Why the certificate does not answer the questionnaire automatically
ISO/IEC 27001 specifies requirements for an information security management system (ISMS). The organization defines its scope, assesses risks, selects appropriate treatment and continually improves the system. Certification covers that defined scope; it is not a blanket statement about every product, location or individual customer control.
Customer questionnaires commonly mix management-system requirements, technical safeguards, privacy, cloud architecture, incident processes and contractual commitments. “ISO 27001 certified” is relevant context, but rarely a complete answer.
- Is the requested product or location inside the certification scope?
- Does the answer describe a documented rule or actual operational practice?
- Is the source current, approved and suitable for the exact claim?
- Does the customer also require evidence, a metric or a contractual commitment?
Which ISMS artefacts can support an answer
A defensible response pack combines normative documentation with operational evidence. The right source depends on the question. A policy may establish ownership and minimum requirements, for example, but it does not automatically prove that an access review took place.
- Certificate and scope statement for formal coverage
- Statement of Applicability (SoA) for selected and justified controls
- Risk assessment and risk treatment plan for risk-based decisions
- Approved policies and process descriptions
- Current access reviews, tickets, logs or exercise records
- Supplier assessments, incident records and management-review outputs
The proper role of the Statement of Applicability
The Statement of Applicability connects risk treatment to selected information security controls. It records which controls were determined necessary, how their implementation is treated and why particular Annex A controls are not required.
For questionnaire work, the SoA is therefore a valuable index, but not universal proof. An entry may show that a control is addressed by the ISMS. Whether it applies to the specific product and operates effectively often requires additional documents or records.
Annex A is not a rigid checklist that every organization must implement identically. ISO/IEC 27001 follows a risk-based approach. Customer requirements should not be marked compliant automatically merely because control names look similar.
A six-step review-ready workflow
1. Decompose the customer question
Separate compound questions into precise claims. One row may ask about encryption, key management, logging and retention at the same time.
2. Check product and certification scope
Determine which legal entities, locations, services and systems are genuinely covered by the source.
3. Map primary source and operational evidence
Connect the answer to the strongest available passage and add records when the question asks about execution or effectiveness.
4. Draft with boundaries
Describe the current state precisely. Avoid absolute wording where scope, exceptions or partial coverage matter.
5. Keep missing evidence visible
Assign unsupported points to an owner. Plausible language must never replace missing implementation.
6. Approve and version
Security, Legal, Privacy or the technical owner approves the external claim. Source, version and approval status remain traceable.
Where AI saves time — and where it must not decide
AI can structure large questionnaires, retrieve similar approved answers, suggest relevant document passages and draft initial responses. Its strongest economic value is faster research and more consistent reuse.
It does not automatically know the legal or technical boundary of a certificate. Nor can it reliably determine whether a documented control operates effectively in the requested service. Scope, evidence quality, exceptions and external commitments require an accountable person.
A controlled workflow therefore shows answer, source, confidence and missing evidence together. Automation is useful when it exposes uncertainty, not when it hides uncertainty behind polished language.
Common ISO 27001 questionnaire mistakes
- Using the certificate as the answer to every technical detail.
- Failing to compare certification scope with the requested product.
- Treating the SoA as implementation evidence when operational records are missing.
- Reusing old customer answers without source and version checks.
- Describing planned measures in the present tense as existing controls.
- Answering a compound question with Yes when only one part is evidenced.
- Letting Sales send risky commitments before Security or Legal review.
Definition of done for a defensible response
- The claim is precise and avoids unsupported absolutes.
- Product, location and certification scope have been checked.
- Source, passage, version and applicability are recorded.
- Operational evidence supplements policy where effectiveness is requested.
- Partial coverage, exceptions and missing evidence remain visible.
- An accountable person approved the external statement.
Frequently asked questions
Does an ISO 27001 certificate answer a security questionnaire?
No. It is important assurance for the certified ISMS scope, but it does not automatically replace product-, architecture- or customer-specific detail.
Is the Statement of Applicability sufficient evidence?
It is a central source for selected controls and their justification. Questions about implementation or effectiveness often require additional policies, process descriptions or operational records.
Must every Annex A control be implemented?
ISO/IEC 27001 follows a risk-based approach. The organization determines necessary controls and records its decisions in the SoA; Annex A is a reference set, not an identical blanket checklist for every organization.
Can TrustRespond confirm ISO 27001 conformity?
No. TrustRespond supports research, evidence mapping and review of questionnaire responses. Certification, audit conclusions and accountable external approval remain with qualified people and organizations.
Test an ISO 27001 questionnaire with real evidence
In the pilot, we process up to 50 anonymized questions and identify which ISMS sources are strong, where evidence is missing and which responses need expert approval.
Official sources
- ISO/IEC 27001:2022 — ISMS requirements
- ISO/IEC 27002:2022 — information security controls
- ISO/IEC JTC 1/SC 27 — Statement of Applicability auditing practice note
Editorial note: checked against the official ISO sources on 25 July 2026.
