Exemplar Global Certified Courses from USD 119. Ending Soon!

Auditing Leadership: Evidence That Top Management Owns the ISMS

AW

Team @ Audit Workshop

15 min read
Auditing Leadership: Evidence That Top Management Owns the ISMS

Why Leadership Is the Hardest Clause to Audit in ISO 27001

Most auditors are comfortable in the weeds. They can sample access logs, check the Statement of Applicability, verify that risk treatment plans are signed off. What trips many auditors up is Clause 5, specifically the question of whether top management genuinely owns the Information Security Management System or whether they have simply allowed it to exist somewhere in the organisation while the IT team gets on with it.

ISO 27001 Clause 5.1 places direct obligations on top management. Not the CISO. Not the Information Security Manager. Top management. The standard requires that these leaders demonstrate commitment, not just endorse it on paper. That distinction matters enormously when you are sitting across from a CEO or a board representative in an audit interview.

This article is a practical guide to auditing ISMS leadership. It covers what evidence to look for, what questions to ask, how to recognise genuine commitment versus cosmetic compliance, and how to write a defensible finding when the evidence does not stack up.

What ISO 27001 Clause 5.1 Actually Requires

Before you can audit leadership commitment, you need to be precise about what the standard demands. Clause 5.1 of ISO 27001:2022 sets out twelve specific ways in which top management must demonstrate commitment to the ISMS. These include:

  • Establishing the information security policy and objectives
  • Ensuring the ISMS requirements are integrated into business processes
  • Ensuring the necessary resources are available
  • Communicating the importance of information security
  • Directing people to contribute to ISMS effectiveness
  • Supporting other relevant management roles to demonstrate their leadership
  • Promoting continual improvement
  • Supporting the ISMS to achieve its intended outcomes

None of these can be fully delegated. A manager can be assigned responsibility for day to day ISMS operations under Clause 5.3, but the commitment itself must come from the top. When you audit this clause, you are not looking for a policy document signed by the CEO three years ago. You are looking for current, observable, verifiable evidence that leadership is actively engaged.

The Most Common Failure Mode: Delegation Without Oversight

In practice, the most frequent finding against Clause 5.1 is not that top management has done nothing. It is that they have delegated everything and then disengaged entirely. The IT Security Manager runs the risk assessment. The compliance team manages the audit programme. The CISO writes the reports. And the executive team receives a one page summary once a year at the management review, nods, and moves on.

This pattern looks fine on paper. The documents exist. The processes run. But when you interview the CEO or COO and ask them to describe the organisation's top three information security risks, they cannot answer. When you ask what decisions they made about the ISMS in the last six months, they have to check with someone else. When you ask whether the information security objectives are aligned with the business strategy, they look uncertain.

That is a leadership gap. And it is your job as an auditor to surface it through evidence, not impression.

Planning the Leadership Audit: Where to Start

Before you sit down with any executive, do your document review. You want to understand what the organisation claims about its leadership commitment before you test whether those claims hold up.

Documents to Request in Advance

  • The information security policy, including the version date and who approved it
  • Management review records from the last twelve months
  • Meeting minutes or board papers that reference information security
  • The ISMS scope document
  • Information security objectives and any progress reports
  • Resource allocation records, including budget approvals for security initiatives
  • Any communication from top management about information security to staff

Work through these before the interview. Look for signatures, dates, and specificity. A policy signed five years ago by someone who has since left the organisation tells you something. Management review minutes that contain no discussion of ISMS performance, only a list of agenda items marked as noted, tell you something else.

Who to Interview

Interview at least one member of top management directly. In a smaller organisation, this might be the Managing Director or CEO. In a larger organisation, look for the person who has ultimate accountability for information security risk, which is often the COO, CRO, or a board committee chair.

Also interview the person assigned responsibility under Clause 5.3, typically the CISO or Information Security Manager. The contrast between what these two people say can be revealing. If the ISMS manager describes a system that is fully integrated into business decisions, but the executive cannot describe any of it, you have a disconnect worth investigating.

Interview Questions That Reveal Real Commitment

The quality of your audit interview determines whether you find the truth or just the rehearsed answer. Many organisations prepare their executives for audit interviews. That is not inherently a problem. But prepared answers tend to be general, and general answers are testable.

Opening Questions

Start broad and let the executive talk. You are listening for specificity, ownership, and awareness.

  • Can you describe your organisation's approach to information security and how you are personally involved in it?
  • What are the most significant information security risks the organisation faces at the moment?
  • How does information security fit into the organisation's overall strategy?

A leader who genuinely owns the ISMS will answer these questions with specifics. They will name actual risks. They will reference actual decisions. They will connect information security to business outcomes, not just compliance requirements.

Probing Questions

Once you have the opening answer, probe for depth.

  • You mentioned data breach risk. What controls has the organisation put in place to address that, and how do you know they are working?
  • When did you last review the information security objectives? What changed as a result?
  • If the ISMS manager came to you today and said a critical control had failed, what would happen next?
  • How do you ensure that information security is considered when the organisation takes on a new supplier or launches a new service?

These questions are harder to answer from a briefing note. They require the executive to demonstrate actual knowledge of the system, not just awareness that it exists.

Resource Questions

Clause 5.1 specifically requires top management to ensure resources are available. This is one of the most concrete and testable requirements in the clause.

  • How is the information security budget determined? Who approves it?
  • Has there been a situation in the last twelve months where additional resources were needed for the ISMS? What happened?
  • Are there any resource constraints affecting the ISMS right now?

Budget conversations reveal a great deal. If the executive cannot describe how security investment decisions are made, or if they indicate that the ISMS team has to fight for resources every year with no guaranteed baseline, that is relevant to your assessment of Clause 5.1 conformity.

Reading the Management Review Records

The management review is the formal mechanism through which top management evaluates ISMS performance. Under Clause 9.3, these reviews must consider specific inputs and produce documented outputs. But as an auditor focused on Clause 5.1, you are looking at the management review from a different angle: does it show that top management is engaged, informed, and making decisions?

Watch for these patterns in the records:

  • Thin inputs: If the review record shows only a list of agenda items with no actual data, no performance metrics, no risk status updates, it suggests the review is a formality rather than a genuine evaluation.
  • No decisions: A management review that produces no outputs, or only vague commitments to maintain the current approach, is not demonstrating the active oversight that Clause 5.1 requires.
  • Wrong participants: If the review is attended only by the ISMS team with no actual top management representative present, that is a direct nonconformity against Clause 9.3 and also evidence of a Clause 5.1 gap.
  • Infrequent reviews: ISO 27001 requires reviews at planned intervals. One review in three years is not conforming, regardless of how thorough it was.

Cross reference the review records with your interview findings. If the executive says they review ISMS performance quarterly but the records show one review in eighteen months, you have a discrepancy that needs to be followed up.

Auditing the Information Security Policy as a Leadership Artefact

The information security policy is required under Clause 5.2. But it is also one of the clearest indicators of whether top management is genuinely engaged with the ISMS or whether the policy was written by a consultant and signed without being read.

When you review the policy, look for:

  • Whether it is appropriate to the organisation's purpose and context. A generic template policy that could apply to any business in any industry is a warning sign.
  • Whether it includes information security objectives or a framework for setting them. A policy that contains no measurable direction is difficult to implement and impossible to evaluate.
  • Whether it has been communicated to relevant parties. Ask the executive how staff were made aware of the policy. Ask a couple of staff members whether they know what the information security policy says.
  • Whether it is available to interested parties as appropriate. This might mean external parties such as customers or suppliers, depending on the organisation's context.

A policy that was last reviewed three years ago, contains no reference to the organisation's current risk environment, and was approved by someone who no longer works there is not evidence of active leadership. It is evidence of a system running on autopilot.

For a deeper look at what an effective information security policy should contain, see our article on writing an information security policy that meets Clause 5.2.

Tracing Integration Into Business Processes

Clause 5.1 requires top management to ensure that ISMS requirements are integrated into the organisation's business processes. This is one of the most substantive requirements in the clause and one of the most commonly overlooked in audits that focus only on the ISMS documentation.

Integration means that information security is considered when the organisation makes business decisions, not just when it runs its annual risk assessment. Look for evidence of integration in:

New Product or Service Development

Ask whether information security is considered when the organisation develops a new product or service. Is there a formal process for assessing security requirements before launch? Can the executive point to an example where a security concern influenced a product decision?

Supplier and Vendor Management

Supplier relationships are a major source of information security risk. Ask how the organisation evaluates the security posture of new suppliers. Is there a process? Who approves exceptions? Has top management ever been involved in a supplier decision on security grounds?

Change Management

When the organisation makes significant operational or technical changes, is information security part of the change approval process? Ask for an example of a recent significant change and walk through how security was considered.

If information security only appears in the ISMS documents and not in the organisation's actual operating decisions, you have evidence of a system that is managed in isolation rather than integrated into the business.

Communication: What Does It Look Like in Practice?

Clause 5.1 requires top management to communicate the importance of information security and of conforming to ISMS requirements. This is an active obligation. It is not satisfied by a policy document sitting on the intranet.

Ask the executive directly: how do you communicate the importance of information security to staff? Look for examples such as:

  • All staff communications from senior leadership about security incidents, risks, or expectations
  • Security awareness campaigns that are visibly sponsored by senior leadership
  • Messages at team meetings or company briefings where leadership has spoken about information security
  • Onboarding materials that include a message from leadership about the organisation's security culture

Then test the claim. When you speak to staff during the audit, ask them whether they have heard from senior leadership about information security. Ask them what the organisation expects of them. If the answer is that they received a phishing simulation email once but have never heard leadership speak about why security matters, the communication requirement is not being met.

Recognising the Difference Between Conformity and Genuine Ownership

There is a meaningful difference between an organisation that conforms to Clause 5.1 on paper and one where top management genuinely owns the ISMS. As an auditor, you are looking for conformity, but you should also be honest about what you are observing.

Signs of genuine ownership include:

  • Executives who can speak about information security risks without prompting or referring to notes
  • Evidence that security considerations have influenced business decisions, not just ISMS documents
  • A management review process that produces real outputs and drives real change
  • Staff who associate information security with leadership expectations, not just IT rules
  • A budget process where security investment is treated as a business priority, not an IT overhead

Signs of cosmetic compliance include:

  • A signed policy that no one can explain
  • Management review records that are detailed but contain no evidence of actual discussion
  • Executives who refer every question to the ISMS manager
  • Security objectives that have not changed in three years despite significant changes to the business
  • Staff who have never heard leadership speak about information security

You cannot raise a nonconformity against an executive's attitude. But you can raise a nonconformity against the absence of documented evidence that top management has communicated the importance of information security, or that the management review produced outputs, or that the policy has been reviewed in line with the organisation's own schedule.

Writing the Finding When Leadership Evidence Is Weak

If your audit reveals that top management commitment is present in name but absent in practice, you need to write a finding that is specific, evidence based, and clearly linked to a clause requirement. Vague findings like top management could be more engaged with the ISMS will not drive corrective action.

A well written finding might read:

Clause 5.1 of ISO 27001:2022 requires top management to communicate the importance of information security and of conforming to ISMS requirements. During interviews with three staff members across two departments, none were able to identify any communication from top management regarding information security expectations in the preceding twelve months. The management review record dated [date] contains no reference to communication activities. No other evidence of top management communication was provided during the audit.

This finding is specific. It names the clause. It describes the evidence gathered and the gap identified. It does not make assumptions about intent. It gives the organisation something concrete to address.

For practical guidance on structuring findings like this, the article on how to gather audit evidence that stands up to scrutiny is worth reviewing before you plan your next ISMS audit.

Practical Audit Tips for the Leadership Clause

A few practical points from experience conducting ISMS audits across a range of industries and organisation sizes:

  • Do not accept the briefing note answer. When an executive gives you a polished, general answer, follow up with a specific example. Genuine knowledge survives follow up questions. Rehearsed answers often do not.
  • Use the management review as your anchor. It is the most auditable expression of top management engagement. If the review is thin, follow that thread.
  • Look for integration, not just documentation. The most important question is not whether the documents say the right things. It is whether information security is actually shaping business decisions.
  • Cross reference your sources. What the executive says, what the ISMS manager says, what the records show, and what staff say should be broadly consistent. Significant gaps between these sources are worth investigating.
  • Be fair. Top management in a small organisation may be deeply engaged with the ISMS without having formal records of every conversation. Look for the substance of engagement, not just its documentation. But where the standard requires documented evidence, the absence of documentation is still a finding.

Auditing leadership is also covered in detail in our article on how to audit top management without losing the room, which addresses the interpersonal dynamics of these interviews alongside the technical requirements.

Building Your Skills for ISMS Auditing

Auditing an Information Security Management System is a specialist skill. The technical environment is complex, the risks are significant, and the leadership clause requires a level of interpersonal confidence that takes practice to develop. If you are building your capability in this area, the right training makes a real difference.

Audit Workshop delivers ISO 27001 auditor training at Foundation, Internal Auditor, and Lead Auditor levels, all taught by Dilawar Laghari, a certified lead auditor with over 14 years of compliance experience and more than 500 external certification audits completed across Australia, the Middle East, and South Asia. The courses are built around real audit scenarios, not just standard text, and they give you the practical skills to audit leadership clauses with confidence, not just the technical controls.

Whether you are an information security professional looking to build your audit credentials, or a quality or compliance manager expanding into ISO 27001, the training is designed to get you audit ready quickly. Courses are available live and self paced to fit around your existing commitments.

Frequently Asked Questions

Clause 5.1 requires top management to demonstrate commitment to the ISMS in twelve specific ways, including establishing the information security policy, ensuring resources are available, communicating the importance of information security, and integrating ISMS requirements into business processes. These obligations cannot be fully delegated. The standard distinguishes between the responsibility that can be assigned to an ISMS manager under Clause 5.3 and the commitment that must come from top management itself.
Start Learning

Ready to Build Real Audit Skills?

Join practitioners training with ISO auditors who've conducted 500+ external certification audits.

ISO 9001:2026 Lead Auditor Training Course
Launching on 22 Sept 20265+ enrolled
View Details
Exemplar Global certified
ISO 9001:2026 Lead Auditor Training Course badge
ISO 9001:2026 Lead Auditor

Quality Management Systems (QMS)

Lead AuditorSelf-Paced OnlineDigital BadgeVideo Lessons
USD 299USD 789
ISO 45001:2018 Lead Auditor Training Course
15+ enrolled
View Details
Exemplar Global certified
ISO 45001:2018 Lead Auditor Training Course badge
ISO 45001:2018 Lead Auditor

Occupational Health and Safety Management Systems (OHSMS)

Lead AuditorSelf-Paced OnlineDigital BadgeVideo Lessons
USD 249USD 789
ISO 14001:2026 Lead Auditor Training Course
10+ enrolled
View Details
Exemplar Global certified
ISO 14001:2026 Lead Auditor Training Course badge
ISO 14001:2026 Lead Auditor

Environmental Management Systems (EMS)

Lead AuditorSelf-Paced OnlineDigital BadgeVideo Lessons
USD 249USD 789
Exemplar Global Recognised Training Provider digital badge

Audit Workshop is an Exemplar Global Recognised Training Provider

Globally Recognised, Certified Training

Pass an Exemplar Global Certified course and you earn a Certificate of Attainment and an Exemplar Global digital badge. Audit Workshop graduates can apply for third-party Personnel Certification through Exemplar Global.

  • 12 months of Graduate certification
  • Access to Exemplar Global Community
  • Digital badges and a certificate
  • Access to webinars, events, and online resources

Learn Anytime

No fixed schedule. Start, pause, and pick up exactly where you left off.

Practical Content

Every lesson is built from real-world ISO auditing experience.

Instant Certificate

Download your digital certificate the moment you complete the course.

Lifetime Access

Course materials are yours to keep and revisit long after you complete.