{"description":"Runs on the existing audit item. Assess ISO/IEC 27001 certification readiness across ISMS scope, clauses, risk treatment, Annex A applicability, internal assurance, gaps, and audit-entry governance. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","edges":[{"id":"e-iso-clause-control-review-iso-readiness-closure","source":"iso-clause-control-review","target":"iso-readiness-closure"}],"isPublic":true,"itemTypeSlug":"audit","metadata":{"capabilities":["iso27001-certification-readiness"],"controlVerbs":{"UC-AUDIT-13":"tests"},"controls":["UC-AUDIT-13"],"department":"internal-audit","domains":["audit"],"framework":"iso-27001","kind":"iso27001-certification-readiness","library":{"aliases":[{"source":"studio-seed","sourceTemplateId":"coworkcanvas:template:iso27001-certification-readiness"}],"canonicalUrl":"https://workflow-library.com/all/?w=audit-iso27001-certification-readiness","contentDigest":"sha256:a8f5c42a865b29fd211a9798d94cde470f226c702287bd2a970df0597fb6a334","prerequisites":{"anchorItemType":{"slug":"audit"},"evidenceDestinations":[{"description":"Restricted native step results, attached documents, durable item fields and native approvals.","id":"review-evidence"}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:audit-iso27001-stage1-documentation-review"}],"roles":[{"contribution":"expertise","description":"Engagement lead. Assess clauses and Statement of Applicability.","id":"reviewer-1","nodeIds":["iso-clause-control-review"]},{"contribution":"approval","description":"Independent audit supervisor. Approve ISO 27001 readiness record.","id":"reviewer-2","nodeIds":["iso-readiness-closure"]}],"status":"declared"},"provenance":[{"source":"brain/scripts/studio-seed","sourceTemplateId":"coworkcanvas:template:iso27001-certification-readiness"}],"releaseId":"sha256:a8f5c42a865b29fd211a9798d94cde470f226c702287bd2a970df0597fb6a334","schemaVersion":1,"sourceTemplateId":"workflow-library:audit-iso27001-certification-readiness"},"lineOfDefense":"assure","mappingStatus":"mapped","risks":[],"slug":"audit-iso27001-certification-readiness","source":"coworkcanvas-gallery","standards":[],"teams":["internal-audit"]},"name":"ISO 27001 Certification Readiness","nodes":[{"data":{"instructions":"**Objective**\nAssess clauses and Statement of Applicability. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the approved ISMS scope, context and interested-party analysis, organization and asset inventories, architecture, legal and contractual obligations, risk methodology, prior audits, incidents, and change plans.\n2. Use the scoped ISMS, policies and objectives, risk methodology and assessment, treatment plan, Statement of Applicability, Annex A controls, documented processes, competence records, monitoring, and corrective actions.\n\n**Procedure**\n1. Reconcile the scope to actual activities and dependencies, identify outsourced processes and interfaces, verify leadership ownership, select the applicable standard edition and certification stage, and document defensible exclusions or constraints.\n2. Evaluate each clause requirement, trace risks to treatment decisions, verify inclusion and exclusion rationale in the Statement of Applicability, inspect representative implementation evidence, and identify missing or contradictory documentation and practice.\n\n**Record in AssureSwarm**\n1. Capture the standard reference, scope statement, products, entities, locations, systems, interfaces, outsourced dependencies, interested parties, certification objective, target dates, exclusions, changes, and limitations. Also record standard edition and criteria; iSMS scope statement.\n2. Link the clause assessment and Statement of Applicability, document evidence, implementation observations, risk-treatment alignment, exclusions, owners, gaps, and required document or practice updates. Also record statement of Applicability reference.\n\n**Exit criteria**\nEngagement lead provides expertise: The ISMS and readiness boundary are coherent and approved inputs, material interfaces are visible, and criteria or scope ambiguities are resolved before clause assessment. Every clause and applicability decision has evidence or a visible gap, risk treatment and control status reconcile, and unsupported exclusions are assigned for correction.","kind":"task","label":"Assess clauses and Statement of Applicability","requiredApprovals":1},"id":"iso-clause-control-review"},{"data":{"controls":["UC-AUDIT-13"],"instructions":"**Objective**\nApprove ISO 27001 readiness record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review internal audit program and results, management-review minutes and inputs, security objectives and measures, nonconformities, corrective actions, competence records, document control, gap tracker, and certification-body prerequisites.\n2. Review all stage records, current scope and criteria, clause evidence, Statement of Applicability, treatment plan, internal audit, management review, corrective actions, readiness decision, and certification-body coordination.\n\n**Procedure**\n1. Check required assurance cycles and inputs, validate corrective-action root causes and evidence, assess whether records cover the scoped ISMS, identify open major dependencies, sequence closure and operating history, and challenge schedule pressure.\n2. Trace material readiness statements to evidence, confirm gaps and unsupported exclusions remain visible, reconcile document versions and owners, verify conditions and timing, and return incomplete or inconsistent analysis for correction.\n\n**Record in AssureSwarm**\n1. Document the readiness decision, internal audit and management-review status, gaps and nonconformities, corrective actions, evidence history, competence or document issues, conditions, owners, and due dates. Also record certification readiness.\n2. Capture the authorized reviewer, final scope, criteria and Statement of Applicability references, readiness result, conditions, gaps and corrective actions, owners, dates, proposed certification next step, and reassessment triggers. Also record iSO 27001 readiness summary.\n\n**Exit criteria**\nIndependent audit supervisor provides approval: An approver accepts the supported readiness disposition, all conditions are owned and time-bound, and readiness is not described as certification or a registrar conclusion. The authorized reviewer accepts an internal readiness record for planning; workflow closure neither certifies the ISMS nor predicts or replaces the certification body’s determination.","kind":"task","label":"Approve ISO 27001 readiness record","requiredApprovals":1},"id":"iso-readiness-closure"}],"sourceTemplateId":"workflow-library:audit-iso27001-certification-readiness"}
