Table of contents
ISO/IEC 27001:2022 Annex A 5.36
ISO 27001 Annex A 5.36 Compliance with policies and standards for information security requires organisations to review compliance regularly. Documented reviews ensure staff and technical systems follow security rules and meet audit standards.
Key Takeaways
- Review policy compliance regularly: Check that managers and teams carry out daily work in line with published security rules.
- Store review logs centrally: Keep compliance reports, gap assessments, and action plans in a central document repository.
- Automate technical checks: Use system monitoring tools and compliance scans to verify device configurations automatically.
- Assign compliance ownership: Require department heads to review their own operational units and report gaps on a set schedule.
- Address non-compliance quickly: Log security gaps as corrective actions and resolve non-conformities before external audits.
- Maintain independent reviews: Combine self-assessments with objective internal audits to ensure impartial compliance checks.
- Report findings to leadership: Present compliance metrics and audit findings during routine management review meetings.
- Drive continuous improvement: Update security standards and training whenever compliance reviews highlight recurring weaknesses.
How to Implement ISO 27001 Annex A 5.36
- Define compliance review rules: Write a documented policy review procedure and store it in your central document repository.
- Set a compliance review schedule: Establish planned calendar dates to assess policy adherence across all business departments.
- Run automated configuration scans: Deploy tools to check that servers, user endpoints, and cloud systems meet baseline security standards.
- Train managers on assessment steps: Teach team leaders how to review staff practices, permissions, and records against security policies.
- Log compliance gaps: Record every discovered policy violation or technical deviation in a central corrective action tracker.
- Assign corrective action owners: Appoint named individuals and set fixed deadlines to resolve identified compliance gaps.
- Perform spot checks: Conduct unannounced checks on clean desk rules, password safety, and physical access controls.
- Report results to executives: Share compliance review summaries with leadership to guide security budget and policy decisions.
- Update policies after reviews: Refine confusing or impractical policies when repeated non-compliance indicates process friction.
When you’re ready to bring compliance into one place

How to Audit ISO 27001 Annex A 5.36
- Review compliance schedules: Inspect written review plans to verify regular assessments occur across all departments and systems.
- Sample completed review reports: Check recent departmental assessment logs to confirm managers evaluated staff and systems.
- Verify automated compliance scans: Inspect system audit logs to confirm automated scans verify endpoint and network configurations.
- Track corrective actions: Sample flagged policy gaps to verify teams assigned remediation owners and closed issues on time.
- Interview team leaders: Ask department managers how they verify that their team members follow organizational security rules.
- Inspect spot check records: Review notes from unannounced audits to confirm teams carry out regular physical and digital checks.
- Check management review inputs: Confirm leadership receives and discusses compliance review reports during formal meetings.
- Verify auditor independence: Confirm internal auditors do not review their own operational areas or direct responsibilities.
Audit Evidence Checklist
- Compliance review procedure: Maintain a documented policy review procedure with full version history in your central repository.
- Annual review calendar: Supply a formal schedule showing completed and planned compliance assessments across all departments.
- Departmental review reports: Provide signed records showing manager reviews of operational security practices.
- Automated scan reports: Supply dashboard exports proving systems scan endpoints and cloud accounts against security baselines.
- Corrective action logs: Maintain an active tracking register showing remediated policy deviations and resolution dates.
- Management review minutes: Supply meeting notes proving executives reviewed policy compliance findings and action plans.
- Spot check audit logs: Provide records from physical walkthroughs checking clear desk and clean screen compliance.
What to Teach Employees
- Understand compliance duties: Teach staff that following published security rules is a mandatory part of everyday work.
- Participate in regular reviews: Instruct workers to assist managers openly during internal checks, audits, and spot checks.
- Report policy gaps safely: Encourage staff to flag impractical security rules so policies can be improved and simplified.
- Avoid bypassing rules: Warn workers against taking unapproved security shortcuts to finish tasks faster.
- Follow corrective instructions: Teach staff to complete assigned remediation steps promptly when security reviews identify gaps.
- Know how compliance protects: Educate workers on how policy adherence protects client data and prevents severe business loss.
Common Implementation Challenges
- Treating compliance as a tick-box: Teams rush through checklists without testing real security habits. Conduct practical spot checks.
- Ignoring identified gaps: Reviews uncover non-compliance but nobody fixes root causes. Track all findings in a formal action register.
- Overly complex policies: Staff ignore rules that create friction in daily workflows. Simplify policies to make compliance easy.
- Lack of manager involvement: Department leaders assume compliance belongs solely to IT. Train managers to run reviews within their teams.
- Manual verification bottlenecks: Checking systems manually takes too much time. Use automated tools to audit technical baselines.
- Fear of reporting mistakes: Staff hide non-compliant practices from auditors. Foster a blameless culture focused on fixing process gaps.
How to Measure Effectiveness (KPIs)
- Policy review completion rate: Track the percentage of scheduled compliance reviews completed on time across all units.
- Technical baseline compliance rate: Measure the proportion of systems meeting automated security standards during scans.
- Corrective action closure speed: Measure the average number of days taken to resolve identified policy non-conformities.
- Repeat non-compliance rate: Track the percentage of security review findings that recur across consecutive audits.
- Spot check pass rate: Measure the proportion of successful spot checks for clean desks, screen locks, and access controls.
- External audit finding count: Monitor the number of non-conformities raised by external auditors during ISO 27001 assessments.
Related ISO 27001 Controls
ISO 27001 Control A 5.36 connects to several other ISO 27001 requirements:
- Clause 9.1: Monitoring, measurement, analysis, and evaluation.
- Clause 9.2: Internal audit requirements.
- Annex A 5.35: Independent review of information security.
