ISO 27001 internal audit: checklist and how to prepare it

By Kike Gandia · Co-Founder & CEO, OSCP

Before an external auditor reviews your ISMS, the standard itself requires you to audit it yourself. ISO 27001's internal audit isn't a bureaucratic formality: it's the filter meant to catch deviations before the certification body finds them, when fixing them already costs time and credibility.

What clause 9.2 of ISO 27001 requires

The standard requires running internal audits "at planned intervals" — in practice, annually — to check that the ISMS meets both the organization's own requirements and the standard's, and that it is effectively implemented and maintained. The result must be documented and feed into management review (clause 9.3) and the nonconformity and corrective action process (clause 10.2).

Who can run the internal audit? The independence requirement

The standard requires the auditor to be objective and impartial: they cannot audit their own work. This doesn't mean it has to be external — a mid-sized company can train an employee from a different department as a certified internal auditor (for example, with an ISO 27001 lead auditor course) — but in practice, many SMBs without enough staff to guarantee that independence choose to outsource the internal audit to an external consultant, who also brings experience facing real certification auditors.

What a full internal audit reviews

Coverage of the 93 Annex A controls against the Statement of Applicability; evidence that documented policies and procedures are actually applied, not just written down; incident, change and access records; the state of the risk assessment and whether it still reflects current reality; follow-up on corrective actions from previous audits; and interviews with process owners to verify they know and apply the procedures that affect them.

Checklist before the external audit

1) The Statement of Applicability is up to date and matches the controls actually implemented. 2) Every nonconformity from the previous internal audit has a corrective action closed or on schedule. 3) Minutes exist from the last management review cycle. 4) Mandatory records (incidents, access, training, changes) are complete and recently dated. 5) Key staff can explain, without a script, how they apply the procedures that affect them. If any of these five points fails, it's cheaper to fix it before the external audit than after.

Major nonconformity, minor, observation: why the label matters

Audit findings do not carry equal weight, and confusing the categories leads teams to spend the same effort on very different things:

CategoryWhat it meansTypical exampleConsequence
Major nonconformityA requirement of the standard is unmet, or the failure is systemicNo risk assessment exists, or management review has never been heldBlocks certification until closed and verified
Minor nonconformityAn isolated lapse in a process that otherwise worksTwo user accounts created this quarter without the approval recordClosed with a corrective action and a deadline; does not block the certificate
Observation or opportunity for improvementBreaches nothing, but points at a future riskAccess reviews happen, but depend on one single personNo formal action required; document the decision

The practical difference between major and minor is almost never the apparent severity of the finding, but whether it is an isolated case or a signal that the process does not exist. Two missing records is a minor; no record at all across the whole year for that same process is a major, even though the control is identical.

How it gets planned: the audit programme

Clause 9.2 does not ask for an audit, it asks for an audit programme: what gets audited, when, against what criteria, and by whom. A sensible programme for a mid-sized organisation spreads the work into blocks across the year and states in writing, for each block, what evidence will be requested and who will be interviewed. One split that works: first block, ISMS governance — policy, scope, risk assessment, SoA, management review minutes — interviewing leadership and the system owner; second block, people and suppliers — training, joiners and leavers, contracts and confidentiality agreements, supplier evaluation — with HR and procurement; third block, technical operation — access management, backups and restores, vulnerability management and patching, change management, logging — with IT; and fourth block, incidents and continuity, reviewing the year's real incidents and the recovery tests. Auditing in blocks has one non-trivial advantage: it spreads the load on the team and lets corrective actions from the first block be closed before the certification audit arrives.

FAQ

How often does the internal audit need to happen?

At least once a year, and always before each external certification or surveillance audit. Many organizations audit in blocks throughout the year (for example, technical controls in one quarter, organizational processes in another) instead of doing it all at once.

Does the internal audit replace the certification audit?

No. Both are complementary and mandatory: the internal one is a requirement of the standard you must fulfil yourself; the certification audit is run by an accredited external body and is the one that issues (or maintains) the certificate.

What happens if the internal audit finds a serious nonconformity?

It gets documented, a corrective action is opened with a deadline and owner, and it's tracked until closed. Finding and fixing a nonconformity during the internal audit is exactly what the system is meant to do: it's worse if the certification auditor finds it first.

How long does it take, and how much of the team's time does it consume?

In a small organisation with a narrow scope, fieldwork usually takes one to three days, plus preparation and report writing. What needs planning is not the auditor's days but the availability of the people being interviewed: each process owner needs to block a slot and have their records to hand. An internal audit squeezed between meetings ends up producing findings that only reflect that nobody had time to locate the evidence.

What documentation should be ready before the auditor arrives?

The current ISMS documentation with version and date — policy, scope, risk assessment, SoA, treatment plan — the previous audit report and its corrective actions, and the records for the period under audit. Those records are what actually get examined: incident log, access reviews, training delivered, changes deployed, backup restore tests and supplier evaluations. Handing them over indexed and dated shortens the audit noticeably.

Can the same consultancy that implemented our ISMS run it?

For the internal audit, yes: the standard requires objectivity and impartiality, not corporate independence, and many organisations solve it with a different consultant inside the same provider who took no part in the implementation. Where separation is non-negotiable is certification: whoever implements cannot certify. If the provider cannot guarantee that internal separation, the clean answer is to have a third party run the internal audit.

What gets delivered at the end?

A report stating the scope and dates audited, the criteria applied, the people interviewed, findings classified as major, minor or observations, and the evidence supporting each one. That report is itself mandatory evidence: the certification auditor will ask for it, and will check that the findings in it have corrective actions with real follow-up, not a "closed" field filled in the same day.

Related service

ISO 27001 implementation consulting

Related content

Sources

Request my ISMS's internal audit