Assessment workflow
1. Establish and approve the AIMS scope
Section titled “1. Establish and approve the AIMS scope”Complete the scope record, included systems, exclusions, interested parties, owner, approver and version. Verify that the save indicator confirms the current scope was saved.
2. Define assessment criteria and evidence period
Section titled “2. Define assessment criteria and evidence period”Record the licensed standard edition, internal criteria, locations, population, sampling approach and evidence cutoff. Conclusions must be tied to this basis.
3. Work through clauses 4–10
Section titled “3. Work through clauses 4–10”Assess each atomic check. Use the on-screen advisory to understand:
- The audit objective.
- Questions to ask.
- Evidence to inspect.
- A bounded audit test.
- Common failure patterns.
- Implementation and reassessment guidance.
4. Decide conformity
Section titled “4. Decide conformity”Choose Not assessed, Conformity supported, Partial evidence or Nonconformity. Record rationale that identifies evidence, sample, observed result, exceptions, owner and reassessment trigger.
5. Record assurance depth
Section titled “5. Record assurance depth”Separately choose Unverified, Documented, Implemented or Assured. Do not infer operating effectiveness from a favourable conformity label.
6. Complete the Annex A SoA
Section titled “6. Complete the Annex A SoA”For all 38 controls:
- Determine applicability.
- Record risk-linked justification.
- Assess applicable controls.
- Document justified exclusions.
- Resolve every undetermined decision.
7. Link evidence
Section titled “7. Link evidence”Use controlled documents, completed records, operating data, meeting records, audits, tests, findings, corrective actions and management decisions from inside the scope and evidence period.
8. Perform audit tests
Section titled “8. Perform audit tests”Use representative, traceable samples. Record population, selection method, criteria, result, exceptions and reviewer. Where a result depends on technical control, test the control safely.
9. Raise and classify findings
Section titled “9. Raise and classify findings”Record nonconformities and weaker observations consistently. Link each to the atomic check, evidence, cause, correction, corrective action, owner, due date and verification.
10. Review completeness and contradictions
Section titled “10. Review completeness and contradictions”Before whole-scope analysis or conclusion, confirm:
- Every core check is assessed.
- Every Annex A decision is resolved.
- Every applicable Annex A control is assessed.
- Exclusions are adequately justified.
- Conformity-supported claims have rationale and evidence.
- Adverse findings and failed tests are reflected.
11. Write the human conclusion
Section titled “11. Write the human conclusion”State:
- AIMS scope and criteria.
- Assessment period and evidence cutoff.
- Supported strengths.
- Material nonconformities.
- SoA status.
- Evidence and sampling limitations.
- Corrective-action priorities.
- Confidence and next review.
Confirmation records the assessor’s conclusion only. It is not certification.
12. Maintain and improve
Section titled “12. Maintain and improve”Update the assessment after material scope or system change, audit findings, incidents, new obligations, management review decisions and corrective-action verification.
Completion checklist
Section titled “Completion checklist”- Scope approved and visibly saved.
- Licensed standard and criteria identified.
- All 173 clause checks assessed.
- All 38 Annex A applicability decisions resolved.
- Conformity and assurance recorded separately.
- Rationale is scope- and evidence-specific.
- Tests are representative and traceable.
- Nonconformities reflect adverse evidence.
- Corrective actions include cause and effectiveness verification.
- Human conclusion states limitations and evidence cutoff.