Common
Compliance Mistakes
After multiple ISO certifications and audits, these are the patterns that keep appearing, and how to fix them before the auditor finds them first.
1. Policies That Don't Reflect Reality
The most common finding: a polished Information Security Policy that describes a process nobody actually follows. Policies are written once, approved by management, and then forgotten in a SharePoint folder.
The fix: write policies after observing what actually happens. Then train staff on them. Then ask staff to describe the process, without looking at the document. If they can't, the policy isn't working.
2. Risk Register as a One-Time Exercise
Completing a risk assessment to get the certificate, then never touching the register again. Auditors will check the date of last review. A risk register last updated 18 months ago is an immediate finding.
The fix: schedule quarterly reviews in the calendar as recurring events. Assign an owner. Even a brief "no significant changes" entry is better than silence, as long as it's documented.
3. No Evidence of Awareness Training
Many organizations do security awareness training, they just don't document it. Attendance records, completion certificates, quiz results, even email confirmations of viewing a training video, all of these count as evidence.
The fix: whatever training platform you use, export and archive completion records. Keep them organized by year and employee. When an auditor asks "how do you ensure staff are trained?" you should be able to pull evidence in under two minutes.
4. Access Reviews That Never Happen
ISO 27001 requires periodic review of access rights. In practice, this means: someone must formally verify, at a defined interval, that every user has appropriate access, and that terminated employees, role changes, and project exits are reflected.
The fix: quarterly access reviews, documented in a simple spreadsheet or ticket. Manager confirms their team's access is correct. IT confirms the list matches. Any changes are recorded. Takes 30 minutes per department.
5. Supplier Contracts Without Security Clauses
You can have excellent internal security and then hand sensitive data to a supplier with no contractual obligations around how they protect it. Under ISO 27001 and GDPR, this is a gap, and a liability.
The fix: create a standard security annex for supplier contracts. Cover: data handling obligations, breach notification timelines, right to audit, sub-processor restrictions, and data return/deletion on contract end. Legal can help, but the requirements come from your security team.
6. Incident Response Plan That Was Never Tested
Having an IRP is required. Having one that has been tested, even in a tabletop exercise, is what separates organizations that contain incidents from those that panic through them.
The fix: run a tabletop exercise once a year. Pick a realistic scenario (ransomware, data breach, account compromise). Walk through the IRP step by step. Document what worked, what didn't, and update the plan accordingly.
7. Treating Compliance as IT's Problem
Information security compliance touches HR (onboarding/offboarding), Legal (contracts), Finance (vendor payments), and every department that handles data. When it's treated as purely an IT responsibility, the gaps in those other areas go unaddressed.
The fix: assign a compliance owner in each department. Their job is to be the local point of contact, to ensure their team follows policies, and to flag issues. IT manages the tools, compliance is everyone's responsibility.