ISO 27001 Evidence
ISO 27001:2022 Annex A control register, evidence collection, audit trail, risk treatment and coverage-gap reporting — all inside Odoo
Run your ISO 27001:2022 Information Security Management System evidence workflow directly in Odoo. Catalog every Annex A control, attach the evidence that proves each one is operating, log audit events, manage risk treatment, and surface the controls that are missing recent evidence — so you walk into a certification or surveillance audit with the paper trail already assembled. Self-contained, no external services, no subscriptions.
Key Features
Annex A:2022 Control Catalog
All 93 Annex A controls seeded across the four 2022 themes — Organizational (A.5), People (A.6), Physical (A.7) and Technological (A.8). Each iso27001.control carries its clause reference, theme and owner.
Statement of Applicability
Decide applicable vs. not-applicable per control and record inclusion / exclusion justifications right on the record. Print the full SoA as a themed QWeb PDF in one click for your auditor.
CAPA (Corrective / Preventive)
iso27001.capa runs a closed-loop nonconformity workflow — root-cause analysis, action plan, owner, due date and priority — through draft → open → in progress → pending verification → closed, with a mandatory effectiveness check before a CAPA may close.
Evidence Register
Link iso27001.evidence items to controls with multi-file attachments, an evidence type (policy / log / screenshot / certificate / other), the collector, free-text notes and a draft → confirmed → archived lifecycle.
Audit-Event Trail
Capture review, finding and closure events per control in iso27001.audit.event with severity (info / minor / major / critical), close and reopen actions and a full mail.thread history for every entry.
Risk Treatment Register
iso27001.risk scores likelihood × impact into an automatic severity band, records the treatment strategy (accept / mitigate / transfer / avoid), the owner and target date, and drives the risk through its own state machine.
Coverage-Gap Report
The iso27001.coverage.report.wizard lists every control without recent evidence — configurable age threshold and theme filter — and exports the gap list to CSV for your management review.
Review-Cadence Helpers & Reminders
Set a per-control review interval, filter overdue controls at a glance, and mark a control reviewed with one click. A daily scheduled action raises to-do activities for overdue reviews and overdue CAPAs on their owners.
Pivot & Graph Dashboards
Analyse controls by theme and implementation state, and CAPAs by type and status, with built-in pivot and graph views. Mail-thread tracking on controls, evidence, risks and CAPAs keeps the who-and-when for free.
Use Cases
Screenshots
One-click Statement of Applicability PDF — every Annex A:2022 control, applicable/excluded totals, justifications and evidence count, grouped by theme.
CAPA register — corrective / preventive actions with priority, owner, due date, effectiveness result and overdue highlighting.
CAPA closed-loop workflow — draft → open → in progress → pending verification → closed, with root-cause, action plan and a mandatory effectiveness check.
Control pivot dashboard — Annex A themes against implementation state so you see coverage at a glance.
CAPA graph dashboard — corrective vs. preventive actions broken down by lifecycle state.
Control record — state statusbar, Statement of Applicability decision with justification, and evidence / open-CAPA stat buttons.
Module overview
Evidence register
Why Choose This Module
A focused, honest ISMS evidence tool — not a bloated GRC suite. It depends only on base and mail, stores everything inside your own Odoo database, calls no external service and needs no subscription. You get the full Annex A:2022 catalog, real evidence and audit-event workflows, a working risk register and a coverage-gap report, so the day-to-day of keeping ISO 27001 audit-ready lives where the rest of your business already runs.
Specifications
- Compatible: Odoo 18.0 / 19.0 (Community & Enterprise)
- License: OPL-1
- Languages: English
- Author: Pokutsoft
- Dependencies: base, mail
- Models: iso27001.control, iso27001.evidence, iso27001.audit.event, iso27001.risk, iso27001.capa, iso27001.coverage.report.wizard
- Support: support@pokutsoft.com
Update date: 2026-07-10
| Availability |
Odoo Online
Odoo.sh
On Premise
|
| Odoo Apps Dependencies |
Discuss (mail)
|
| Lines of code | 1400 |
| Technical Name |
iso27001_evidence |
| License | OPL-1 |
| Website | https://pokutsoft.com/ |
Odoo Proprietary License v1.0 This software and associated files (the "Software") may only be used (executed, modified, executed after modifications) if you have purchased a valid license from the authors, typically via Odoo Apps, or if you have received a written agreement from the authors of the Software (see the COPYRIGHT file). You may develop Odoo modules that use the Software as a library (typically by depending on it, importing it and using its resources), but without copying any source code or material from the Software. You may distribute those modules under the license of your choice, provided that this license is compatible with the terms of the Odoo Proprietary License (For example: LGPL, MIT, or proprietary licenses similar to this one). It is forbidden to publish, distribute, sublicense, or sell copies of the Software or modified copies of the Software. The above copyright notice and this permission notice must be included in all copies or substantial portions of the Software. THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
Please log in to comment on this module