ISO27K

ISO 27001 clause 5: leadership and policy

Clause 5 is three requirements long and it is the one clause you cannot delegate to the person running the project. An auditor tests it by interviewing whoever signed the policy, and the interview goes badly for the same reason every time.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

Clause 5 of ISO/IEC 27001:2022 carries three requirements: 5.1 leadership and commitment, 5.2 policy, and 5.3 organizational roles, responsibilities and authorities. It is the shortest of the seven auditable clauses and the one most likely to produce a finding that cannot be fixed by writing a document, because what it asks for is evidence that people with authority actually did something. A signed policy alone does not close clause 5. An auditor will ask the person who signed it what the top information security risk to the business is, and the answer is the audit result.

What clause 5.1 asks top management to do

Eight things, and the word used is shall. Top management here means the people who direct and control the organization at the highest level, so in a forty-person Canadian company that is the CEO and possibly one other executive, not the security lead and not the consultant.

Clause 5.1 obligations and the evidence that closes each
What top management shall doEvidence an auditor accepts
Ensure the policy and objectives are established and compatible with the strategic directionThe approved policy, plus objectives that reference something the business actually cares about
Ensure the ISMS requirements are integrated into the organization's processesSecurity steps inside existing processes: onboarding, change management, procurement. Not a parallel process nobody uses
Ensure the resources needed are availableA budget line, a headcount, or a signed contract. This is the one that gets tested with a number
Communicate the importance of effective information security managementAll-hands slides, a written message, an onboarding deck. Dated
Ensure the ISMS achieves its intended outcomesThe management review record, which is where this is demonstrated
Direct and support people to contribute to the effectiveness of the ISMSObjectives in performance reviews, time allocated, or a named owner released from other work
Promote continual improvementImprovement items raised by management rather than only by the auditor
Support other management roles to demonstrate leadership in their areasEngineering, HR and finance leads who can each describe their own security responsibilities

Read the eight together and the pattern is clear. Six of them are satisfied by things that happen in meetings and one is satisfied by money. None of them is satisfied by a document that top management approved without reading, which is the arrangement clause 5 exists to catch.

What the information security policy has to contain

Clause 5.2 requires one policy, not twenty. This causes more confusion than anything else in the clause, because the word policy is used two ways in an ISO 27001 project. The clause 5.2 policy is a top-level statement of intent, typically two pages. The access control policy, the cryptography policy and the supplier policy are Annex A artifacts and are a different thing entirely.

Appropriate to the purpose of the organization
It has to say what the organization does. A policy that would apply unchanged to a hospital, a bank and a game studio has failed this test, and template policies fail it by design.
Includes objectives or a framework for setting them
Either the actual objectives or a stated method for setting and reviewing them. The second option is usually better, because objectives change more often than the policy should.
Includes a commitment to satisfy applicable requirements
Legal, regulatory and contractual. For a Canadian company that means naming PIPEDA or the provincial statute that displaces it, plus customer contract terms.
Includes a commitment to continual improvement
One sentence, and it has to be true, which clause 10 will test.
Available as documented information
Version controlled under clause 7.5, with an approval date and an approver.
Communicated within the organization
Evidence of receipt, not evidence of publication. An intranet page nobody opened is a weak answer and a training acknowledgement is a strong one.
Available to interested parties as appropriate
Usually a public summary or a copy provided on request. You do not have to publish the whole thing.

The two-page test

If your clause 5.2 policy is thirty pages, you have merged the top-level policy with the control-level policies, and the cost of that shows up later: every change to a technical standard now requires executive re-approval, and the version an auditor samples is usually stale. Keep the top-level policy to two pages, keep it stable for years, and let the control-level documents change underneath it on their own approval routes.

Clause 5.3 and who has to be named

Clause 5.3 requires top management to assign responsibility and authority for two specific things: ensuring the management system conforms to the standard, and reporting on the performance of the management system to top management. That is a narrower requirement than most role matrices assume. You do not have to appoint a chief information security officer, and the standard never uses the phrase.

What you do have to be able to show is that a named person holds those two duties, knows they hold them, and has the authority to act on them. The failure pattern is a matrix listing twelve roles where the person named for ISMS performance reporting learns about it during the audit interview. Where there is nobody internal with the time or the standing to hold it, a fractional security lead can, provided the arrangement gives them real authority and provided they are then not also your internal auditor, because clause 9.2 asks for auditors who do not audit their own work.

What the auditor asks the CEO

Stage 2 includes a top management interview, usually 30 to 60 minutes, and it is not a formality. The questions are predictable, which is the useful part.

  1. What does this management system cover, and why did you draw the boundary there. Tests clause 4.3 and whether leadership owns the scope decision.
  2. What are the top information security risks to this business. Tests whether the risk assessment reached the top of the organization or stopped at the security team.
  3. What did you decide at the last management review. Tests clause 9.3 and whether the meeting happened with the person answering in the room.
  4. What resources have you committed this year. Tests 5.1 c) with a number, and vague answers here become findings.
  5. What are the objectives and how are they measured. Tests clause 6.2, and an executive who cannot name one of four objectives is a real finding.
  6. What would happen if the security lead resigned tomorrow. Tests 5.3 and resource adequacy at the same time.

Preparing for this is legitimate and expected. Rehearsing answers to questions nobody at the top can actually answer is not, because the follow-up question is always for the evidence.

Why clause 5 findings escalate

A nonconformity is major when a requirement is entirely absent or when the failure is systemic rather than isolated, and clause 5 failures are structurally more likely to be both. If the management review never happened, the requirement is absent rather than inconsistently met. If top management cannot describe the system they are accountable for, that is not one missing record, it is evidence that the integration required by 5.1 b) did not occur. The mechanics of what happens next, and the timelines for closing it, are on the nonconformity page.

30 to 60 minutes Top management interview at stage 2

When the owner really is the whole management layer

The counter-case, and it matters because most Canadian companies buying a first certificate are small. In a twenty-person company the founder is top management, the budget holder, the risk owner and frequently the person who configured single sign-on. Auditors know this. Clause 5 does not require a separation of those hats and it does not require a board. What it requires is that the decisions are visible.

An owner-run ISMS reads well when three things are true. The founder can describe the risks in business terms rather than reading them from a register. There is a dated record of decisions, even if it is a monthly meeting with two people in it, which is a legitimate management review if it covers the required inputs. And the person who performs the internal audit is somebody else, bought in, at $6,000 to $15,000 CAD a year, because that is the one duty the founder cannot hold as well.

It reads badly when the founder delegated the entire project to a consultant and appears for the interview cold. That is the single most common way a small company fails clause 5, and it costs more than the two hours of executive time that would have prevented it. The readiness page covers how to test for it before the certification body does.

What to actually produce

  • The policy. Two pages, approved and dated by top management, naming what your organization actually does.
  • Proof it was received. Acknowledgement per person, not a link on an intranet.
  • The two assigned duties. A named owner for ISMS conformity and a named owner for reporting ISMS performance upward, both of whom can confirm it.
  • The resourcing evidence. An approved budget line, a headcount, or a signed contract. Clause 5.1 c) is tested with a number.
  • Minutes with decisions in them. Top management discussing security outcomes, not only approving documents someone else wrote.
  • Objectives the executive can state without notes.
  • A one-page brief for whoever sits the top management interview, built from the six questions above.

Get help closing the clause 5 gap

Tell us where you are and we will match you with Canadian firms that work with executives rather than only with security teams.

Get matched

Common questions

Who counts as top management for ISO 27001?

The person or group who directs and controls the organization at the highest level. In a small Canadian company that is the founder or CEO, and possibly a co-founder or CFO. It is not the security manager, the IT director or the consultant, and naming one of those as top management is a finding rather than a shortcut.

How long should the information security policy be?

Two pages is normal and sufficient for clause 5.2. It has to be appropriate to what your organization does, frame or state the objectives, commit to meeting applicable requirements and to continual improvement, and be communicated. The detailed access control, cryptography and supplier policies sit underneath it as Annex A artifacts and are approved separately.

Do we need to appoint a CISO to satisfy clause 5.3?

No. The standard requires that responsibility for ISMS conformity and for reporting ISMS performance is assigned to someone with the authority to carry it, and it does not name a job title. A part-time or fractional arrangement is acceptable. What is not acceptable is a name on a matrix that the named person cannot confirm during an interview.

Does the CEO have to attend the audit?

For the top management interview at stage 2, yes, or whoever genuinely holds that role. Certification bodies schedule it specifically and will raise a finding if nobody at that level is available. Book it as a fixed appointment when the audit dates are agreed rather than treating it as a slot that can move.

Can the policy just be a template with our name on it?

It can start as one, and it cannot stay as one. Clause 5.2 a) requires the policy to be appropriate to the purpose of the organization, and a document that describes no specific business fails that requirement on its face. Editing a template so it names what you do, what you hold and which Canadian privacy statute applies to you takes about an hour and removes the easiest finding on the page.

What is the difference between the policy and the Statement of Applicability?

The policy is a short statement of intent required by clause 5.2 and approved by top management. The Statement of Applicability is required by clause 6.1.3 and records a decision on all 93 Annex A controls with justifications. They serve different clauses, they are approved by different people in most organizations, and neither substitutes for the other.