Why Leadership Is the Hardest Clause to Audit in ISO 27001
Most auditors are comfortable in the weeds. They can sample access logs, check the Statement of Applicability, verify that risk treatment plans are signed off. What trips many auditors up is Clause 5, specifically the question of whether top management genuinely owns the Information Security Management System or whether they have simply allowed it to exist somewhere in the organisation while the IT team gets on with it.
On this page
ISO 27001 Clause 5.1 places direct obligations on top management. Not the CISO. Not the Information Security Manager. Top management. The standard requires that these leaders demonstrate commitment, not just endorse it on paper. That distinction matters enormously when you are sitting across from a CEO or a board representative in an audit interview.
This article is a practical guide to auditing ISMS leadership. It covers what evidence to look for, what questions to ask, how to recognise genuine commitment versus cosmetic compliance, and how to write a defensible finding when the evidence does not stack up.
What ISO 27001 Clause 5.1 Actually Requires
Before you can audit leadership commitment, you need to be precise about what the standard demands. Clause 5.1 of ISO 27001:2022 sets out twelve specific ways in which top management must demonstrate commitment to the ISMS. These include:
- Establishing the information security policy and objectives
- Ensuring the ISMS requirements are integrated into business processes
- Ensuring the necessary resources are available
- Communicating the importance of information security
- Directing people to contribute to ISMS effectiveness
- Supporting other relevant management roles to demonstrate their leadership
- Promoting continual improvement
- Supporting the ISMS to achieve its intended outcomes
None of these can be fully delegated. A manager can be assigned responsibility for day to day ISMS operations under Clause 5.3, but the commitment itself must come from the top. When you audit this clause, you are not looking for a policy document signed by the CEO three years ago. You are looking for current, observable, verifiable evidence that leadership is actively engaged.
Exemplar Global Recognised Training ProviderRTP No. 310970The Most Common Failure Mode: Delegation Without Oversight
In practice, the most frequent finding against Clause 5.1 is not that top management has done nothing. It is that they have delegated everything and then disengaged entirely. The IT Security Manager runs the risk assessment. The compliance team manages the audit programme. The CISO writes the reports. And the executive team receives a one page summary once a year at the management review, nods, and moves on.
This pattern looks fine on paper. The documents exist. The processes run. But when you interview the CEO or COO and ask them to describe the organisation's top three information security risks, they cannot answer. When you ask what decisions they made about the ISMS in the last six months, they have to check with someone else. When you ask whether the information security objectives are aligned with the business strategy, they look uncertain.
That is a leadership gap. And it is your job as an auditor to surface it through evidence, not impression.
Planning the Leadership Audit: Where to Start
Before you sit down with any executive, do your document review. You want to understand what the organisation claims about its leadership commitment before you test whether those claims hold up.
Documents to Request in Advance
- The information security policy, including the version date and who approved it
- Management review records from the last twelve months
- Meeting minutes or board papers that reference information security
- The ISMS scope document
- Information security objectives and any progress reports
- Resource allocation records, including budget approvals for security initiatives
- Any communication from top management about information security to staff
Work through these before the interview. Look for signatures, dates, and specificity. A policy signed five years ago by someone who has since left the organisation tells you something. Management review minutes that contain no discussion of ISMS performance, only a list of agenda items marked as noted, tell you something else.
Who to Interview
Interview at least one member of top management directly. In a smaller organisation, this might be the Managing Director or CEO. In a larger organisation, look for the person who has ultimate accountability for information security risk, which is often the COO, CRO, or a board committee chair.
Also interview the person assigned responsibility under Clause 5.3, typically the CISO or Information Security Manager. The contrast between what these two people say can be revealing. If the ISMS manager describes a system that is fully integrated into business decisions, but the executive cannot describe any of it, you have a disconnect worth investigating.
Interview Questions That Reveal Real Commitment
The quality of your audit interview determines whether you find the truth or just the rehearsed answer. Many organisations prepare their executives for audit interviews. That is not inherently a problem. But prepared answers tend to be general, and general answers are testable.
Opening Questions
Start broad and let the executive talk. You are listening for specificity, ownership, and awareness.
- Can you describe your organisation's approach to information security and how you are personally involved in it?
- What are the most significant information security risks the organisation faces at the moment?
- How does information security fit into the organisation's overall strategy?
A leader who genuinely owns the ISMS will answer these questions with specifics. They will name actual risks. They will reference actual decisions. They will connect information security to business outcomes, not just compliance requirements.
Probing Questions
Once you have the opening answer, probe for depth.
- You mentioned data breach risk. What controls has the organisation put in place to address that, and how do you know they are working?
- When did you last review the information security objectives? What changed as a result?
- If the ISMS manager came to you today and said a critical control had failed, what would happen next?
- How do you ensure that information security is considered when the organisation takes on a new supplier or launches a new service?
These questions are harder to answer from a briefing note. They require the executive to demonstrate actual knowledge of the system, not just awareness that it exists.
Resource Questions
Clause 5.1 specifically requires top management to ensure resources are available. This is one of the most concrete and testable requirements in the clause.
- How is the information security budget determined? Who approves it?
- Has there been a situation in the last twelve months where additional resources were needed for the ISMS? What happened?
- Are there any resource constraints affecting the ISMS right now?
Budget conversations reveal a great deal. If the executive cannot describe how security investment decisions are made, or if they indicate that the ISMS team has to fight for resources every year with no guaranteed baseline, that is relevant to your assessment of Clause 5.1 conformity.
Reading the Management Review Records
The management review is the formal mechanism through which top management evaluates ISMS performance. Under Clause 9.3, these reviews must consider specific inputs and produce documented outputs. But as an auditor focused on Clause 5.1, you are looking at the management review from a different angle: does it show that top management is engaged, informed, and making decisions?
Watch for these patterns in the records:
- Thin inputs: If the review record shows only a list of agenda items with no actual data, no performance metrics, no risk status updates, it suggests the review is a formality rather than a genuine evaluation.
- No decisions: A management review that produces no outputs, or only vague commitments to maintain the current approach, is not demonstrating the active oversight that Clause 5.1 requires.
- Wrong participants: If the review is attended only by the ISMS team with no actual top management representative present, that is a direct nonconformity against Clause 9.3 and also evidence of a Clause 5.1 gap.
- Infrequent reviews: ISO 27001 requires reviews at planned intervals. One review in three years is not conforming, regardless of how thorough it was.
Cross reference the review records with your interview findings. If the executive says they review ISMS performance quarterly but the records show one review in eighteen months, you have a discrepancy that needs to be followed up.
Auditing the Information Security Policy as a Leadership Artefact
The information security policy is required under Clause 5.2. But it is also one of the clearest indicators of whether top management is genuinely engaged with the ISMS or whether the policy was written by a consultant and signed without being read.
When you review the policy, look for:
- Whether it is appropriate to the organisation's purpose and context. A generic template policy that could apply to any business in any industry is a warning sign.
- Whether it includes information security objectives or a framework for setting them. A policy that contains no measurable direction is difficult to implement and impossible to evaluate.
- Whether it has been communicated to relevant parties. Ask the executive how staff were made aware of the policy. Ask a couple of staff members whether they know what the information security policy says.
- Whether it is available to interested parties as appropriate. This might mean external parties such as customers or suppliers, depending on the organisation's context.
A policy that was last reviewed three years ago, contains no reference to the organisation's current risk environment, and was approved by someone who no longer works there is not evidence of active leadership. It is evidence of a system running on autopilot.
For a deeper look at what an effective information security policy should contain, see our article on writing an information security policy that meets Clause 5.2.
Tracing Integration Into Business Processes
Clause 5.1 requires top management to ensure that ISMS requirements are integrated into the organisation's business processes. This is one of the most substantive requirements in the clause and one of the most commonly overlooked in audits that focus only on the ISMS documentation.
Integration means that information security is considered when the organisation makes business decisions, not just when it runs its annual risk assessment. Look for evidence of integration in:
New Product or Service Development
Ask whether information security is considered when the organisation develops a new product or service. Is there a formal process for assessing security requirements before launch? Can the executive point to an example where a security concern influenced a product decision?
Supplier and Vendor Management
Supplier relationships are a major source of information security risk. Ask how the organisation evaluates the security posture of new suppliers. Is there a process? Who approves exceptions? Has top management ever been involved in a supplier decision on security grounds?
Change Management
When the organisation makes significant operational or technical changes, is information security part of the change approval process? Ask for an example of a recent significant change and walk through how security was considered.
If information security only appears in the ISMS documents and not in the organisation's actual operating decisions, you have evidence of a system that is managed in isolation rather than integrated into the business.
Communication: What Does It Look Like in Practice?
Clause 5.1 requires top management to communicate the importance of information security and of conforming to ISMS requirements. This is an active obligation. It is not satisfied by a policy document sitting on the intranet.
Ask the executive directly: how do you communicate the importance of information security to staff? Look for examples such as:
- All staff communications from senior leadership about security incidents, risks, or expectations
- Security awareness campaigns that are visibly sponsored by senior leadership
- Messages at team meetings or company briefings where leadership has spoken about information security
- Onboarding materials that include a message from leadership about the organisation's security culture
Then test the claim. When you speak to staff during the audit, ask them whether they have heard from senior leadership about information security. Ask them what the organisation expects of them. If the answer is that they received a phishing simulation email once but have never heard leadership speak about why security matters, the communication requirement is not being met.
Recognising the Difference Between Conformity and Genuine Ownership
There is a meaningful difference between an organisation that conforms to Clause 5.1 on paper and one where top management genuinely owns the ISMS. As an auditor, you are looking for conformity, but you should also be honest about what you are observing.
Signs of genuine ownership include:
- Executives who can speak about information security risks without prompting or referring to notes
- Evidence that security considerations have influenced business decisions, not just ISMS documents
- A management review process that produces real outputs and drives real change
- Staff who associate information security with leadership expectations, not just IT rules
- A budget process where security investment is treated as a business priority, not an IT overhead
Signs of cosmetic compliance include:
- A signed policy that no one can explain
- Management review records that are detailed but contain no evidence of actual discussion
- Executives who refer every question to the ISMS manager
- Security objectives that have not changed in three years despite significant changes to the business
- Staff who have never heard leadership speak about information security
You cannot raise a nonconformity against an executive's attitude. But you can raise a nonconformity against the absence of documented evidence that top management has communicated the importance of information security, or that the management review produced outputs, or that the policy has been reviewed in line with the organisation's own schedule.
Writing the Finding When Leadership Evidence Is Weak
If your audit reveals that top management commitment is present in name but absent in practice, you need to write a finding that is specific, evidence based, and clearly linked to a clause requirement. Vague findings like top management could be more engaged with the ISMS will not drive corrective action.
A well written finding might read:
Clause 5.1 of ISO 27001:2022 requires top management to communicate the importance of information security and of conforming to ISMS requirements. During interviews with three staff members across two departments, none were able to identify any communication from top management regarding information security expectations in the preceding twelve months. The management review record dated [date] contains no reference to communication activities. No other evidence of top management communication was provided during the audit.
This finding is specific. It names the clause. It describes the evidence gathered and the gap identified. It does not make assumptions about intent. It gives the organisation something concrete to address.
For practical guidance on structuring findings like this, the article on how to gather audit evidence that stands up to scrutiny is worth reviewing before you plan your next ISMS audit.
Exemplar Global Recognised Training ProviderRTP No. 310970Practical Audit Tips for the Leadership Clause
A few practical points from experience conducting ISMS audits across a range of industries and organisation sizes:
- Do not accept the briefing note answer. When an executive gives you a polished, general answer, follow up with a specific example. Genuine knowledge survives follow up questions. Rehearsed answers often do not.
- Use the management review as your anchor. It is the most auditable expression of top management engagement. If the review is thin, follow that thread.
- Look for integration, not just documentation. The most important question is not whether the documents say the right things. It is whether information security is actually shaping business decisions.
- Cross reference your sources. What the executive says, what the ISMS manager says, what the records show, and what staff say should be broadly consistent. Significant gaps between these sources are worth investigating.
- Be fair. Top management in a small organisation may be deeply engaged with the ISMS without having formal records of every conversation. Look for the substance of engagement, not just its documentation. But where the standard requires documented evidence, the absence of documentation is still a finding.
Auditing leadership is also covered in detail in our article on how to audit top management without losing the room, which addresses the interpersonal dynamics of these interviews alongside the technical requirements.
Building Your Skills for ISMS Auditing
Auditing an Information Security Management System is a specialist skill. The technical environment is complex, the risks are significant, and the leadership clause requires a level of interpersonal confidence that takes practice to develop. If you are building your capability in this area, the right training makes a real difference.
Audit Workshop delivers ISO 27001 auditor training at Foundation, Internal Auditor, and Lead Auditor levels, all taught by Dilawar Laghari, a certified lead auditor with over 14 years of compliance experience and more than 500 external certification audits completed across Australia, the Middle East, and South Asia. The courses are built around real audit scenarios, not just standard text, and they give you the practical skills to audit leadership clauses with confidence, not just the technical controls.
Whether you are an information security professional looking to build your audit credentials, or a quality or compliance manager expanding into ISO 27001, the training is designed to get you audit ready quickly. Courses are available live and self paced to fit around your existing commitments.













