New Blog
The Most Common ISO 27001 Non-Conformities (And How to Avoid Them)
ISO 27001 certification is built on strong, well-maintained information security practices, but many organisations still fall short during audits due to recurring non-conformities.
This guide highlights the most common ISO 27001 non-conformities, from outdated risk assessments and incomplete Statements of Applicability to weak access control reviews, supplier security gaps and poor incident management processes.


The Most Common ISO 27001 Non-Conformities (And How to Avoid Them)
Below are the most common ISO 27001 Non-Conformities:
1) Non-Conformity - Outdated and Missing Risk Assessment.
This would be a potential major nonconformity, as the Risk Framework is one of the core requirements of ISO 27001.
How to Avoid It
Ensure that any major organisation changes or new risks are included in the risk register and that they are reviewed at least quarterly by the information security team. Also, ongoing risks are being tracked, and these are updated with dates hence the auditor views it as a live maintained document.
2) Non-Conformity – Statement of Applicability.
The SOA should list all 93 Annex A controls, but often fails to justify adequately why specific controls have been included and some have been excluded.
How to Avoid it
Whichever controls are included or excluded in the Statement of Applicability should have a reference to a document or justification for exclusion. It should be in a well-structured format for external auditors for ease of understanding.
3) Non-Conformity – Awareness, Education and Training
Employees' do not receive adequate security awareness training. There are no phishing simulations being conducted and employee’s participation is not recorded.
How to Avoid it
Organisations need to establish a comprehensive security awareness training programme which would cover all employees. They should also record employee participation and acknowledge that. The training should also cover new threats and real-world incidents. Employee feedback can also be recorded to review training improvements.
4) Non-Conformity - Policy Documentation Gaps
Policies are not accepted, formally signed off and reviewed. Non-adherence of policies.
How to Avoid it
Policies should be accepted by required stakeholders and formally signed off. They should be reviewed at least annually when there are infrastructure changes or changes in technical or security controls, which are updated in the required policies and accepted by required stakeholders. Policies which are created should be adhered to, ensuring that the required controls are effectively implemented by the organisation.
5) Non-Conformity – Lack of Asset Inventory
Asset Inventory is not updated, which can lead to poor visibility and increase security risks. Assets are not classified.
How to Avoid it
Organisations should maintain a comprehensive asset inventory. The latest ISO 27001 standard mandates that organisations should view assets as Information Assets (data, databases, documents) and not only hardware assets. They should also be classified according to their sensitivity and criticality. An information asset owner should be assigned for each asset.
6) Non-Conformity - Poor Supplier and Third-Party Security Evaluation
Suppliers are engaged without formal security agreements in place, and no due diligence is carried out before they're onboarded, leaving the organisation exposed to supply chain attacks.
How to Avoid it
Establish clear security assurance criteria for important suppliers, requiring e.g. certifications, compliance reports, independent audits or filled security questionnaires as proof of security. Conducting a thorough supplier due diligence prior to onboarding any supplier.
7) Non-Conformity – Access Control Review
Access to information is granted inconsistently instead of using standardised roles and least privilege principles. No formal process for approving, modifying, or revoking access, making it unclear who can authorise changes. Access rights are not periodically reviewed, leading to e.g. former employees still having access to sensitive systems they don't need.
How to Avoid it
Organisations should implement role-based access control (RBAC) and follow the principle of least privilege, so users only have the access needed for their job. Access rights should be reviewed regularly, for example quarterly by asset owners, to confirm they still align with current roles and to remove any access that's no longer needed.
8) Non-Conformity – Incident Management Process not defined clearly.
Employees don't know how to report security incidents, increasing the risk of unnoticed breaches, or documentation of previous incidents is not properly maintained, making it difficult to analyse past incidents and improve response strategies.
How to Avoid it
Incident response roles should be clearly assigned, such as an incident manager, technical lead, and communications lead.
Organisations should also have response plans in place for common and severe incidents, with regular drills, such as tabletop exercises, to stay prepared.
9) Non-Conformity – Management Reviews not being conducted for the Information Security Management System.
Lack of top management participation in the management review meetings and reviews not being conducted.
How to Avoid it
Management reviews should be conducted regularly to assess ISMS effectiveness, with reports of the results and management feedback retained as records. Minutes of these meetings should also be recorded, as they serve as evidence of top management participation and are often reviewed by external auditors.
Conclusion
Avoiding ISO 27001 non-conformities comes down to keeping your ISMS active, well-documented and regularly reviewed. By maintaining clear evidence, updating key processes and involving the right stakeholders, organisations can strengthen compliance and improve audit readiness.
To learn more, visit the official ISO/IEC 27001 standard. If you want to start your certification journey, visit our ISO 27001 service page.
Share your challenge with us and we’ll help you find the right level of support for your business.














