ISO 27001 Security Questionnaire Answers: A 5-Type Model
ISO 27001 questionnaire answers sorted into five question types, with an evidence skeleton, a reuse calculation and the scope check buyers actually read.

An ISO 27001 security questionnaire rarely stops at whether you hold the certificate. One question asks that. The other eighty ask how a specific control operates inside your environment, and those are the ones that come back for a second round. An answer that survives the buyer's review names the scope it applies to, states what the control does in plain words, points at the document or record that proves it, and carries a date.
That is the whole model. What follows is how to apply it: how to sort the questions before writing anything, what to attach to each type, the arithmetic that tells you whether reusable answers pay off at your volume, and where answers quietly rot between workbooks.
Five question types, and why they need different answers
Nearly every ISO-referenced workbook decomposes into five kinds of question. Sorting them first is worth twenty minutes, because each type has a different evidence artefact and a different way of failing.
| Type | What the asker is checking | What to attach | Where it goes wrong |
|---|---|---|---|
| 1. Certification status | That a certificate exists, and what it covers | Certificate plus the scope statement | Sending the certificate alone and letting the buyer assume the scope |
| 2. Control existence | That a named control is written down and owned | The operative policy clause, not the policy title | Quoting a document name as if it were a control |
| 3. Control operation | That the control actually ran, recently | A record: review minutes, ticket, log export, test report | "Yes, per our policy" — an existence answer to an operation question |
| 4. Scope and applicability | That the control covers the product being bought | The applicability line plus an explicit boundary | Answering for the whole company when the buyer uses one product |
| 5. Deviation or roadmap | What is absent, who owns it, and by when | An exception record with owner and target date | Writing "planned" with no date attached |
Read the verb before you write. Do you have, do you maintain, is there a policy for are existence questions, and a clause reference closes them. How often, when did you last, who approved, how do you verify are operation questions. Useful working rule: treat any operation question you answered with a policy quote as an open item rather than a finished answer, and route it back to the control owner before export.
Type 4 is the one most teams underweight. A buyer purchasing one product does not care that your London office runs quarterly access reviews if the product they are buying is operated by a different team on a different platform. Scope the answer to what they are buying and say so in the first line.
The certificate question is the one people answer wrong
Certificates are issued against a stated scope, and the scope statement — not the certificate graphic — is the part a competent reviewer reads. Confirm the exact wording with the body that issued yours before you quote it anywhere.
Four lines are worth checking every time you attach it:
- The legal entity named. After a reorganisation or a holding-company change, the name on the certificate and the name on the contract stop matching, and nobody notices until legal review.
- The services or products named. If the buyer's product is not in that list, say so in the same answer rather than letting them find out at contract stage.
- The sites, platforms or regions named. A scope tied to one data centre does not silently extend to a new region you launched last quarter.
- The validity dates and the certification body. Reviewers check both, and an expired attachment reads worse than an honest note that recertification is under way.
If the product being purchased sits outside the certified scope, the workable answer is three sentences: what the certificate covers, what the product runs on instead, and which controls from the same control set are applied to it with what evidence. That answer is harder to write and much harder to argue with.
An answer skeleton that holds up in review
Four fields, in this order. It is deliberately dull, and dullness is the point — a reviewer can check it in fifteen seconds.
- Scope line — which entity, product and environment this answer describes.
- Control statement — what happens, in the present tense, in operational language.
- Evidence pointer — the document and clause, or the record type and system, that proves it.
- Status and date — in place since when, last verified when, or the exception with an owner.
Fictional example. The wording is the point, not the facts.
Weak: "Yes. Access is reviewed regularly in line with our access control policy."
Better: "In scope: Acme Ledger (EU production), operated by Acme GmbH. Privileged access to production is reviewed each quarter by the platform lead, with removals actioned through the standard change ticket. Evidence: Access Control Policy §4.3, plus review minutes and the associated tickets for the last four quarters. Last review completed 14 July 2026. Read-only analytics access to the staging environment is out of this review cycle and is covered separately."
The second version answers an operation question with an operation answer, names its own boundary, and volunteers the exception. That last move is counter-intuitive for people new to this work: flagging your own gap in the answer usually shortens the exchange, because the alternative is the buyer discovering it in round two and then doubting everything around it.
For the mechanics of turning approved answers into a maintained set rather than a folder of last year's documents, see Build a Security Questionnaire Answer Library That Lasts.
Check which edition of Annex A the workbook uses
Control numbering in Annex A changed between the older edition of the standard and the 2022 one, and questionnaires in circulation still mix the two. If a workbook cites control identifiers, confirm which edition it is built on before mapping your answers, and check the numbering against the standard text your own auditor works from. Where the workbook's identifiers and your Statement of Applicability disagree, answer against the control description in the question rather than the number — then note the mapping you used in the answer. It takes one extra sentence and prevents a mismatch that looks, from the buyer's side, like a missing control.
The evidence arithmetic behind reuse
Here is the calculation that decides whether an answer library is worth building at your volume. The figures below are a planning model, not a measurement — run it again with your own timings after the next workbook.
Take a 120-question ISO-referenced workbook. Those questions do not point at 120 distinct pieces of evidence. Modelled at roughly one evidence object per 3.5 questions, you are looking at about 34 distinct objects — a policy clause, a review record, a test report, a subprocessor list, and so on, each reused across three or four answers.
- Sourcing: ~34 objects × 25 minutes to locate the current version, confirm it is still accurate and get the owner to sign off ≈ 14 hours
- Writing: 120 questions × 4 minutes to scope and phrase ≈ 8 hours
- First pass total ≈ 22 hours, of which roughly two-thirds is not writing at all
The second workbook against the same product can skip most of the 14 hours — but only if each object was saved with its source document, its owner and its approval date. Save the answer text alone and you save the cheap half.
Two rules fall out of the model. Below roughly two ISO-referenced workbooks a year, a shared drive and a strict naming convention carry you, and tooling adds overhead you will not recover. Past roughly six a year, the bottleneck stops being writing and becomes knowing which version of an answer was approved, by whom, and whether the underlying evidence has since changed — a version-control problem wearing a questionnaire costume.
Tools that draft from your own uploaded documents can compress the eight-hour writing half. Compliance Concierge works this way: answers are drafted with citations back to the documents you uploaded, and nothing leaves the workspace without passing a human-review gate, with hosting in Frankfurt. The 14-hour half stays human, because only your team can say which document is the current one and whether the control still runs that way. The trade-offs of that split are set out in AI Security Questionnaire Automation With Human Review.
What to write when you are not certified
Plenty of teams receive ISO-referenced questionnaires without holding the certificate. The failure mode here is the phrase "aligned with ISO 27001", which tells a reviewer nothing and invites them to assume the least generous reading.
Split your position into three explicit buckets and answer each question against the right one:
- Implemented and evidenced — the control runs and you can show a record of it running.
- Documented but not independently examined — the policy exists and is followed; no external party has tested it.
- Not in place — with an owner and, where one exists, a target date.
Say which bucket each answer sits in. If you hold other third-party evidence — a penetration test summary, an external audit report of some kind — reference what it covers and what it does not, rather than letting it stand in for the whole control set. And avoid describing any of this as a compliance outcome; describe the controls and let the buyer's assessor draw their own conclusion. That is their job, and taking it from them tends to backfire.
Where answers go stale, and how it happens quietly
Reused answers fail on freshness far more often than on accuracy. Each of these has a refresh trigger and a way of failing without anyone noticing.
| Evidence | Refresh trigger | Silent failure |
|---|---|---|
| Certificate and scope statement | Validity end date; each surveillance cycle | The legal entity is renamed after a reorg and the certificate no longer matches the contract |
| Penetration test summary | Next test; any significant architecture change | The report covers a version of the product you no longer ship |
| Subprocessor list | Each new vendor added | Procurement onboards a tool without telling the security team |
| Access review records | Each review cycle | The review happened but was never minuted, so there is nothing to attach |
| Incident response exercise | Each exercise | The runbook was updated after an incident; the exercise was never repeated against it |
The cheap control is a single date field on every stored answer — evidence last verified — and a rule that anything older than your review cycle gets re-checked before it is exported rather than after a buyer questions it. A broader version of that discipline is covered in Security Questionnaire Best Practices: 12 Reliable Rules.
Three questions that come up every time
Can we answer "Yes" if the control exists but has never been tested? Split the answer instead of choosing. State that the control is documented and operating, state that it has not been independently tested, and name the date of the next planned test if one is scheduled. A qualified yes with a date reads as control; an unqualified yes that unravels in a follow-up call does not.
Should we attach the full Statement of Applicability? Decision rule: attach it when the buyer's questions are organised by Annex A control identifiers, since it answers dozens of them at once. Do not attach it when the workbook is written in plain operational language — you would be handing over a document that raises questions the buyer had not asked, including about controls marked as not applicable, and each of those becomes a new thread.
How do we answer a question that assumes a control we deliberately do not use? Answer the risk the question is aimed at, not the mechanism it names. If it asks about anti-virus agents on servers and you run immutable images rebuilt on every deploy, describe the property being achieved, the evidence for it, and why the named mechanism is not used in that environment. Answering "N/A" alone is what gets escalated.
The case where none of this works
A buyer sends a workbook written for an on-premise vendor — questions about server room access, physical media handling, endpoint agents on machines you do not own — and every answer becomes a paragraph explaining why the question does not map. Sixty of those and the document stops being an assessment.
At that point the productive move is not a better answer library. It is a thirty-minute call with their assessor to agree which sections apply, then answering the agreed subset properly and marking the rest with one shared note. Teams that do this early tend to finish faster than teams that answer all 200 questions faithfully — and if you want the general intake and triage sequence that surrounds it, that is set out in How to answer security questionnaires: step-by-step guide.
This article is operational guidance, not legal or certification advice. Confirm the scope and wording of your own certification with the body that issued it, and verify any regulatory question with qualified counsel.
From guidance to finished work
Answer the next questionnaire with evidence.
Upload the questionnaire and the policies behind it. Compliance Concierge drafts cautious, cited answers while every final decision stays with a human reviewer.