AuditXYZ

Lesson 4 of 5

ISO 27001 Internal Audit: Planning and Execution

13 min readIntermediate

ISO 27001 Internal Audit

Internal audits are a mandatory requirement of ISO 27001 (clause 9.2). They serve two purposes: verifying that your ISMS conforms both to the standard's requirements and to your own policies, and identifying opportunities for improvement before an external auditor — or an attacker — finds the gaps for you. At least one full internal audit must be completed before your Stage 2 certification audit, and the programme must continue at planned intervals for as long as you hold the certificate.

Founders often treat the internal audit as bureaucratic theater — an audit of yourself, by yourself, to prepare for the real audit. That framing costs you twice. First, certification bodies read your internal audit reports closely; a shallow, finding-free internal audit is itself a red flag that suggests the check function of your ISMS does not really operate. Second, a genuine internal audit is the cheapest dress rehearsal you will ever get: every problem it finds is a problem the certification auditor does not find first.

What Clause 9.2 Actually Requires

The requirements are specific and auditable:

  • Conduct internal audits at planned intervals (annually at minimum in practice; the standard says "planned intervals," and your audit programme defines them)
  • Verify conformity to both the organization's own ISMS requirements and the requirements of ISO 27001 itself
  • Maintain an audit programme covering frequency, methods, responsibilities, planning requirements, and reporting — taking into account the importance of the processes and the results of previous audits
  • Define audit criteria and scope for each audit
  • Select auditors and conduct audits ensuring objectivity and impartiality — auditors cannot audit their own work
  • Report results to relevant management
  • Retain documented evidence of the programme and results

Every one of these bullet points is something a certification auditor will ask to see. Missing audit programme? Finding. Auditor who audited their own department? Finding. Results never reported to management? Finding.

The Independence Problem (and How Small Companies Solve It)

The requirement that auditors not audit their own work is the hardest constraint for startups, where the person who built the ISMS is often the only person who understands it. You have four workable options:

OptionHow It WorksCostBest For
Cross-functional internal auditorTrain someone outside the ISMS build (e.g., an engineer auditing HR controls, a finance lead auditing IT)Low (training time; a short lead-auditor or internal-auditor course helps)Companies with 30+ people and available bandwidth
External consultant / vCISOHire an independent practitioner to run the audit annuallyRoughly $3,000–$10,000 per audit depending on scopeStartups without spare qualified staff — the most common choice under ~100 employees
Compliance platform partner networkMany automation platforms broker fixed-fee internal auditsSimilar to consultants, often bundledTeams already on a platform
Internal audit teamDedicated function with its own reporting lineHeadcountLarger organizations, regulated industries

Two cautions. Your external internal auditor must be independent of your certification body — a CB cannot audit its own consulting work, and accreditation rules prohibit CBs from consulting for their certification clients. And whoever audits, the ISMS owner can (and should) coordinate logistics but must not decide the findings.

Building the Audit Programme

The programme is the multi-year plan; each audit is one execution of it. A good programme is risk-based: areas with higher risk, recent change, or previous nonconformities get audited more often and more deeply.

A common pattern for a small company: one full-scope audit annually, covering all clauses 4–10 and sampling across the applicable Annex A controls, timed 2 to 3 months before the external audit so there is room to close findings. Larger organizations often split coverage — for example, quarterly audits each covering a slice (governance clauses, technical controls, people/physical controls, suppliers and incidents) — as long as the full ISMS is covered within the cycle.

For each individual audit, document up front: scope (which entities, locations, processes, clauses, and controls), criteria (ISO 27001:2022 plus your own policies, procedures, and the Statement of Applicability), method (document review, interviews, observation, sampling), schedule, and auditor(s).

Conducting the Audit

A practical flow for a full-scope audit at a startup, typically 2 to 5 auditor-days:

1. Preparation. The auditor reviews the ISMS documentation set — scope, policy, risk assessment and treatment plan, SoA, procedures, prior audit reports, and the corrective action log — and builds a working checklist mapped to clauses and sampled controls.

2. Opening meeting. Brief; confirms scope, schedule, and interviewees.

3. Evidence gathering. Four methods, used in combination:

  • Document review — do required documents exist, and are they current, approved, and version-controlled?
  • Interviews — process owners describe what they actually do. The auditor compares the answer with the documented procedure; divergence between the two is the single richest source of findings.
  • Observation — watch the process happen: an access review being performed, a visitor signed in, a change deployed through the pipeline.
  • Sampling of records — pull samples across the period: five recent joiners (screening, contracts, training?), five leavers (access revoked, when?), a month of changes (approved?), recent incidents (handled per procedure?), backup restore tests, vulnerability remediation tickets against SLA.

4. Closing meeting. Preliminary findings presented to management; factual corrections invited.

Interview technique matters more than checklists. "Show me" beats "do you have." An auditor who asks "do you perform access reviews?" gets "yes." An auditor who asks "show me the Q1 access review for the production AWS account, and walk me through what you did with the two flagged accounts" gets the truth.

Classifying and Reporting Findings

Use the same taxonomy your certification body will use, so nothing is lost in translation:

  • Major nonconformity — total absence of a required element, or a systemic breakdown (no internal audits performed; risk assessment never done; a mandatory clause unaddressed)
  • Minor nonconformity — an isolated lapse in an otherwise functioning process (one quarter's access review missed; a policy past its review date; one leaver's access removed late)
  • Opportunity for improvement (OFI) — conforms, but could be better; no corrective action required
  • Some auditors add observations for items worth watching

The audit report should state scope, criteria, method, and dates; summarize what was examined; list each finding with the objective evidence behind it and the clause/control it breaches; and be distributed to relevant management. Findings must be factual and evidence-based — "clause 9.3 management review not performed in the last 12 months; last minutes dated [date]" — never opinion or blame.

Corrective Action: Where the Value Is Realized

Clause 10.2 takes over from here, and this is what certification auditors examine hardest, because it proves the improvement loop works:

  1. Correction — fix the immediate instance (restore the missed review)
  2. Root cause analysis — why did it happen? "Human error" is not a root cause; "no calendar-driven trigger and no named owner after the ops lead left" is
  3. Corrective action — change the system so it cannot easily recur (automated quarterly task with escalation)
  4. Verification of effectiveness — later, confirm the fix actually worked, and record that verification

Track all of this in a corrective action log with owners and due dates. An internal audit whose findings sit unactioned for months converts each of them into evidence of a second nonconformity — against clause 10.2.

Common Internal Audit Findings

The recurring hit list, worth pre-checking before your auditor does: incomplete or stale risk assessments; SoA out of sync with the risk register or reality; missing or incomplete security awareness training records; gaps between documented policy and actual practice (the classic); missing or thin management review records against clause 9.3's required inputs; unreviewed supplier lists; access reviews missed or undocumented; backup restores never tested; and corrective actions from the previous audit still open. Addressing these before the certification audit saves significant time, money, and Stage 2 drama.

Internal Audit Checklist

  • Audit programme documented: frequency, methods, responsibilities, reporting; risk-based rationale stated
  • Auditor independence solved and defensible (no one audits their own work)
  • Audit scheduled 2–3 months before the external audit, leaving remediation time
  • Scope and criteria defined per audit, covering clauses 4–10 and sampled Annex A controls across the cycle
  • Evidence gathered via documents, interviews, observation, and record sampling — not documents alone
  • Findings classified (major/minor/OFI) with objective evidence and clause references
  • Report issued to management; results feed the management review (clause 9.3)
  • Every nonconformity has correction, root cause, corrective action, owner, and due date
  • Effectiveness of past corrective actions verified and recorded
  • Prior audit findings reviewed — repeats escalated as systemic issues
  • All records retained as documented information (clause 7.5)

Frequently Asked Questions

How often must we run internal audits?

The standard says "at planned intervals" — you define them in the programme, but certification bodies expect the full ISMS covered at least once per certification cycle and, in practice, an audit every 12 months. Annual full-scope is the near-universal pattern for small and mid-sized organizations.

Can the person who built our ISMS run the internal audit?

Not credibly, and usually not acceptably — they would be auditing their own work, which clause 9.2 prohibits. Use a trained colleague from another function for areas they did not build, or bring in an external auditor. For startups where one person built everything, external is effectively the only clean answer.

Does the internal auditor need a certification like ISO 27001 Lead Auditor?

The standard requires competence, not a specific certificate. In practice, a lead auditor or internal auditor course is the easiest way to demonstrate competence and dramatically improves audit quality. If you hire externally, ask for the credential and for references from similar-sized clients.

Is it bad if our internal audit finds a lot of problems?

The opposite. Certification auditors trust an internal audit that found real nonconformities and drove them to closure far more than one reporting universal perfection. Zero findings on a young ISMS reads as a rubber stamp. What hurts you is not findings — it is findings without corrective action, or external auditors finding things your internal audit obviously should have.

What is the difference between the internal audit and the management review?

Different clauses, different actors, different questions. The internal audit (9.2) is an independent conformity check — does the ISMS meet requirements? The management review (9.3) is leadership's evaluation — is the ISMS suitable, adequate, and effective, and what resources or changes does it need? Internal audit results are a mandatory input to the management review. You need both, documented separately, before Stage 2.

Can we use our compliance automation platform's dashboard as the internal audit?

No. Continuous control monitoring is valuable evidence and can sharply reduce audit effort, but clause 9.2 requires a planned, independent audit activity with defined criteria, scope, and reported results — human judgment applied to the whole management system, including the parts (risk process, leadership, documentation, corrective action) no dashboard measures. Use the platform's data within the audit, not instead of it.

In the next lesson, we will cover the certification process.


Many teams pair a compliance platform with an independent internal auditor from its partner network. AuditXYZ helps you compare compliance automation platforms and find qualified auditors for both internal audits and certification.