Audit & Certification · Free Excel template
ISO 27001 Internal Audit Checklist and Workbook (Free Excel Template)
This free ISO 27001 internal audit checklist is the workbook I would hand to an internal auditor preparing an ISMS for surveillance or certification. It covers every management system requirement in clauses 4 to 10 and all 93 Annex A controls from ISO/IEC 27001:2022, in one structured Excel file.
Record the evidence you review, grade each requirement, log nonconformities with root causes and corrective actions, and watch the dashboard update automatically. It is built for real audits, not for ticking boxes.
- 25clause requirements
- 93Annex A controls
- 6working tabs
- Freeno sign-up
What's inside the workbook
For: Internal auditors, ISMS managers, compliance leads and consultants preparing for surveillance or certification audits.
- 01
Introduction🔒
How to use the workbook, the colour legend and grading guidance.
- 02
Audit Plan
Organisation, scope, audit criteria, objectives, audit team and a day-by-day schedule.
- 03
Clauses 4-10
All 25 management system requirements, each with a practical audit question, evidence, auditee and result.
- 04
Annex A Controls
All 93 controls across the Organisational, People, Physical and Technological themes, with SoA applicability, implementation status and result.
- 05
Findings & CAP
Nonconformity and OFI register with objective evidence, root cause, corrective action, owner, due date, status and automatic days overdue.
- 06
Dashboard
Live results by clause and control, conformity rate, Statement of Applicability coverage, open actions and a chart for the closing meeting.
- Dropdowns for every result and status
- Colour coded conformity
- Automatic dashboard and chart
- Overdue action tracking
- Print ready, A4 landscape
- Works in Microsoft Excel 2016 and later
What is an ISO 27001 internal audit?
Clause 9.2 of ISO/IEC 27001 requires organisations to conduct internal audits at planned intervals to confirm the information security management system (ISMS) conforms to the organisation's own requirements and to the standard, and that it is effectively implemented and maintained.
A good internal audit does more than satisfy an external auditor. It tests whether controls actually work, gives top management honest input for the management review (clause 9.3), and finds problems while they are still cheap to fix.
What the workbook covers
Clauses 4 to 10 are the mandatory management system requirements: context of the organisation, leadership, planning, support, operation, performance evaluation and improvement. Each of the 25 requirements in the workbook comes with an audit question written in plain English, so less experienced auditors know what good evidence looks like.
Annex A lists 93 reference controls grouped into four themes:
- Organisational controls: 37 (5.1 to 5.37)
- People controls: 8 (6.1 to 6.8)
- Physical controls: 14 (7.1 to 7.14)
- Technological controls: 34 (8.1 to 8.34)
Record whether each control is applicable in your Statement of Applicability, how well it is implemented, and the audit result. The dashboard turns those entries into coverage and conformity figures automatically.
Grading findings: major nonconformity, minor nonconformity or OFI
Consistent grading is what makes an audit credible. The workbook uses the grading most certification bodies recognise:
- Major nonconformity: a requirement is not met at all, or a systemic failure undermines the ISMS's ability to achieve its intended outcomes.
- Minor nonconformity: a single or isolated lapse that does not, on its own, undermine the ISMS.
- Opportunity for improvement (OFI): not a nonconformity, but something that could be done better.
Every finding should be backed by objective evidence. The Findings & CAP tab prompts for it, along with the root cause, so corrective actions fix the cause rather than the symptom.
Built for ISO/IEC 27001:2022
The 2022 revision restructured Annex A from 114 controls in 14 domains into 93 controls in four themes, merging many controls and adding 11 new ones, including threat intelligence, information security for cloud services, ICT readiness for business continuity, configuration management, data leakage prevention, monitoring activities and secure coding. The transition period for the 2013 edition ended on 31 October 2025, so audits should now be performed against the 2022 edition.
Control titles in the workbook are abbreviated for reference. Always audit against your licensed copy of the standard and your organisation's Statement of Applicability.
How to use the ISO 27001 Internal Audit Workbook
- 1
Plan the audit
Complete the Audit Plan tab with the organisation, ISMS scope, audit criteria, objectives, audit team and schedule.
- 2
Load your Statement of Applicability
On the Annex A Controls tab, mark each control as applicable or not and record its implementation status.
- 3
Audit and record evidence
Interview auditees, sample records and observe controls. Record the evidence reviewed and a result for every clause and applicable control.
- 4
Log findings
Record each nonconformity and opportunity for improvement on Findings & CAP with a reference such as NC-001, and enter that reference against the clause or control.
- 5
Agree corrective actions
Agree root causes, corrective actions, owners and due dates with auditees. Days overdue calculate automatically.
- 6
Report and follow up
Use the Dashboard for the closing meeting and management review, then verify corrective actions and close findings.
Get the ISO 27001 Internal Audit Workbook
Free download. No sign-up, no email required.
Frequently asked questions
Is this ISO 27001 audit checklist based on the 2022 version?
Yes. It follows ISO/IEC 27001:2022, including the restructured Annex A with 93 controls in four themes.
Does it include every Annex A control?
Yes. All 93 Annex A controls are listed: 37 organisational, 8 people, 14 physical and 34 technological controls.
Can I use it for my certification audit?
It is designed for internal audits and certification readiness. Certification audits are performed by an accredited certification body using its own process, but completing this workbook first means you walk into that audit with evidence organised and gaps already addressed.
How often should ISO 27001 internal audits be performed?
The standard requires audits at planned intervals. Most organisations cover the full ISMS scope at least once a year, often split into smaller audits across the year, and audit higher-risk areas more frequently.
Who can conduct an ISO 27001 internal audit?
Anyone competent and objective. Internal auditors should understand the standard and audit techniques, and must not audit their own work. Many organisations use a trained internal auditor or an independent consultant.
Does it work in Google Sheets?
It is built for Microsoft Excel 2016 or later, including Microsoft 365 and Excel for the web. Google Sheets can open it, but some formatting, charts and protection may behave differently.
More free templates
Third-Party & Supplier Risk
Third-Party Risk Management Questionnaire
A weighted supplier security questionnaire with 60 questions across 17 domains, including AI usage, with automatic scoring, inherent risk tiering and an onboarding recommendation.
View template →US Defense · CMMC 2.0
CMMC Level 1 & 2 Readiness Workbook
Self-assess against the official CMMC 2.0 requirements: 15 for Level 1 and all 110 NIST SP 800-171 Rev 2 requirements for Level 2, with automatic SPRS scoring and POA&M eligibility.
View template →Risk Assessment · NIST SP 800-30
Cyber Security Risk Assessment Workbook
Identify, analyse and treat cyber risks with the NIST SP 800-30 method, a 5x5 matrix, a 25-risk starter library, a live heat map and treatment mapped to NIST SP 800-53.
View template →Templates
Browse all templates
Expert-built Excel tools for audits, assessments and supplier reviews.
See all →