ISO 27001 Evidence
ISO 27001:2022 Annex A control register, evidence collection, audit trail, risk treatment and coverage-gap reporting — all inside Odoo
Run your ISO 27001:2022 Information Security Management System evidence workflow directly in Odoo. Catalog every Annex A control, attach the evidence that proves each one is operating, log audit events, manage risk treatment, and surface the controls that are missing recent evidence — so you walk into a certification or surveillance audit with the paper trail already assembled. Self-contained, no external services, no subscriptions.
Key Features
Annex A:2022 Control Catalog
All 93 Annex A controls seeded across the four 2022 themes — Organizational (A.5), People (A.6), Physical (A.7) and Technological (A.8). Each iso27001.control carries its clause reference, theme and owner.
Statement of Applicability
Decide applicable vs. not-applicable per control and record inclusion / exclusion justifications right on the record. Print the full SoA as a themed QWeb PDF in one click for your auditor.
CAPA (Corrective / Preventive)
iso27001.capa runs a closed-loop nonconformity workflow — root-cause analysis, action plan, owner, due date and priority — through draft → open → in progress → pending verification → closed, with a mandatory effectiveness check before a CAPA may close.
Evidence Register
Link iso27001.evidence items to controls with multi-file attachments, an evidence type (policy / log / screenshot / certificate / other), the collector, free-text notes and a draft → confirmed → archived lifecycle.
Audit-Event Trail
Capture review, finding and closure events per control in iso27001.audit.event with severity (info / minor / major / critical), close and reopen actions and a full mail.thread history for every entry.
Risk Treatment Register
iso27001.risk scores likelihood × impact into an automatic severity band, records the treatment strategy (accept / mitigate / transfer / avoid), the owner and target date, and drives the risk through its own state machine.
Coverage-Gap Report
The iso27001.coverage.report.wizard lists every control without recent evidence — configurable age threshold and theme filter — and exports the gap list to CSV for your management review.
Review-Cadence Helpers & Reminders
Set a per-control review interval, filter overdue controls at a glance, and mark a control reviewed with one click. A daily scheduled action raises to-do activities for overdue reviews and overdue CAPAs on their owners.
Pivot & Graph Dashboards
Analyse controls by theme and implementation state, and CAPAs by type and status, with built-in pivot and graph views. Mail-thread tracking on controls, evidence, risks and CAPAs keeps the who-and-when for free.
Use Cases
Screenshots
One-click Statement of Applicability PDF — every Annex A:2022 control, applicable/excluded totals, justifications and evidence count, grouped by theme.
CAPA register — corrective / preventive actions with priority, owner, due date, effectiveness result and overdue highlighting.
CAPA closed-loop workflow — draft → open → in progress → pending verification → closed, with root-cause, action plan and a mandatory effectiveness check.
Control pivot dashboard — Annex A themes against implementation state so you see coverage at a glance.
CAPA graph dashboard — corrective vs. preventive actions broken down by lifecycle state.
Control record — state statusbar, Statement of Applicability decision with justification, and evidence / open-CAPA stat buttons.
Module overview
Evidence register
Why Choose This Module
A focused, honest ISMS evidence tool — not a bloated GRC suite. It depends only on base and mail, stores everything inside your own Odoo database, calls no external service and needs no subscription. You get the full Annex A:2022 catalog, real evidence and audit-event workflows, a working risk register and a coverage-gap report, so the day-to-day of keeping ISO 27001 audit-ready lives where the rest of your business already runs.
Specifications
- Compatible: Odoo 18.0 / 19.0 (Community & Enterprise)
- License: OPL-1
- Languages: English
- Author: Pokutsoft
- Dependencies: base, mail
- Models: iso27001.control, iso27001.evidence, iso27001.audit.event, iso27001.risk, iso27001.capa, iso27001.coverage.report.wizard
- Support: support@pokutsoft.com
Update date: 2026-07-10