iso27001-audit-prep

Pressure-tests ISO 27001 ISMS audit readiness through six forcing questions and structured verdict output.

25.3k|3.6k|Updated Oct 19, 2025
One-click install
npx skills add https://github.com/alirezarezvani/claude-skills --skill iso27001-audit-prep
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: iso27001-audit-prep
Source: https://github.com/alirezarezvani/claude-skills/tree/main/compliance-os/skills/iso27001-audit-prep
Command: npx skills add https://github.com/alirezarezvani/claude-skills --skill iso27001-audit-prep

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Preparing for an ISO 27001 internal, surveillance, or certification audit is high-stakes and easy to get wrong — stale risk registers, missing access review records, and incomplete management review inputs are the most-cited findings. This Skill pressure-tests your ISMS against six auditor-style forcing questions before the real audit happens.

Core Features & Use Cases

  • Six-Question Audit Interrogation: Covers audit scope and 3-year coverage, risk register freshness, access review evidence, supplier management, incident response records, and Clause 9.3 management review inputs.
  • Structured Readiness Verdict: Produces a markdown report with per-control pass/fail status, cross-framework impact (SOC 2, ISO 42001, GDPR), and a READY / CLOSE-CRITICALS-FIRST / NOT-READY verdict with top 3 actions.
  • Cross-Framework Routing: Links to SOC 2, GDPR, ISO 42001, and compliance-readiness skills for reuse across overlapping control frameworks.
  • Use Case: Before your annual Clause 9.2 internal audit, run the interrogation against your ISMS scope to surface gaps in access review records and risk register linkage, then assign corrective actions with owners and timelines.

Quick Start

Ask the AI to run an ISO 27001 audit readiness check on your ISMS scope using the six forcing questions and produce a readiness verdict report.

Frequently Asked Questions about iso27001-audit-prep

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I prepare for an ISO 27001 internal audit?

Run a six-question readiness interrogation covering audit scope and 3-year coverage, risk register freshness, access review records, supplier inventory, incident response evidence, and Clause 9.3 management review inputs. Each question maps to specific Annex A controls with sample-based evidence checks.

What are the most common ISO 27001 audit findings?

Access review records are the most-cited finding area, covering Annex A.5.15, A.8.2, and A.8.3 controls. Supplier management under A.5.19-A.5.21 is the second most-cited area, followed by stale risk registers lacking Annex A control linkage.

Does ISO 27001 audit prep overlap with SOC 2 compliance?

Yes, SOC 2 shares roughly 75 percent control overlap with ISO 27001, and ISO 42001 reuses about 60 percent. The skill includes cross-framework mapping so findings can be routed to SOC 2, GDPR Article 32, and ISO 42001 audit preparation workflows.

How often should the ISO 27001 risk register be refreshed?

Quarterly refresh is expected, with annual as the minimum acceptable cadence. Every high or critical risk must link to at least one Annex A control treating it, and residual risk acceptance must be documented and signed.

When should I run an ISO 27001 audit readiness check?

Run it before the annual Clause 9.2 internal audit, before stage 1 or stage 2 certification audits, before surveillance audits in years two and three, after material ISMS scope changes, and post-incident when a breach triggers an ad-hoc audit.