Consultant reviewing an ISO 27001 control register on screen
Secure Chain Horizon

ISO 27001 control management that survives the surveillance audit.

Horizon holds your Annex A control set, ownership, evidence and Statement of Applicability in one place, so the ISMS reflects what's actually happening between audits rather than what was true on certification day.

Annex A controls tracked
93
Controls with named owner
100%
Evidence past review date
0
Illustrative figures
The challenge

Certification is a moment. The controls have to hold for three years.

ISO 27001:2022 replaced the old fourteen-domain structure with 93 controls across four themes — organisational, people, physical and technological — and most organisations manage the transition fine on paper, at the point of certification. The harder problem arrives afterwards, when the control set has to keep functioning through annual surveillance audits and the eventual recertification, with staff changes, new systems and shifting risk exposure all pulling at the same document set.

The usual failure mode isn't a missing control; it's a control that was implemented once, evidenced once, and then left. A firewall rule review that happened for the initial audit and never again. A supplier due diligence check that was current at certification and is now eighteen months out of date. An access review that a departed employee used to run, with nobody quite sure who picked it up.

Spreadsheets make this worse rather than better. A control register in a shared workbook has no owner enforcement, no automatic flag when a review date passes, and no version history to show an auditor what changed between last year's evidence and this year's. When someone finally opens it before an audit, the gaps are discovered under time pressure rather than managed as they arose.

The Statement of Applicability compounds the problem, because it's meant to be a living justification of which controls apply and why, not a document written once during the Stage 1 audit and quietly ignored afterwards. Auditors increasingly ask how the SoA is kept current, and 'we update it before the next audit' is a weaker answer than most organisations realise until they're asked it directly.

None of this is really about the controls being wrong. It's about the absence of a mechanism to keep ownership, evidence and review dates connected to the actual control set as time passes and the organisation changes shape.

  • Controls evidenced once at certification, never revisited
  • No single owner accountable when a review date passes
  • Statement of Applicability drifting from the live control set
  • Evidence scattered across email, shared drives and individual laptops
Our approach

One register, one owner per control, one place for the evidence.

Horizon's control register lists all 93 Annex A controls under their four themes, with each control assigned a named owner, an implementation status and a review date. Nothing sits unowned, and nothing is left to memory — the register makes it obvious at a glance which controls are current, which are approaching review, and which have drifted.

The Statement of Applicability is built from the same data rather than maintained separately. Inclusion or exclusion decisions and their justifications are recorded against each control, so the SoA stays aligned to the actual control set instead of becoming a static document that quietly diverges from reality after the first audit.

Evidence is attached directly to the control it supports — a policy document, a configuration export, a training completion record — with version history retained and an expiry reminder set. When a policy is due for review or a screenshot is a year old, Horizon flags it before it becomes a finding rather than after.

Internal audit and nonconformity tracking close the loop. Findings are logged against the relevant control with a corrective action, an owner and a target closure date, so there's a visible record of what was found, who fixed it and when, ready to show a surveillance auditor without reconstructing the story from memory.

We work alongside your own information security lead rather than around them. Horizon gives them the structure to keep the ISMS current between audits, and where it's useful we bring the same senior consultants who support ISO 27001 implementation to help interpret findings or plan the surveillance cycle.

  • Every Annex A control assigned to a named owner with a review date
  • Statement of Applicability generated from live control data, not a separate document
  • Evidence library with expiry reminders and version history per control
  • Nonconformities tracked from finding to closure against the relevant control
What's included

Everything in the engagement, set out up front.

Everything needed to run Annex A control management as ongoing practice rather than an annual scramble.

Full Annex A control register

All 93 controls across the four themes, pre-loaded and ready to assign owners and status against your ISMS.

Statement of Applicability support

Inclusion and exclusion decisions recorded and justified against live control data, not a document maintained separately.

Evidence library

Policies, configuration exports and records attached per control, with expiry reminders and version history.

Review date tracking

Automatic flags as control reviews fall due, so nothing is rediscovered for the first time during an audit.

Internal audit and nonconformity log

Findings recorded against the relevant control with corrective actions, owners and closure dates.

Role-based access

Control owners see what's assigned to them; the ISMS lead sees the whole register and audit trail.

Deliverables

What you receive.

  • Pre-populated 93-control Annex A register
  • Control ownership assignment across the organisation
  • Statement of Applicability aligned to live control status
  • Evidence attached and version-controlled per control
  • Review date schedule with automated reminders
  • Nonconformity and corrective action log
  • Audit-ready evidence export by control or theme
  • Executive dashboard summarising control status
Who it suits

Built for organisations that need the work done properly.

Newly certified organisations

Businesses that have just achieved ISO 27001:2022 and want the control set managed properly from day one rather than left in the certification consultant's spreadsheet.

Organisations facing surveillance audits

Teams who know the annual surveillance visit is coming and want evidence and ownership current before the auditor asks for it.

ISMS leads inheriting a register

Information security managers who've taken over an ISMS built by someone else and need to see, quickly, what's owned, current and overdue.

Multi-site or multi-team organisations

Businesses where control ownership genuinely sits across IT, HR, facilities and compliance, and needs distributing rather than centralising on one person.

Outcomes & benefits

What changes once the work is done.

What changes once control management moves off spreadsheets and into a working register.

Surveillance audits with fewer surprises

Evidence and ownership current throughout the year, not assembled in the fortnight before the auditor arrives.

A Statement of Applicability that reflects reality

Inclusion and exclusion decisions kept in step with the actual control set, defensible when questioned.

Clear accountability per control

Every control has a named owner, removing the ambiguity that leaves gaps unnoticed until an audit finds them.

Evidence that doesn't go stale

Expiry reminders catch policies and records before they're out of date, not after an auditor points it out.

A visible nonconformity trail

Findings tracked from identification through corrective action to closure, ready to show on request.

Less disruption at recertification

A control set maintained continuously through the three-year cycle, rather than rebuilt under pressure at the end of it.

Control management is an ongoing discipline, not a certification exercise.

It's worth being direct about what Horizon is and isn't. It's a platform for managing your control register, evidence and Statement of Applicability — it does not certify you, and it doesn't replace the judgement of an accredited certification body carrying out your Stage 1, Stage 2 or surveillance audits. What it does is remove the administrative reason those audits go badly: evidence that can't be found, owners who've moved on, review dates nobody tracked.

The four-theme structure introduced in the 2022 revision — organisational, people, physical and technological — was meant to make Annex A easier to reason about, and it generally does, but only if the register reflects that structure rather than a flat list nobody's reorganised since the transition. Horizon keeps the theme grouping visible so you can see at a glance where control coverage is strong and where it's thin.

We work with organisations across Chesterfield, Sheffield, Derby, Nottingham, Leeds, Manchester, Birmingham and London on ISO 27001 implementation and ongoing ISMS support, and the pattern is consistent: the organisations that find surveillance audits straightforward are the ones where control ownership and evidence review happened continuously through the year, not the ones with the most polished document set on the day.

If you're mid-implementation rather than already certified, Horizon works the same way — the register, ownership and SoA support are built as you go, so there's no separate exercise later to retrofit a working control structure onto a certificate you've already been awarded.

Frequently asked questions

Questions we are asked most often.

How does Horizon map to Annex A of ISO 27001:2022?

Horizon holds all 93 Annex A controls across the four themes — organisational, people, physical and technological — with each control given an owner, an implementation status and a review date. You can filter by theme, by owner or by outstanding review, and the control register underpins the Statement of Applicability rather than sitting apart from it.

Does Horizon generate our Statement of Applicability?

It supports it rather than replaces the judgement behind it. Horizon tracks which controls are included or excluded, records the justification against each, and keeps the SoA aligned to the live control set, so the document reflects what's actually in place instead of a spreadsheet frozen at certification and never updated.

Is Horizon a substitute for our certification body?

No. Horizon is a management platform, not a certification body, and it does not replace an accredited auditor. What it does is keep your control evidence, ownership and review history organised so that when an external audit happens, the answers and the supporting documents are already in one place rather than assembled under time pressure.

How does evidence expiry work in practice?

Each piece of evidence attached to a control — a policy, a configuration export, a training record — carries an expiry or review date. Horizon flags items approaching that date so evidence doesn't quietly go stale between audits, and it keeps prior versions so you can show what changed and when if an auditor asks.

Can we use Horizon if we're not certified yet?

Yes. Many organisations start using the control register and SoA support during implementation, before their first certification audit, so the structure is already in place rather than built retrospectively. It works equally well for organisations maintaining certification through subsequent surveillance cycles.

Who typically owns controls day to day?

It varies by organisation, but control ownership is usually split between IT, HR, facilities and a compliance or information security lead, reflecting the mix of technological, people, physical and organisational controls in Annex A. Horizon assigns ownership at the control level so accountability doesn't default to one person managing everything.

Does Horizon handle nonconformities from internal audit?

Yes. Internal audit findings and nonconformities are logged against the relevant control, with a corrective action, an owner and a closure date, so there's a visible trail from finding to resolution rather than a nonconformity noted once and never followed up.

Is Horizon hosted in the UK?

Yes, Horizon is hosted in the UK. Access is role-based, so control ownership, evidence and audit records are visible to the people who need them without giving every user the same level of access across the whole ISMS.

See how your Annex A controls would sit in Horizon.

We'll walk through the control register with your own ISMS in mind — no pressure, just an honest look at where ownership and evidence stand today.

Book a Horizon walkthrough