ISO 27001A.5 — Compliance with policies, rules and standards for information security
A.5.36
Compliance with policies, rules and standards for information security
ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026
Objective
Review compliance with the organization's information security policies, rules, and standards regularly.
Points of focus
- Compliance review methods defined
- Coverage of key policies
- Findings tracked to remediation
- Results reported to management
Implementation notes
Combine continuous metrics (MFA coverage, review completion) with periodic internal audit (A.5.35). Maintain an exception register with risk acceptance and end dates. Report systemic noncompliance to management review. Keep this distinct from legal compliance (A.5.31) — here you test adherence to your ISMS rules.
Audit tip: Show an internal audit finding against a policy and the verified fix.
Evidence auditors typically request:
- Internal audit reports against policies
- Control self-assessment results
- Exception register with expiry
- Management review inputs on compliance status
Common gaps
- Exceptions without expiry or owner
- Policy compliance assumed from training completion alone
- Findings closed without verifying effectiveness
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| ISO 27001 | A.5.36 | This control |
Primary sources
- ISO/IEC 27001:2022 Annex A: ISO/IEC 27001:2022 Annex A (A.5.36)
Frequently Asked Questions
No. Pen tests inform technical risk; A.5.36 also checks policy and process adherence.
Internal audit or competent independent reviewers for formal reviews; control owners for ongoing self-checks.
A.5.35 is independent review of information security; A.5.36 emphasises compliance with your stated policies and standards.