How to keep ISO 27001 Policies “Alive” between audits

Consultants Like Us are great believers in collaboration. and celebrating great tools when we see them.  This is why, after meeting with dayspring software we asked them to write a blog about their ISO 27001 platform which solves a very particular problem for those who have achieved certification….  If you’ve ever struggled with the management of your polices and documentation, then read on and get in touch with Consultants Like Us or dayspring to learn more.

ISO27001 Certified – Now what?

You did it: you’re ISO 27001 certified. The audit is complete, the certification badge is on your website, and the pressure is off – at least for now.

For many organisations, achieving ISO 27001 certification is treated as the end of a long and demanding process. In reality, it marks the beginning of a quieter, ongoing challenge: keeping policies version-controlled, up to date, and actively used across the organisation long after the auditors have left.

Certification is the starting point, not the finish line. The standard requires organisations to maintain and continually improve their Information Security Management System (ISMS). In practice, that means policies can’t simply sit in shared drives, collecting digital dust until the next surveillance audit.

The good news is that keeping policies “alive” doesn’t have to mean hours of admin every month. It just needs a system. Here’s how to do it without it taking over your life.

ISO 27001 Risk Meeting

What do we mean by keeping policies “alive”?

When auditors conduct your surveillance audit, they’ll expect to see evidence that since your last audit policies have been reviewed, any changes have been communicated to the people they apply to, and that these documents are embedded in day-to-day operations – not just written and filed away.

Specifically, they’re looking for three things:

  1. There’s a clear audit trail: who changed what, when, and why.
  2. Reviews happened on schedule: this maps directly to the standard’s requirement for regular review and continual improvement. Missed or inconsistent reviews are a common finding.
  3. Staff knew about changes: when a policy was updated, the right people were informed, read and acknowledged the new version. This is crucial for demonstrating that policies are actually in use.

If your answer is “we reviewed it, but I can’t say when or what changed” or “they said they’d read it in an email somewhere,” that’s a gap.

ISO 27001 Incident Response

Can SharePoint and Shared Drives Manage ISO 27001 Policies Effectively?

Most SMBs land on SharePoint, Google Drive, or a shared folder as their policy home. And honestly, for storing documents? They’re fine. The problem is that they don’t govern policies – they just store them.

There are no automatic email reminders when a policy’s annual review is due. No structured version history with a clear record of what changed and when. No time-stamped record of who’s acknowledged a policy – or who hasn’t. There’s certainly no single-click report you can hand an auditor to prove your policies were communicated and version-controlled.

Instead, all of that falls back on you to do manually, stitching together evidence from spreadsheets and email threads, and taking hours of your time. What could be a controlled, repeatable process becomes reactive, time-consuming, and difficult to evidence confidently.

A pattern often emerges in surveillance audits: the policies themselves aren’t the problem. The challenge is proving they’ve been maintained over time and embedded into the organisation.

The intent is there, but the evidence isn’t. The distinction that matters is this:

  • A shared drive stores your policies.
  • A policy management tool governs them.
  • For ISO 27001 maintenance, you need governance: not just storage.

ISO27001 - Policies

Who Should Own ISO 27001 Policies?

One of the most underrated reasons ISO 27001 policies go stale is that nobody actually owns them. The CISO (or the person wearing that hat) did a great job getting everything in place for certification, and then life moves on.

In some cases, organisations address this by using expert ISO 27001 consultants to draft and maintain the necessary policies on their behalf. In practice, whether they’re internal or external, every policy in your ISMS should have a named owner.

That person is responsible for ensuring the policy is up to date, that reviews happen on schedule, and that it’s been appropriately communicated to and understood by the people it applies to. This doesn’t need to be a full-time role, but it does need to be explicit and supported by a system that makes ownership both visible and actionable.

In Dayspring, for example, each policy has a named owner with clear responsibilities, supported by automated workflows. They act as the point of contact for questions, manage who needs to see and acknowledge the policy, and have access to audit-ready reports demonstrating version control and policy acknowledgements when needed.

They also receive automated reminders when reviews are due and can upload new versions and complete reviews within the system—so ownership isn’t just assigned, but carried through in practice.

If – for example — your Acceptable Use Policy is owned by your IT Manager and your Business Continuity Plan is owned by the Operations Manager, the load is distributed and nothing relies on one person holding everything together.

ISO 27001 Explanation

Software Tools for Managing ISO 27001 Policies

Here’s the honest truth: even with clear ownership and the best intentions, ISO 27001 policies don’t manage themselves and things slip over time. Review deadlines get missed, updates don’t get communicated, and when your surveillance audit comes around, evidence has to be pulled together at the last minute.

This is exactly the gap that purpose-built policy management software solves. Tools like Dayspring are designed for organisations that want to stay audit-ready without hours of administrative work, making it easier to see what’s up to date, what needs attention, and what’s missing.

Automated annual review reminders, version-specific acknowledgement tracking, document ownership, and one-click audit-ready reports showing that policies are maintained and communicated mean the evidence is always there, not something you have to scramble to reconstruct.

ISO27001 - Policies Happy woman

How Do You Know If Your ISO 27001 Policies Will Pass an Audit?

Both the content of your policies and how they’re managed matter. Auditors will first look at whether your policies are appropriate for your organisation; looking at whether they’re aligned to your risks, clearly written, and covering the right areas.

Many organisations work with ISO 27001 consultants, such as Consultants Like Us, to review policy content and carry out internal audits ahead of time.

This external input can help ensure everything is aligned with the standard.

But beyond content, they’re also looking for evidence that those policies are being managed and maintained. That means showing they’ve been reviewed on schedule, updated when needed, and communicated to the people they apply to – and that these people understand them.

A simple way to test this is to ask: If an auditor asked for evidence tomorrow, could we show when this policy was last reviewed, what changed, and that the relevant people have read and understood the latest version?

If the answer is yes, brilliant. If it’s “probably” or “I think so,” that’s your signal to tighten things up before you’re sitting across from the auditor. 

ISO 27001

The Bottom Line

The ISO 27001 certification often unlocks opportunities: new contracts, new markets, and increased trust. But keeping that certification requires effort. A year on, auditors aren’t looking at what you created—they’re looking at what’s been updated and maintained.

If you’re looking for a simple way to manage your ISO policies without adding to your admin burden, Dayspring Software is a policy management platform built for exactly this. Book a free consultation here.

ISO27001 Policies