An ISO 27001 internal audit is the mandatory self-assessment that tells you whether your ISMS actually works — before a certification body decides that for you. Clause 9.2 of ISO 27001:2022 requires it, and a missing, rushed or purely documentary one is among the most common reasons organizations lose time at Stage 2. This guide explains what clause 9.2 demands, who is allowed to run the audit, a seven-step method you can follow, and the records an auditor will ask to see in 2026.
For the wider picture, see our complete ISO 27001:2022 guide.
What an ISO 27001 internal audit must prove
Clause 9.2 is short, and people routinely under-read it. It is split into two parts. Clause 9.2.1 (General) requires you to conduct internal audits at planned intervals to determine whether the ISMS conforms both to your own requirements for it and to the requirements of the standard, and whether it is effectively implemented and maintained. Clause 9.2.2 (Internal audit programme) requires you to plan, establish, implement and maintain an audit programme covering frequency, methods, responsibilities, planning requirements and reporting.
That wording sets two separate tests, and most audit programs only pass the first:
- Conformity — does the documented ISMS match what ISO 27001:2022 and your own policies say it should be?
- Effectiveness — is it actually operating, and is it achieving the outcomes you set for it?
Clause 9.2.2 adds further obligations that auditors check directly: consider the importance of the processes concerned and the results of previous audits when building the program; define audit criteria and scope for each individual audit; select auditors and run audits in a way that ensures objectivity and impartiality; report results to relevant management; and retain documented information as evidence of both the audit program and the audit results.
Scope-wise, an internal audit has to reach the management system clauses 4 through 10 and the Annex A controls you declared applicable in your Statement of Applicability. ISO 27001:2022 has 93 Annex A controls across four themes — 37 organizational, 8 people, 14 physical and 34 technological — so a single sitting rarely covers everything well.
ISO 27001 internal audit vs the certification audit
The two are often confused, which leads to the wrong effort in the wrong place. The internal audit is first-party: you run it on yourself, and its purpose is to find problems while there is still time to fix them. The certification audit is third-party, carried out by an accredited body, and its purpose is to decide whether you get a certificate.
| Internal audit (clause 9.2) | Certification audit | |
|---|---|---|
| Who runs it | Your own staff or a contracted auditor acting on your behalf | An accredited certification body |
| Purpose | Find and fix gaps; feed the clause 9.3 management review | Decide whether to grant or maintain certification |
| Frequency | At planned intervals you define — commonly a full cycle every 12 months | Stage 1 and Stage 2, then surveillance audits, then recertification at three years |
| Output | Internal audit report with findings and corrective actions | Audit report and a certification decision |
| Consequence of a finding | You raise a corrective action under clause 10.2 | A major nonconformity can delay or block certification |
| Mandatory? | Yes — required by the standard itself | Only if you want a certificate |
The practical link between them is that Stage 2 auditors will read your internal audit report. If it found nothing, they will assume you did not look hard enough. Our guide to Stage 1 vs Stage 2 covers what happens next.
Who can carry out an ISO 27001 internal audit
An ISO 27001 internal audit does not require an external consultant, and it does not require a formally certified lead auditor. What clause 9.2.2 requires is objectivity and impartiality of the audit process. In practice that means an auditor must not audit their own work — the person who wrote the access control policy cannot be the person who signs off that it operates.
Three arrangements normally satisfy this:
- Cross-functional internal auditors. Someone from finance audits IT, someone from engineering audits HR. Cheapest, and works well once people are trained.
- A contracted independent auditor. Common for teams under about 50 people where nobody is sufficiently removed from the ISMS. Note that your certification body cannot do this for you without compromising its own impartiality.
- A hybrid. Internal staff run rolling control checks through the year; an external auditor runs one deeper annual pass.
For auditor competence and technique, ISO 19011:2018 gives the general guidance on auditing management systems, and ISO/IEC 27007:2020 adds ISMS-specific guidance on the audit programme, conducting the audit, and auditor competence. Neither is mandatory, but both are what a good auditor will have read.
How to run an ISO 27001 internal audit in seven steps
This is the sequence that turns an ISO 27001 internal audit into defensible records rather than a tick-box exercise.
- Build the audit program, not just the audit. Map every clause and every applicable Annex A control to a slot in a 12-month calendar. Weight it: put high-risk processes and areas with previous findings earlier and more often. This document is what clause 9.2.2 is really asking for.
- Define criteria and scope for the individual audit. Write down what you are auditing against (the standard, your policies, contractual obligations) and where the boundary is — which sites, systems, teams and time period. Vague scope is the root of most weak internal audits.
- Prepare a checklist tied to evidence. For each clause and control, write the specific question and the specific artifact that would answer it. “Is access reviewed?” is weak. “Show me the Q2 access review for the production cloud account, with the removals actioned” is auditable.
- Collect evidence three ways. Interview the control owner, observe the process running, and sample records. One source is an assertion; three is evidence. Sample sizes should be proportionate — a handful of records per control is normal, more where risk is high.
- Classify what you find. Use consistent categories: major nonconformity (a requirement is absent or systemically failing), minor nonconformity (an isolated lapse), observation, and opportunity for improvement. State the requirement breached and the objective evidence — nothing about who to blame.
- Report to management. Clause 9.2.2 requires results to reach relevant management, and clause 9.3 requires internal audit results as an input to the management review. A report that circulates only among the security team does not meet either clause.
- Drive corrective action to closure. Under clause 10.2 each nonconformity needs a reaction, an evaluation of the cause, a corrective action, a check that the action worked, and retained documented information. Open findings with no closure evidence are worse than no findings at all.
If you have not yet mapped your current position against the standard, run a gap analysis first — auditing a system you have not baselined wastes the audit.
What the certification auditor will ask to see
Expect these five ISO 27001 internal audit artifacts to be requested by name, and expect them to be cross-checked against each other:
- The audit program covering the full ISMS over a defined period.
- Audit plans showing criteria and scope for each audit performed.
- Evidence of auditor independence from the areas they audited.
- Audit reports with findings, including negative ones.
- Corrective action records with root cause, action taken, and verification of effectiveness.
The cross-check matters. If your Statement of Applicability declares 90 controls applicable but your audit preparation only ever touched 20 of them, the gap is visible immediately.
Five mistakes that turn an internal audit into a finding
These ISO 27001 internal audit mistakes recur constantly, and all five are avoidable:
- A document review dressed up as an audit. Reading policies proves conformity at best. Effectiveness needs sampled operating evidence.
- No findings at all. A clean first internal audit of a new ISMS is not credible, and experienced auditors treat it as a red flag.
- Auditing your own work. The fastest way to fail clause 9.2.2, and one that is trivially visible from job titles.
- Findings raised but never closed. Missing verification of effectiveness breaches clause 10.2 and creates a second nonconformity on top of the first.
- Auditing only the controls, not the clauses. Annex A is the visible half; clauses 4 to 10 — context, leadership, planning, support, operation, performance evaluation and improvement — are where major nonconformities are usually raised.
You can check the scope and current status of the standard on the official ISO/IEC 27001 page at iso.org. Two dates matter for your audit criteria: the 2013 to 2022 transition period closed on 31 October 2025, so 2013 certificates are no longer valid, and Amendment 1:2024 added climate change considerations to clauses 4.1 and 4.2 — it is published free of charge and your checklist should reflect it.
Turn the checklist into a working audit program
Building the audit program, the checklists, the report template and the corrective action register from scratch is usually two to three weeks of drafting. Our ISO 27001 Toolkit ships 175 auditor-written templates mapped to ISO 27001:2022 — including the internal audit programme, clause-by-clause and Annex A checklists, audit report and corrective action forms — editable in Word and Excel for $99.
Frequently asked questions
How often is an ISO 27001 internal audit required?
The standard says “at planned intervals” and deliberately sets no fixed frequency. You define the interval and justify it based on risk, process importance and previous results. The common approach is a programme that covers the entire ISMS at least once every 12 months, with higher-risk areas audited more often.
Can we do the internal audit ourselves?
Yes. ISO 27001 requires objectivity and impartiality, not an external firm or a certified lead auditor qualification. Internal staff are acceptable provided they do not audit their own work and are competent for what they are auditing. Small teams often contract an independent auditor simply because nobody in-house is sufficiently removed from the ISMS.
What is the difference between an internal audit and a gap analysis?
A gap analysis is an informal readiness check, usually run once at the start, comparing where you are against what the standard requires. The ISO 27001 internal audit is a formal, repeating, evidence-based process required by clause 9.2, with defined criteria, independent auditors, documented findings and corrective actions. A gap analysis will not satisfy clause 9.2.
Do we need an internal audit before the Stage 1 audit?
You need at least one complete cycle finished before Stage 2, and having it done before Stage 1 is far safer — Stage 1 checks readiness, and a missing internal audit is a standard reason to be told you are not ready. The management review under clause 9.3 should also have taken place, since it consumes the audit results.
What happens if the internal audit finds a major nonconformity?
Nothing bad, provided you handle it under clause 10.2: correct the immediate issue, evaluate the root cause, implement corrective action, verify it worked, and retain the records. Finding and closing a major nonconformity yourself is exactly what the clause exists for, and it demonstrates a working ISMS rather than a failing one.