ISO27001:2022 – A5.36 – Compliance with policies and standards for information security

Introduction to ISO 27001 – A5.36

The ISO standard includes multiple controls that work together, and ISO 27001 – A5.36 is another one of those closely linked to A5.35 – Independent Review of Information Security. If you’ve planned and conducted independent reviews correctly, you’re likely already gathering the evidence needed to show compliance with your policies, rules, and standards.

What does the standard require?

“Compliance with the organisation’s information security policy, topic-specific policies, rules and standards shall be regularly reviewed.”

(A5.36 – Compliance with Policies and Standards for Information Security)

This means you must verify that your information security measures align with your stated policies, topic-specific rules, and internal standards. It’s not enough to have them written down—they must be followed.

Why is this required?

Policies set expectations. But just writing them doesn’t mean people will follow them. This control ensures that your organisation regularly checks for compliance across all levels—whether it’s a clear desk policy (A7.7), acceptable use (A5.10), access control (A5.15), or backup management (A8.13).

If compliance is not checked, you risk having policies that are ignored, misunderstood, or misaligned with actual practices—creating gaps in your security posture.

What the auditor is looking for

The auditor will want to see:

  • A formal audit plan that includes checks against your policies
  • Audit records and reports that document findings
  • Minutes of management review meetings discussing compliance or non-compliance
  • Corrective action plans where deviations from policy were identified
  • Performance reviews where your HR function or managers have 1-2-1 meetings with team members 

For example, if your Clear Desk Policy says no paperwork should be left out overnight, is that being followed? If not, what corrective actions have you taken?  How about those phishing exercises you’re running? (you DO perform some phishing exercises, right?) What happens to the output? What about ‘repeat offenders’? What do you do about those who break the rules?  Remember you’ve not written these policies for the fun of it!

Policies are there to offer clear guidance and set expectations and if there is an infringement, you need to know about it as soon as possible – and then take action.

What do you need to do?

  1. Develop an audit plan that incorporates policy compliance checks.
  2. Map your audits to specific policies. For example, if reviewing IT, ensure cryptography policies are being followed in practice.
  3. Use real policies, not generic ones. Avoid downloading templates or AI-generated content without tailoring—it must reflect your actual practices.
  4. Review policies regularly as part of your ISMS review and audit cycle.
  5. Discuss what actions should be taken (with HR) should someone breach your policies.

Make it a habit to ask: “Are we doing what we said we would do in this policy?” If not, find out why and act.

Q & A

What does ‘compliance’ mean in this context?

It means doing what your policies say. If your visitor policy says guests must wear badges, you need to ensure this happens. Non-compliance, even on simple things, could indicate a broader culture issue.

How often should we review our policies?

Reviews should follow your audit schedule—at least annually, and whenever there are significant changes to your organisation or technology. Include compliance checks as part of your regular audit process.

Difficulty Rating

1 out of 5 – This control is straightforward. Include compliance checks in your audit programme, and you’ll meet this requirement with minimal effort.

Final Tip

This is a practical control. If your policies reflect reality and you audit them regularly, compliance will follow. The key is to avoid writing policies for the sake of it—make sure they match what your business actually does.

 We are ISO 27001 Consultants who provide ‘Compliance without Complexity’® and we know we can help you… we even wrote a book about it. For more information on how to implement ISO 27001, written by ISO 27001 consultants like us, you should buy our book…t “The Real Easy Guide to ISO27001”—available now on Amazon for practical advice.

ISO 27001 – A5.36