An ISO 27001 compliance checklist should follow the standard's own clauses 4 to 10, because that is how an auditor works: context and scope recorded, leadership commitment shown, risks assessed and a Statement of Applicability across all 93 Annex A controls, resources and competence in place, the system operated with dated records, an internal audit and a management review held, and nonconformities corrected. Each line below is something you must be able to show, not merely have decided.

Clause 4, context

  • The internal and external issues affecting your information security management system, recorded
  • Interested parties and what they require of you
  • The scope, documented, with any exclusions justified
  • The processes of the system and how they interact

Clause 5, leadership

  • An information security policy, approved, communicated and available
  • Roles, responsibilities and authorities assigned and understood
  • Evidence top management is involved, not merely named

Clause 6, planning

  • A risk assessment with a stated methodology and acceptance criteria
  • A risk treatment plan
  • The Statement of Applicability: all 93 Annex A controls, applicable or excluded, each justified
  • Measurable security objectives, with plans to achieve them
  • Changes to the system planned rather than improvised

Clause 7, support

  • Resources determined and provided
  • Competence evidenced for the people doing the work
  • Awareness activities, with records of who attended
  • Internal and external communication about the system
  • Documented information controlled and versioned

Clause 8, operation

  • The processes above actually operating, with records
  • Risk assessments performed at planned intervals and after significant change
  • The risk treatment plan implemented

Clause 9, performance evaluation

  • What is monitored and measured, by what method, and when
  • An internal audit programme, and audits performed against it
  • Management review, with the inputs and outputs the clause lists

Clause 10, improvement

  • Nonconformities recorded, with correction and cause
  • Corrective actions, with a check that the action worked
  • Evidence of continual improvement

The two that fail audits

Records covering a period. Every line above says "show". A policy dated last week does not evidence a year of operation.

Internal audit and management review. Both are mandatory before certification and both are commonly missing or too thin at Stage 2.

If you want this mapped to a specific product rather than in the abstract, our clause-by-clause coverage states which of these StandardOS holds records for and which it does not.