ISO 27001 Clause 9.2 Internal Audit requires organisations to run planned audits to check their security management system. Documented review programmes ensure controls satisfy ISO standards, meet company rules, and remain effective across all business operations.
Table of contents
Key Takeaways
- Conduct planned internal audits: Run internal audits at planned intervals to confirm security controls meet ISO 27001 requirements.
- Store audit rules centrally: Keep audit programmes, schedules, checklists, and reports in a central document repository.
- Maintain auditor objectivity: Select impartial, trained auditors who do not audit their own direct work or daily processes.
- Base schedules on risk: Plan audit frequency based on process criticality, past failure trends, and recent operational changes.
- Define clear audit criteria: Establish explicit scopes, objectives, and test methods for every scheduled internal review.
- Report findings to management: Deliver detailed audit reports with nonconformities and improvement areas to relevant managers.
- Track corrective actions: Ensure process owners fix identified control gaps without delay to prevent repeat failures.
- Retain documented proof: Maintain full audit records and evidence files to prove programme execution during certification reviews.
How to Implement ISO 27001 Clause 9.2
- Draft an internal audit procedure: Write clear guidelines for planning, conducting, and reporting audits, storing them in your central repository.
- Build an annual audit schedule: Create a calendar schedule ensuring all management system clauses and Annex A controls get reviewed within the cycle.
- Train competent auditors: Ensure selected internal staff or outsourced assessors complete formal training on audit methods and standards.
- Prepare tailored audit checklists: Develop standard question sets covering policies, operational evidence, and staff interviews for each area.
- Gather representative samples: Review actual operational records, tickets, logs, and user accounts to verify practical compliance.
- Hold opening and closing meetings: Agree on audit scopes at kickoff and present initial findings to process owners before leaving.
- Publish formal audit reports: Detail positive findings, minor gaps, major nonconformities, and improvement opportunities clearly.
- Log findings in an action register: Record all audit gaps in a central corrective action tracker with assigned owners and due dates.
- Feed results into management reviews: Summarise internal audit outcomes for executive leadership evaluation during planned reviews.
When you’re ready to bring compliance into one place

How to Audit ISO 27001 Clause 9.2
- Review internal audit policies: Inspect written procedures to verify mandatory rules govern audit planning, execution, and reporting.
- Verify annual programme coverage: Check the audit schedule to confirm all system clauses and relevant security controls were assessed.
- Evaluate auditor independence: Check auditor assignments against organisational charts to ensure no one audited their own functional duties.
- Inspect completed audit reports: Sample past internal audit files to verify thorough testing, clear evidence notes, and balanced reporting.
- Verify auditor qualifications: Check training records and certifications to ensure internal auditors possess adequate technical competence.
- Track nonconformity follow-through: Reconcile internal audit findings against corrective action registers to verify timely resolution.
- Interview internal auditors: Speak with audit team members to assess how they gather samples, handle objections, and record evidence.
- Confirm management review inputs: Verify that leadership received and reviewed complete audit summaries during formal management meetings.
Audit Evidence Checklist
- Internal audit procedure: Maintain a documented audit procedure with complete revision history in your central repository.
- Annual internal audit schedule: Supply an approved timetable showing planned review dates for all clauses, teams, and controls.
- Completed audit reports: Provide signed reports containing scopes, findings, evidence notes, and agreed action plans.
- Auditor competency certificates: Supply training logs and qualification certificates for internal auditors or outsourced providers.
- Completed audit checklists: Maintain detailed worksheets and interview notes recorded during internal audit sessions.
- Corrective action logs: Provide active tracking sheets showing root causes, remediation tasks, and closure proofs for audit gaps.
- Executive briefing minutes: Supply management review records proving leaders reviewed internal audit performance.
What to Teach Employees
- View audits as improvement tools: Teach workers that audits help protect the business and find process gaps safely.
- Provide honest evidence: Instruct staff to answer auditor questions openly and share real operational records without fear.
- Never hide mistakes: Reassure employees that identifying weak controls helps management fix underlying systemic issues.
- Understand your policies: Educate staff on the specific security guidelines and runbooks that apply to their daily roles.
- Act on audit findings fast: Instruct action owners to complete assigned audit remediation tasks before agreed deadlines.
- Know how to verify auditors: Remind workers to verify internal auditor identities before sharing sensitive files or system access.
Common Implementation Challenges
- Auditor bias and conflict of interest: Small teams assign staff to audit their own work. Cross-train staff across different departments to audit each other.
- Rushing audits before external visits: Cramming all audits into one week causes shallow checks. Spread reviews evenly across a twelve-month calendar.
- Failing to sample real evidence: Auditors rely on verbal answers without inspecting proof. Mandate document and log sampling in all checklists.
- Unresolved audit findings: Gaps sit in registers for months without remediation. Enforce strict closure deadlines backed by management reviews.
- Ignoring Annex A controls: Audits check core clauses but skip technical safeguards. Ensure checklists cover all applicable Annex A security controls.
- Inadequate auditor training: Untrained staff miss technical gaps or create friction. Provide formal training on ISO auditing principles.
How to Measure Effectiveness (KPIs)
- Audit schedule completion rate: Track the percentage of scheduled internal audits completed on time within the annual programme.
- Control coverage percentage: Measure the proportion of mandatory ISO clauses and Annex A controls audited over the year.
- Audit finding closure speed: Measure the average number of days taken to resolve nonconformities raised during internal audits.
- Repeat finding rate: Track the percentage of internal audit gaps identical to findings raised in previous audit cycles.
- External audit finding correlation: Track how many external audit gaps were caught in advance by internal audit reviews.
- Auditor training compliance: Track the percentage of active internal auditors with current, verified audit training credentials.
Related ISO 27001 Controls
ISO 27001 Clause 9.2 connects to several other ISO 27001 requirements:
- ISO 27001 Clause 9.3 Management Review: This control requires management to evaluate the results of internal audits to determine ISMS suitability.
- ISO 27001 Clause 10.1 Continual Improvement: Internal audits provide the vital data needed to identify opportunities for system growth.
- ISO 27001 Clause 10.2 Nonconformity and Corrective Action: This clause governs the formal process for fixing the gaps identified during an internal audit.
