What Clause 9.2 actually requires, who is allowed to be the auditor when your whole company is twelve people, and a checklist you can run this week.
An ISO 27001 internal audit is a formal check of your own information security management system against ISO/IEC 27001:2022 and against your own documented rules. Clause 9.2 makes it mandatory, before certification and at planned intervals afterwards. To pass, an ISO 27001 internal audit needs five things: a written audit programme, a defined scope and criteria per audit, an auditor who did not build the thing being audited, findings recorded and graded, and a report that reaches management. For a small team the audit takes two to four days.
Clause 9.2 of ISO/IEC 27001:2022 reads best as a list of deliverables. Clause 9.2.1 says you must audit at planned intervals to confirm the ISMS conforms to your own requirements and to the standard, and is effectively implemented. Clause 9.2.2 says how to run the programme. Note what Clause 9.2 does not say: it names no frequency, requires no external or certified auditor, and does not ask you to audit every control every year. The standard is maintained by ISO/IEC JTC 1/SC 27.
| Clause 9.2.2 requirement | What satisfies it | Where it lives |
|---|---|---|
| An audit programme covering frequency, methods, responsibilities, planning and reporting | One page naming each audit, its quarter, scope and auditor | Internal audit programme |
| Defined audit criteria and scope for each audit | A plan stating the clauses and Annex A controls in scope | Audit plan |
| Auditors selected to ensure objectivity and impartiality | A named auditor with no operational responsibility for the area | Audit plan and competence record |
| Results reported to relevant management | A report issued to the ISMS owner and tabled at management review | Report and review minutes |
| Documented information retained as evidence | Programme, plans, working papers, findings and closure evidence | Your evidence repository |
Certification bodies expect the full scope of your ISMS covered across the three year certification cycle, and at least one complete internal audit before your stage 2 audit.
ISO 27001 requires objectivity and impartiality, which in practice means one rule: an auditor must not audit their own work. Nobody audits a process they own, a system they administer, or a document they wrote. Nothing in ISO/IEC 27001:2022 requires the internal auditor to be external, to hold a lead auditor certificate, or to have attended a course.
In a company of twelve people the workable options are a colleague from another function auditing the ISMS, a peer swap with a company at a similar stage, a contractor engaged for two or three days, or a non executive with the right background. The combination that fails is the one companies most often try, where the person who wrote the policies, built the controls and holds the risk register also signs the audit report. A certification auditor spots that in ten minutes, because the report finds almost nothing.
A useful ISO 27001 internal audit checklist is organised by what you sample, not by what you read. Reading the policy proves the policy exists. Sampling three leavers and checking their access was revoked proves the control worked. The checklist below covers a full scope audit of a small ISMS, in sections you can run across the year.
| Audit area | What to sample | Evidence that closes it |
|---|---|---|
| Clauses 4 to 6 | Scope statement, interested parties, security objectives | Objectives with measured values, not aspirations |
| Risk assessment and treatment | Three risks at random, traced to treatment and controls | Dated assessment, treatment plan, residual risk accepted by a named owner |
| Statement of Applicability | Five Annex A controls, including one you excluded | A justification per control saying why, not just applicable or not |
| Access control | Three joiners, three leavers, plus the last access review | Access granted on approval and removed on exit, with dates |
| Suppliers and cloud services | Your three most critical suppliers | Due diligence record, contract security terms, a review date that has passed |
| Incident management | Every incident in the period, or the record showing none | Log with detection, response, closure and lessons learned |
| Backup and continuity | The most recent restore test | Dated result showing what was restored and whether it worked |
| Change and vulnerability management | Five changes and the current vulnerability report | Approvals, and remediation inside your stated timeframes |
| Awareness and competence | Everyone who joined in the period | Training records with dates, matched to the joiner list |
| Clauses 7 to 10 | Management review inputs and outputs, previous corrective actions | Minutes covering every required input, actions closed with evidence |
Two rows matter more than the rest. The Statement of Applicability is the document a certification auditor holds you to line by line, and the risk assessment is what everything else traces back to. If your audit has time for two areas only, audit those two.
The largest cost of an ISO 27001 internal audit is your own time, not a fee. Run in house with a colleague from another function, the cash cost is close to zero. The figures below are planning estimates for an ISMS covering roughly 5 to 50 people, not quoted prices, and sit separately from the certification body's fee.
| Cost item | Who pays | Planning estimate, September 2026 |
|---|---|---|
| Audit programme and first audit plan | Your team | Half a day once, then reused |
| A first full scope internal audit | Your team | 2 to 4 days of auditor time, plus half a day per area owner |
| Report writing and grading findings | Your team | Half a day to one day |
| Fixing the nonconformities found | Your team | Variable, budget one to two weeks |
| External consultant to audit instead | You, optional | Quoted per day, varies widely by market, get two quotes |
| Internal auditor training course | You, optional | Vendor priced. Not required by Clause 9.2 |
| Tool holding the controls, evidence and audit trail | You | CertAssist is US$225 per month on the launch price, normally US$375 per month, or US$3,999 per year |
| The certification audit | Certification body | Separate cost, quoted by the body |
For what the certificate costs beyond the internal audit, see the CertAssist guide to ISO 27001 certification cost.
Grading is where internal audits go soft, and a soft internal audit is worse than none, because it tells your certification body that your audit programme does not work. ISO 27001 does not define the grades. The grading below is the convention certification bodies apply.
| Grade | What it means | Effect at certification |
|---|---|---|
| Major nonconformity | A requirement is not implemented, or the failure is so widespread the ISMS cannot be relied on | Certification withheld until corrected and verified |
| Minor nonconformity | A single lapse against a requirement otherwise in place, such as one leaver removed late | Certificate can still issue, with a corrective action plan |
| Observation | Conformant today, heading towards a problem | No action required, but repeats become findings |
| Opportunity for improvement | A suggestion, with no requirement breached | None. Do not use it to soften a real nonconformity |
Every nonconformity needs a root cause, a correction, a corrective action and a closure date. Correction fixes the instance, corrective action fixes the reason. An audit that closes ten findings by fixing ten instances raises the same ten next year.
An ISO 27001 internal audit report has no prescribed format. Keep it to a few pages covering the scope and criteria, the dates, the auditor and why they were impartial, the records examined, what was sampled and how many items, the findings with grades, and an explicit conclusion on whether the ISMS conforms and is effectively implemented. That conclusion is what Clause 9.2.1 asks for, so write it. The common weakness is a report listing what was reviewed but never what was sampled. "Reviewed the access control policy" is not evidence of an audit. "Sampled six accounts against the approved access list, two discrepancies found" is. ISO 19011, the guidelines for auditing management systems, comes from ISO/TC 176/SC 3.
At certification, the internal audit is itself an audited area. The certification auditor asks for the programme and checks it covers the whole ISMS across the cycle, tests the auditor's independence, reads the report to confirm findings were graded and closed with evidence, and checks the results reached management review. They also look for a plausible balance of findings: a first internal audit raising zero nonconformities reads as a sign the audit was not real. The CertAssist guide on what auditors really look for in your evidence sets out the same standard of proof.
Bring in an external auditor if your scope includes a regulated activity you have no internal expertise in, if a previous certification audit raised a major nonconformity against Clause 9.2 itself, if the ISMS is run by one person with no impartial colleague available, or if a customer has contractually specified an independent internal audit.
CertAssist is also not right for everyone. CertAssist has no integrations by design, so it does not connect to your cloud, identity provider or code repository and will not collect evidence automatically. If continuous monitoring across hundreds of assets saves you more than it costs, a platform built around integrations fits better. CertAssist includes an ISO 27001 Internal Audit framework alongside ISO 27001:2022, so you can record conformity, raise findings and track them to closure where your controls already sit. No tool replaces the certification body, and no tool conducts your internal audit for you.
An ISO 27001 internal audit is an examination of your own information security management system against ISO/IEC 27001:2022 and your own documented policies, carried out by someone impartial. Clause 9.2 requires it. Its purpose is to confirm the ISMS conforms and is effectively implemented, and to raise nonconformities before a certification body finds them.
Anyone competent and impartial, including your own staff. ISO 27001 requires only that auditors are selected to ensure objectivity and impartiality, which means nobody audits their own work. In a small organisation that usually means a colleague from another function, a peer swap with another company, or a contractor for two or three days.
ISO 27001 requires internal audits at planned intervals and names no frequency. Certification bodies expect at least one audit covering the full ISMS scope before your stage 2 certification audit, then continued audits so the whole scope is covered across the three year cycle. Most small organisations run one full audit a year, or four quarterly ones.
An ISO 27001 internal auditor audits your own ISMS on your organisation's behalf and needs no formal certificate. A lead auditor is trained to a recognised course and, working for a certification body, leads the audit team and can recommend certification. Internal auditing is a role you can fill in house, provided the person does not audit their own work.
CertAssist lays out every ISO 27001 control and the ISO 27001 Internal Audit framework side by side, with editable policy and evidence templates and read-only auditor access. CertAssist has no integrations and no system access, and costs US$225 a month.
See pricing FrameworksFlat US$225 a month launch price (normally US$375), or US$3,999 a year (12 months for the price of 11). All prices in USD.