Search "ISO 27001 checklist" and almost every result is really just an Annex A control list. That's only half the standard. Clauses 4 through 10 — the actual management system requirements — are what most self-led implementations underestimate, and what auditors check before they even look at your controls.
The clauses, in the order they actually get built
- Clause 4 — Context of the organization. Your scope statement, internal/external issues, and interested parties. Auditors start here because it defines what everything else is measured against.
- Clause 5 — Leadership. A documented, approved Information Security Policy and clearly assigned roles — proof that this isn't just an IT project nobody senior signed off on.
- Clause 6 — Planning. Your risk assessment and objectives. This is what should be driving your Annex A control selection, not the other way around.
- Clause 7 — Support. Competence, awareness training, and documented information — the unglamorous administrative backbone auditors check for consistency.
- Clause 8 — Operation. Evidence the risk treatment plan is actually being executed, not just written down.
- Clause 9 — Performance evaluation. Internal audit and management review — proof the ISMS checks itself, not just that it exists.
- Clause 10 — Improvement. Nonconformities and corrective actions. Auditors read this as a sign your ISMS can catch and fix its own problems.
- Annex A — 93 controls across four themes, selected based on your risk assessment. Browse the full list with plain-English explanations on our Annex A controls page.
Why this matters for your checklist
A self-led implementation that treats Annex A as the whole standard usually produces a Statement of Applicability that looks complete but isn't grounded in a real risk assessment — which is exactly the mismatch an auditor is trained to catch. Build clauses 4 through 6 first; Annex A gets easier and more defensible once it does.