Audit the ISMS internally on a set schedule to learn whether it meets the organization's own ISMS requirements and those of ISO/IEC 27001 and whether it is effectively in place and kept up; plan and maintain one or more audit programmes that fix how often, how, by whom, with what planning and with what reporting audits happen, weighted by how important the processes are and what earlier audits found; set criteria and scope for each audit; choose auditors and run audits so the process is objective and impartial; report results to the relevant managers; and keep documented evidence of the programme and results. Implementation points (general practice; the 27003 guidance text is not held): cover the whole ISMS over a cycle, test effectiveness as well as conformity, and use ISO 19011 for auditing guidance.
This control maps to 18 controls across 14 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 18 it maps to, and the evidence behind each claim, over MCP and REST.