ISO 27001 internal audit: checklist and how to prepare it

By the QuantumSec team

Before an external auditor reviews your ISMS, the standard itself requires you to audit it yourself. ISO 27001's internal audit isn't a bureaucratic formality: it's the filter meant to catch deviations before the certification body finds them, when fixing them already costs time and credibility.

What clause 9.2 of ISO 27001 requires

The standard requires running internal audits "at planned intervals" — in practice, annually — to check that the ISMS meets both the organization's own requirements and the standard's, and that it is effectively implemented and maintained. The result must be documented and feed into management review (clause 9.3) and the nonconformity and corrective action process (clause 10.2).

Who can run the internal audit? The independence requirement

The standard requires the auditor to be objective and impartial: they cannot audit their own work. This doesn't mean it has to be external — a mid-sized company can train an employee from a different department as a certified internal auditor (for example, with an ISO 27001 lead auditor course) — but in practice, many SMBs without enough staff to guarantee that independence choose to outsource the internal audit to an external consultant, who also brings experience facing real certification auditors.

What a full internal audit reviews

Coverage of the 93 Annex A controls against the Statement of Applicability; evidence that documented policies and procedures are actually applied, not just written down; incident, change and access records; the state of the risk assessment and whether it still reflects current reality; follow-up on corrective actions from previous audits; and interviews with process owners to verify they know and apply the procedures that affect them.

Checklist before the external audit

1) The Statement of Applicability is up to date and matches the controls actually implemented. 2) Every nonconformity from the previous internal audit has a corrective action closed or on schedule. 3) Minutes exist from the last management review cycle. 4) Mandatory records (incidents, access, training, changes) are complete and recently dated. 5) Key staff can explain, without a script, how they apply the procedures that affect them. If any of these five points fails, it's cheaper to fix it before the external audit than after.

FAQ

How often does the internal audit need to happen?

At least once a year, and always before each external certification or surveillance audit. Many organizations audit in blocks throughout the year (for example, technical controls in one quarter, organizational processes in another) instead of doing it all at once.

Does the internal audit replace the certification audit?

No. Both are complementary and mandatory: the internal one is a requirement of the standard you must fulfil yourself; the certification audit is run by an accredited external body and is the one that issues (or maintains) the certificate.

What happens if the internal audit finds a serious nonconformity?

It gets documented, a corrective action is opened with a deadline and owner, and it's tracked until closed. Finding and fixing a nonconformity during the internal audit is exactly what the system is meant to do: it's worse if the certification auditor finds it first.