Short answer
An ISO 27001 internal audit, required by clause 9.2, checks at planned intervals whether the ISMS meets your own requirements and the standard, and whether it is effectively implemented and maintained. You need an audit programme, defined criteria and scope for each audit, objective and impartial auditors, and reported results with corrective actions.
Key takeaways
- Plan a programme that covers all of clauses 4 to 10 and applicable Annex A controls over the cycle.
- Auditors must be objective and impartial; they shouldn't audit their own work.
- A full internal audit and management review must run before the Stage 2 audit.
- Findings need evidence, a requirement reference and a corrective action owner.
What clause 9.2 asks for
Clause 9.2 requires internal audits at planned intervals to provide information on whether the ISMS conforms to your own requirements and to ISO/IEC 27001, and whether it is effectively implemented and maintained. You must plan an audit programme, including frequency, methods, responsibilities and reporting, considering the importance of the processes and previous audit results. For each audit, define criteria and scope, select auditors who are objective and impartial, report results to relevant management, and keep documented information as evidence.
Build the audit programme
Most organisations audit the whole ISMS once a year, split into several smaller audits. Higher-risk areas, areas with previous findings, and areas that changed recently get audited more often.
| Quarter | Audit | Covers |
|---|---|---|
| Q1 | Management system | Clauses 4–7: scope, leadership, risk assessment and treatment, SoA, competence, documents |
| Q2 | Access and operations | A.5.15–A.5.18, A.8.2, A.8.5, A.8.8, A.8.15, A.8.32 |
| Q3 | People, suppliers and incidents | A.6.1–A.6.8, A.5.19–A.5.23, A.5.24–A.5.28 |
| Q4 | Continuity, physical and evaluation | A.5.29–A.5.30, A.7, A.8.13–A.8.14, clauses 9–10 |
Objectivity with a small team
The standard asks for objectivity and impartiality, not a separate department. In a small organisation, people can audit areas they don't work in, or swap audits with a partner company. Using an external consultant for internal audit is also common. What isn't acceptable is the person who runs a control auditing that same control.
Running the audit
- Agree the scope, criteria and dates with the auditees in an audit plan.
- Review documents first: the procedures and records relevant to the scope.
- Interview control owners and ask them to show how the control works.
- Sample records, for example 10 to 25 items per control, depending on frequency and risk.
- Grade findings as nonconformities (major or minor) or opportunities for improvement.
- Hold a closing meeting, then issue the report to management.
Write findings that hold up
A good finding states the requirement, the evidence and the gap. For example: "Clause A.5.18 and the access control policy require quarterly user access reviews. For the finance system, no review was performed in Q1 or Q2 2026 (two of four quarters sampled). Access rights were not reviewed as required." Each nonconformity then needs a corrective action under clause 10.2, with a root cause, an owner and a due date.
Certification auditors check that the internal audit happened, covered the scope and led to action. A clean internal audit report with no findings at all often prompts more questions, not fewer.
Checklist
Before Stage 2
0 of 5 done
Put this into practice on QULDEX
Frequently asked questions
Can my own team do the ISO 27001 internal audit?
Yes, as long as auditors are objective and impartial, which in practice means they don't audit their own work. Small teams often swap areas or use an external consultant.
How often is an ISO 27001 internal audit required?
At planned intervals set in your audit programme. Most organisations cover the whole ISMS at least once a year, with higher-risk areas audited more often.
Must the internal audit be finished before certification?
Certification bodies expect at least one internal audit and one management review to have operated before the Stage 2 audit.