Last updated: 3 October 2026
Quick answer: An ISO 27001 internal audit is a planned, independent check, required by clause 9.2, of whether your information security management system meets your own requirements and the standard, and is effectively implemented and maintained. You need an audit programme, defined criteria and scope, objective auditors, reports to management and retained evidence.
The internal audit is one of the few ISO 27001 activities that certification auditors always examine closely. It is how the organisation checks itself before anyone else does, and a weak one usually shows up as findings in the external audit.
This guide explains what clause 9.2 requires, how to build an audit programme, who can act as auditor, how to run an audit from planning to report, and the mistakes that most often cause nonconformities. It includes a sample audit programme you can adapt.
What does ISO 27001 internal audit clause 9.2 require?
Clause 9.2 requires the organisation to conduct internal audits at planned intervals and to manage them through a documented audit programme. It is split into two subclauses in ISO/IEC 27001:2022.
Clause 9.2.1: general
Internal audits must provide information on whether the information security management system (ISMS):
- conforms to the organisation’s own requirements for its ISMS;
- conforms to the requirements of ISO 27001 itself; and
- is effectively implemented and maintained.
Clause 9.2.2: internal audit programme
The organisation must plan, establish, implement and maintain one or more audit programmes, including frequency, methods, responsibilities, planning requirements and reporting. In doing so it must:
- take into account the importance of the processes concerned and the results of previous audits;
- define the audit criteria and scope for each audit;
- select auditors and conduct audits so that the process is objective and impartial;
- ensure results are reported to relevant management; and
- retain documented information as evidence of the audit programme and the audit results.
The 2022 edition made “planning requirements” an explicit part of the audit programme, but the substance of the clause is familiar to anyone who worked with the 2013 version. All 2013 certificates had to be transitioned by 31 October 2025, when they expired or were withdrawn under IAF MD 26, so every certified ISMS is now audited against the 2022 text.
How often should you carry out an ISO 27001 internal audit?
The standard says “at planned intervals” and leaves the frequency to you. In practice, most organisations audit at least once a year and plan the programme so that the whole ISMS, including all applicable Annex A controls, is covered within the certification cycle.
Base the frequency on risk, as clause 9.2.2 requires. Processes that are critical, recently changed or had findings last time should be audited more often. Stable, low-risk areas can be audited less frequently, as long as the full scope is covered over time.
In practice: schedule the main internal audit so its results feed the management review (clause 9.3) and leave time to close findings before the external surveillance or recertification audit.
Who can perform an internal audit?
Anyone competent who can be objective and impartial. The key rule is that auditors should not audit their own work. You can use internal staff from another department, a trained colleague from a different site, or an external consultant acting on your behalf.
Guidance comes from two standards. ISO/IEC 27007:2020 covers ISMS audit programmes, conducting audits and auditor competence. ISO 19011, the general guideline for auditing management systems, was revised as ISO 19011:2026, published in May 2026. The Chartered Quality Institute describes the revision as evolutionary, expanding guidance on remote auditing, digital tools, audit programme management and auditor competence. Its predecessor, ISO 19011:2018, set out seven auditing principles that remain a sound basis for any internal audit: integrity, fair presentation, due professional care, confidentiality, independence, an evidence-based approach and a risk-based approach.
ISO/IEC 27007 is also under revision, so check for a new edition before updating your audit procedure.
Common mistake: asking the ISMS manager or CISO to audit the ISMS they designed and run. Even if they are skilled, the independence of the audit is compromised, and certification auditors are likely to question it. Smaller organisations often solve this by outsourcing the internal audit or swapping auditors with a partner organisation.
How do you build an internal audit programme?
An audit programme is the plan for all audits over a period, typically one to three years. It sets out what will be audited, when, by whom and against which criteria. A simple table is usually enough.
| Quarter | Audit area | Criteria | Why now | Auditor |
|---|---|---|---|---|
| Q1 | Clauses 4 to 7: context, leadership, planning, support | ISO 27001 clauses; ISMS policy | New risk owners appointed | External consultant |
| Q2 | Risk assessment and treatment; Statement of Applicability | Clauses 6.1.2, 6.1.3, 8.2, 8.3; risk methodology | Critical process; finding last year | External consultant |
| Q2 | Annex A people and physical controls (5 and 7) | SoA; HR and facilities procedures | New office opened | Internal auditor from finance |
| Q3 | Annex A technological controls (8), access and change management | SoA; access control and change policies | Cloud migration completed | External consultant |
| Q3 | Supplier and cloud security | Annex A 5.19 to 5.23; supplier policy | Key supplier changed | Internal auditor from operations |
| Q4 | Performance evaluation and improvement (clauses 9 and 10) | Clauses 9.1, 9.3, 10.1, 10.2 | Before management review | External consultant |
This is an illustrative example. Tailor it to your scope, sites and risk profile, and update it when significant changes happen. Store it with approval history in your policy and document management so the programme itself counts as retained documented information. Auditors will usually sample Annex A controls from your Statement of Applicability, so keep it current.
How do you run an ISO 27001 internal audit step by step?
Every individual audit follows the same cycle: plan, prepare, perform, report and follow up.
- Define scope and criteria. State which processes, locations and controls are in scope, and which requirements (standard clauses, policies, procedures, contracts, laws) you are auditing against.
- Prepare an audit plan. Agree dates, interviewees and the documents to review. Share it with auditees in advance.
- Build a checklist. Turn criteria into questions and evidence to sample. Review previous findings and the risk register to focus on what matters.
- Hold an opening meeting. Confirm scope, timing and how findings will be reported.
- Collect evidence. Interview staff, observe activities and sample records such as access reviews, change tickets, training records and supplier assessments.
- Evaluate findings. Classify each as a conformity, nonconformity (major or minor) or opportunity for improvement, and record the evidence behind it.
- Hold a closing meeting. Present findings and agree next steps.
- Report to relevant management. Issue a written report with scope, criteria, findings and conclusions.
- Follow up. Nonconformities go into your corrective action process under clause 10.2: react, find the root cause, fix it and check the fix is effective.
Tracking findings and corrective actions to closure is where many ISMSs slip. A structured compliance assessment with linked tasks and evidence keeps every finding visible until it is verified as closed.
If you want to run your next audit cycle with checklists, evidence and actions in one place, start your 14-day free trial.
Internal audit vs external certification audit: what is the difference?
The internal audit is your own check; the external audit is the certification body’s independent assessment. Both look at the same standard, but their purpose and consequences differ.
| Aspect | Internal audit (clause 9.2) | External certification audit |
|---|---|---|
| Who performs it | Your staff or a consultant acting for you | An accredited certification body |
| Purpose | Find and fix issues; inform management | Decide whether to grant or maintain certification |
| Frequency | At planned intervals you define | Initial audit, then surveillance and recertification audits |
| Output | Internal report, corrective actions, input to management review | Certification decision and external findings |
| Relationship | Evidence of it is reviewed by the external auditor | Checks that the internal audit is effective |
What evidence should you keep from internal audits?
Clause 9.2.2 requires documented information as evidence of the audit programme and the audit results. Keep:
- the approved audit programme and any changes to it;
- audit plans, with scope and criteria for each audit;
- checklists and working notes showing evidence sampled;
- auditor competence and independence records;
- audit reports and the record of reporting to management;
- corrective action records and verification of effectiveness.
How can one internal audit cover other frameworks?
If your ISMS also supports NIS2, DORA or SOC 2, design audit criteria to cover the overlapping requirements in the same fieldwork. For financial entities, DORA Article 6(6) requires the ICT risk management framework of financial entities, other than microenterprises, to be subject to internal audit by auditors on a regular basis in line with the audit plan. An ISO 27001 audit programme can be extended to meet that requirement.
Cross-framework control mapping shows which control evidence satisfies which requirements, so auditors sample once and report against several frameworks. Our article on managing overlapping EU regulations explains the unified control approach. For the standard itself, see our ISO 27001 framework page.
Key takeaways
- Clause 9.2 requires planned internal audits run through a documented, risk-based audit programme.
- Audit against both your own ISMS requirements and ISO 27001, and check effectiveness, not just paperwork.
- Auditors must be objective and impartial: never let people audit their own work.
- Report results to management, feed them into management review and track nonconformities to closure under clause 10.2.
- Retain evidence of the programme and results; the certification body will ask for it.
Frequently asked questions
Is an internal audit mandatory for ISO 27001 certification?
Yes. Clause 9.2 is a mandatory requirement, so an organisation cannot conform to ISO 27001 without planned internal audits. Certification bodies expect to see evidence that at least one internal audit and a management review have taken place before the initial certification audit, and that the audit programme continues throughout the certification cycle.
Do we have to audit every Annex A control every year?
No. The standard requires audits at planned intervals based on the importance of processes and previous results, not annual coverage of every control. Many organisations cover the full ISMS and all applicable controls over the certification cycle, auditing higher-risk areas more often. The audit programme should show how full coverage is achieved.
Can we outsource the ISO 27001 internal audit?
Yes. An external consultant can perform the internal audit on your behalf, which is common in smaller organisations that lack independent internal auditors. The organisation still owns the audit programme, must receive and act on the results, and remains responsible for corrective actions. Avoid using the same consultant who implemented the ISMS.
What qualifications does an internal auditor need?
ISO 27001 does not require a specific certificate. Auditors must be competent and objective. Competence usually combines knowledge of the standard, auditing techniques based on ISO 19011 and ISO/IEC 27007, and enough understanding of the audited area. Many organisations use lead auditor or internal auditor training courses to demonstrate competence.
How is a major nonconformity different from a minor one?
A major nonconformity usually means a requirement is not met at all or there is a systemic failure, such as no risk assessment. A minor one is an isolated lapse that does not undermine the ISMS. ISO 27001 does not define these grades, so state your own definitions in the audit procedure.
Making your internal audit add value
A good ISO 27001 internal audit does more than satisfy clause 9.2. It gives management an honest view of how well security works, finds problems before the certification body or an attacker does, and drives improvement. Plan it around risk, keep it independent, and follow every finding through to a verified fix.
If you would like help planning and running your ISMS audit programme, contact us or book a demo or start your 14-day free trial.
