ISO 27001 Internal Audit Checklist: Clause 9.2 Guide
A practical first-party audit checklist for testing whether your ISMS is implemented, effective and maintained—not just documented.
An ISO 27001 internal audit is the organisation’s own structured test of its information security management system. It should show whether the ISMS conforms to ISO/IEC 27001:2022, to the organisation’s own requirements and to its Statement of Applicability—and whether it actually works in practice.
This guide is deliberately different from an ISO 27001 Stage 1 and Stage 2 audit preparation checklist. That article helps you prepare for the certification body. This one helps you run recurring first-party audits before and after certification, including surveillance preparation and continual improvement.
Use a checklist to make the audit complete and repeatable. Do not use it as a substitute for professional judgement, process sampling or evidence of effectiveness.
What Clause 9.2 requires
Clause 9.2 requires internal audits at planned intervals. The organisation must plan, establish, implement and maintain an audit programme that considers the importance of the processes concerned, changes affecting the organisation and the results of previous audits. The programme also needs defined methods, responsibilities, planning requirements and reporting.
Auditors must be objective and impartial. A person should not audit their own work. A small organisation can use a trained colleague from another area, exchange audits with a partner organisation or appoint an independent external auditor. The official ISO/IEC 27001:2022 standard page describes ISO 27001 as the requirements standard for establishing, maintaining and continually improving an ISMS.
Internal audit, certification audit and management review
| Activity | Purpose | Typical output |
|---|---|---|
| Internal audit | Test conformity and effectiveness before problems reach customers, incidents or the certification body. | Audit plan, evidence, findings, report and corrective actions. |
| Stage 1 / Stage 2 certification audit | Independent assessment by the certification body for initial certification. | Audit findings and certification decision. |
| Surveillance audit | Check that the certified ISMS continues to operate between recertification audits. | Surveillance findings and continued certification. |
| Management review | Top management evaluates suitability, adequacy, effectiveness and improvement needs. | Decisions, resources, objectives and improvement actions. |
How to build a risk-based audit programme
- Define the audit universe: list the ISMS scope, processes, sites, systems, suppliers, roles and applicable Annex A controls.
- Set frequency and depth: audit higher-risk or recently changed areas more often. Cover the complete ISMS over the programme cycle; do not force every topic into one audit.
- Consider previous results: give priority to repeated findings, overdue actions, incidents, major changes and weak effectiveness indicators.
- Assign an impartial auditor: record competence, independence and any safeguards.
- Approve the programme: document timing, methods, criteria, responsibilities and reporting arrangements.
ISO 27001 internal audit checklist
For every question, record the audit criterion, sampled evidence, interviewee or system checked, result, finding reference and follow-up action. Replace generic questions with your actual scope, risks and SoA.
| Area | Questions to ask | Evidence to sample |
|---|---|---|
| Scope and context | Does the ISMS scope still reflect services, locations, interfaces, interested parties and legal or contractual requirements? | Scope statement, context review, requirements register, organisation changes. |
| Leadership and objectives | Does top management provide direction, resources and measurable information-security objectives? | Policy approval, objectives, KPI results, management decisions and resource records. |
| Risk assessment | Are risk criteria, assets, threats, impacts, owners and acceptance decisions applied consistently? | Risk methodology, current risk register, completed assessments and accepted residual risks. |
| Risk treatment and SoA | Can each material risk be traced to treatment, selected controls, responsible owners and evidence? | Risk treatment plan, Statement of Applicability, action status and control records. |
| Support and competence | Do people understand their security responsibilities and receive suitable awareness or training? | Role descriptions, training records, induction, awareness tests and communications. |
| Operational control | Are security processes performed as planned, including change, incident, supplier and documented-information control? | Tickets, incident records, supplier reviews, approvals, procedures and version history. |
| Annex A effectiveness | Do applicable controls work as described in the SoA, and are exceptions and residual risks controlled? | Sample access reviews, offboarding, backup tests, logs, vulnerability records, physical checks and security tests. |
| Performance evaluation | Are monitoring, measurement, internal audits and management reviews used to identify trends and decisions? | Metrics, audit programme, previous reports, management-review minutes and action tracking. |
| Improvement | Are nonconformities corrected at the root cause, and is effectiveness checked after closure? | Finding records, cause analysis, corrective actions, due dates and effectiveness reviews. |
How to sample Annex A controls
Do not copy all 93 Annex A controls into a generic tick-box list. The 2022 edition contains 93 controls, but the organisation’s Statement of Applicability determines which controls apply and how they are implemented. Select samples based on risk, scope, change and prior findings.
A useful evidence chain is: risk → treatment decision → SoA control → procedure or technical configuration → operating record → effectiveness result. For example, an access-control sample might follow a joiner, mover and leaver from approval through provisioning, review and timely removal.
Recording findings and corrective actions
Write findings so another person can understand the requirement, objective evidence and gap without attending the audit. Separate correction from corrective action: restoring one missed access review is a correction; improving ownership, reminders and review controls may be the corrective action.
- State the criterion or internal requirement.
- Describe the sampled evidence and the factual gap.
- Assess the risk and agree an owner and due date.
- Identify the cause rather than only rewriting the document.
- Verify implementation and later effectiveness before closure.
Internal audit report structure
A useful internal audit report should allow someone who did not attend the audit to understand what was examined, how the conclusion was reached and what happens next. Keep the report concise, but make the audit trail clear. At minimum, include:
- Audit definition: objective, scope, criteria, dates and the areas or processes included.
- People and independence: auditors, participants, responsibilities and a statement explaining how impartiality was maintained.
- Method and limits: audit methods, interviews, document reviews, samples, systems or sites checked, and any limitations.
- Results: conforming practices, improvement opportunities and nonconformities, each supported by objective evidence and the relevant requirement.
- Follow-up: corrective-action owners, deadlines, priorities, escalation route and the method for checking effectiveness.
- Conclusion and control: conclusion on conformity and effectiveness, distribution, approval and the record-retention reference.
Practical tips for maintaining conformity
- Audit changed areas soon after major system, supplier, organisation or regulatory changes.
- Ask process owners to demonstrate a real recent transaction, not only show a policy.
- Link findings to incidents, risks, SoA entries and management-review decisions.
- Keep a programme-level view so an apparently closed audit does not leave a high-risk process untouched.
- Use the internal audit to improve the ISMS; do not turn it into a ceremonial pre-check for the external auditor.
Frequently asked questions
How often must an ISO 27001 internal audit be performed?
ISO 27001 requires audits at planned intervals and an audit programme. It does not prescribe one universal frequency for every process. Set frequency according to risk, importance, changes and previous results, and ensure the programme covers the ISMS appropriately.
Does an internal audit have to cover all 93 Annex A controls?
No. Audit the controls applicable to your organisation and recorded in the Statement of Applicability, together with the management-system requirements and your own ISMS requirements.
Can the ISMS manager audit their own work?
That creates an objectivity risk. Assign an impartial auditor or introduce safeguards such as peer review or an independent external audit.
Is an internal audit required after ISO 27001 certification?
Yes. Maintaining a certified ISMS requires continued performance evaluation, including internal audits at planned intervals. The audit programme provides evidence that the system remains implemented and effective.
Related ISO 27001 guidance
For external audit preparation, see the Stage 1 and Stage 2 checklist. For the inputs to this audit, see the guides to the ISO 27001 risk assessment, risk treatment plan and Statement of Applicability.
How Sternberg Consulting supports you
We help SMEs design risk-based audit programmes, conduct impartial internal audits and turn findings into effective corrective actions. Our ISO 27001 consulting supports the full ISMS lifecycle.
ISO/IEC 27001:2022 is a requirements standard for information security management systems. Its purpose includes maintaining and continually improving an ISMS, which is why internal audit evidence should demonstrate a living system rather than a static document set. ISO/IEC 27001:2022 overview.