Skip to content
arrow_back
search
Annex A 5.36 verified ISO/IEC 27001:2022

Review compliance with information security policies

Regularly check if your organisation's security policies and rules are being followed.

record_voice_over

Plain language

This control is about checking regularly to make sure your organisation is following its own information security rules and standards. If this isn't done, there might be security weaknesses that could lead to data breaches or compliance issues with laws like the Privacy Act 1988.

Framework

ISO/IEC 27001:2022

Control effect

Preventative

ISO 27001 domain

Organisational controls

Classifications

N/A

Official last update

24 Oct 2022

Control Stack last updated

19 Mar 2026

Maturity levels

N/A

Official control statement

Compliance with the organization’s information security policy, topic-specific policies, rules and standards shall be regularly reviewed.
verified ISO/IEC 27001:2022 Annex A 5.36
priority_high

Why it matters

Without regular compliance reviews, staff may not follow the organisation’s security policies and standards, increasing audit nonconformities and security incidents.

settings

Operational notes

Schedule quarterly compliance reviews against the organisation’s information security and topic-specific policies; sample evidence (logs, approvals, training) and track corrective actions to closure.

Mapping detail

Mapping

Direction

Controls