Audit & Certification · Free Excel template

ISO 27001 Internal Audit Checklist and Workbook (Free Excel Template)

This free ISO 27001 internal audit checklist is the workbook I would hand to an internal auditor preparing an ISMS for surveillance or certification. It covers every management system requirement in clauses 4 to 10 and all 93 Annex A controls from ISO/IEC 27001:2022, in one structured Excel file.

Record the evidence you review, grade each requirement, log nonconformities with root causes and corrective actions, and watch the dashboard update automatically. It is built for real audits, not for ticking boxes.

  • 25clause requirements
  • 93Annex A controls
  • 6working tabs
  • Freeno sign-up
Download the free template .xlsx · 72 KB · Excel 2016+ / Microsoft 365 · Updated Oct 2026

What's inside the workbook

For: Internal auditors, ISMS managers, compliance leads and consultants preparing for surveillance or certification audits.

  1. 01

    Introduction🔒

    How to use the workbook, the colour legend and grading guidance.

  2. 02

    Audit Plan

    Organisation, scope, audit criteria, objectives, audit team and a day-by-day schedule.

  3. 03

    Clauses 4-10

    All 25 management system requirements, each with a practical audit question, evidence, auditee and result.

  4. 04

    Annex A Controls

    All 93 controls across the Organisational, People, Physical and Technological themes, with SoA applicability, implementation status and result.

  5. 05

    Findings & CAP

    Nonconformity and OFI register with objective evidence, root cause, corrective action, owner, due date, status and automatic days overdue.

  6. 06

    Dashboard

    Live results by clause and control, conformity rate, Statement of Applicability coverage, open actions and a chart for the closing meeting.

  • Dropdowns for every result and status
  • Colour coded conformity
  • Automatic dashboard and chart
  • Overdue action tracking
  • Print ready, A4 landscape
  • Works in Microsoft Excel 2016 and later

What is an ISO 27001 internal audit?

Clause 9.2 of ISO/IEC 27001 requires organisations to conduct internal audits at planned intervals to confirm the information security management system (ISMS) conforms to the organisation's own requirements and to the standard, and that it is effectively implemented and maintained.

A good internal audit does more than satisfy an external auditor. It tests whether controls actually work, gives top management honest input for the management review (clause 9.3), and finds problems while they are still cheap to fix.

What the workbook covers

Clauses 4 to 10 are the mandatory management system requirements: context of the organisation, leadership, planning, support, operation, performance evaluation and improvement. Each of the 25 requirements in the workbook comes with an audit question written in plain English, so less experienced auditors know what good evidence looks like.

Annex A lists 93 reference controls grouped into four themes:

  • Organisational controls: 37 (5.1 to 5.37)
  • People controls: 8 (6.1 to 6.8)
  • Physical controls: 14 (7.1 to 7.14)
  • Technological controls: 34 (8.1 to 8.34)

Record whether each control is applicable in your Statement of Applicability, how well it is implemented, and the audit result. The dashboard turns those entries into coverage and conformity figures automatically.

Grading findings: major nonconformity, minor nonconformity or OFI

Consistent grading is what makes an audit credible. The workbook uses the grading most certification bodies recognise:

  • Major nonconformity: a requirement is not met at all, or a systemic failure undermines the ISMS's ability to achieve its intended outcomes.
  • Minor nonconformity: a single or isolated lapse that does not, on its own, undermine the ISMS.
  • Opportunity for improvement (OFI): not a nonconformity, but something that could be done better.

Every finding should be backed by objective evidence. The Findings & CAP tab prompts for it, along with the root cause, so corrective actions fix the cause rather than the symptom.

Built for ISO/IEC 27001:2022

The 2022 revision restructured Annex A from 114 controls in 14 domains into 93 controls in four themes, merging many controls and adding 11 new ones, including threat intelligence, information security for cloud services, ICT readiness for business continuity, configuration management, data leakage prevention, monitoring activities and secure coding. The transition period for the 2013 edition ended on 31 October 2025, so audits should now be performed against the 2022 edition.

Control titles in the workbook are abbreviated for reference. Always audit against your licensed copy of the standard and your organisation's Statement of Applicability.

How to use the ISO 27001 Internal Audit Workbook

  1. 1

    Plan the audit

    Complete the Audit Plan tab with the organisation, ISMS scope, audit criteria, objectives, audit team and schedule.

  2. 2

    Load your Statement of Applicability

    On the Annex A Controls tab, mark each control as applicable or not and record its implementation status.

  3. 3

    Audit and record evidence

    Interview auditees, sample records and observe controls. Record the evidence reviewed and a result for every clause and applicable control.

  4. 4

    Log findings

    Record each nonconformity and opportunity for improvement on Findings & CAP with a reference such as NC-001, and enter that reference against the clause or control.

  5. 5

    Agree corrective actions

    Agree root causes, corrective actions, owners and due dates with auditees. Days overdue calculate automatically.

  6. 6

    Report and follow up

    Use the Dashboard for the closing meeting and management review, then verify corrective actions and close findings.

Get the ISO 27001 Internal Audit Workbook

Free download. No sign-up, no email required.

Download (.xlsx, 72 KB)

Frequently asked questions

Is this ISO 27001 audit checklist based on the 2022 version?

Yes. It follows ISO/IEC 27001:2022, including the restructured Annex A with 93 controls in four themes.

Does it include every Annex A control?

Yes. All 93 Annex A controls are listed: 37 organisational, 8 people, 14 physical and 34 technological controls.

Can I use it for my certification audit?

It is designed for internal audits and certification readiness. Certification audits are performed by an accredited certification body using its own process, but completing this workbook first means you walk into that audit with evidence organised and gaps already addressed.

How often should ISO 27001 internal audits be performed?

The standard requires audits at planned intervals. Most organisations cover the full ISMS scope at least once a year, often split into smaller audits across the year, and audit higher-risk areas more frequently.

Who can conduct an ISO 27001 internal audit?

Anyone competent and objective. Internal auditors should understand the standard and audit techniques, and must not audit their own work. Many organisations use a trained internal auditor or an independent consultant.

Does it work in Google Sheets?

It is built for Microsoft Excel 2016 or later, including Microsoft 365 and Excel for the web. Google Sheets can open it, but some formatting, charts and protection may behave differently.

Muhammad Anwar

Built by

Muhammad Anwar

Cybersecurity & Compliance Assurance Leader, ISO 27001 Lead Auditor and Certified GRC Auditor. This template is based on the approach I use in real assessments across Defence, Federal Government and critical infrastructure.

More free templates