Clause 4 · Context of the organization

4.1 — Understanding the organization and its context

The requirement that comes before every other requirement: you cannot manage risk to a context you have never actually described.

Mandatory requirementDocumented information required: No

In plain language

In plain language: 4.1 requires you to identify the external and internal issues that matter to your ability to achieve what you want your ISMS to achieve — things like your regulatory environment, your competitive market, your organizational culture, and your available capabilities.

Position in the standard

4.1 · Understanding the organization and its context ← you are here
See also: 4.2 · 4.3 · 4.4

Why this requirement exists

A generic ISMS, copied from a template with no reference to your actual situation, tends to miss the risks that matter most to you specifically. A healthcare company and a fintech startup face wildly different external pressures; this requirement forces that difference to actually shape the ISMS instead of being ignored.

Scenario: a company expanding into the European market adopts an ISMS built for its original domestic operations, never updating its context analysis to reflect new GDPR exposure. Risk decisions downstream keep assuming a regulatory environment that no longer fully applies, and the gap surfaces only when a European customer’s security questionnaire asks something the ISMS was never built to answer.

What the standard expects

The standard expects the organization to determine external and internal issues relevant to its purpose and that affect its ability to achieve the intended outcomes of its ISMS. Since Amendment 1:2024, the standard adds an explicit note that the organization shall determine whether climate change is a relevant issue — reflecting growing recognition that climate-related disruption (extreme weather affecting data centre availability, supply chain instability) is a legitimate context factor, not just an environmental, social, and governance talking point.

In practice

  • Cover external issues: regulatory and legal requirements, market and competitive conditions, technology trends, and relationships with suppliers or partners.
  • Cover internal issues: organizational structure, culture, governance, available resources, and existing capabilities and constraints.
  • Explicitly note whether climate-related disruption is a relevant issue for your organization — for many, this will be a brief, documented "not currently significant" rather than a deep analysis, but it must be a considered answer, not an omission.
  • Revisit the analysis when the organization changes materially, not just once at certification.

Evidence the auditor will ask for

  • A documented context analysis covering external and internal issues.
  • Evidence climate change was explicitly considered, even if the conclusion was that it is not currently significant.
  • A traceable link between identified issues and later decisions — risk criteria, scope, objectives.

Common pitfalls

  • A generic context analysis copied from a template, disconnected from the organization’s actual industry and situation.
  • No mention of climate change at all — since Amendment 1:2024, silence on the topic is itself a gap.
  • Context analysis performed once at certification and never revisited despite significant organizational change.

Related requirements

Parent link: Clause 4 · Context of the organization

2013 → 2022 mapping

2022 version 2013 version Nature of change
4.1 Understanding the organization and its context4.1 Same titleStable requirement; climate change note added by Amendment 1:2024

Frequently asked questions

Is the climate change requirement mandatory for everyone?
Determining whether it is relevant is mandatory; the outcome is not predetermined. An organization can conclude climate change is not a significant issue for its ISMS, as long as that conclusion was actually considered and documented.
Does my certification body require re-assessment for Amendment 1:2024?
Requirements vary by certification body and transition timeline; check with your specific certifier for the applicable deadline to demonstrate conformity with the amendment.

Build your ISMS around your real context, not a template.

Sentrix helps you document context, including the 2024 climate change consideration, and keep it current as your organization changes.