What Keel's ISO 27001 rows are, and what they are not
This one is not an exclusion list. Every requirement of clauses 4 to 10 is in scope. What is declared instead is the grain Keel scores them at, and the two counts the total is built from.
The grain
Every requirement of clauses 4 to 10 is in scope. What is declared is the grain: Keel scores them at the standard’s second-level clause rather than at every sub-clause beneath it, while Annex A’s 93 controls are scored at the standard’s own leaf level. A readiness percentage here is a percentage of 116 rows at that depth, not of every sub-clause the standard states.
As it appears on the framework page. Keel scores ISO/IEC 27001 clauses 4-10 at the standard’s second-level clause (4.1, 6.1, 7.5 and so on) rather than at every sub-clause beneath them, while Annex A’s 93 controls are scored at the standard’s own leaf level. A readiness percentage here is therefore a percentage of 116 rows at that depth, not of every sub-clause the standard states.
A coarser grain is not a narrower scope. A coarser grain is not a narrower scope. Nothing in clauses 4 to 10 is left unscored, and a workspace at 100% here has answered for every management-system requirement the standard states. What it has not done is answer for each of them separately, and a certification body will ask at its own grain rather than at Keel’s.
What the coarser grain costs
The cost of the coarser grain is the denominator, not the coverage. Keel itself cites ISO 27001 sub-clauses this model does not contain as rows, and they are listed below so the gap between what Keel says elsewhere and what it scores here is visible rather than something a reader has to notice. Each of them sits inside a row that is authored, and that row’s summary carries the sub-clause content in aggregate.
-
6.1.2carried by 6.1Keel cites it at: Two evidence artifacts in Keel’s artifact catalog, and the guided journey.
-
6.1.3carried by 6.1Keel cites it at: The same two artifacts and the guided journey, and the in-app Statement of Applicability page, which cites "Clause 6.1.3 d" specifically.
-
9.2.2carried by 9.2Keel cites it at: The audit-program feature, in the app, on the marketing site and in the docs.
Out entirely
-
Clause 1States no auditable requirementScope. States what the standard is for and to whom it applies.
-
Clause 2States no auditable requirementNormative references. Points at other documents the standard relies on.
-
Clause 3States no auditable requirementTerms and definitions. You cannot comply with a definition.
What has not been verified
Keel does not hold a copy of ISO/IEC 27001:2022. These are the figures behind the 116 that rest on Keel's own inventory rather than on the published text, said out loud rather than left for someone to find.
-
Keel has not confirmed this against the published standardThe 23 second-level clauses of clauses 4 to 10
Keel’s own authored inventory: clause 4 has 4, clause 5 has 3, clause 6 has 3, clause 7 has 5, clause 8 has 3, clause 9 has 3, clause 10 has 2. No independent source has been read to confirm that clauses 4 to 10 of ISO/IEC 27001:2022 define exactly these 23 and no others: iso.org returned 403 when Keel tried to read the clause structure, checked 2026-08-16, and Keel does not hold a copy of the standard. Note that 6.3, planning of changes, was added by the 2022 revision, so a pre-2022 recollection of this list is wrong.
-
Keel has not confirmed this against the published standardThe Annex A structure: 93 controls across four themes
A.5 Organizational 37, A.6 People 8, A.7 Physical 14, A.8 Technological 34. This is the widely published structure of the 2022 revision and it was carried forward rather than re-verified against the standard. What IS asserted by a test is the per-theme distribution of the 93 controls Keel authored, which is a claim about Keel’s content rather than about the published text.
-
Keel has not confirmed this against the published standardHow many leaves clauses 4 to 10 really have
Not stated, deliberately. A number here would be interpolation from the ISO 9001 and ISO 42001 models, and it would look like evidence. The register records the absence instead, and the way to close it is to acquire the standard and enumerate the sub-clauses from the published text.
The inconsistency with ISO 9001
ISO 9001:2015 is the same harmonized management-system skeleton and Keel models it to its own numbered leaf level: 7.5.1, 7.5.2, 7.5.3, 9.2.1, 9.2.2, 9.3.1 and so on. Two management-system standards, two different depth rules. That inconsistency is real, it is not resolved, and resolving it means acquiring ISO/IEC 27001:2022. It is published here rather than left for a reader to discover by comparing two framework pages.
Where this comes from
Hold a copy of the standard and think one of these is wrong? That is the point of publishing it, so tell us which line. The full framework is at ISO/IEC 27001.