ISO/IEC 27001:2022: awareness, training & human risk
If your organisation is pursuing or maintaining ISO/IEC 27001:2022 certification — often because banks, telcos or multinational customers demand it — your certification auditor will spend real time on the human layer of your ISMS. Awareness and competence are mandatory clauses, not optional controls. This page explains exactly what the standard requires of your people, and how AfriPhish produces the records your auditor will ask to see.
What ISO/IEC 27001:2022 requires on awareness and human risk
Clause 7.2 — Competence. You must determine the competence needed by people whose work affects information security performance, ensure they are competent through education, training or experience, take actions to close gaps — and retain documented information as evidence of competence. The evidence requirement is written into the clause itself: an auditor is entitled to ask for the records, not just the intention.
Clause 7.3 — Awareness. Everyone working under your control must be aware of the information security policy, their own contribution to the effectiveness of the ISMS, and the implications of not conforming. "Everyone" includes contractors and temporary staff, and awareness must be demonstrable — a poster in the kitchen does not satisfy a stage 2 audit.
Annex A control 6.3 — Information security awareness, education and training. Personnel must receive appropriate awareness, education and training, and regular updates to the organisation's policy and procedures relevant to their function. The control expects an ongoing programme, sensitive to roles, not a single induction session.
Supporting Annex A controls. Several other controls only work when people are trained: A.5.10 (acceptable use of information and other associated assets) presumes staff know and have acknowledged the rules; the A.8.7 protection-against-malware control explicitly pairs technical defences with user awareness, since phishing remains the dominant malware delivery path; and event-reporting controls depend on employees recognising and escalating suspicious activity through a known channel.
Clauses 9 and 10 — audit, review, improvement. Your internal audit and management review must cover the awareness programme like any other part of the ISMS: is it operating, is it effective, is it improving? That implies metrics — completion rates, simulation outcomes, trend lines — reviewed by management and acted on. A programme with no measurements cannot demonstrate continual improvement.
The obligations AfriPhish helps you evidence
| ISO/IEC 27001:2022 requirement | AfriPhish module | Evidence produced |
|---|---|---|
| Clause 7.2 competence records | Role-aware training library, incl. a dedicated IT/SecOps track | Per-user completion records, quiz scores, assignment dates |
| Clause 7.3 awareness of policy and contribution | Awareness training + policy distribution | Completion logs tied to named policies and versions |
| Annex A 6.3 ongoing programme with updates | Scheduled campaigns and training series | A dated campaign history showing regular, recurring activity |
| A.5.10 acceptable use acknowledged | Policy management with e-signature attestation | Versioned, timestamped signature registers per employee |
| A.8.7 user-facing anti-malware awareness | Phishing simulations across realistic scenario families | Click, credential-submission and report rates per campaign |
| Clause 9 measurement for audit and review | Human risk scoring, reports and analytics | Trend reports and risk scores ready for management review packs |
Because simulations, training and attestations share one data model, effectiveness is measured, not asserted: you can show that the people who clicked in March completed remedial training in April and stopped clicking by June.
What auditors typically ask for
Certification and surveillance audits of the human layer are predictable. Expect requests for:
- Competence and training records (clause 7.2) — who needed what training, who completed it, and the documented result.
- Awareness evidence (clause 7.3 and A.6.3) — programme plans, campaign dates, and per-person completion logs covering employees and contractors.
- Policy acknowledgement registers — signatures against the current version of the information security and acceptable-use policies.
- Simulation and testing results — proof that awareness effectiveness is verified in practice, with trend data across campaigns.
- Management review inputs — the awareness and human-risk metrics that reached management, and what was decided in response.
- Nonconformity follow-up — evidence that repeat-clickers or non-completers were identified and addressed, closing the improvement loop.
All of the above export directly from AfriPhish, scoped to your audit period.
See where your organisation stands
Before your next stage 1, gap-assess the human layer. Take the free 4-minute Human Risk Maturity Assessment — it benchmarks your awareness programme against what clauses 7.2, 7.3 and Annex A 6.3 actually require, and highlights what an auditor would flag.
Working towards certification with a consultant or internal team? Book a demo and we will show you the exact reports that go into an ISMS evidence file.