readiness, or a surveillance audit.

## When to Run

- Before annual Clause 9.2 internal audit
- Before stage 1 / stage 2 ISO 27001 certification audit
- Before surveillance audit (year 2 / year 3)
- After a material change to ISMS scope (new business unit, product line, or SaaS adoption)
- Post-incident (a breach triggers an ad-hoc ISMS audit)
- Quarterly during a high-growth phase

## The Six ISMS Questions

### 1. What's the audit scope, and is rolling 3-year coverage on track?
No 3-year coverage discipline means no defensible programme. Every Clause 4-10 requirement and every applicable Annex A control must be audited at least once per 3-year cycle. Confirm auditor independence — no self-audit on any sample.

### 2. When was the risk register last refreshed, and are treatments linked to Annex A controls?
A stale risk register is a certification finding. Expect quarterly refresh, annual minimum. Every high/critical risk must link to at least one Annex A control treating it, with residual risk acceptance documented and signed.

### 3. Show the access review records — quarterly cadence, the last 4 quarters.
Most-cited finding area. Covers Annex A.5.15, A.8.2, and A.8.3 access controls. Sample real records pulled from the IAM system, not curated audit-prep packs. For each employee terminated in the last 90 days, confirm deprovisioning evidence within a 24-hour SLA, and review privileged access at finer granularity.

### 4. What's the supplier inventory and last review evidence?
Second-most-cited finding area. Covers Annex A.5.19-A.5.21 supplier management. Critical SaaS suppliers should be reviewed at least annually, DPAs signed for personal-data sub-processors, and AI-specific contract clauses added where third-party AI services are in use.

### 5. Where's the incident response evidence and post-incident review?
Annex A.5.24-27 and A.6.8 — a high-stakes audit area. Severity definitions must be documented and consistently applied. The last 5 incidents need a post-incident review (PIR) within a 30-day SLA. GDPR Article 33/34 notification timing must align with A.5.24. Maintain a blameless retro culture, not a punitive one.

### 6. What's the management review cadence and inputs?
Clause 9.3 required inputs are prescriptive and easy to miss: audit results, risks, performance, nonconformities, opportunities. Schedule annual minimum, quarterly preferred for mature programs. Outputs must be documented and tracked to closure. An integrated review across frameworks is preferable to separate reviews.

## Method

Plan the audit programme by mapping every clause and Annex A control to a 3-year rolling schedule, then run a mock-audit readiness check against it. Cross-framework reuse is significant: SOC 2 shares roughly 75% control overlap, and ISO 42001 shares roughly 60% reuse — map shared evidence once rather than collecting it twice.

## Output

Produce a verdict report covering: the decision being made (programme-plan / finding-severity / cert-readiness / incident-followup); audit programme status (clauses scheduled, Annex A controls scheduled, rolling 3-year coverage gaps, auditor independence); risk register health (last refresh date, high/critical risks missing an Annex A link, residual risk acceptance completeness); high-stakes controls status (A.5.15/A.8.2/A.8.3 access control, A.5.19-A.5.21 supplier management, A.5.24-27/A.6.8 incident response, A.8.15-16 logging — each pass/fail with sample); management review status (last date, Clause 9.3 inputs present, overdue action items); and cross-framework impact (SOC 2 controls affected, ISO 42001 controls affected if applicable, GDPR Article 32 controls affected). Close with a verdict — READY, CLOSE-CRITICALS-FIRST, or NOT-READY — and the top 3 actions with owner and corrective-action timeline.

## Routing

Escalate to a multi-framework compliance-readiness view, a SOC 2 audit prep for the 75%-overlap cross-walk, an ISO 42001 AIMS cross-walk, a GDPR audit for Article 32 organizational-measures overlap, or an executive cybersecurity strategy review. Log the verdict.

Bundle Download

Includes SKILL.md and bundled support files where provided. Risk acknowledgement is required.

Install Targets

Syntic App

  1. 1. Create a dedicated folder for this skill in your local skills library.
  2. 2. Place SKILL.md into that folder.
  3. 3. Restart Syntic and invoke this skill on matching tasks.

Syntic Code (CLI)

  1. 1. Save SKILL.md in your local Syntic Code skills directory.
  2. 2. Keep related files in the same skill folder.
  3. 3. Run in a safe environment and validate outputs.

Source

https://github.com/alirezarezvani/claude-skills/blob/main/compliance-os/skills/iso27001-audit-prep/SKILL.md

Open Source Link
Compliance

Related Skills