What Clause 9.2 Requires
Clause 9.2 requires the organization to conduct internal audits at planned intervals, and it defines exactly what those audits must establish: whether the ISMS conforms both to the organization's own requirements for it and to the requirements of ISO 27001 itself, and whether the ISMS is effectively implemented and maintained. Two yardsticks, in other words — your rules and the standard's rules — plus a judgment on whether the system genuinely works in practice.
Behind the individual audits sits a programme requirement: you must plan, establish, implement, and maintain one or more audit programmes that set out audit frequency, methods, responsibilities, planning requirements, and reporting. The programme must take into account the importance of the processes being audited and the results of previous audits — riskier and previously problematic areas get audited harder and more often. For each individual audit you must define the audit criteria and scope, select auditors and conduct the audit in a way that preserves the objectivity and impartiality of the process (no one audits their own work), and ensure results reach the relevant management. Documented information must be retained as evidence of both the programme's implementation and the audit results.
Why This Clause Exists
To give the organization an independent early-warning system — a structured way to find its own nonconformities and effectiveness gaps before the certification body, a customer, or an incident finds them first.
What This Really Means
Internal audit is the dress rehearsal you run on yourself — except the standard treats it as far more than a rehearsal. It is the one mechanism in Clause 9 that systematically tests conformity: someone independent walks through your ISMS asking "does this match what the standard requires, does it match what your own policies say, and is it actually operating?" Certification bodies read the quality of your internal audit as a proxy for the seriousness of the whole management system.
Get the two-level structure clear. The audit programme is the multi-audit schedule — typically spanning a year, often the full three-year certification cycle — showing how the entire ISMS (all the clauses plus every Annex A control applicable in your SoA) gets covered over time, who audits what, by which method, and how results get reported. Each individual audit then has its own defined criteria (ISO 27001 plus your own policies and procedures) and scope (which departments, processes, sites, or controls this time). Full coverage does not mean auditing all 93 controls every quarter; it means a defensible plan where everything is touched across the cycle and high-importance or previously problematic areas come up more often.
Objectivity and impartiality is where small organizations sweat, because the rule is blunt: you cannot audit your own work. The person who built the access management process cannot be the one who audits it. Small organizations have two workable options: train staff from different functions to audit across team lines — an engineer audits HR security processes, an operations person audits engineering's — or buy internal audit as a service from an external provider (external in delivery, "internal" in function: it is still your first-party audit). Either way, document independence per assignment, because auditors check the assignment matrix against the org chart.
What certification auditors treat as the heart of 9.2: a real programme rather than a single annual checkbox, demonstrably competent and independent auditors, and findings that look like findings. The classic Stage 2 observation is an internal audit conducted two days before the certification visit, covering everything, finding nothing. That artifact tells the auditor more than any polished procedure — it says the audit was performed for the certificate, not for the organization.
Why It Matters
Internal audit is where the ISMS develops the capacity to criticize itself. Monitoring (9.1) tells you how controls perform; internal audit tells you whether the system conforms and holds together — and it is the cheapest place to discover that it does not. Every finding your internal auditor raises is a finding the certification body does not get to raise six weeks later, and a defect you fix on your own schedule instead of under a corrective-action deadline.
The certification stakes are as hard as they get. Certification bodies expect at least one full internal audit completed — with results and corrective actions visibly in motion — before Stage 2; its absence is a near-automatic major nonconformity, and at Stage 1 a missing or hollow audit programme is one of the most common reasons readiness gets questioned. The quality bar matters too: an audit with no findings, no evidence trail, or an auditor marking their own homework can itself be written up.
What failure looks like in practice:
- •Certification blocker – no completed internal audit before Stage 2 leaves you unable to demonstrate the ISMS checks itself; expect a major nonconformity or a postponed audit
- •Expensive discovery – gaps you could have found internally for the cost of a few audit days surface instead as certification findings or live incidents
- •Impartiality nonconformity – the ISMS implementer auditing their own implementation invalidates the results, however thorough the work papers look
- •Starved improvement loop – Clause 10.2 corrective action runs on findings; a toothless audit programme leaves the improvement engine with nothing real to process
- •Zero-findings red flag – an audit that finds nothing does not reassure an experienced certification auditor; it tells them where to dig harder
Regional Compliance Context
Indian organizations under sector regulation usually already carry mandated audit obligations — RBI master directions require periodic information-systems audits for regulated entities, and SEBI's CSCRF imposes cyber audit requirements on market intermediaries. Rather than running these as separate exercises, fold them into one audit programme with multiple criteria sets: a single well-planned audit cycle can serve the ISMS internal audit, the RBI/SEBI obligation, and management's own assurance needs, with each report mapped to the criteria it addresses. One programme, consistently executed, is also far easier to evidence than three overlapping ones.
Documented Information Required
Internal audit programme
MandatoryThe multi-period schedule showing how the full ISMS — clauses and applicable Annex A controls — is covered across the cycle, with frequency, methods, auditor responsibilities, and reporting lines. Good programmes visibly weight audit frequency by process importance and prior findings.
Internal audit results
MandatoryThe audit reports and supporting records for each audit: criteria and scope, auditor identity, evidence sampled, findings classified by severity, and proof of distribution to relevant management. Findings should trace forward into corrective actions.
Internal audit procedure
RecommendedHow audits are planned, conducted, reported, and followed up — including finding classifications (major, minor, opportunity for improvement) and the rules that protect auditor independence. Not explicitly mandated, but the practical backbone of a repeatable programme.
Auditor competence and independence records
RecommendedTraining certificates (internal auditor or lead auditor courses), CVs, and a per-audit assignment record confirming the auditor has no responsibility for the area audited. This is the evidence auditors ask for the moment independence looks thin.
See the full ISO 27001 mandatory documents checklist for every document and record the standard requires.
How to Implement Clause 9.2
Write the Internal Audit Procedure
Define how audits are planned, executed, reported, and followed up: methods (interviews, document review, sampling, technical verification), finding classifications, reporting templates, and the independence rule stated plainly — no one audits work they own or performed. This procedure is what makes audits repeatable when people change.
Build a Risk-Weighted Audit Programme
Map the full ISMS — Clauses 4–10 and every SoA-applicable Annex A control — across the audit cycle so everything is covered within it. Weight frequency by process importance and previous results: areas with prior nonconformities, recent incidents, or high inherent risk get audited sooner and more often. Document the weighting logic; auditors ask for it.
Solve the Auditor Problem: Competence Plus Independence
Pick your model early. Cross-functional: train two or more staff (a typical internal auditor course is about two days) and assign them across team lines so nobody audits their own area. External: engage an internal-audit-as-a-service provider, common and fully acceptable for small organizations. Record competence evidence and a per-assignment independence confirmation either way.
Plan Each Audit with Explicit Criteria and Scope
For every audit, issue a short audit plan: criteria (ISO 27001:2022 clauses and controls in scope, plus your own policies and procedures), scope (departments, processes, sites, systems), schedule, and auditees. Share it with the audited area in advance — internal audit is not a sting operation, and prepared auditees produce better evidence.
Conduct the Audit and Record Objective Evidence
Run an opening meeting, then gather evidence by sampling: pull actual access reviews, actual incident tickets, actual training records — not assurances that they exist. Record what was examined for every finding and conclusion, classify findings by severity, and close with a meeting where findings are confirmed with the auditee so there are no surprises in the report.
Report Results to Relevant Management
Issue a formal report covering scope, criteria, evidence sampled, findings, and conclusions on conformity and effectiveness. Distribute it to the managers who own the audited areas and to top management — audit results are a mandatory input to management review (9.3), so the report should arrive in a form that forum can act on.
Drive Findings into Corrective Action and Track Closure
Route every nonconformity into the Clause 10.2 process: root cause, correction, corrective action, and verification that the fix worked. Track finding aging, report overdue actions at management review, and feed closure status into the next cycle of the programme — repeat findings are the strongest signal an area needs more audit attention.
Audit Evidence
During Stage 1 and Stage 2 of your ISO 27001 certification audit, auditors will expect the following evidence to demonstrate conformity with Clause 9.2:
Documentation
- Audit programme showing planned coverage of the full ISMS across the cycle, with frequency, methods, and responsibilities — and visible weighting by importance and prior results
- Per-audit plans defining criteria and scope for each engagement
- Audit reports with findings, severity classifications, and references to the objective evidence sampled
- Auditor competence records and per-assignment independence confirmations
- Evidence results reached management — report distribution records and management review minutes citing audit outcomes — and that findings entered the corrective action log
Interviews
- The internal auditor on method, sampling approach, and their independence from the areas they audited
- The ISMS manager on how the programme was constructed and how previous results changed its weighting
- A member of management on what the last internal audit found and what was decided in response
Observations
- Tracing one finding end to end: working papers to report to corrective action to closure verification
- Checking auditor assignments against the org chart for self-audit — the person who operates a process appearing as its auditor
- Inspecting dates: whether the programme ran as scheduled through the year or compressed into the weeks before the certification audit
Practitioner Insights

The pattern certification auditors know by heart: a single internal audit dated days before Stage 2, full ISMS scope, zero nonconformities. What that tells me as an auditor is that the audit was a deliverable, not an inquiry — and it makes me sample harder everywhere else. Schedule your internal audit six to eight weeks before Stage 2 so corrective actions have visible closure, and treat real findings as an asset: an internal audit that raised genuine nonconformities and closed them is the single strongest exhibit you can put in front of a certification body.

A forty-person company has no audit department, and that is fine — the standard never asks for one. Two workable patterns: send two people from different functions on a short internal auditor course and have them audit across each other's domains, or buy a few days of internal audit from an external provider each year. The implementation mistake I keep finding is checklists that restate the standard — "Is there an access control policy? Yes." Write checklist questions that demand evidence instead: "Show me the last three quarterly access reviews and who signed them off." The first kind of audit produces paper; the second produces findings.
Common Challenges & Solutions
Challenge
Nobody in the organization is both competent to audit and independent of the ISMS they would be auditing.
Solution
Use one of the two small-organization models: train staff from different functions to audit across team lines (an internal auditor course takes about two days), or engage an external provider to deliver the internal audit function. Both are fully acceptable to certification bodies. Whichever you choose, record competence evidence and confirm independence in writing for each assignment.
Challenge
The internal audit gets scheduled days before Stage 2, leaving no time to act on anything it finds.
Solution
Plan backwards from the certification date: internal audit complete at least 6–8 weeks before Stage 2, management review after the audit so its results are a real input, and a corrective-action window in between. The certification body wants to see the loop turn — finding, root cause, fix, verification — not a freshly printed report with the ink still wet.
Challenge
The programme is one annual everything-audit that exhausts the team and skims every topic.
Solution
Slice the programme into smaller process-based audits spread across the year — access management in Q1, supplier security in Q2, incident management and logging in Q3, and so on — with full coverage achieved across the cycle. Smaller scopes produce deeper sampling, findings that mean something, and a programme that demonstrably ran all year.
Challenge
Audits keep producing zero findings, or only cosmetic ones, and leadership cites that as proof all is well.
Solution
Rebuild the method: evidence-demanding checklists, defined sampling rules (pull N records per process, not one), and auditor training on grading severity honestly. Then reset the culture from the top — findings are the product of an audit, not an embarrassment to be negotiated away. A clean bill of health from a shallow audit is the most expensive false comfort in the ISMS.
Challenge
Findings get raised, reported, and then quietly die — the same issues reappear every audit cycle.
Solution
Route every finding into the Clause 10.2 workflow with a named owner, a due date, and a root-cause statement, and require verification of effectiveness before closure. Report finding aging at management review so overdue actions are a leadership problem, not an auditor's nagging. Feed repeat findings back into the programme as triggers for increased audit frequency on that area.