ISO 27001 Is a Management System, Not a Checklist

The most common — and most expensive — misunderstanding about ISO 27001 is that it's a list of security controls you tick off. It isn't. ISO/IEC 27001:2022 certifies an Information Security Management System (ISMS): a living set of processes for identifying risk, deciding what to do about it, and proving — continuously — that the controls actually work. The controls in Annex A are the easy part. The management system around them is what an auditor actually certifies, and what most first attempts get wrong.

For UAE businesses, certification increasingly isn't optional in practice. Enterprise buyers, government tenders, and overseas partners ask for it before they sign. A certificate is how you prove security maturity to someone who can't audit you themselves. This is a practical walkthrough of how to get there — from the perspective of running the engagements, not reciting the standard.

(We've covered two adjacent topics separately: what certification actually costs by company size, and how to build the ISO 27005 risk register that sits at the heart of the ISMS. This piece is the end-to-end journey.)

What the Standard Requires

ISO 27001:2022 has two parts, and the work lives in both.

The management-system clauses (4–10) are mandatory and non-negotiable. They are the heart of certification:

  • Clause 4 — Context. Define what your ISMS covers (the scope) and who your interested parties are.
  • Clause 5 — Leadership. Top management must own it. An information security policy, signed off and resourced. This is not a job you can fully delegate to IT.
  • Clause 6 — Planning. Risk assessment and risk treatment, plus the Statement of Applicability — the document everything hinges on (more below).
  • Clause 7 — Support. Competence, awareness, documented information.
  • Clause 8 — Operation. Actually running the risk assessment and treatment you planned.
  • Clause 9 — Performance evaluation. Internal audit and management review — mandatory, and the two things first-timers most often skip until the auditor asks.
  • Clause 10 — Improvement. Corrective action when things go wrong.

Annex A controls — the 2022 revision streamlined these to 93 controls across four themes: Organizational (37), People (8), Physical (14), and Technological (34). You don't implement all 93 blindly; you implement the ones your risk assessment says you need, and you justify the rest in the Statement of Applicability.

If you were certified to the 2013 version, the transition window to 2022 has closed — 2022 is now the only current version. New certifications are all to 2022.

The Statement of Applicability — the Document Everything Hinges On

If there is one artefact an auditor lives in, it's the Statement of Applicability (SoA). It lists every Annex A control and, for each, states: is it applicable, is it implemented, and why (or why not). It's the bridge between your risk assessment and your controls — proof that what you've implemented is driven by actual risk, not guesswork.

A weak SoA — controls marked "applicable" with no justification, or "not applicable" with no rationale — is the single fastest way to fail Stage 1. Get the SoA right and the rest of the audit goes smoothly.

How Certification Actually Works

Certification is done by an accredited certification body (a registrar), not by your implementation partner — independence rules forbid the same party doing both. The process:

  1. Stage 1 audit — a documentation and readiness review. The auditor checks your ISMS exists: scope, policy, risk assessment, SoA, internal audit, management review. Most failures here are missing mandatory documents or an empty management-review record.
  2. Stage 2 audit — the implementation audit. The auditor samples controls and asks for evidence they operate. "Show me the last three access reviews." "Show me the incident log." This is where a paper-only ISMS collapses.
  3. Certification — valid for three years, with annual surveillance audits to confirm the ISMS is still operating, and a full recertification at year three.

The lesson: the auditor tests whether your system runs, not whether it's written. Evidence is everything.

The Implementation Journey — What Good Looks Like

  1. Scope it tightly. What's in the ISMS — which entities, locations, systems, services. Over-scoping is the most common way to make certification harder and more expensive than it needs to be.
  2. Gap assessment. Current state against clauses 4–10 and Annex A. Output: a gap register with severity, effort, and dependencies.
  3. Risk assessment + treatment. A repeatable methodology (ISO 27005 aligns well), a populated risk register, and a treatment decision for each risk. This drives the SoA.
  4. Build the document stack. The mandatory policies and procedures — tailored to how you actually operate, not generic templates an auditor has seen a hundred times.
  5. Implement controls. The operational changes: access reviews, asset register, supplier security, change management, logging, training records.
  6. Run a real internal audit (Clause 9.2). Mandatory, and your dress rehearsal. Find the gaps before the certification body does.
  7. Hold a management review (Clause 9.3). Leadership reviews the ISMS performance. Minute it.
  8. Stage 1 → remediate → Stage 2. You're ready.

The Mistakes We See Most Often

  • Treating it as an IT project. ISO 27001 is a leadership and process standard. Without top-management ownership (Clause 5), it fails at Stage 1.
  • Generic policies. Downloaded templates that don't match how you work are obvious to an auditor and unenforceable in practice.
  • Skipping internal audit and management review. They're mandatory. Empty records here are an automatic Stage 1 finding.
  • A SoA with no justifications. The fastest path to a failed documentation review.
  • Evidence collected the week before the audit. Thin, rushed, and obvious. Real ISMSs generate evidence as business-as-usual.
  • Over-scoping. Pulling every system and location into scope multiplies the work. Scope to what matters, expand later.

Timeline and How to Start

A realistic ISO 27001 implementation runs 4–6 months for an SME (under ~100 staff) and 6–9 months for larger organisations — gap assessment, document stack, control implementation, internal audit, management review, then the certification body's Stage 1 and Stage 2. The certification body's fees are separate from implementation and paid directly to them.

The best first step is a gap assessment: it gives you a costed, prioritised picture of exactly what certification will take for your scope, and surfaces the quick wins you can start immediately. You can't plan the work until you can see it.

Working With Underwings

We run ISO 27001 as implementation, not advice — gap assessment, risk register, the full policy stack, control implementation alongside your team, a real internal audit, and we attend your Stage 1 and Stage 2 audits with you. Led by a named ISO 27001 Lead Auditor, not handed to a junior. Transparent AED pricing, fixed written quotes within 48 hours, and a limited number of founding-client places at preferential rates while we build our public track record.

If ISO 27001 is on your roadmap — or a customer just asked for it — a free 30-minute scoping call will tell you where you genuinely stand. Book at book.underwings.org, email [email protected], or call +971 50 567 0394.

Manoj Prabhakaran is an ISO 27001 Lead Auditor (CPTS, Azure Security) and leads GRC and compliance at Underwings Cybersecurity Solutions, Abu Dhabi.