Compliance · Audit March 2026

Common
Compliance Mistakes

After multiple ISO certifications and audits, these are the patterns that keep appearing, and how to fix them before the auditor finds them first.

1. Policies That Don't Reflect Reality

The most common finding: a polished Information Security Policy that describes a process nobody actually follows. Policies are written once, approved by management, and then forgotten in a SharePoint folder.

The fix: write policies after observing what actually happens. Then train staff on them. Then ask staff to describe the process, without looking at the document. If they can't, the policy isn't working.

2. Risk Register as a One-Time Exercise

Completing a risk assessment to get the certificate, then never touching the register again. Auditors will check the date of last review. A risk register last updated 18 months ago is an immediate finding.

The fix: schedule quarterly reviews in the calendar as recurring events. Assign an owner. Even a brief "no significant changes" entry is better than silence, as long as it's documented.

PatternCompliance treated as a project has a start date, an end date (the audit), and then silence. Compliance treated as a process is never finished, it just keeps running quietly in the background.

3. No Evidence of Awareness Training

Many organizations do security awareness training, they just don't document it. Attendance records, completion certificates, quiz results, even email confirmations of viewing a training video, all of these count as evidence.

The fix: whatever training platform you use, export and archive completion records. Keep them organized by year and employee. When an auditor asks "how do you ensure staff are trained?" you should be able to pull evidence in under two minutes.

4. Access Reviews That Never Happen

ISO 27001 requires periodic review of access rights. In practice, this means: someone must formally verify, at a defined interval, that every user has appropriate access, and that terminated employees, role changes, and project exits are reflected.

The fix: quarterly access reviews, documented in a simple spreadsheet or ticket. Manager confirms their team's access is correct. IT confirms the list matches. Any changes are recorded. Takes 30 minutes per department.

5. Supplier Contracts Without Security Clauses

You can have excellent internal security and then hand sensitive data to a supplier with no contractual obligations around how they protect it. Under ISO 27001 and GDPR, this is a gap, and a liability.

The fix: create a standard security annex for supplier contracts. Cover: data handling obligations, breach notification timelines, right to audit, sub-processor restrictions, and data return/deletion on contract end. Legal can help, but the requirements come from your security team.

6. Incident Response Plan That Was Never Tested

Having an IRP is required. Having one that has been tested, even in a tabletop exercise, is what separates organizations that contain incidents from those that panic through them.

The fix: run a tabletop exercise once a year. Pick a realistic scenario (ransomware, data breach, account compromise). Walk through the IRP step by step. Document what worked, what didn't, and update the plan accordingly.

Auditor perspectiveAuditors aren't looking for perfection. They're looking for evidence that you have a system, that it runs, and that you improve it when it fails. A well-documented near-miss with a proper corrective action is more impressive than a clean record with no evidence of anything.

7. Treating Compliance as IT's Problem

Information security compliance touches HR (onboarding/offboarding), Legal (contracts), Finance (vendor payments), and every department that handles data. When it's treated as purely an IT responsibility, the gaps in those other areas go unaddressed.

The fix: assign a compliance owner in each department. Their job is to be the local point of contact, to ensure their team follows policies, and to flag issues. IT manages the tools, compliance is everyone's responsibility.