GuideJuly 18, 20269 min read

ISO/IEC 27001 Annex A Awareness Controls in Practice

Awareness and training obligations in ISO/IEC 27001 Annex A are easy to state and hard to evidence. Here is how phishing simulation and training programs translate into audit-ready ISMS records.

Which Annex A Controls Cover Awareness

The 2022 revision of ISO/IEC 27001 Annex A consolidates people-related requirements, including information security awareness, education, and training, into the People controls category, reflecting a broader shift toward treating human behavior as a control domain in its own right rather than an afterthought to technical controls. The core expectation is that personnel receive awareness education and training appropriate to their job function, updated regularly, and that the organization can demonstrate this happened, not merely that a policy document says it should.

Related controls in the same section touch on terms and conditions of employment, disciplinary processes, and responsibilities after termination or change of employment, all of which connect to awareness in practice: a disciplinary process that is inconsistently or punitively applied to phishing simulation results, for instance, undermines the very awareness control it is meant to support by discouraging honest reporting. Reading these controls in isolation from each other is a common audit-preparation mistake; an examiner will often trace how they interact.

This article keeps its control references general and points to the awareness, education, and training clause as the anchor point, since exact clause numbering can shift between standard revisions and organizations should always confirm current wording against their certified scope and the specific revision they are audited against, rather than relying on secondary sources, including this one, for the authoritative text.

Which Annex A control covers awareness

The awareness requirement sits in Annex A control A.6.3, information security awareness, education and training. It asks that personnel and, where relevant, interested parties receive appropriate awareness education and training, together with regular updates to organizational policies and procedures relevant to their job function.

Two words in that control do most of the work. Appropriate means the content should match what the person actually does, so a finance team handling payment instructions should not receive the same generic module as everyone else. Regular means awareness is a continuing obligation, not an induction task completed once.

A common point of confusion when searching: A.6.3 in Annex A is not the same as clause 6.3 of the main standard, which concerns planning of changes. Auditors asking about awareness evidence are asking about A.6.3.

What Auditors Actually Look For

An ISO 27001 auditor evaluating the awareness control is not looking for a training slide deck; they are looking for evidence that the organization identified who needs what kind of awareness content, delivered it, and can show whether it worked. A policy statement that all employees receive annual security awareness training satisfies almost nothing on its own; the auditor wants attendance or completion records tied to individuals, content that maps to identified risks, and ideally some indication of effectiveness measurement.

A recurring finding in real audits is a program that trains everyone identically regardless of role, when the standard's expectation, read in the context of risk-based management systems generally, is that awareness content should be appropriate to the audience: a teller-facing simulation program that never varies its scenarios by role, department, or observed risk looks like a compliance exercise rather than a risk-based control, and auditors increasingly probe for that distinction.

The strongest audit evidence combines three things: training delivery records, who was assigned what, when, and whether they completed it, simulation results showing applied behavior rather than just knowledge recall, and a documented feedback loop showing the organization adjusted its program based on results. An organization that can show its click rate trend, its reporting rate trend, and a management review noting an intervention taken in response, has a materially stronger evidence package than one showing completion percentages alone.

How Simulation Data Becomes ISMS Evidence

Phishing simulation results map directly onto the awareness control's expectation of demonstrable effectiveness, provided the data is retained and organized correctly: campaign records showing target scope, template used, click and report rates, and any follow-up action taken constitute exactly the kind of objective evidence an ISMS internal audit or external certification audit expects to see under the awareness clause. Raw click-through numbers alone are weak evidence; the trend over time, correlated with the training interventions delivered in response, is what demonstrates a functioning control rather than a one-off activity.

Just-in-time awareness delivery, triggered automatically at the moment of a simulated click, produces a particularly clean evidence trail because the system logs the trigger event, the content delivered, and the timestamp in one continuous record, which is far easier to present to an auditor than reconstructing a manual training assignment history after the fact. This kind of tight causal linkage, a click leads to immediate targeted content which leads to a logged completion, is exactly the PDCA in miniature an auditor is trained to look for within a single control.

The phish-reporting loop closes a gap that pure simulation data leaves open: an organization that only measures clicks has no evidence employees can also act as a detective control, whereas a reporting rate trend, tied to a documented review and reward process, demonstrates the awareness control functioning as intended, converting trained personnel into an active layer of the ISMS rather than a passive population being tested. Retain reporting statistics and review records with the same rigor as training completion logs, since both feed the same control.

Mapping to the ISMS and Continuous Improvement

Annex A controls do not exist in isolation from the main-clause requirements around risk assessment and the Plan-Do-Check-Act cycle, and awareness content should trace back to the organization's own risk assessment rather than a generic template library. If the risk assessment identifies business email compromise or invoice fraud as elevated risks for the finance department specifically, the awareness and simulation program should show a documented decision to weight content accordingly, not a uniform program applied without reference to the risk register.

The Check and Act stages are where most awareness programs are weakest in practice: an organization runs simulations and training but rarely documents a formal management review of the resulting metrics feeding back into scope or content changes for the following period. A simple quarterly review record, showing the metrics examined, the conclusion drawn, and any resulting change to the program, converts an ad hoc set of activities into a demonstrable management system control that satisfies the standard's continuous improvement expectation.

For organizations also managing OJK, BSSN, or UU PDP obligations alongside ISO 27001 certification, the same underlying evidence, campaign records, reporting rate trends, training completion logs, and management review minutes, generally satisfies multiple frameworks simultaneously with different framing rather than requiring separate data collection efforts. Building the evidence trail once, structured cleanly, and mapping it to each framework's specific requirements as needed is far more sustainable than running parallel, disconnected compliance exercises.

A Practical Evidence Checklist

At minimum, an ISMS supporting the awareness control should be able to produce, on request: a current risk-based rationale for what awareness content is delivered to which population, individual-level training assignment and completion records for the audit period, phishing simulation campaign records including targeting, template, and results, and reporting rate data for the same period.

It should also be able to show a documented management review that examined these metrics at least annually, ideally quarterly, along with any resulting change to the program's scope, content, or targeting, and disciplinary or corrective action records showing consistent, non-punitive handling of simulation results in a way that has not measurably suppressed reporting behavior over time.

None of this needs to be produced manually at audit time if the underlying platform generates it as a byproduct of running the program: campaign results, JIT delivery logs, reporting statistics, and completion records that already exist in the system used to run simulations and training should be exportable directly into the evidence package an auditor requests, rather than reconstructed from spreadsheets after the fact. Building the audit trail into the operating system of the program, rather than treating it as a separate compliance task, is what keeps this control sustainable year over year.

Key takeaways

  • The awareness, education, and training control expects demonstrable delivery and effectiveness, not a policy statement alone.
  • Auditors look for role-appropriate content and a documented feedback loop, not identical training for every employee.
  • Simulation click rates, reporting rates, and JIT delivery logs are strong ISMS evidence when retained and trended over time.
  • Map awareness content to your own risk assessment, and document the quarterly or annual management review that closes the PDCA loop.
  • The same evidence trail can generally satisfy ISO 27001, OJK, and UU PDP expectations simultaneously if structured cleanly from the start.

Build a program that sticks

Claro helps you run simulation, training, and reporting in one place.

Request a demo