Industry newsStandards

ISO 27001 without the theatre: certifying a system you actually run

9 May 20267 min readFinalogic Advisory
Auditor reviewing certification documentation at a desk

A certificate earned through a binder of policies nobody follows is a liability, not an asset.

The 2022 revision of ISO/IEC 27001 reduced Annex A to 93 controls organised into four themes, and introduced attributes that make the control set easier to map onto other frameworks. That mapping is where most of the value sits: a well-built ISMS should carry a substantial share of DORA, NIS2 and client due-diligence requirements without duplicated effort.

The failure mode we see most often is an ISMS designed for the audit rather than the organisation. Risk assessments performed once and never revisited. A statement of applicability that excludes controls without a defensible rationale. Internal audits conducted by the person who wrote the procedure being audited.

A system that works looks unremarkable: risks reviewed on a cadence tied to change, corrective actions with owners and dates, management review that produces decisions. Certification then becomes a by-product of operating well rather than a project undertaken every three years.

Contact

Start a confidential conversation.

Tell us about your regulatory deadline, audit finding or certification target. We respond within one business day with a qualified point of contact.

Office
Kafkasou 9, 2112, Aglantzia, Nicosia, Cyprus