ISO 27001

ISO 27001 internal audit: how to plan it, run it and report it

Clause 9.2 requires an internal audit programme before certification and every year after. Here is how to plan it, stay objective with a small team, and write findings that survive the certification audit.

Short answer

An ISO 27001 internal audit, required by clause 9.2, checks at planned intervals whether the ISMS meets your own requirements and the standard, and whether it is effectively implemented and maintained. You need an audit programme, defined criteria and scope for each audit, objective and impartial auditors, and reported results with corrective actions.

Key takeaways

  • Plan a programme that covers all of clauses 4 to 10 and applicable Annex A controls over the cycle.
  • Auditors must be objective and impartial; they shouldn't audit their own work.
  • A full internal audit and management review must run before the Stage 2 audit.
  • Findings need evidence, a requirement reference and a corrective action owner.

What clause 9.2 asks for

Clause 9.2 requires internal audits at planned intervals to provide information on whether the ISMS conforms to your own requirements and to ISO/IEC 27001, and whether it is effectively implemented and maintained. You must plan an audit programme, including frequency, methods, responsibilities and reporting, considering the importance of the processes and previous audit results. For each audit, define criteria and scope, select auditors who are objective and impartial, report results to relevant management, and keep documented information as evidence.

Build the audit programme

Most organisations audit the whole ISMS once a year, split into several smaller audits. Higher-risk areas, areas with previous findings, and areas that changed recently get audited more often.

QuarterAuditCovers
Q1Management systemClauses 4–7: scope, leadership, risk assessment and treatment, SoA, competence, documents
Q2Access and operationsA.5.15–A.5.18, A.8.2, A.8.5, A.8.8, A.8.15, A.8.32
Q3People, suppliers and incidentsA.6.1–A.6.8, A.5.19–A.5.23, A.5.24–A.5.28
Q4Continuity, physical and evaluationA.5.29–A.5.30, A.7, A.8.13–A.8.14, clauses 9–10

Objectivity with a small team

The standard asks for objectivity and impartiality, not a separate department. In a small organisation, people can audit areas they don't work in, or swap audits with a partner company. Using an external consultant for internal audit is also common. What isn't acceptable is the person who runs a control auditing that same control.

Running the audit

  1. Agree the scope, criteria and dates with the auditees in an audit plan.
  2. Review documents first: the procedures and records relevant to the scope.
  3. Interview control owners and ask them to show how the control works.
  4. Sample records, for example 10 to 25 items per control, depending on frequency and risk.
  5. Grade findings as nonconformities (major or minor) or opportunities for improvement.
  6. Hold a closing meeting, then issue the report to management.

Write findings that hold up

A good finding states the requirement, the evidence and the gap. For example: "Clause A.5.18 and the access control policy require quarterly user access reviews. For the finance system, no review was performed in Q1 or Q2 2026 (two of four quarters sampled). Access rights were not reviewed as required." Each nonconformity then needs a corrective action under clause 10.2, with a root cause, an owner and a due date.

Certification auditors check that the internal audit happened, covered the scope and led to action. A clean internal audit report with no findings at all often prompts more questions, not fewer.

Checklist

Before Stage 2

0 of 5 done

Put this into practice on QULDEX

Frequently asked questions

Can my own team do the ISO 27001 internal audit?

Yes, as long as auditors are objective and impartial, which in practice means they don't audit their own work. Small teams often swap areas or use an external consultant.

How often is an ISO 27001 internal audit required?

At planned intervals set in your audit programme. Most organisations cover the whole ISMS at least once a year, with higher-risk areas audited more often.

Must the internal audit be finished before certification?

Certification bodies expect at least one internal audit and one management review to have operated before the Stage 2 audit.

Sources

  1. ISO/IEC 27001:2022 Information security management systems: Requirements, ISO
  2. ISO 19011:2018 Guidelines for auditing management systems, ISO
  3. ISO/IEC 27007:2020 Guidelines for information security management systems auditing, ISO