Why SMEs Fail ISO 27001 Audits

Why SMEs Fail ISO 27001 (And What It Really Takes to Succeed)

SPOILER: Most organisations don’t fail certification because they lack documentation. They fail because they mistake a management system for a compliance project. If you want to know more… read on.

NB: AI was used in this post – ACTUAL Intelligence and a bit of Yorkshire honesty! 😅

INTRODUCTION

If you’ve spent any time in the ISO 27001 world, you’ll have heard the same post-mortem over and over. A well-intentioned SME spends months building a set of policies and procedures, books a certification audit and then hits a wall of major nonconformities they never saw coming.

The problems are pretty familiar and often seen;

  • leadership that can’t explain the scope,
  • risk assessments that bare’s no relationship to operational reality,
  • internal audits hurriedly completed the week before Stage 2(!)

But these are actually visible symptoms of a problem, not causes. After years of working with organisations at every stage of certification, I find that the root cause is almost always the same:

“They were trying to pass an audit rather than build a management system.”

Let’s start by saying something that needs to be said… ISO 27001 is not a documentation standard. It is a management system standard! (key word – ‘management’; a noun ‘the act of managing and controlling’)

I’m going to get in to this in more detail, but let’s be very clear – If you’re approaching ISO 27001 like it’s an ‘admin problem’, then do yourself a favour and save yourself some money and STOP! It’s honestly not worth the headache and heartache (and you’ll save me having to explain why your ‘paper shield’ failed to protect you when the brown sticky-stuff hit the oscilating equipment!!)

I say this because it’s this distinction that changes everything about how certification should be approached.

Ok… now I’ve got that off my chest, let’s look at seven mistakes that I think derail SME’s when they try and implement ISO 27001. We’ll start at number seven and go down to the number 1 slot (just like they do on ‘Top of the flops’! (why seven? No idea… I just stopped at seven – I could go on longer, but seven felt about right).

ISO27001 - Policies

Mistake No 7: Treating ISO 27001 as a documentation exercise 

Ok, I might have mentioned this one at the start, but it bares repeating…

The most pervasive misconception is that an ISMS is a collection of policies and documented procedures. I think this arks back to the ‘ISO9001 Quality Manual’ days, when people thought you had to document EVERYTHING (“Process #1 – “How to make a cup of tea”(!)). 

That’s the bad old days. But we still see organisations buy policy template packs or using ChatGPT to create bland, ugly and irrelevant documents. Then they spend weeks formatting them and arrive at Stage 2 with what they think are impressive-looking ISMS files…  And then the auditors see through it within minutes (HINT: Auditors can smell fresh ink on a policy like a mouse can smell fresh cheese!)

Sometimes SMEs will find their way in to ISO 27002 (the guidance) and will document a whole raft of things that aren’t even relevant (rmember ISO27001 talks about ‘should’, noit ‘shall’).

Keep in mind that controls documented in policies that no employee has read, understands or follows are not controls at all, and auditors are trained to test whether the management system actually operates effectively (key word).

Auditors interview staff, observe processes, and trace decisions back to documented procedures. A “paper system” is identified quickly and the resulting nonconformities typically run deep, because the gap between documentation and reality goes deep and is not a surface level problem.

The FIX: Stop asking “do we have a policy for this?” and start asking “What do we actually do?”, “Can we demonstrate it?” and “Do we need to document it?”. Just keep in mind that ISO 27001 is meant to certify you have a management system not a set of documents!

 

ISO 27001 Compliance

Mistake No 6: Leadership sign the policy and then disappear!

Clause 5 of ISO 27001:2022 is unambiguous. Top management must demonstrate leadership and commitment. They must establish the information security policy, ensure integration into business processes, direct and support persons contributing to the ISMS, and promote continual improvement. These are not box-ticking obligations. They are structural requirements for the system to function.

But it is common for leadership to delegate ISO entirely to a quality manager, a compliance officer, or an external consultant, and treat it as an IT project with an admin burden. The result is therefore predictable. When employees observe that senior management doesn’t know what the ISMS covers, or worse… when they see and hear senor management role-their-eyes or sigh at the prospect of attending security meetings, the rest of the business also see it as a burden and something to avoid.

If Top Management can’t articulate the organisation’s top information security risks, can’t eplain why ISO 27001 is important or doesn’t attend management reviews, the message is received clearly: this is someone else’s project.

Let me be blunt here – An ISMS without visible leadership commitment will not survive its first surveillance audit. The tone from the top isn’t a soft cultural nicety. It’s a hard audit criterion (often the ‘soft’ can be the hardest thing to do!)

So let me be REALLY blunt… If Top Management can’t demonstrate they’re invested in this process, then stop now. Go do something more interesting and save yourself the headache and the money.

THE FIX: You need Top Management onboard so have a clear understanding of the benefits of ISO 27001 before you start. Understand it from the business perspective and apply it pragmatically in your business.

ISO 27001 and ISO 42001

Mistake 05: Getting the scope wrong from the start

Scoping is one of the most consequential early decisions in any ISO 27001 implementation, and one of the most frequently botched. Keep in mind that to ‘scope’ something is to determine what needs to be examined.

Unfortunartely when it comes to ‘scoping’ ISO 27001, SMEs often go in one of two directions: scoping so broadly that the ISMS becomes unmanageable, or scoping so narrowly that auditors question whether the certification has any meaningful coverage.

But a poorly defined scope creates cascading problems. Assets, processes, third parties, and interfaces that sit at the boundary of an unclear scope create confusion, and confusion creates nonconformities.

  • “Is this function in or out of scope?”
  • “Is this system in or out of scope?”
  • “Shall we keep the scope focused on product or service?”

These are all conversations we’ve heard after a scope has been set, which means the scope hasn’t been fully or correctly defined.

In ISO 27001 terms, the scope defines everything that follows: the information assets you must protect, the risks you must assess, the controls you must implement, and the interfaces you must manage.

The right scope is not the widest possible scope or the most defensible scope. It is the scope that reflects how the business actually operates and where the meaningful information security risks sit. That requires genuine organisational understanding, not a template.

THE FIX: Certification succeeds when scope follows business reality.  Work with your Top Management to understand why you’re implementing ISO 27001 and what’s critical. From here you can set out a realistic scope.

    ISO 27001 and ISO 42001 confusion

    Mistake No 4: Risk Management becomes a spreadsheet exercise (and a beast!)

    I honestly struggled with this ‘mistake’ because I considered putting it at number 1 (it’s THAT important)! Why?

    Risk Management is the beating heart of ISO 27001:2022, security and business.

    Clause 6 requires organisations to define a risk assessment process, identify risks to the confidentiality, integrity and availability of information, evaluate and treat those risks, and maintain documented evidence.

    This may surprise you to hear but Annex A controls (all 93 of them(!) in the 2022 edition) are NOT a mandatory implementation checklist. Shocking right?! But it’s true. They are a reference set from which applicable controls are selected based on risk.

    But in practice, many SMEs perform a risk assessment as a one-time exercise, complete a Statement of Applicability that bears limited relationship to their actual risk landscape, and consider the matter closed until the next audit cycle.

    The question you should be asking is; “Why have we implemented this control? Is it based on a risk?” If there’s no risk, then why the need for the control?

    Experienced auditors look for evidence that risk management is a living process – they’re not looking for another spreadsheet that is just a pandoras box of all the problems in your business(!).

    Auditors expect to see that new assets and threats are captured, that risk treatment decisions are traceable to specific identified risks, and that the risk register is reviewed when the business changes. A risk assessment completed in February that doesn’t reflect a major new cloud platform deployed in March is not risk management. It’s just risk theatre.

    I could go on about Risk Management (it’s another one of my favourite topics!), but in order to keep this blog on point I just want to repeat by saying that risk management is at the heart of whatwe do in security and and business.  If you make a decision to open a new office, then there are risks associated to it. So why haven’t you documented what those risks are and how you’re going to control them? Making risk based decisions ensures you don’t get blind sided and hit with something you never considered.

    THE FIX: Risk management is not a document. It’s how you decide what matters, so speak to your business about their objectives and understand whats happening in the business. Consider the risks at regular intervals, not just at a 6hr ‘Risk Workshop’ (which everyone will dread and will result in little more than a long list of ‘bad stuff’ you think will impress an auditor (but it won’t!).

    ISO27001 and FCA relationships

    Mistake No3: Building the ISMS around a single person

    This failure is especially common in SMEs, where resource constraints make it tempting to concentrate ISMS ownership to one person. One individual writes the policies, manages the asset register, coordinates the internal audit programme, liaises with the certification body, and becomes the institutional memory of the entire system.

    The system appears to function right up until that person takes extended leave, moves to a new role, becomes overwhelmed or leaves because now they are skilled ISO 27001 professionals! At that point, the ISMS effectively ceases to operate, because no one else understands it, owns it, or has been involved in it.

    A management system, by definition, must be embedded in how the organisation works, not dependent on one person’s knowledge and effort.

    ISO 27001 requires that roles, responsibilities and authorities are assigned and communicated. That means distributed ownership, documented processes that others can follow, and an information security function that outlasts any single individual.

    When I review an organisations ISMS I’m looking for policies, risks and processes that are owned by different people. If I see that all risks are owned by one individual then I’m going to know instantly the business isn’t really involved (and if I’ve noticed it, you can bet that an experienced auditor will too!)

    THE FIX: Spread the love! Involve other people in the process of building your ISMS.  Even in small businesses this is possible because not all risks can (or should) be owned by one person.  If you’re struggling with this one, this is where Consultants Like Us come in, or your outsurced HR or IT functions.  Security is a team sport – if one person owns ISO, nobody owns ISO. 

    ISO 27001

    Mistake No2: Treating audits as bureaucratic hurdles

    This goes back to mistake number 6, where leaders aren’t truly engaged in the process and see the whole process as a burden.

    Internal audits and management reviews occupy a specific and important position in the ISO 27001 framework. Clauses 9.2 and 9.3 are not administrative formalities they are the mechanisms by which an organisation monitors whether its ISMS is achieving its intended outcomes and driving continual improvement (a fundamental requirement of ISO 27001).

    Organisations that rush their internal audits, complete them without genuine independence, or produce management review minutes that say everything is fine regardless of the evidence, are not maintaining an ISMS. They are simply going through the motions and ultimately the ISMS will not deliver what it’s meant to deliver (a more secure business).

    The purpose of an internal audit is to find problems before the certification body does, or worse – before ‘bad actors’ do! 

    Ask yourself this…Who would you rather find that your access controls aren’t being managed effectively? An auditor or a hacker who manages to gain access to your network through weak access controls or elevated priveleges?

    A clean internal audit report in an immature system is not a reassuring sign. it is a warning sign. When a Stage 2 audit surfaces major nonconformities that a competent internal audit should have caught months earlier, the certification body’s confidence in the entire system is undermined.

    THE FIX: Internal audits are supposed to give you confidence that controls are in place and are operating effectively.  Audits aren’t there to ‘find fault’. Ensure audits are carred out regularly (based on risk) by competent, trained and experienced auditors. If this means going external to your business, or sending people on training courses then so-be-it; Just remember the requirement is for ‘independent internal audits’.

    ISO 27001 Man at desk

     Mistake No1: Treating Certification as a ‘finishing line’

    And here we are at Number 1, and the this may be the most expensive mistake of all. Organisations work intensively toward initial certification, achieve the certificate, and then… stop(!)

    Processes that were monitored closely during implementation begin to drift. Documentation goes stale. Training lapses. Controls weaken. Management Reviews and audits drop out of the calendar in favour of the next ‘big project’.  

    Staff awareness built before the audit fades and by the time the first annual surveillance audit arrives, the ISMS has digital dust and moss all over it!

    Nonconformities that weren’t present at certification have appeared and the auditor’s first question; “what has changed since certification?”, exposes an organisation that has not treated its ISMS as a living system and then major noncomformities start to appear, putting at risk the certification.

    THE FIX: ISO 27001 is built around the Plan-Do-Check-Act cycle. Certification validates that a management system exists and is operating. It is intended to be the beginning of system maturity, not its conclusion. Organisations that understand this invest in the ongoing activity that keeps the system effective: regular risk reviews, updated training, continuous monitoring, and an audit programme that genuinely challenges the system.

    More questions?

    These seven mistakes are not independent failures. They are expressions of a single underlying misconception: that ISO 27001 is a compliance project with a defined end, rather than a management discipline that improves how an organisation manages information security risk on an ongoing basis.

    Let me say this clearly for those at the back of the class… The organisation that copies templates or uses AI to produce a document library will fail.

    The organisation that builds a system, understood by its people, owned by its leadership, grounded in its actual risk landscape, and subject to genuine monitoring and review will not just achieve certification; They will maintain it, and derive real security value from it.

    ISO 27001 was never designed to produce certificates. It was designed to produce more secure organisations. The certificate is the evidence that the system is working, not the proof that a project has concluded.

    Every certification failure, weak leadership, poor risk management, inadequate audits, disengaged employees, documentation that no one follows, traces back to one decision made at the outset:

    “Are we trying to pass an audit, or are we trying to improve how we manage information security for the benefit of our business and our customers?”

    The answer to that question determines everything that follows.

    If this resonates and you’re wondering where to start making changes for the better, or you’d like some support to refresh your approach to maintaining your ISMS, the pit stop crew at Consultants Like Us are happy to help!

    We are ISO 27001 Consultants who provide ‘Compliance without Complexity’® and we know we can help you… we even wrote a book about it. For more information on how to implement ISO 27001, written by ISO 27001 consultants like us, you like to consider buying our book, “The Real Easy Guide to ISO27001” which is available on Amazon. 

    If you’d like to talk through any of the points above, please get in touch.

    Whether it’s to discuss if ISO 27001 is right for you or to help understand how to approach other ISO standards (like ISO 42001 for Artificial Intelligence Management) then contact us today for a FREE consultation.