Skip to content

ISO 27001 mandatory clauses 4 to 10, explained

By Sam Rivera, Founder, SentinelPanda · February 13, 2026 · 4 min read · ISO 27001

ISO 27001 is a management system standard. The 93 Annex A controls are the visible half; clauses 4 to 10 are the management system itself, and they decide whether the audit goes well.

4Context5Leadership6Planning(risk)7Support8Operation9Performanceevaluation10Improvement Plan Plan Do Check Act Clause 6 (risk assessment + treatment) is the engine — every applicable Annex A control traces back here.
ISO 27001 mandatory clauses 4–10 as a Plan-Do-Check-Act pipeline. Clause 6 (risk) is where Annex A applicability is decided.

Why the clauses matter more than the controls

It is tempting to treat ISO 27001 as "the Annex A control library" — and most readiness software does exactly that. Certification bodies do not. Stage 1 of the audit walks the documented management system: scope, policy, risk methodology, internal audit, management review, and continual improvement. If the management system is weak, the certifier writes findings against the clauses and may not even get to most of Annex A. Spending the first quarter on the controls and the last week on the clauses is a common failure mode.

The clauses also outlive any particular control catalogue. When Annex A was restructured in 2022, the clauses did not move — because the management system is the durable part of the standard. Investing in the clauses is investing in the program, not in a single revision.

Clause 4 — Context of the organisation

Identify internal and external issues that affect the information security objectives, list the interested parties and their relevant requirements, and define the scope of the ISMS — which business units, locations, services, and information assets are inside, and which are explicitly excluded.

The scope statement is short but matters: it is the boundary against which every later control and evidence sample is judged. An ambiguous scope is the most common Stage 1 finding.

Clause 5 — Leadership

Top management commitment, an information security policy that has been issued and communicated, and clearly assigned roles, responsibilities, and authorities for the ISMS.

Auditors will read the policy and look for evidence it has been distributed, acknowledged, and is being followed. They will also ask the named ISMS owner (often the CISO) to talk through how it is being run — answering this well is mostly about being present and prepared, not about presenting evidence.

Clause 6 — Planning

The risk assessment and treatment process under 6.1, information security objectives under 6.2, and planning of changes under 6.3. This is the largest of the clauses and the one that connects the management system to Annex A: every applicable control on the Statement of Applicability traces back to a risk treatment decision made here.

A defensible risk methodology — repeatable, with a written acceptance threshold and treatment options — is more useful than a perfect risk register. Auditors look for the method, the run history, and the decisions, not the spreadsheet.

Clause 7 — Support

Resources, competence, awareness, communication, and documented information. In practice: budget for the program, a defined competence matrix for ISMS roles, an awareness programme that staff can demonstrably evidence having completed, and a document control process so policies have versions and review dates.

The documented-information requirement is easy to fail and easy to fix: every controlled document has an owner, a version, a review cadence, and an approval trail. Most ISMS tooling — including SentinelPanda — handles this automatically.

Clause 8 — Operation

Operational planning and control, including how risk assessments and treatments are carried out on an ongoing basis. This is the clause that says "do what you said you would do" and where evidence of operating the program lives — control execution, evidence collection, treatment plan progress.

Clause 9 — Performance evaluation

Monitoring, measurement, analysis, and evaluation (9.1), internal audit (9.2), and management review (9.3). Internal audit must be planned, run by competent and independent staff, and produce findings that feed corrective action. Management review must be held at planned intervals with a defined input set (audit results, performance trends, risk and incident reports) and produce decisions.

A missed or thin management review is the single most common Stage 2 finding. Schedule them, prepare the input pack, and minute the outputs.

Clause 10 — Improvement

Continual improvement (10.1) and nonconformity and corrective action (10.2). Every finding from internal audit, management review, incident, or external audit must be tracked through a corrective action workflow with root cause analysis. The standard does not require zero findings — it requires the ones you have to be closed properly. A clean corrective action register is more reassuring to an auditor than no findings at all.

ISO 27001 Statement of Applicability SOC 2 or ISO 27001: which first?

Run your compliance program in one workspace.