Skip to main contentChat with us

ISO 27001:2022 Requirements  ·  Performance Evaluation

Clause 9.2
Internal audit

To give the organization an independent early-warning system — a structured way to find its own nonconformities and effectiveness gaps before the certification body, a customer, or an incident finds them first.

Last reviewed: June 12, 2026  ·  Authored by TÜV SÜD & BSI Certified Lead Auditors

What Clause 9.2 Requires

Clause 9.2 requires the organization to conduct internal audits at planned intervals, and it defines exactly what those audits must establish: whether the ISMS conforms both to the organization's own requirements for it and to the requirements of ISO 27001 itself, and whether the ISMS is effectively implemented and maintained. Two yardsticks, in other words — your rules and the standard's rules — plus a judgment on whether the system genuinely works in practice.

Behind the individual audits sits a programme requirement: you must plan, establish, implement, and maintain one or more audit programmes that set out audit frequency, methods, responsibilities, planning requirements, and reporting. The programme must take into account the importance of the processes being audited and the results of previous audits — riskier and previously problematic areas get audited harder and more often. For each individual audit you must define the audit criteria and scope, select auditors and conduct the audit in a way that preserves the objectivity and impartiality of the process (no one audits their own work), and ensure results reach the relevant management. Documented information must be retained as evidence of both the programme's implementation and the audit results.

Why This Clause Exists

To give the organization an independent early-warning system — a structured way to find its own nonconformities and effectiveness gaps before the certification body, a customer, or an incident finds them first.

What This Really Means

Internal audit is the dress rehearsal you run on yourself — except the standard treats it as far more than a rehearsal. It is the one mechanism in Clause 9 that systematically tests conformity: someone independent walks through your ISMS asking "does this match what the standard requires, does it match what your own policies say, and is it actually operating?" Certification bodies read the quality of your internal audit as a proxy for the seriousness of the whole management system.

Get the two-level structure clear. The audit programme is the multi-audit schedule — typically spanning a year, often the full three-year certification cycle — showing how the entire ISMS (all the clauses plus every Annex A control applicable in your SoA) gets covered over time, who audits what, by which method, and how results get reported. Each individual audit then has its own defined criteria (ISO 27001 plus your own policies and procedures) and scope (which departments, processes, sites, or controls this time). Full coverage does not mean auditing all 93 controls every quarter; it means a defensible plan where everything is touched across the cycle and high-importance or previously problematic areas come up more often.

Objectivity and impartiality is where small organizations sweat, because the rule is blunt: you cannot audit your own work. The person who built the access management process cannot be the one who audits it. Small organizations have two workable options: train staff from different functions to audit across team lines — an engineer audits HR security processes, an operations person audits engineering's — or buy internal audit as a service from an external provider (external in delivery, "internal" in function: it is still your first-party audit). Either way, document independence per assignment, because auditors check the assignment matrix against the org chart.

What certification auditors treat as the heart of 9.2: a real programme rather than a single annual checkbox, demonstrably competent and independent auditors, and findings that look like findings. The classic Stage 2 observation is an internal audit conducted two days before the certification visit, covering everything, finding nothing. That artifact tells the auditor more than any polished procedure — it says the audit was performed for the certificate, not for the organization.

Why It Matters

Internal audit is where the ISMS develops the capacity to criticize itself. Monitoring (9.1) tells you how controls perform; internal audit tells you whether the system conforms and holds together — and it is the cheapest place to discover that it does not. Every finding your internal auditor raises is a finding the certification body does not get to raise six weeks later, and a defect you fix on your own schedule instead of under a corrective-action deadline.

The certification stakes are as hard as they get. Certification bodies expect at least one full internal audit completed — with results and corrective actions visibly in motion — before Stage 2; its absence is a near-automatic major nonconformity, and at Stage 1 a missing or hollow audit programme is one of the most common reasons readiness gets questioned. The quality bar matters too: an audit with no findings, no evidence trail, or an auditor marking their own homework can itself be written up.

What failure looks like in practice:

  • Certification blocker – no completed internal audit before Stage 2 leaves you unable to demonstrate the ISMS checks itself; expect a major nonconformity or a postponed audit
  • Expensive discovery – gaps you could have found internally for the cost of a few audit days surface instead as certification findings or live incidents
  • Impartiality nonconformity – the ISMS implementer auditing their own implementation invalidates the results, however thorough the work papers look
  • Starved improvement loop – Clause 10.2 corrective action runs on findings; a toothless audit programme leaves the improvement engine with nothing real to process
  • Zero-findings red flag – an audit that finds nothing does not reassure an experienced certification auditor; it tells them where to dig harder

Regional Compliance Context

Indian organizations under sector regulation usually already carry mandated audit obligations — RBI master directions require periodic information-systems audits for regulated entities, and SEBI's CSCRF imposes cyber audit requirements on market intermediaries. Rather than running these as separate exercises, fold them into one audit programme with multiple criteria sets: a single well-planned audit cycle can serve the ISMS internal audit, the RBI/SEBI obligation, and management's own assurance needs, with each report mapped to the criteria it addresses. One programme, consistently executed, is also far easier to evidence than three overlapping ones.

Documented Information Required

Internal audit programme

Mandatory

The multi-period schedule showing how the full ISMS — clauses and applicable Annex A controls — is covered across the cycle, with frequency, methods, auditor responsibilities, and reporting lines. Good programmes visibly weight audit frequency by process importance and prior findings.

Internal audit results

Mandatory

The audit reports and supporting records for each audit: criteria and scope, auditor identity, evidence sampled, findings classified by severity, and proof of distribution to relevant management. Findings should trace forward into corrective actions.

Internal audit procedure

Recommended

How audits are planned, conducted, reported, and followed up — including finding classifications (major, minor, opportunity for improvement) and the rules that protect auditor independence. Not explicitly mandated, but the practical backbone of a repeatable programme.

Auditor competence and independence records

Recommended

Training certificates (internal auditor or lead auditor courses), CVs, and a per-audit assignment record confirming the auditor has no responsibility for the area audited. This is the evidence auditors ask for the moment independence looks thin.

See the full ISO 27001 mandatory documents checklist for every document and record the standard requires.

How to Implement Clause 9.2

1

Write the Internal Audit Procedure

Define how audits are planned, executed, reported, and followed up: methods (interviews, document review, sampling, technical verification), finding classifications, reporting templates, and the independence rule stated plainly — no one audits work they own or performed. This procedure is what makes audits repeatable when people change.

2

Build a Risk-Weighted Audit Programme

Map the full ISMS — Clauses 4–10 and every SoA-applicable Annex A control — across the audit cycle so everything is covered within it. Weight frequency by process importance and previous results: areas with prior nonconformities, recent incidents, or high inherent risk get audited sooner and more often. Document the weighting logic; auditors ask for it.

3

Solve the Auditor Problem: Competence Plus Independence

Pick your model early. Cross-functional: train two or more staff (a typical internal auditor course is about two days) and assign them across team lines so nobody audits their own area. External: engage an internal-audit-as-a-service provider, common and fully acceptable for small organizations. Record competence evidence and a per-assignment independence confirmation either way.

4

Plan Each Audit with Explicit Criteria and Scope

For every audit, issue a short audit plan: criteria (ISO 27001:2022 clauses and controls in scope, plus your own policies and procedures), scope (departments, processes, sites, systems), schedule, and auditees. Share it with the audited area in advance — internal audit is not a sting operation, and prepared auditees produce better evidence.

5

Conduct the Audit and Record Objective Evidence

Run an opening meeting, then gather evidence by sampling: pull actual access reviews, actual incident tickets, actual training records — not assurances that they exist. Record what was examined for every finding and conclusion, classify findings by severity, and close with a meeting where findings are confirmed with the auditee so there are no surprises in the report.

6

Report Results to Relevant Management

Issue a formal report covering scope, criteria, evidence sampled, findings, and conclusions on conformity and effectiveness. Distribute it to the managers who own the audited areas and to top management — audit results are a mandatory input to management review (9.3), so the report should arrive in a form that forum can act on.

7

Drive Findings into Corrective Action and Track Closure

Route every nonconformity into the Clause 10.2 process: root cause, correction, corrective action, and verification that the fix worked. Track finding aging, report overdue actions at management review, and feed closure status into the next cycle of the programme — repeat findings are the strongest signal an area needs more audit attention.

Audit Evidence

During Stage 1 and Stage 2 of your ISO 27001 certification audit, auditors will expect the following evidence to demonstrate conformity with Clause 9.2:

Documentation

  • Audit programme showing planned coverage of the full ISMS across the cycle, with frequency, methods, and responsibilities — and visible weighting by importance and prior results
  • Per-audit plans defining criteria and scope for each engagement
  • Audit reports with findings, severity classifications, and references to the objective evidence sampled
  • Auditor competence records and per-assignment independence confirmations
  • Evidence results reached management — report distribution records and management review minutes citing audit outcomes — and that findings entered the corrective action log

Interviews

  • The internal auditor on method, sampling approach, and their independence from the areas they audited
  • The ISMS manager on how the programme was constructed and how previous results changed its weighting
  • A member of management on what the last internal audit found and what was decided in response

Observations

  • Tracing one finding end to end: working papers to report to corrective action to closure verification
  • Checking auditor assignments against the org chart for self-audit — the person who operates a process appearing as its auditor
  • Inspecting dates: whether the programme ran as scheduled through the year or compressed into the weeks before the certification audit

Practitioner Insights

Surendra Pal Singh

The pattern certification auditors know by heart: a single internal audit dated days before Stage 2, full ISMS scope, zero nonconformities. What that tells me as an auditor is that the audit was a deliverable, not an inquiry — and it makes me sample harder everywhere else. Schedule your internal audit six to eight weeks before Stage 2 so corrective actions have visible closure, and treat real findings as an asset: an internal audit that raised genuine nonconformities and closed them is the single strongest exhibit you can put in front of a certification body.

Surendra Pal Singh · CISO, DPO, CISA, ISO 27001, 27701, 42001 Lead Auditor
Saundhi Chauhan

A forty-person company has no audit department, and that is fine — the standard never asks for one. Two workable patterns: send two people from different functions on a short internal auditor course and have them audit across each other's domains, or buy a few days of internal audit from an external provider each year. The implementation mistake I keep finding is checklists that restate the standard — "Is there an access control policy? Yes." Write checklist questions that demand evidence instead: "Show me the last three quarterly access reviews and who signed them off." The first kind of audit produces paper; the second produces findings.

Saundhi Chauhan · ISO 27001, 27701 Lead Auditor

Common Challenges & Solutions

Challenge

Nobody in the organization is both competent to audit and independent of the ISMS they would be auditing.

Solution

Use one of the two small-organization models: train staff from different functions to audit across team lines (an internal auditor course takes about two days), or engage an external provider to deliver the internal audit function. Both are fully acceptable to certification bodies. Whichever you choose, record competence evidence and confirm independence in writing for each assignment.

Challenge

The internal audit gets scheduled days before Stage 2, leaving no time to act on anything it finds.

Solution

Plan backwards from the certification date: internal audit complete at least 6–8 weeks before Stage 2, management review after the audit so its results are a real input, and a corrective-action window in between. The certification body wants to see the loop turn — finding, root cause, fix, verification — not a freshly printed report with the ink still wet.

Challenge

The programme is one annual everything-audit that exhausts the team and skims every topic.

Solution

Slice the programme into smaller process-based audits spread across the year — access management in Q1, supplier security in Q2, incident management and logging in Q3, and so on — with full coverage achieved across the cycle. Smaller scopes produce deeper sampling, findings that mean something, and a programme that demonstrably ran all year.

Challenge

Audits keep producing zero findings, or only cosmetic ones, and leadership cites that as proof all is well.

Solution

Rebuild the method: evidence-demanding checklists, defined sampling rules (pull N records per process, not one), and auditor training on grading severity honestly. Then reset the culture from the top — findings are the product of an audit, not an embarrassment to be negotiated away. A clean bill of health from a shallow audit is the most expensive false comfort in the ISMS.

Challenge

Findings get raised, reported, and then quietly die — the same issues reappear every audit cycle.

Solution

Route every finding into the Clause 10.2 workflow with a named owner, a due date, and a root-cause statement, and require verification of effectiveness before closure. Report finding aging at management review so overdue actions are a leadership problem, not an auditor's nagging. Feed repeat findings back into the programme as triggers for increased audit frequency on that area.

Frequently Asked Questions

How often does ISO 27001 require internal audits?
The standard says "at planned intervals" and leaves the frequency to your audit programme. In practice, certification bodies expect the full ISMS to be covered at least annually — either in one audit or, better, sliced into several smaller audits through the year — with higher-risk or previously problematic areas audited more often. Whatever interval you set, the programme must show you kept to it.
Can we do the internal audit ourselves, or do we have to hire someone?
You can absolutely do it internally, provided the auditors are competent and independent of the work they audit. The constraint is impartiality, not employment: the person who built or operates a process cannot audit it. Organizations too small to staff that separation routinely outsource the internal audit function — it remains an "internal" (first-party) audit even when an external provider delivers it.
Does our internal auditor need a formal certification?
No specific certificate is mandated — the requirement is demonstrable competence. In practice, a recognized internal auditor or lead auditor course (typically two to five days) is the standard evidence, paired with audit experience or supervised first audits. Keep the certificates and training records; auditor competence is one of the first things certification bodies sample under this clause.
Do we have to audit all 93 Annex A controls every year?
No. The requirement is a programme that covers your ISMS — including the controls applicable in your Statement of Applicability — across the audit cycle, with frequency weighted by importance and previous results. Many organizations cover everything annually because their scope is small; larger ones legitimately spread full coverage across two to three years, as long as the programme shows the plan and the rationale.
Can the consultant who implemented our ISMS perform our internal audit?
It is a direct conflict with the objectivity and impartiality requirement — they would be auditing their own work, and certification bodies challenge it. If you used implementation consultants, have the internal audit performed by different people: a separate firm, or a clearly separated team within the same firm with documented safeguards. The cleanest answer, and the one that never invites questions, is a different provider entirely.
What happens if our internal audit finds a major nonconformity right before certification?
That is the system working, not failing. Document the nonconformity, run root-cause analysis, implement correction and corrective action, and bring the evidence trail to Stage 2 — certification auditors respond far better to a found-and-fixed major than to an implausibly clean report. A nonconformity you found yourself demonstrates the audit programme has teeth; one the certification body finds first demonstrates it does not.

Written By Expert Auditors

Surendra Pal Singh
Surendra Pal Singh
Chief Information Security Officer & Data Protection Officer
CISODPOCISAMCSEITILISO 27001 Lead AuditorISO 27701 Lead AuditorISO 42001 Lead Auditor
Saundhi Chauhan
Saundhi Chauhan
Lead Auditor
ISO 27001 Lead AuditorISO 27701 Lead Auditor
Last reviewed: June 2026Content verified by certified lead auditors

Get in touch

Book a free consultation or send us your requirements. We respond within 24 hours.

Quick Call

Pick a time slot

Send Requirements

Get a custom quote in 24 hours

We're Online

⚠️ Business inquiries only. Personal email addresses will be rejected.

24hr Response
Free Consultation
No Obligations