Security controls only work if people actually follow them. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations draft immaculate, comprehensive security policies, stick them in a PDF on an obscure intranet page, and assume that documentation equals protection. Write-and-forget policies are useless. Local workarounds become the norm, controls degrade quietly over time, and non-compliance is only discovered during a major security incident or a painful audit finding. Annex A 5.36 is about closing the dangerous gap between documented intent and operational reality.
ISO 27001:2022 includes Annex A 5.36 to ensure your organisation actively monitors, reviews, and enforces compliance with its own internal information security policies, rules, and standards, taking prompt corrective action when deviations are spotted. This control replaces former 2013 requirements (18.2.2 and 18.2.3) and reinforces that internal compliance monitoring is an essential preventive and corrective feedback loop for your Information Security Management System (ISMS).
Quick Summary: What ISO 27001 Annex A 5.36 Requires
At a practical level, Annex A 5.36 is about verifying that your agreed security rules are working as intended across daily operations. It does not demand constant technical surveillance or auditing every single workstation daily; it expects a structured, risk-based approach to confirming compliance. Here is what you need to do in plain English:
- Publish Accessible, Clear Security Rules: Ensure internal policies, rules, and technical standards are easy to find, plain to read, and clearly assigned to operational roles.
- Assign Compliance Oversight Ownership: Designate explicit managers, security leads, or internal assurance roles responsible for checking compliance within their teams.
- Conduct Regular Compliance Reviews: Perform scheduled, risk-tiered reviews—combining management spot-checks, automated technical scans, and process sampling.
- Identify & Analyze Root Causes of Non-Compliance: Determine whether a policy violation is an isolated mistake, a bad habit, or the result of an overly restrictive, impractical process.
- Execute Proportionate Corrective Action: Remediate deviations deliberately through retraining, process adjustments, or technical policy enforcement.
- Verify Corrective Action Effectiveness: Re-audit non-compliant areas after remediation to confirm that the underlying cause has been resolved and risk is reduced.
Why Assuming Internal Compliance Is a Critical Hazard
When an organisation assumes that employees and technical teams follow policies without active monitoring, “operational drift” sets in. Staff find convenient workarounds to bypass friction, system administrators deploy default configurations to save time, and security controls slowly break down behind the scenes.
Ignoring internal policy compliance monitoring exposes your business to severe hazards:
- Silent Control Degradation: Unmonitored security controls (like clear desk rules, backup verifications, or port blocking) failing quietly without leadership knowing (Annex A 5.37).
- Uncontrolled “Shadow IT” Expansion: Employees adopting unvetted third-party cloud apps or file-sharing tools because corporate tools feel cumbersome, bypassing security baselines (Annex A 6.7).
- Failed External Audits: Facing severe non-conformities during ISO 27001 certification or surveillance audits because operational evidence fails to match written policy promises.
- Blame-Driven Culture Following Incidents: Discovering widespread policy non-compliance only after a breach occurs, leading to panic, finger-pointing, and legal liability.
My 8 Step Plan to Implement Annex A 5.36 Fast
You do not need a heavy-handed internal police force to satisfy an ISO 27001 auditor. Here is my pragmatic, 8-step plan to establish an audit-ready internal compliance framework.
1. Ensure Policies Are Accessible and Actionable
People cannot comply with rules they cannot find or understand. Make compliance simple from the start:
- Host all approved Information Security Policies (Annex A 5.1) and technical standards on a centralized, searchable intranet landing page.
- Translate complex policy language into plain, actionable “Dos and Don’ts” cheat sheets for non-technical staff.
- Link policy expectations directly to daily operational procedures (Annex A 5.37) and role-based training modules (Annex A 6.3).
2. Assign Explicit Compliance Oversight Responsibilities
Internal compliance fails when “everyone” is responsible, because nobody actually owns it:
- Assign operational department leads (e.g., HR, Finance, Engineering) explicit responsibility for monitoring security policy compliance within their teams.
- Task your Information Security Manager / CISO with overseeing the overarching compliance review schedule and reporting findings to leadership.
- Define clear escalation pathways for reporting unmanaged or systemic non-compliance directly to executive management.
3. Establish a Tiered Compliance Review Schedule
Deploy a combination of automated checks, process sampling, and management walk-throughs across different operational tiers:
- Automated Technical Compliance (Continuous): Use Mobile Device Management (MDM), Endpoint Detection and Response (EDR), and Cloud Security Posture Management (CSPM) to automatically audit endpoint encryption, firewall states, and patch levels (Annex A 8.9).
- Operational Process Sampling (Monthly/Quarterly): Sample user access reviews (Annex A 8.3), backup restoration logs (Annex A 8.13), and change management tickets (Annex A 8.32) to verify procedural compliance.
- Physical & Behavioral Walk-Throughs (Bi-Annually): Conduct friendly out-of-hours sweeps to check clear desk/clear screen compliance (Annex A 7.7) and physical security perimeter controls (Annex A 7.1).
4. Triage and Assess Non-Compliance Events
Treat policy deviations as valuable signals rather than simple failures. Evaluate identified non-compliance pragmatically:
- Log all identified policy deviations in a central Internal Compliance Register or ISMS Risk Register.
- Assess the information security risk level of the deviation (High, Medium, Low) based on potential confidentiality, integrity, or availability impact.
- Determine whether the non-compliance is an isolated human error or an indicator of a wider systemic failure.
5. Conduct Root-Cause Analysis (The “5 Whys”)
Before applying penalties or issuing warnings, understand *why* the non-compliance occurred:
- Ask why the rule was bypassed: Was the policy ambiguous? Was the technical tool broken? Was the employee never trained? Is the policy fundamentally unworkable for daily operations?
- Distinguish between accidental oversight, lack of awareness, impractical process design, and intentional policy evasion.
- If a policy is routinely violated by an entire team, re-evaluate the policy itself—it may need updating to reflect modern technical realities.
6. Implement Proportionate Corrective Action
Design corrective actions that address the underlying root cause rather than applying a temporary patch:
- Awareness/Training Gaps: Deliver targeted re-education or role-based coaching (Annex A 6.3).
- Technical Control Failures: Automate enforcement via Group Policy or MDM configuration (e.g., locking USB ports rather than just asking staff not to use them).
- Impractical Policies: Revise the policy via formal change control to establish a secure, realistic workflow.
- Intentional Negligence: Initiate formal HR disciplinary processes (Annex A 6.4).
7. Verify Corrective Action Effectiveness
A corrective action plan is incomplete until you prove that it actually worked:
- Schedule a follow-up review 30–90 days post-remediation to re-audit the non-compliant process or system.
- Verify that the corrective action successfully eliminated the root cause without introducing new operational friction or security risks.
- Document the re-audit findings and formally close out the non-compliance ticket in your ISMS register.
8. Report Compliance Metrics to Executive Leadership
Provide executive management with visibility over internal compliance health to drive continuous ISMS improvement:
- Include key internal compliance metrics (e.g., percentage of compliant endpoints, open policy deviation counts, repeat non-compliance trends) in quarterly CISO dashboard reports.
- Present internal compliance review summaries as formal input during your annual ISMS Management Review.
- Use compliance trends to justify budget requests for technical automation or additional security resources.
Common Implementation Pitfalls and How to Fix Them
When preparing clients for ISO 27001 audits, I frequently spot the same internal compliance review mistakes. Here are the main traps and how to solve them:
- Problem: Assuming Documented Policies Mean Everyone Is Automatically Complying
Ninja Solution: Establish a risk-based review schedule combining automated technical scans and sampling to verify operational reality. - Problem: Treating Every Policy Deviation as an Employee Disciplinary Offense
Ninja Solution: Conduct root-cause analysis first; most non-compliance stems from confusing policies or broken tools rather than malice. - Problem: Logging Non-Compliance Findings but Never Following Up to Verify Fixes
Ninja Solution: Mandate a formal 30-to-90-day re-audit gate before any compliance deviation ticket can be closed. - Problem: Auditing Technical Teams Manual-by-Manual While Ignoring Executive Compliance
Ninja Solution: Apply compliance reviews universally across all departments and seniority tiers, including executive leadership.
The ISO 27001 Ninja Bottom Line
ISO 27001 Annex A 5.36 is about keeping your security controls alive, relevant, and effective in the real world. Written policies define your intent, but active compliance monitoring ensures that intent is realized across daily operations.
By making policies accessible, assigning compliance oversight, conducting tiered reviews, analyzing root causes, applying proportionate corrective action, verifying remediation effectiveness, and reporting metrics to executive leadership, you close the gap between policy and reality, build a true culture of security resilience, and satisfy your ISO 27001 auditor with complete confidence.
