# ISMS internal audit procedure

Source: https://aestech.com.au/policy-templates/#isms-internal-audit-procedure
Markdown URL: https://aestech.com.au/policy-templates/isms-internal-audit-procedure.md

How to plan and run internal ISMS audits under ISO 27001 clause 9.2, from programme to follow-up.

Frameworks: ISO 27001

Use this as a starting point only. Adapt it to your real scope, systems, legal obligations, customer commitments and operating process.

```text
1. Purpose
This procedure defines how [Company Pty Ltd] plans, conducts and follows up internal audits of the Information Security Management System (ISMS), so that management receives objective evidence that the ISMS conforms to ISO/IEC 27001:2022 and to our own requirements, and that it is effectively implemented and maintained.

2. Scope
Applies to all processes, controls, teams and locations inside the ISMS scope statement, including outsourced processes for which [Company] retains responsibility.

3. Audit programme
3.1 The [ISMS Manager] maintains a rolling audit programme covering every ISMS clause and every applicable Annex A control at least once per [certification cycle, typically 3 years], with higher-risk areas audited at least annually.
3.2 Programme inputs: risk assessment results, incident history, prior audit findings, changes to systems or suppliers, and certification body feedback.
3.3 The programme records, for each audit: scope, criteria, method (interview, document review, technical sampling), auditor, and planned month.

4. Auditor independence and competence
4.1 Auditors must not audit their own work or areas they manage. Where the team is small, use a trained auditor from another function, a peer company arrangement, or an external contractor.
4.2 Auditors must have completed [internal auditor training / ISO 27001 lead auditor course] and be approved by the [ISMS Manager].

5. Planning each audit
5.1 At least [10] business days before fieldwork, the auditor issues an audit plan stating scope, criteria (ISO 27001 clauses, Annex A controls, internal policies), interviewees, and evidence to be sampled.
5.2 Auditees confirm availability and pre-supply requested documents.

6. Fieldwork
6.1 Open with a short briefing confirming scope and method.
6.2 Gather objective evidence: interview staff, review records, observe practice, and sample system configurations. Record what was examined, not only conclusions.
6.3 Test that controls operate as described, not merely that documents exist.

7. Findings and reporting
7.1 Classify each finding as: major nonconformity, minor nonconformity, observation, or opportunity for improvement, with the criterion breached and the evidence.
7.2 Issue the audit report to the auditee and [top management] within [5] business days of fieldwork.
7.3 Nonconformities enter the corrective action process per the [Nonconformity and Corrective Action Procedure].

8. Follow-up
The auditor verifies completion and effectiveness of corrective actions by [agreed due dates] and records closure. Overdue actions are escalated to [management review].

9. Roles and responsibilities
[ISMS Manager]: owns the programme and this procedure. Auditors: plan, execute, report, verify closure. Auditees: provide access and evidence, own corrective actions. [Top management]: receives results, resources the programme.

10. Records
Retain the audit programme, audit plans, evidence notes, reports and closure records for at least [3] years in [location].

11. Review
Review this procedure at least annually and after any certification audit. Owner: [ISMS Manager]. Version: [x.y]. Approved by: [name/role]. Date: [date].
```

Full template pack: https://aestech.com.au/policy-templates/policy-pack.md