The ISO 27001 Internal Audit: Clause 9.2 in Practice
Clause 9.2 of ISO 27001 requires you to audit your own ISMS at planned intervals, before and between the external audits. It is not optional and it is not a formality: a missing or superficial internal audit is one of the most common reasons a Stage 2 certification audit goes badly.
Done well, the internal audit is a rehearsal that finds problems while they are still cheap to fix. This guide covers the four things auditors examine: the audit programme, the independence of whoever performs it, how the audit itself is conducted, and what happens to the findings afterwards.
Building the audit programme
The standard asks for an audit programme, not just a one-off audit. That means a documented plan showing which parts of the ISMS are audited, when, by whom, and using what criteria. The programme should consider the importance of each process and the results of previous audits, so a high-risk area or one that produced findings last time gets audited sooner and more deeply.
You do not have to audit everything at once. Many organisations run a full-scope internal audit before certification, then rotate through areas across the three-year certificate cycle, provided the whole ISMS is covered. Whatever the rhythm, the complete cycle and its rationale must be written down, because the external auditor will ask to see the programme, not just the last report.
Independence and who can audit
Auditors must be objective and impartial: nobody should audit their own work. In a large organisation that is easy, since an internal audit function or a different department can do it. In a ten-person startup it is harder, and the standard allows pragmatism, for example the engineering lead auditing HR security processes while an operations person audits the engineering controls.
Outsourcing the internal audit to a consultant is common and perfectly acceptable, and often worthwhile for a first certification because an experienced auditor knows what the certification body will probe. What matters is competence and independence, both of which you should be able to evidence: keep a short record of auditor qualifications or experience alongside the audit report.
Running the audit: checklist and evidence
A checklist approach keeps the audit systematic: work through the clauses 4 to 10 requirements and the applicable Annex A controls from your Statement of Applicability, and for each one record what evidence was examined and whether it conforms. Evidence means documents, records, system configurations, and interviews, not just an assertion that a policy exists.
Sample rather than boil the ocean: pick a handful of joiners and leavers to test access control, a few changes to test change management, a couple of incidents to test response. Findings should be classified, typically as nonconformities (a requirement is not met), observations, and opportunities for improvement, and each nonconformity should state the requirement, the evidence, and the gap in plain language so the owner can act on it.
Findings, corrective action, and management review
An internal audit that produces zero findings is a red flag to certification bodies, not a badge of honour. Findings are the point. Each nonconformity needs a corrective action with an owner and a deadline, and clause 10 expects you to look at root cause, not just patch the symptom.
The results then feed the management review required by clause 9.3: leadership must see the audit results, the status of corrective actions, and decide on any changes to the ISMS. This closing of the loop, audit to finding to action to management decision, is exactly the trail the external auditor follows. Platforms such as Drata can track controls, findings, and corrective actions in one place so that trail stays intact between audits.
ISO 27001 policy templates
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.
Automate ISO 27001 with Drata
Drata maps the controls, collects evidence automatically, and keeps you audit-ready. Automated, continuous compliance with deep integrations.
FAQ
- Can we do the ISO 27001 internal audit ourselves?
- Yes, provided the auditor is competent and does not audit their own work. Small teams often cross-audit between departments or hire an external consultant to perform the internal audit, which is fully acceptable under the standard.
- How often is an internal audit required?
- At planned intervals defined by your audit programme. In practice most organisations audit the full ISMS at least annually, and a complete internal audit must be done before the Stage 2 certification audit.
- What happens if the internal audit finds nonconformities?
- That is normal and expected. Raise corrective actions with owners and deadlines, address root causes, and record the closure. Findings you found and fixed yourself are far better than findings the certification body discovers.