Audit & Certification

ISO 27001 Internal Audit: A Step-by-Step Guide With Checklist

How to plan and run an ISO 27001 internal audit: scope, audit programme, clauses 4 to 10, Annex A sampling, grading findings and closing corrective actions.

Muhammad Anwar
· 5 min read

An ISO 27001 internal audit is where most information security management systems either prove themselves or quietly fall apart. Certification bodies expect it, management reviews depend on it, and done well it finds problems while they are still cheap to fix. Done badly, it becomes a box-ticking exercise that tells leadership everything is fine until the external auditor arrives.

This guide walks through how I plan and run an ISO 27001 internal audit, step by step, against ISO/IEC 27001:2022.

What the standard actually requires

Clause 9.2 of ISO/IEC 27001:2022 requires internal audits “at planned intervals” to confirm that the ISMS:

  • conforms to your own requirements and to the standard, and
  • is effectively implemented and maintained.

The 2022 edition split clause 9.2 into two parts: 9.2.1 (general) and 9.2.2 (the internal audit programme). In practice that means you need an audit programme covering frequency, methods, responsibilities, planning requirements and reporting, not just a single audit once a year. The programme must take into account the importance of the processes concerned and the results of previous audits.

Two rules trip organisations up most often:

  1. Objectivity and impartiality. Auditors must not audit their own work.
  2. Results reach management. Audit results must be reported to relevant management and retained as documented evidence.

Step 1: Build a risk-based audit programme

Most organisations aim to cover the full ISMS scope at least once in a three-year certification cycle, and more often once a year, usually split into smaller audits. Weight the programme towards:

  • processes and controls tied to your highest risks
  • areas with previous nonconformities
  • anything that changed significantly: new systems, outsourcing, restructures, mergers
  • controls added in the 2022 revision that may be less mature, such as threat intelligence (5.7), cloud services (5.23) and configuration management (8.9)

Step 2: Plan each audit

For each audit, write a short plan that records:

  • Scope and criteria: which clauses, Annex A controls, sites and teams, and what you are auditing against (the standard, your policies, your Statement of Applicability).
  • Objectives: for example, “confirm the access review process operates effectively across all critical systems”.
  • Auditors and auditees: who is involved, and confirmation that auditors are independent of the area.
  • Schedule: opening meeting, interviews, walkthroughs and closing meeting.

My free ISO 27001 internal audit workbook has an Audit Plan tab that captures all of this in one place.

Step 3: Audit the management system (clauses 4 to 10)

Clauses 4 to 10 are mandatory. No exclusions are allowed, so every internal audit programme must cover them. The questions I ask most often:

  • Clause 4, context: Is the ISMS scope documented and does it still reflect the business? Are interested parties and their requirements identified?
  • Clause 5, leadership: Is the information security policy approved and communicated? Are roles assigned, and do people know them?
  • Clause 6, planning: Is there a repeatable risk assessment method? Does the Statement of Applicability match the risk treatment plan? Are objectives measurable?
  • Clause 7, support: Can you evidence competence, awareness and document control?
  • Clause 8, operation: Was the risk assessment actually performed at planned intervals and after significant change?
  • Clause 9, performance evaluation: Is monitoring defined? Did management review cover all required inputs?
  • Clause 10, improvement: Are nonconformities corrected, with root causes addressed?

Step 4: Sample the Annex A controls

The 2022 Annex A has 93 controls in four themes: 37 organisational, 8 people, 14 physical and 34 technological. You do not need to test all 93 in every audit. Sample them based on risk and on your Statement of Applicability, and rotate coverage across the programme.

For each sampled control, look for three kinds of evidence:

  1. Documented: the policy or procedure says what should happen.
  2. Implemented: records show it happened (tickets, logs, review sign-offs).
  3. Effective: it achieved its purpose. An access review that never removes anyone is implemented but probably not effective.

Interview the people who operate the control, not just the people who wrote the policy, and pick samples yourself rather than accepting the ones you are handed.

Step 5: Grade findings consistently

Consistent grading is what makes an audit credible. Most certification bodies use three categories:

  • Major nonconformity: a requirement is not met at all, or a systemic failure undermines the ISMS.
  • Minor nonconformity: an isolated lapse that does not, on its own, undermine the ISMS.
  • Opportunity for improvement (OFI): not a nonconformity, but something that could be done better.

Every finding needs objective evidence: what you saw, where, and which requirement it relates to. “The team seemed unsure about incident response” is an opinion. “Two of three analysts interviewed could not locate the incident response procedure (clause 7.3, control 5.24)” is a finding.

Step 6: Report, correct and follow up

Hold a closing meeting, agree the findings, then issue a short written report. For each nonconformity, the auditee should:

  1. contain the immediate problem (correction)
  2. find the root cause
  3. take corrective action so it does not recur
  4. provide evidence, which the auditor then verifies before closing

Track actions to closure with owners and due dates, and feed the results into management review (clause 9.3). That loop is what turns the audit into improvement rather than paperwork.

Common mistakes I see

  • Auditing documents, not reality. A perfect policy set with no operating evidence is a major risk.
  • The same auditor every year. Fresh eyes find different things.
  • No link to risk. If the audit programme ignores your top risks, it is not giving leadership the assurance it needs.
  • Findings that never close. Overdue corrective actions are one of the first things an external auditor checks.

If you are preparing for a broader assessment, the same discipline applies to IRAP readiness and to board reporting on cyber risk.

Frequently asked questions

How often should an ISO 27001 internal audit be done?

The standard says “at planned intervals”. Most organisations cover the full ISMS at least once a year, often split into several smaller audits, and audit high-risk areas more frequently.

Who can perform an ISO 27001 internal audit?

Anyone who is competent and objective. Auditors must not audit their own work. Many organisations use a trained internal auditor, an internal audit function or an independent consultant.

Does the internal audit have to cover every Annex A control?

Not in every audit. Clauses 4 to 10 must always be covered across the programme, while Annex A controls can be sampled based on risk and rotated so that applicable controls are covered over the cycle.

What is the difference between a major and a minor nonconformity?

A major nonconformity is a missing requirement or a systemic failure that undermines the ISMS. A minor nonconformity is an isolated lapse that does not, on its own, undermine the system.


Want an independent ISO 27001 internal audit or certification readiness review? See audit and certification services or download the free audit workbook.

Muhammad Anwar

Cybersecurity & Compliance Assurance Leader specialising in the ISM, PSPF, NIST SP 800-53, SOCI Act and AI governance (ISO 42001). Views are my own.