ISO 27001 doesn't audit your technology — it audits your Information Security Management System, the programme by which you manage risk. Which raises a quiet question for 2026: when your organisation deployed AI agents, did your ISMS notice? Because your certification auditor will.
Agents are in scope the moment they act
An ISMS covers the systems that touch the information you've promised to protect. Agents that call tools, read records, and act on production systems are unambiguously such systems — and the Annex A controls around logging, monitoring, and operations apply to their activity just as they do to human-driven activity.
"Did the ISMS notice" is not a rhetorical jab; it's a checklist. Does the asset register list the agents? Does the risk assessment have entries for what they can reach? Do the operating procedures say who reviews their activity, and is there a record of those reviews happening? In most organisations the honest answers are no, no, and no — not from negligence, but because agents arrived between certification cycles and slotted into nobody's existing checklist. The awkward part is evidential: your existing controls were evidenced with mechanisms designed for people and conventional software. Agent activity needs its own answer to "show me this control operating."
What the pack contributes
An ISO 27001 Evidence Pack assembles that answer for the agent-activity slice of your ISMS: agent and tool inventories, monitoring evidence per control, signed event samples, and a control-by-control narrative aligned to your Statement of Applicability — the document your audit actually runs against. Alignment to the SoA is the practical point: your auditor doesn't walk a generic checklist, they walk your declared control set, and evidence organised any other way makes them do the mapping themselves, at your hourly expense.
Because the evidence is drawn from the live recorded trail, a surveillance audit gets the same quality of answer as the certification audit did. That's worth dwelling on: ISO certification isn't a one-time event but a three-year cycle with annual surveillance in between, and the classic failure mode is the control that was polished for certification and quietly decayed by the first surveillance visit. Evidence that accumulates continuously can't decay that way — the record for any month exists because the recorder ran that month, not because anyone prepared.
The division of labour, stated plainly
ISO 27001 covers an entire management programme, and we are precise about which part is ours. The ISMS itself — scope decisions, the risk assessment, the Statement of Applicability — stays yours: those are governance deliverables no vendor can produce for you honestly. Wytness evidences the AI-agent activity controls within the scope you've drawn; it does not implement risk management, supplier management, or HR security on your behalf. Any tool that claims to "do ISO 27001 for you" is describing a different standard.
Why recorded evidence suits an ISMS
The standard's deepest idea is that security is a continuously operating system, not an annual event. Evidence generated continuously — every agent action signed and chained as it happens — matches that philosophy in a way that assembled-for-audit artefacts never quite do. When the auditor picks a week from eight months ago, the record for that week already exists, already verifies, and was already being watched by the anomaly engine at the time. Monitoring that demonstrably operated is a different class of answer from monitoring that demonstrably exists — and the difference is precisely what separates a conforming ISMS from a documented one.
The control mapping lives on the ISO 27001 page. Questions about your Statement of Applicability? Ask us.