ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. Independent Review Follow-Up Checklist

Independent Review Follow-Up Checklist

1. Purpose

The Independent Review Follow-Up Checklist provides a structured process for determining whether findings identified during an independent information-security review have been appropriately addressed.

The follow-up confirms:

  • Corrective actions were implemented
  • Supporting evidence is available
  • Actions addressed the underlying issue
  • Controls are operating as intended where applicable
  • Residual risks have been assessed
  • Risk acceptance has been appropriately documented
  • Findings can be closed or require further action
  • Recurring issues are identified
  • Management receives appropriate follow-up information

Core Principle

Review Finding → Verify Action → Evaluate Effectiveness → Assess Residual Risk → Close or Escalate → Report → Improve


2. When to Use

Use this checklist after an independent review where findings, observations, recommendations, or corrective actions require follow-up.

It may also be used when:

☐ Significant findings were identified
☐ Corrective actions have passed their target dates
☐ Management requested follow-up
☐ High/Critical risks were identified
☐ A finding requires effectiveness testing
☐ Risk acceptance was temporary
☐ Previous findings require revalidation
☐ A recurring issue was identified
☐ A customer or regulatory commitment requires verification


3. Follow-Up Information

FieldDetails
Follow-Up ID
Original Review ID
Original Review Date
Original Report Reference
Organization
Review Scope
Follow-Up Date
Follow-Up Reviewer
Reviewer Organization
Independent of Original Activity?☐ Yes ☐ No
Report Date
Status☐ Draft ☐ Final

4. Original Review Summary

Original Review Objective

Original Review Scope

Original Review Period

Start: ______________________

End: ________________________

Original Review Result

☐ Satisfactory
☐ Satisfactory with Observations
☐ Improvement Required
☐ Significant Improvements Required
☐ Further Assessment Required


5. Findings Requiring Follow-Up

Finding IDFindingSeverityOwnerOriginal Due DateCurrent Status
IR-001
IR-002
IR-003

6. Follow-Up Scope

Define which findings and corrective actions will be reviewed.

☐ All findings
☐ Critical findings
☐ High-risk findings
☐ Overdue findings
☐ Selected findings
☐ Recurring findings
☐ Risk-accepted findings
☐ Other: ______________________

Scope Rationale


7. Follow-Up Criteria

The follow-up should be performed against defined criteria.

☐ Original finding
☐ Original recommendation
☐ Corrective action plan
☐ Organization policy
☐ Security procedure
☐ Risk treatment plan
☐ Contractual requirement
☐ Legal/regulatory requirement
☐ Control requirement
☐ Management commitment
☐ Other: ______________________

Criteria Details

CriterionReferenceApplicable Finding

8. Reviewer Independence

Before beginning the follow-up, assess reviewer independence.

☐ Reviewer is sufficiently independent
☐ No relevant conflict of interest identified
☐ Reviewer has appropriate competence
☐ Reviewer understands the original finding
☐ Reviewer understands the follow-up scope
☐ Reviewer has appropriate access to evidence
☐ Any limitations are documented

Independence Assessment


9. Corrective Action Review

For each finding, verify whether the agreed corrective action was implemented.

Finding IDCorrective ActionOwnerDue DateImplemented?Evidence Available?
☐ Yes ☐ No☐ Yes ☐ No
☐ Yes ☐ No☐ Yes ☐ No

10. Finding-by-Finding Follow-Up

Finding ID: IR-____

Original Finding

Original Risk

Original Severity

☐ Critical
☐ High
☐ Medium
☐ Low
☐ Observation

Original Corrective Action

Action Owner

Original Target Date


11. Implementation Verification

Determine whether the corrective action was actually implemented.

☐ Fully implemented
☐ Partially implemented
☐ Not implemented
☐ Cannot be verified

Implementation Evidence

EvidenceDescriptionDateResult

Implementation Notes


12. Evidence Quality Review

Assess whether the evidence is sufficient to support the claimed remediation.

☐ Evidence is relevant
☐ Evidence is current
☐ Evidence covers the required scope
☐ Evidence is attributable
☐ Evidence is complete
☐ Evidence is reliable
☐ Evidence demonstrates implementation
☐ Evidence demonstrates operation where required

Evidence Result

☐ Sufficient
☐ Partially Sufficient
☐ Insufficient

Evidence Gaps


13. Root Cause Addressed

Determine whether the corrective action addressed the underlying cause.

☐ Root cause identified
☐ Root cause addressed
☐ Contributing factors addressed
☐ Recurrence risk considered
☐ Process/control updated where required

Assessment


14. Control Effectiveness

Where the corrective action changes or improves a control, determine whether the control is now operating as intended.

Control

Effectiveness Assessment

☐ Effective
☐ Partially Effective
☐ Ineffective
☐ Not Yet Determined

Evidence

Testing Performed

☐ Evidence review
☐ Sampling
☐ Configuration review
☐ Technical testing
☐ Interview
☐ Observation
☐ Retest
☐ Other: ______________________


15. Operating Effectiveness

Where sufficient time has passed, assess whether the corrected control is operating consistently.

Consider:

☐ Control operated during the review period
☐ Required activities were completed
☐ Required evidence was retained
☐ Exceptions were identified and handled
☐ Control owner understands responsibility
☐ No significant recurrence observed

Operating Effectiveness Result


16. Recurrence Assessment

Determine whether the original issue has occurred again.

☐ No recurrence identified
☐ Similar issue identified
☐ Recurring issue
☐ Systemic issue
☐ Unable to determine

Evidence

Recurrence Impact


17. Residual Risk Assessment

After remediation, reassess the remaining risk.

Original Risk: ______________________

Current Risk: _______________________

Residual Risk

☐ Low
☐ Medium
☐ High
☐ Critical

Residual Risk Rationale


18. Risk Acceptance Review

Where the organization has accepted residual risk:

☐ Risk acceptance exists
☐ Correct risk owner approved acceptance
☐ Acceptance remains valid
☐ Acceptance period has not expired
☐ Conditions remain applicable
☐ Compensating controls remain effective

Risk Acceptance Reference

Risk Acceptance Decision

☐ Remains Accepted
☐ Requires Reassessment
☐ Requires Escalation
☐ No Longer Required


19. Overdue Corrective Actions

Identify actions that were not completed by the agreed date.

FindingOwnerDue DateDays OverdueReasonCurrent RiskEscalation

Management Action Required


20. Deferred Actions

Where corrective actions have been formally deferred:

FindingOriginal ActionReason for DeferralNew DateApprovalRisk Treatment

Deferral should not be treated as closure unless the organization’s approved risk-management process explicitly permits it.


21. Corrective Action Effectiveness

Assess whether the action achieved its intended outcome.

Effectiveness Questions

☐ Did the action address the original finding?
☐ Did it address the root cause?
☐ Did it reduce the identified risk?
☐ Did it prevent or reduce recurrence?
☐ Is the control sustainable?
☐ Is evidence being generated consistently?
☐ Are additional actions required?

Overall Effectiveness

☐ Effective
☐ Partially Effective
☐ Ineffective
☐ Not Yet Determined

Comments


22. Follow-Up Finding Status

Based on the follow-up evidence:

☐ Closed
☐ Partially Closed
☐ Remains Open
☐ Risk Accepted
☐ Further Corrective Action Required
☐ Further Review Required

Status Rationale


23. Additional Corrective Action

Where the original corrective action was ineffective or incomplete:

New ActionOwnerPriorityDue DateStatus

Additional Action Required


24. Follow-Up Findings

Record any new findings identified during the follow-up.

Finding IDNew FindingSeverityRiskOwnerDue Date
FU-001
FU-002

A follow-up review should not automatically be limited to confirming closure if new material evidence identifies an additional security weakness within the agreed scope.


25. Positive Improvements

Document improvements achieved since the original review.

AreaImprovementEvidence

Examples:

  • Improved access review
  • Reduced privileged access
  • Improved vulnerability remediation
  • Improved logging
  • Improved incident response
  • Improved supplier oversight
  • Improved evidence retention
  • Improved backup testing
  • Improved policy governance

26. Follow-Up Summary

FindingOriginal SeverityCurrent StatusCorrective ActionEffectivenessResidual Risk
IR-001
IR-002
IR-003

27. Follow-Up Results by Status

StatusNumber
Closed
Partially Closed
Open
Risk Accepted
Further Action Required
Further Review Required

28. Follow-Up Results by Severity

SeverityTotalClosedOpenOverdue
Critical
High
Medium
Low
Observation

29. Management Escalation

Escalate findings where:

☐ Critical/high-risk finding remains open
☐ Corrective action is significantly overdue
☐ Risk increased
☐ Corrective action was ineffective
☐ Issue has recurred
☐ Risk acceptance expired
☐ Management commitment was not fulfilled
☐ Additional resources are required

Escalation Record

DateFindingEscalated ToReasonDecision

30. Follow-Up Conclusion

Based on the follow-up procedures performed and evidence reviewed:

☐ Corrective actions were effectively implemented.

☐ Corrective actions were generally implemented, with minor improvements required.

☐ Significant corrective actions remain outstanding.

☐ One or more corrective actions were ineffective.

☐ Residual risks require management attention.

☐ Further review is required.

Conclusion


31. Recommendation

☐ Close the original finding
☐ Keep the finding open
☐ Extend the corrective-action deadline
☐ Initiate additional corrective action
☐ Perform another follow-up review
☐ Escalate to management
☐ Obtain formal risk acceptance
☐ Other: ______________________

Recommendation Rationale


32. Management Response

Management Comments

Management Decision

Management Representative: ______________________

Role: _________________________________________

Date: _________________________________________


33. Follow-Up Approval

Follow-Up Reviewer

Name: ______________________________

Organization: _______________________

Signature/Approval: __________________

Date: ______________________________

Management Representative

Name: ______________________________

Role: _______________________________

Approval: ___________________________

Date: ______________________________


34. Evidence Register

Evidence IDDescriptionSourceDateFindingResult

Evidence should be stored securely and linked to the appropriate finding or corrective action.


35. Workpaper References

Workpaper IDDescriptionFinding
WP-FU-001
WP-FU-002
WP-FU-003

36. Follow-Up Report Distribution

RecipientRoleOrganizationAccess Level

The follow-up report should be distributed only to authorized recipients.


37. Confidentiality and Handling

The follow-up may contain information about:

  • Security weaknesses
  • Vulnerabilities
  • Control deficiencies
  • Internal systems
  • Risks
  • Corrective actions
  • Security architecture
  • Incidents

Therefore:

☐ Access restricted
☐ Secure storage used
☐ Authorized distribution only
☐ Evidence protected
☐ Retention requirement identified
☐ Secure disposal requirement identified

Do not include passwords, API keys, private keys, or authentication secrets in the report.


38. AWS SaaS Startup Example

Original Finding

Finding: Privileged AWS access review evidence was incomplete.

Severity: Medium

Original Risk: Unnecessary privileged access could remain active without timely detection.

Original Corrective Action

  • Review all privileged AWS accounts.
  • Remove unnecessary access.
  • Update access-review procedure.
  • Establish recurring quarterly review.
  • Retain review evidence.

Follow-Up Activities

Step 1 — Review AWS Population

The reviewer obtains the current privileged-account listing.

☐ Completed

Step 2 — Review Access Review

The reviewer verifies that the latest quarterly access review was completed.

☐ Completed

Step 3 — Sample Accounts

A sample of privileged accounts is selected and compared against:

  • Approved access
  • Business justification
  • IAM permissions
  • MFA status
  • Review evidence

☐ Completed

Step 4 — Review Evidence

Evidence demonstrates that:

  • Accounts were identified
  • Owners reviewed access
  • Unnecessary access was removed
  • Review approval was recorded

☐ Evidence Sufficient

Step 5 — Effectiveness

The reviewer examines whether the updated process operated during the subsequent review period.

☐ Effective

Follow-Up Result

Status: Closed

Residual Risk: Low

Closure Basis: Corrective action was implemented and follow-up evidence demonstrated that the revised access-review process was operating as intended.


39. Startup-Friendly Follow-Up Model

A startup can perform follow-up using a simple four-stage model.

1. What Was Fixed?

Confirm the corrective action was actually implemented.

2. Is There Evidence?

Confirm objective evidence exists.

3. Does It Work?

Where appropriate, test whether the control now operates effectively.

4. Can We Close It?

Assess residual risk and formally close or escalate the finding.

Fix → Evidence → Verify → Close

For high-risk findings, add:

Root Cause → Effectiveness Testing → Residual Risk → Management Approval


40. Common Mistakes

Avoid:

  • Closing findings based only on management confirmation.
  • Treating a completed ticket as proof of effectiveness.
  • Reviewing only the documentation and not actual operation.
  • Ignoring whether the root cause was addressed.
  • Failing to reassess residual risk.
  • Allowing overdue actions to remain unreported.
  • Reusing the original evidence without confirming it is still valid.
  • Treating risk acceptance as permanent.
  • Failing to identify recurring issues.
  • Allowing the same weakness to reappear without escalation.
  • Performing follow-up without sufficient independence.
  • Testing systems beyond the approved scope.
  • Retaining unnecessary sensitive credentials in workpapers.

41. Relationship With Other ISMS Documents

DocumentRelationship
Independent Review ProcedureDefines the original review process
Independent Review ReportRecords original findings
Security Findings RegisterTracks findings
Corrective Action TrackerTracks remediation
Risk RegisterTracks associated risks
Risk Acceptance RegisterRecords accepted residual risks
Information Security ReviewProvides broader security assessment
Internal Audit ReportMay generate related findings
Management ReviewReviews significant outstanding risks
ISMS Improvement LogTracks broader improvements
Annual Security Review PlanProvides future review activities

42. ISO/IEC 27001 Connection

Independent review follow-up supports the organization’s ability to verify corrective actions, evaluate control effectiveness, manage residual risk, and drive continual improvement.

The Independent Review Follow-Up Checklist is not a universally prescribed ISO/IEC 27001 form. The organization should determine the appropriate follow-up method based on:

  • Risk
  • Finding severity
  • ISMS scope
  • Control requirements
  • Internal audit arrangements
  • Business requirements
  • Legal/regulatory obligations
  • Customer requirements
  • Contractual requirements
  • Previous findings
  • Significant changes

A follow-up activity should also be clearly distinguished from an independent certification audit unless it is formally planned and performed as such.


43. Audit Evidence Checklist

Retain appropriate evidence such as:

☐ Original independent review report
☐ Original finding
☐ Corrective-action record
☐ Updated risk assessment
☐ Remediation evidence
☐ Follow-up workpapers
☐ Testing evidence
☐ Sampling records
☐ Effectiveness assessment
☐ Residual-risk assessment
☐ Risk acceptance
☐ Management response
☐ Closure approval
☐ Follow-up report
☐ Additional corrective actions


44. Final Follow-Up Audit Trail

For every significant finding, the organization should be able to demonstrate:

What was originally identified?
What corrective action was agreed?
Who was responsible?
Was the action completed on time?
What evidence demonstrates completion?
Was the evidence independently or appropriately verified?
Did the action address the root cause?
Is the control now operating effectively?
Did the issue recur?
What residual risk remains?
Was risk acceptance required?
Can the finding be closed?
If not, what additional action is required?
Was management informed?

Final Principle

Follow-up is not simply checking whether an action was completed. It is the process of establishing whether the original security weakness was actually addressed, whether the control is effective, whether the risk is appropriately managed, and whether the organization can defensibly close the finding.