Skip to content
compliancebase
ISO 27001A.5 — Compliance with policies, rules and standards for information security

A.5.36

Compliance with policies, rules and standards for information security

ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026

Objective

Review compliance with the organization's information security policies, rules, and standards regularly.

Points of focus

  • Compliance review methods defined
  • Coverage of key policies
  • Findings tracked to remediation
  • Results reported to management

Implementation notes

Combine continuous metrics (MFA coverage, review completion) with periodic internal audit (A.5.35). Maintain an exception register with risk acceptance and end dates. Report systemic noncompliance to management review. Keep this distinct from legal compliance (A.5.31) — here you test adherence to your ISMS rules.

Audit tip: Show an internal audit finding against a policy and the verified fix.

Evidence auditors typically request:

  • Internal audit reports against policies
  • Control self-assessment results
  • Exception register with expiry
  • Management review inputs on compliance status

Common gaps

  • Exceptions without expiry or owner
  • Policy compliance assumed from training completion alone
  • Findings closed without verifying effectiveness

Cross-Framework Mapping

FrameworkRequirementImplementation note
ISO 27001A.5.36This control

Primary sources

Frequently Asked Questions

No. Pen tests inform technical risk; A.5.36 also checks policy and process adherence.

Internal audit or competent independent reviewers for formal reviews; control owners for ongoing self-checks.

A.5.35 is independent review of information security; A.5.36 emphasises compliance with your stated policies and standards.

Framework versions referenced in this page:

  • ISO/IEC 27001ISO/IEC 27001:2022

Last verified: July 2026 · Primary sources linked above