Information and Cyber Security

Must-Have Documents & Evidence for an ISO/IEC 27701 Audit

Author: Pooja Rawat
Jul 23, 2026
52

Privacy used to live in the legal folder. Today, it lives in procurement, customer trust, and breach response. UNCTAD’s Global Cyberlaw Tracker follows privacy and data-protection legislation across 195 countries. Cisco’s 2025 Data Privacy Benchmark found that 99% of respondents said external privacy certifications are important when choosing a vendor, and IBM’s 2025 breach research put the global average cost of a data breach at USD 4.4 million. ISACA’s 2026 privacy research adds even more urgency: 14% of organizations reported a material privacy breach in the previous 12 months, and 19% expect one in the next 12 months.

Must-Have Documents & Evidence for an ISO/IEC 27701 Audit

There is also a version wrinkle that smart teams should not ignore. ISO’s official catalog shows that ISO/IEC 27701:2019 has been withdrawn and ISO/IEC 27701:2025 is now the current edition, published in October 2025 as Edition 2. The updated standard is now an independent management system standard, while many implementation guides still reflect the older 2019 model that extended ISO/IEC 27001 and ISO/IEC 27002. That is why some sources still talk about ISO 27001 as a prerequisite, while current ISO guidance says ISO/IEC 27701 can be used alone.

Top Must-Have Documents and Evidence for an ISO/IEC 27701 Audit

Below are the top must-have documents and evidence for an ISO/IEC 27701.

1. Scope, Governance, and Leadership Records Come First

Your foundation should include a defined PIMS scope and boundaries, role determination for each processing activity, a signed privacy policy, privacy objectives, and a roles-and-responsibilities matrix. Auditors want to see who owns privacy, what parts of the organization are in scope, what PII is covered, and whether you are acting as a controller, a processor, or both. If those basics are fuzzy, everything that follows becomes harder to defend.

2. Your Processing Inventory is the Backbone of the Audit

That means Article 30-style records of processing, data flow maps, system inventories, purposes of processing, categories of data subjects and PII, recipients, transfer routes, retention periods, and relevant security measures. This is the moment where privacy stops sounding strategic and starts looking operational. If your records of processing are outdated, your lawful-basis decisions, notices, DSAR responses, and vendor oversight will all look shaky, too.

3. Risk Evidence is Where Audit Maturity Becomes Visible

You need a privacy risk assessment methodology, completed privacy risk assessments, risk evaluation results, a privacy risk treatment plan, and a Statement of Applicability explaining which controls apply and why. For higher-risk activities, you also need DPIAs or PIAs, residual-risk decisions, and proof that selected controls were actually implemented. Auditors are not just asking, “Did you think about privacy risk?” They are asking, “Show me how you identified it, scored it, treated it, and tracked it.”

4. Transparency and Rights Evidence often Decide how Smooth your Audit Feels

Keep lawful-basis documentation, consent collection and withdrawal logs where consent is used, privacy notices, employee notices, DSAR procedures, request logs, identity-verification steps, and response-timeline tracking. Secure Privacy’s guidance is especially useful here because it makes the right point: ISO/IEC 27701 is not about policy theater. Auditors expect operating evidence, and common failures include weak identity verification, poor timeline tracking, and not being able to prove what happened to a request.

5. Third-party and Role-specific Records are Non-negotiable

If you are a controller, keep data processing agreements, data-sharing agreements, joint-controller arrangements where relevant, transfer mechanisms, and DPIAs for high-risk processing. If you are a processor, keep documented controller instructions, authorized subprocessor lists, subprocessor agreements, due diligence records, assistance logs for controller requests, and end-of-contract return or deletion evidence. This is not a theory. Google Cloud publicly states that its PIMS has an accredited ISO/IEC 27701 certification as a PII processor after an independent third-party audit, which shows just how market-facing controller and processor proof has become.

6. Operational Proof Closes the Loop

You should have training and competence records, awareness completion records, incident and breach logs, internal audit reports, management review minutes, nonconformity and corrective-action records, and documented information controls such as version history, retention, distribution, storage, and access rules. QGlobal, Neumetric, and ISMS.online all reinforce the same truth: documentation is not just what you wrote once. It is what you control, review, update, and can prove people actually use.

Conclusion

Auditors do not want a beautiful privacy binder. They want a believable privacy story with proof at every step. If your PIMS scope is clear, your processing records are current, your privacy risks are documented, your controls are justified, your rights-handling evidence is searchable, and your management reviews show continual improvement, your ISO/IEC 27701 audit becomes far more predictable.

This is where Azpirantz ISO 27701 Privacy Information Management Consultancy helps organizations move from scattered privacy documentation to structured, audit-ready evidence. From defining the PIMS scope and mapping PII processing activities to preparing privacy risk assessments, Statement of Applicability, policies, procedures, and evidence records, Azpirantz supports organizations in building a practical and compliant Privacy Information Management System.

In a market where trust, certification, and privacy proof increasingly influence buying decisions, ISO/IEC 27701 readiness does more than help you pass an audit. With the right consulting support, you can strengthen privacy governance, demonstrate accountability, and earn the trust of customers, regulators, partners, and stakeholders.

FAQs

1. What documents are mandatory for ISO/IEC 27701?

  • At minimum, expect to maintain a PIMS scope, privacy policy, records of processing, privacy risk assessment and treatment plan, Statement of Applicability, key procedures for DSARs, consent, retention and incidents, relevant supplier agreements, training records, internal audit reports, and management review minutes. Auditors also expect current records that prove those documents are being used.

2. Is ISO 27001 required for ISO/IEC 27701?

  • For the withdrawn 2019 edition, ISO/IEC 27701 was structured as an extension to ISO/IEC 27001 and ISO/IEC 27002, so many older guides treat ISO 27001 as a prerequisite or simultaneous requirement. Under the current ISO/IEC 27701:2025 edition, ISO states the standard can be used alone as an independent management system standard.

3. What evidence do auditors usually ask for in an ISO/IEC 27701 audit?

  • Auditors typically ask for three types of evidence: documentary evidence, such as policies and risk files; records and logs, such as training, incidents, audits, and DSAR handling; and demonstrated practice, such as walkthroughs, interviews, and live proof that controls work as described.

4. What is the difference between controller and processor evidence?

  • Controller evidence focuses on lawful basis, consent, privacy notices, DPIAs, data subject rights, and processor contracts. Processor evidence focuses on controller instructions, subprocessor approvals, assistance to controllers, confidentiality, and deletion or return of data at contract end.

5. How often should ISO/IEC 27701 documents be reviewed?

  • They should be reviewed regularly and whenever there is a major change in processing, systems, business structure, suppliers, or legal requirements. The strongest audit files are current, version-controlled, and backed by records that cover the audit period rather than a one-time compliance exercise.
Ready To Get Started?
We're Here To Help