What does an ISO 27001 audit day actually involve?
Most people preparing for their first ISO 27001 audit have no idea what the actual day looks like.
An audit day is mostly conversation and evidence review. The auditor asks how a control actually works in practice, asks to see evidence — a ticket, a log, a signed policy — and checks whether what's documented matches what people actually do.
The teams that struggle aren't usually the ones with imperfect controls — they're the ones whose documentation doesn't match reality.
Why does the documentation-practice gap matter more than the controls themselves?
Because an auditor isn't grading your ISMS against an abstract ideal — they're checking whether the control you wrote down is the control you're actually running. A team with a slightly weaker but honestly-documented access review process will usually fare better than a team with a strong process on paper that nobody actually follows, because the second gap undermines confidence in every other control in the audit.
That's the real preparation work: not perfecting controls in the weeks before an audit, but closing the gap between what's written and what's practiced, year-round. Evidence should be a byproduct of doing the work — a ticket that gets created because access really was reviewed — not something assembled retroactively once the audit is scheduled.