ISO27001:2022 – A5.35 – Independent review of information security

Introduction to ISO 27001 – A5.35

If your ISO27001 management system is going to be effective, you need to ensure there is an independent review of everything that you’re doing. That’s exactly what ISO 27001 – A5.35 is about—maintaining objectivity, planning reviews, and evaluating how information security is implemented across people, processes, and technologies.

What does the standard require?

“The organisation’s approach to managing information security and its implementation including people, processes and technologies shall be reviewed independently at planned intervals, or when significant changes occur.”

(ISO 27001 – A5.35 – Independent Review of Information Security)

Key phrases to note:

  • Independently reviewed – Reviews must be objective and not self-assessed.
  • Planned intervals – Reviews should follow a schedule.
  • People, processes, and technology – Reviews must consider all aspects of your ISMS.

Why is this required?

The phrase “you can’t mark your own homework” applies perfectly here. Independent reviews provide objectivity, clarity, and assurance. They help uncover blind spots or gaps that internal stakeholders may miss due to familiarity, bias, or workload.

One example involved a business facing frequent outages. Their IT Manager claimed all tools were functioning correctly. But an independent audit found overlooked misconfigurations. The IT Manager wasn’t negligent—they simply lacked the time and perspective. Independence revealed the root causes.

What the auditor is looking for

  • A review schedule or audit plan that includes internal and external reviews.
  • Evidence of objectivity – Who did the review? Was it internal but independent, or was a third party used?
  • Review outputs – Audit reports, minutes, findings, and follow-up actions.
  • Coverage of all ISMS areas – This includes technology, process, and personnel aspects.

What do you need to do?

  1. Develop an internal audit plan that spans the ISMS lifecycle.
  2. Define objectivity for your organisation. For small businesses, this may mean inter-departmental audits or rotating responsibilities.
  3. Identify other business reviews already happening—penetration testing, IT risk assessments, finance audits, health & safety checks—and document them.
  4. Track all results and follow up with corrective actions where necessary.
  5. Ensure your external certification audit isn’t the only independent check. That’s an “OFI” waiting to happen.

Q & A

Is it possible to get this wrong?

Yes—particularly if you rely solely on internal teams with no attempt to show objectivity. If you don’t have a plan or record of independent reviews, expect a finding during audit. 

Do I have to audit all 93 Annex A controls annually?

No. Nowhere in the standard does it say all 93 controls must be reviewed every year. Adopt a risk-based audit approach. Review high-risk controls more frequently and lower-risk ones less so, across the 3-year ISO27001 certification cycle.

What if my team is too small?

Consider upskilling a colleague from a different department or bringing in an external auditor. Independence is more about objectivity and impartiality than job title.

Difficulty Rating

1 out of 5 – This control is easy to understand and implement but requires planning and consistency. Objectivity must be demonstrated—so document your audit plan, define independence, and track who conducts your reviews.

Final Tip

Ask yourself: “If we had a major breach tomorrow, could we prove our controls were independently reviewed?” If the answer is no, it’s time to adjust your process.

We are ISO 27001 Consultants who provide ‘Compliance without Complexity’® and we know we can help you… we even wrote a book about it. For more information on how to implement ISO 27001, written by ISO 27001 consultants like us, you should buy our book…The Real Easy Guide to ISO27001 – available now on Amazon.

ISO 27001 – A5.35