ISO 27001 Clause 9.2: Internal Audit

· 7 min read · Lyudmil Arkov

Clause 9.2 requires your organization to conduct internal audits at planned intervals to check whether the ISMS conforms to both your own requirements and the requirements of the standard, and whether it is effectively implemented and maintained. Internal audit is the honest mirror of your management system - the mechanism that finds problems before the certification body does. Done well, it turns the external audit into a confirmation rather than a discovery. The clause has two parts: 9.2.1 sets the objective, and 9.2.2 defines the programme that delivers it.

What the clause requires

ISO 27001:2022 Clause 9.2 splits into two sub-clauses.

9.2.1 General requires the organization to conduct internal audits at planned intervals to provide information on whether the ISMS:

  1. Conforms to the organization’s own requirements for its ISMS and to the requirements of the standard
  2. Is effectively implemented and maintained

9.2.2 Internal audit programme requires the organization to plan, establish, implement and maintain one or more audit programmes, including the frequency, methods, responsibilities, planning requirements and reporting. When establishing the programme, the organization must consider the importance of the processes concerned and the results of previous audits. The organization must also:

  • Define the audit criteria and scope for each audit
  • Select auditors and conduct audits in a way that ensures objectivity and the impartiality of the audit process
  • Ensure the results are reported to relevant management

Documented information must be retained as evidence of the implementation of the audit programme and the audit results.

Note the two-word test in 9.2.1: conformity and effectiveness. An auditor can confirm a policy exists (conformity) yet find that nobody follows it (not effective). Clause 9.2 asks for both.

How to implement internal audit

Build a risk-based audit programme, not a single annual event

A common misconception is that “internal audit” means one big audit before the certification visit. Clause 9.2.2 asks for a programme that considers the importance of processes and the results of previous audits. In practice that means auditing higher-risk or previously-weak areas more often, and spreading coverage so the whole ISMS is examined over a defined cycle - typically every 12 months for a certified organization.

A simple programme document records: the audit cycle, which areas are audited when, who audits them, the criteria and scope for each, and how results are reported. For a small company this can be a one-page schedule plus a short procedure.

Define criteria and scope for every audit

Each audit needs a defined scope (which parts of the ISMS, which sites, which processes) and criteria (what you are auditing against - specific clauses, policies, procedures, or Annex A controls). “Audit the ISMS” is too vague to execute. “Audit access control against A.5.15, A.5.18, and the access management policy, covering production systems” is auditable.

Protect objectivity and impartiality

Clause 9.2.2 requires auditors to be selected and audits conducted so the process is objective and impartial. The core rule: auditors should not audit their own work. In a large organization you rotate internal auditors across departments. In a small one where the same person runs and audits security, you have three defensible options:

  • Have a different qualified employee audit the security function
  • Use an external consultant to perform the internal audit
  • Cross-audit - the ISMS manager audits areas they do not operate, and someone else audits the ISMS function itself

Independence is about the audit of a given area, not about the whole company. Document how you achieved it.

Run the audit properly and grade findings

A workable audit cycle: plan (confirm scope, criteria, schedule) - conduct (interviews, document review, sampling evidence) - report (findings with evidence) - follow up (track actions to closure). Grade what you find consistently, for example:

  • Nonconformity - a requirement is not met (major if the ISMS is undermined, minor if isolated)
  • Observation / opportunity for improvement - conforms today but at risk, or could be done better

Every nonconformity from an internal audit feeds Clause 10.2 as a corrective action. This is expected and healthy - an internal audit that never finds anything is usually not looking hard enough.

Report results to relevant management

Findings must reach the people with authority to act, and the summary feeds into the management review under Clause 9.3, where audit results are a required input. Retain the audit plan, the reports, the evidence sampled, and the record of actions taken - this is the documented evidence 9.2 requires.

Connecting 9.2 to the rest of your ISMS

Clause 9.1 connection. Monitoring and measurement gives continuous quantitative signals; internal audit gives periodic in-depth examination. Audits often use 9.1 data to decide where to look.

Clause 9.3 connection. Management review consumes audit results as a defined input, and management decides on resources and actions arising from audit findings.

Clause 10.2 connection. Every nonconformity raised in an internal audit is handled through the nonconformity and corrective action process - root cause, correction, and verification of effectiveness.

Clause 5.3 connection. Roles and responsibilities must establish who owns the audit programme and who has the authority and independence to audit.

Annex A connection. Internal audits test whether the controls declared in your Statement of Applicability are implemented and effective, closing the loop between what you claim and what you do.

What auditors check

A documented, risk-based programme. Certification auditors want to see a planned programme that considers process importance and prior results - not a single audit improvised before their visit.

Full coverage over the cycle. They check that the whole ISMS, including applicable Annex A controls, is audited across the defined cycle, with higher-risk areas covered appropriately.

Genuine impartiality. Auditors probe whether internal auditors audited their own work. If the ISMS manager audited the ISMS they run, expect a finding unless you can show how independence was preserved.

Evidence, not assertion. They review actual internal audit reports, the evidence sampled, and whether findings are supported. An audit report with conclusions but no evidence trail is weak.

Findings that get closed. Certification auditors trace internal audit nonconformities through to corrective action and verified closure. Open findings from a year ago with no action is a serious signal.

Common mistakes to avoid

Auditing your own work. The single most common Clause 9.2 nonconformity. The person who runs security cannot provide an impartial audit of it. Arrange independence and document how.

One rushed audit before certification. A single pre-certification sweep does not satisfy “planned intervals” and a risk-based programme. Auditors can tell the difference between a live programme and a one-off.

Audits that never find anything. A report full of green with no findings suggests the audit was superficial. Real audits surface improvement opportunities and the occasional nonconformity.

Findings with no follow-up. Raising nonconformities and never closing them is worse than not finding them, because it documents a known gap you ignored. Track every finding to verified closure.

Vague scope and criteria. “We audited the ISMS” cannot be evaluated. Each audit needs explicit scope and criteria so results are meaningful and repeatable.

Treating internal audit as a formality. An audit done to tick a box produces box-ticking evidence. The value is in honest examination that makes the certification audit uneventful.

How 27kay can help

We run independent internal audits and help organizations build an audit programme that satisfies Clause 9.2 and genuinely strengthens the ISMS. Our ISO 27001 internal audit service provides the impartiality small teams struggle to achieve internally, with clear findings, evidence, and practical corrective actions. It is part of our wider ISO 27001 implementation work - and you can see how it fits the whole standard in our ISO 27001 knowledge hub.

Facing certification and unsure your internal audit will hold up? Get in touch - we will assess your programme or run the internal audit for you, so nothing surprises you in the external one.