1. Purpose
The Independent Review Follow-Up Checklist provides a structured process for determining whether findings identified during an independent information-security review have been appropriately addressed.
The follow-up confirms:
- Corrective actions were implemented
- Supporting evidence is available
- Actions addressed the underlying issue
- Controls are operating as intended where applicable
- Residual risks have been assessed
- Risk acceptance has been appropriately documented
- Findings can be closed or require further action
- Recurring issues are identified
- Management receives appropriate follow-up information
Core Principle
Review Finding → Verify Action → Evaluate Effectiveness → Assess Residual Risk → Close or Escalate → Report → Improve
2. When to Use
Use this checklist after an independent review where findings, observations, recommendations, or corrective actions require follow-up.
It may also be used when:
☐ Significant findings were identified
☐ Corrective actions have passed their target dates
☐ Management requested follow-up
☐ High/Critical risks were identified
☐ A finding requires effectiveness testing
☐ Risk acceptance was temporary
☐ Previous findings require revalidation
☐ A recurring issue was identified
☐ A customer or regulatory commitment requires verification
3. Follow-Up Information
| Field | Details |
|---|---|
| Follow-Up ID | |
| Original Review ID | |
| Original Review Date | |
| Original Report Reference | |
| Organization | |
| Review Scope | |
| Follow-Up Date | |
| Follow-Up Reviewer | |
| Reviewer Organization | |
| Independent of Original Activity? | ☐ Yes ☐ No |
| Report Date | |
| Status | ☐ Draft ☐ Final |
4. Original Review Summary
Original Review Objective
Original Review Scope
Original Review Period
Start: ______________________
End: ________________________
Original Review Result
☐ Satisfactory
☐ Satisfactory with Observations
☐ Improvement Required
☐ Significant Improvements Required
☐ Further Assessment Required
5. Findings Requiring Follow-Up
| Finding ID | Finding | Severity | Owner | Original Due Date | Current Status |
|---|---|---|---|---|---|
| IR-001 | |||||
| IR-002 | |||||
| IR-003 |
6. Follow-Up Scope
Define which findings and corrective actions will be reviewed.
☐ All findings
☐ Critical findings
☐ High-risk findings
☐ Overdue findings
☐ Selected findings
☐ Recurring findings
☐ Risk-accepted findings
☐ Other: ______________________
Scope Rationale
7. Follow-Up Criteria
The follow-up should be performed against defined criteria.
☐ Original finding
☐ Original recommendation
☐ Corrective action plan
☐ Organization policy
☐ Security procedure
☐ Risk treatment plan
☐ Contractual requirement
☐ Legal/regulatory requirement
☐ Control requirement
☐ Management commitment
☐ Other: ______________________
Criteria Details
| Criterion | Reference | Applicable Finding |
|---|---|---|
8. Reviewer Independence
Before beginning the follow-up, assess reviewer independence.
☐ Reviewer is sufficiently independent
☐ No relevant conflict of interest identified
☐ Reviewer has appropriate competence
☐ Reviewer understands the original finding
☐ Reviewer understands the follow-up scope
☐ Reviewer has appropriate access to evidence
☐ Any limitations are documented
Independence Assessment
9. Corrective Action Review
For each finding, verify whether the agreed corrective action was implemented.
| Finding ID | Corrective Action | Owner | Due Date | Implemented? | Evidence Available? |
|---|---|---|---|---|---|
| ☐ Yes ☐ No | ☐ Yes ☐ No | ||||
| ☐ Yes ☐ No | ☐ Yes ☐ No |
10. Finding-by-Finding Follow-Up
Finding ID: IR-____
Original Finding
Original Risk
Original Severity
☐ Critical
☐ High
☐ Medium
☐ Low
☐ Observation
Original Corrective Action
Action Owner
Original Target Date
11. Implementation Verification
Determine whether the corrective action was actually implemented.
☐ Fully implemented
☐ Partially implemented
☐ Not implemented
☐ Cannot be verified
Implementation Evidence
| Evidence | Description | Date | Result |
|---|---|---|---|
Implementation Notes
12. Evidence Quality Review
Assess whether the evidence is sufficient to support the claimed remediation.
☐ Evidence is relevant
☐ Evidence is current
☐ Evidence covers the required scope
☐ Evidence is attributable
☐ Evidence is complete
☐ Evidence is reliable
☐ Evidence demonstrates implementation
☐ Evidence demonstrates operation where required
Evidence Result
☐ Sufficient
☐ Partially Sufficient
☐ Insufficient
Evidence Gaps
13. Root Cause Addressed
Determine whether the corrective action addressed the underlying cause.
☐ Root cause identified
☐ Root cause addressed
☐ Contributing factors addressed
☐ Recurrence risk considered
☐ Process/control updated where required
Assessment
14. Control Effectiveness
Where the corrective action changes or improves a control, determine whether the control is now operating as intended.
Control
Effectiveness Assessment
☐ Effective
☐ Partially Effective
☐ Ineffective
☐ Not Yet Determined
Evidence
Testing Performed
☐ Evidence review
☐ Sampling
☐ Configuration review
☐ Technical testing
☐ Interview
☐ Observation
☐ Retest
☐ Other: ______________________
15. Operating Effectiveness
Where sufficient time has passed, assess whether the corrected control is operating consistently.
Consider:
☐ Control operated during the review period
☐ Required activities were completed
☐ Required evidence was retained
☐ Exceptions were identified and handled
☐ Control owner understands responsibility
☐ No significant recurrence observed
Operating Effectiveness Result
16. Recurrence Assessment
Determine whether the original issue has occurred again.
☐ No recurrence identified
☐ Similar issue identified
☐ Recurring issue
☐ Systemic issue
☐ Unable to determine
Evidence
Recurrence Impact
17. Residual Risk Assessment
After remediation, reassess the remaining risk.
Original Risk: ______________________
Current Risk: _______________________
Residual Risk
☐ Low
☐ Medium
☐ High
☐ Critical
Residual Risk Rationale
18. Risk Acceptance Review
Where the organization has accepted residual risk:
☐ Risk acceptance exists
☐ Correct risk owner approved acceptance
☐ Acceptance remains valid
☐ Acceptance period has not expired
☐ Conditions remain applicable
☐ Compensating controls remain effective
Risk Acceptance Reference
Risk Acceptance Decision
☐ Remains Accepted
☐ Requires Reassessment
☐ Requires Escalation
☐ No Longer Required
19. Overdue Corrective Actions
Identify actions that were not completed by the agreed date.
| Finding | Owner | Due Date | Days Overdue | Reason | Current Risk | Escalation |
|---|---|---|---|---|---|---|
Management Action Required
20. Deferred Actions
Where corrective actions have been formally deferred:
| Finding | Original Action | Reason for Deferral | New Date | Approval | Risk Treatment |
|---|---|---|---|---|---|
Deferral should not be treated as closure unless the organization’s approved risk-management process explicitly permits it.
21. Corrective Action Effectiveness
Assess whether the action achieved its intended outcome.
Effectiveness Questions
☐ Did the action address the original finding?
☐ Did it address the root cause?
☐ Did it reduce the identified risk?
☐ Did it prevent or reduce recurrence?
☐ Is the control sustainable?
☐ Is evidence being generated consistently?
☐ Are additional actions required?
Overall Effectiveness
☐ Effective
☐ Partially Effective
☐ Ineffective
☐ Not Yet Determined
Comments
22. Follow-Up Finding Status
Based on the follow-up evidence:
☐ Closed
☐ Partially Closed
☐ Remains Open
☐ Risk Accepted
☐ Further Corrective Action Required
☐ Further Review Required
Status Rationale
23. Additional Corrective Action
Where the original corrective action was ineffective or incomplete:
| New Action | Owner | Priority | Due Date | Status |
|---|---|---|---|---|
Additional Action Required
24. Follow-Up Findings
Record any new findings identified during the follow-up.
| Finding ID | New Finding | Severity | Risk | Owner | Due Date |
|---|---|---|---|---|---|
| FU-001 | |||||
| FU-002 |
A follow-up review should not automatically be limited to confirming closure if new material evidence identifies an additional security weakness within the agreed scope.
25. Positive Improvements
Document improvements achieved since the original review.
| Area | Improvement | Evidence |
|---|---|---|
Examples:
- Improved access review
- Reduced privileged access
- Improved vulnerability remediation
- Improved logging
- Improved incident response
- Improved supplier oversight
- Improved evidence retention
- Improved backup testing
- Improved policy governance
26. Follow-Up Summary
| Finding | Original Severity | Current Status | Corrective Action | Effectiveness | Residual Risk |
|---|---|---|---|---|---|
| IR-001 | |||||
| IR-002 | |||||
| IR-003 |
27. Follow-Up Results by Status
| Status | Number |
|---|---|
| Closed | |
| Partially Closed | |
| Open | |
| Risk Accepted | |
| Further Action Required | |
| Further Review Required |
28. Follow-Up Results by Severity
| Severity | Total | Closed | Open | Overdue |
|---|---|---|---|---|
| Critical | ||||
| High | ||||
| Medium | ||||
| Low | ||||
| Observation |
29. Management Escalation
Escalate findings where:
☐ Critical/high-risk finding remains open
☐ Corrective action is significantly overdue
☐ Risk increased
☐ Corrective action was ineffective
☐ Issue has recurred
☐ Risk acceptance expired
☐ Management commitment was not fulfilled
☐ Additional resources are required
Escalation Record
| Date | Finding | Escalated To | Reason | Decision |
|---|---|---|---|---|
30. Follow-Up Conclusion
Based on the follow-up procedures performed and evidence reviewed:
☐ Corrective actions were effectively implemented.
☐ Corrective actions were generally implemented, with minor improvements required.
☐ Significant corrective actions remain outstanding.
☐ One or more corrective actions were ineffective.
☐ Residual risks require management attention.
☐ Further review is required.
Conclusion
31. Recommendation
Recommended Action
☐ Close the original finding
☐ Keep the finding open
☐ Extend the corrective-action deadline
☐ Initiate additional corrective action
☐ Perform another follow-up review
☐ Escalate to management
☐ Obtain formal risk acceptance
☐ Other: ______________________
Recommendation Rationale
32. Management Response
Management Comments
Management Decision
Management Representative: ______________________
Role: _________________________________________
Date: _________________________________________
33. Follow-Up Approval
Follow-Up Reviewer
Name: ______________________________
Organization: _______________________
Signature/Approval: __________________
Date: ______________________________
Management Representative
Name: ______________________________
Role: _______________________________
Approval: ___________________________
Date: ______________________________
34. Evidence Register
| Evidence ID | Description | Source | Date | Finding | Result |
|---|---|---|---|---|---|
Evidence should be stored securely and linked to the appropriate finding or corrective action.
35. Workpaper References
| Workpaper ID | Description | Finding |
|---|---|---|
| WP-FU-001 | ||
| WP-FU-002 | ||
| WP-FU-003 |
36. Follow-Up Report Distribution
| Recipient | Role | Organization | Access Level |
|---|---|---|---|
The follow-up report should be distributed only to authorized recipients.
37. Confidentiality and Handling
The follow-up may contain information about:
- Security weaknesses
- Vulnerabilities
- Control deficiencies
- Internal systems
- Risks
- Corrective actions
- Security architecture
- Incidents
Therefore:
☐ Access restricted
☐ Secure storage used
☐ Authorized distribution only
☐ Evidence protected
☐ Retention requirement identified
☐ Secure disposal requirement identified
Do not include passwords, API keys, private keys, or authentication secrets in the report.
38. AWS SaaS Startup Example
Original Finding
Finding: Privileged AWS access review evidence was incomplete.
Severity: Medium
Original Risk: Unnecessary privileged access could remain active without timely detection.
Original Corrective Action
- Review all privileged AWS accounts.
- Remove unnecessary access.
- Update access-review procedure.
- Establish recurring quarterly review.
- Retain review evidence.
Follow-Up Activities
Step 1 — Review AWS Population
The reviewer obtains the current privileged-account listing.
☐ Completed
Step 2 — Review Access Review
The reviewer verifies that the latest quarterly access review was completed.
☐ Completed
Step 3 — Sample Accounts
A sample of privileged accounts is selected and compared against:
- Approved access
- Business justification
- IAM permissions
- MFA status
- Review evidence
☐ Completed
Step 4 — Review Evidence
Evidence demonstrates that:
- Accounts were identified
- Owners reviewed access
- Unnecessary access was removed
- Review approval was recorded
☐ Evidence Sufficient
Step 5 — Effectiveness
The reviewer examines whether the updated process operated during the subsequent review period.
☐ Effective
Follow-Up Result
Status: Closed
Residual Risk: Low
Closure Basis: Corrective action was implemented and follow-up evidence demonstrated that the revised access-review process was operating as intended.
39. Startup-Friendly Follow-Up Model
A startup can perform follow-up using a simple four-stage model.
1. What Was Fixed?
Confirm the corrective action was actually implemented.
2. Is There Evidence?
Confirm objective evidence exists.
3. Does It Work?
Where appropriate, test whether the control now operates effectively.
4. Can We Close It?
Assess residual risk and formally close or escalate the finding.
Fix → Evidence → Verify → Close
For high-risk findings, add:
Root Cause → Effectiveness Testing → Residual Risk → Management Approval
40. Common Mistakes
Avoid:
- Closing findings based only on management confirmation.
- Treating a completed ticket as proof of effectiveness.
- Reviewing only the documentation and not actual operation.
- Ignoring whether the root cause was addressed.
- Failing to reassess residual risk.
- Allowing overdue actions to remain unreported.
- Reusing the original evidence without confirming it is still valid.
- Treating risk acceptance as permanent.
- Failing to identify recurring issues.
- Allowing the same weakness to reappear without escalation.
- Performing follow-up without sufficient independence.
- Testing systems beyond the approved scope.
- Retaining unnecessary sensitive credentials in workpapers.
41. Relationship With Other ISMS Documents
| Document | Relationship |
|---|---|
| Independent Review Procedure | Defines the original review process |
| Independent Review Report | Records original findings |
| Security Findings Register | Tracks findings |
| Corrective Action Tracker | Tracks remediation |
| Risk Register | Tracks associated risks |
| Risk Acceptance Register | Records accepted residual risks |
| Information Security Review | Provides broader security assessment |
| Internal Audit Report | May generate related findings |
| Management Review | Reviews significant outstanding risks |
| ISMS Improvement Log | Tracks broader improvements |
| Annual Security Review Plan | Provides future review activities |
42. ISO/IEC 27001 Connection
Independent review follow-up supports the organization’s ability to verify corrective actions, evaluate control effectiveness, manage residual risk, and drive continual improvement.
The Independent Review Follow-Up Checklist is not a universally prescribed ISO/IEC 27001 form. The organization should determine the appropriate follow-up method based on:
- Risk
- Finding severity
- ISMS scope
- Control requirements
- Internal audit arrangements
- Business requirements
- Legal/regulatory obligations
- Customer requirements
- Contractual requirements
- Previous findings
- Significant changes
A follow-up activity should also be clearly distinguished from an independent certification audit unless it is formally planned and performed as such.
43. Audit Evidence Checklist
Retain appropriate evidence such as:
☐ Original independent review report
☐ Original finding
☐ Corrective-action record
☐ Updated risk assessment
☐ Remediation evidence
☐ Follow-up workpapers
☐ Testing evidence
☐ Sampling records
☐ Effectiveness assessment
☐ Residual-risk assessment
☐ Risk acceptance
☐ Management response
☐ Closure approval
☐ Follow-up report
☐ Additional corrective actions
44. Final Follow-Up Audit Trail
For every significant finding, the organization should be able to demonstrate:
What was originally identified?
What corrective action was agreed?
Who was responsible?
Was the action completed on time?
What evidence demonstrates completion?
Was the evidence independently or appropriately verified?
Did the action address the root cause?
Is the control now operating effectively?
Did the issue recur?
What residual risk remains?
Was risk acceptance required?
Can the finding be closed?
If not, what additional action is required?
Was management informed?
Final Principle
Follow-up is not simply checking whether an action was completed. It is the process of establishing whether the original security weakness was actually addressed, whether the control is effective, whether the risk is appropriately managed, and whether the organization can defensibly close the finding.
