A.5.35
Independent review of information security
ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026
Objective
Conduct independent reviews of information security and the ISMS at planned intervals or when significant changes occur.
Points of focus
- Scope the review to the ISMS and the controls actually in operation, not a generic checklist
- Confirm the reviewer has no operational responsibility for what they are assessing
- Set a risk-based cadence and trigger reviews after material changes (new product line, acquisition, major incident)
- Route findings into the corrective action register and management review, not a standalone slide deck
Implementation notes
Most SaaS companies under 100 people do not have a dedicated internal audit function, and ISO 27001 does not require one — it requires independence from the area being reviewed. A common pattern: the compliance or security lead reviews engineering-owned controls, and a fractional vCISO or external consultant reviews the compliance function's own controls once a year. Define the review scope against clause 9.2 (internal audit) rather than paraphrasing Annex A text, schedule it on a cadence tied to your certification cycle (commonly annual, more often after a Series B-scale headcount jump or a security incident), and record findings as dated tickets that route into the corrective action process under clause 10.1. Feed a summary into management review under clause 9.3 so leadership sees the same findings the auditor will sample.
Audit tip: Certification bodies check three things in order: who performed the review and whether they were independent of what they tested, what the review actually covered, and whether findings closed out with dated evidence rather than sitting open indefinitely.
Evidence auditors typically request:
- Internal audit charter or engagement letter naming scope, criteria, and reviewer independence
- Dated audit report listing findings, severity, and evidence examined
- Corrective action tickets linked to each finding with owner and closure date
- Management review minutes showing findings were reported to leadership
Common gaps
- The engineer who configured IAM also signs off as the independent reviewer of access control effectiveness
- An audit plan references an annual cadence, but the last completed review predates the current product architecture
- Findings live in a slide deck that was never linked back to a tracked remediation ticket
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| ISO 27001 | A.5.35 | This control |
| SOC 2 | CC4.1, CC4.2 | CC4.1 and CC4.2 cover ongoing and separate evaluations of controls and communication of deficiencies — the closest SOC 2 analog, though SOC 2 does not mandate reviewer independence as explicitly as ISO 27001 clause 9.2. |
Primary sources
- ISO/IEC 27001:2022 Annex A: ISO/IEC 27001:2022 Annex A (A.5.35)