Audit

ISO 27001 internal audit: how to run one that passes

7 September 2026 · 9 min read · CertAssist

What Clause 9.2 actually requires, who is allowed to be the auditor when your whole company is twelve people, and a checklist you can run this week.

An ISO 27001 internal audit is a formal check of your own information security management system against ISO/IEC 27001:2022 and against your own documented rules. Clause 9.2 makes it mandatory, before certification and at planned intervals afterwards. To pass, an ISO 27001 internal audit needs five things: a written audit programme, a defined scope and criteria per audit, an auditor who did not build the thing being audited, findings recorded and graded, and a report that reaches management. For a small team the audit takes two to four days.

Table mapping the five requirements of ISO 27001 Clause 9.2.2 to what satisfies each one: an audit programme document, defined scope and criteria per audit, an impartial auditor who does not audit their own work, results reported to relevant management, and retained records of the programme and its results

What does ISO 27001 Clause 9.2 actually require?

Clause 9.2 of ISO/IEC 27001:2022 reads best as a list of deliverables. Clause 9.2.1 says you must audit at planned intervals to confirm the ISMS conforms to your own requirements and to the standard, and is effectively implemented. Clause 9.2.2 says how to run the programme. Note what Clause 9.2 does not say: it names no frequency, requires no external or certified auditor, and does not ask you to audit every control every year. The standard is maintained by ISO/IEC JTC 1/SC 27.

Clause 9.2.2 requirementWhat satisfies itWhere it lives
An audit programme covering frequency, methods, responsibilities, planning and reportingOne page naming each audit, its quarter, scope and auditorInternal audit programme
Defined audit criteria and scope for each auditA plan stating the clauses and Annex A controls in scopeAudit plan
Auditors selected to ensure objectivity and impartialityA named auditor with no operational responsibility for the areaAudit plan and competence record
Results reported to relevant managementA report issued to the ISMS owner and tabled at management reviewReport and review minutes
Documented information retained as evidenceProgramme, plans, working papers, findings and closure evidenceYour evidence repository

Certification bodies expect the full scope of your ISMS covered across the three year certification cycle, and at least one complete internal audit before your stage 2 audit.

Who can be an ISO 27001 internal auditor in a small team?

ISO 27001 requires objectivity and impartiality, which in practice means one rule: an auditor must not audit their own work. Nobody audits a process they own, a system they administer, or a document they wrote. Nothing in ISO/IEC 27001:2022 requires the internal auditor to be external, to hold a lead auditor certificate, or to have attended a course.

In a company of twelve people the workable options are a colleague from another function auditing the ISMS, a peer swap with a company at a similar stage, a contractor engaged for two or three days, or a non executive with the right background. The combination that fails is the one companies most often try, where the person who wrote the policies, built the controls and holds the risk register also signs the audit report. A certification auditor spots that in ten minutes, because the report finds almost nothing.

Twelve month ISO 27001 internal audit programme for a small team showing four quarterly audits: Q1 covering clauses 4 to 6 and the Statement of Applicability over one day, Q2 covering access control and cryptography controls over one day, Q3 covering operations, supplier and incident controls over one and a half days, and Q4 covering clauses 7 to 10 and management review over one day

What should an ISO 27001 internal audit checklist cover?

A useful ISO 27001 internal audit checklist is organised by what you sample, not by what you read. Reading the policy proves the policy exists. Sampling three leavers and checking their access was revoked proves the control worked. The checklist below covers a full scope audit of a small ISMS, in sections you can run across the year.

Audit areaWhat to sampleEvidence that closes it
Clauses 4 to 6Scope statement, interested parties, security objectivesObjectives with measured values, not aspirations
Risk assessment and treatmentThree risks at random, traced to treatment and controlsDated assessment, treatment plan, residual risk accepted by a named owner
Statement of ApplicabilityFive Annex A controls, including one you excludedA justification per control saying why, not just applicable or not
Access controlThree joiners, three leavers, plus the last access reviewAccess granted on approval and removed on exit, with dates
Suppliers and cloud servicesYour three most critical suppliersDue diligence record, contract security terms, a review date that has passed
Incident managementEvery incident in the period, or the record showing noneLog with detection, response, closure and lessons learned
Backup and continuityThe most recent restore testDated result showing what was restored and whether it worked
Change and vulnerability managementFive changes and the current vulnerability reportApprovals, and remediation inside your stated timeframes
Awareness and competenceEveryone who joined in the periodTraining records with dates, matched to the joiner list
Clauses 7 to 10Management review inputs and outputs, previous corrective actionsMinutes covering every required input, actions closed with evidence

Two rows matter more than the rest. The Statement of Applicability is the document a certification auditor holds you to line by line, and the risk assessment is what everything else traces back to. If your audit has time for two areas only, audit those two.

How much does an ISO 27001 internal audit cost?

The largest cost of an ISO 27001 internal audit is your own time, not a fee. Run in house with a colleague from another function, the cash cost is close to zero. The figures below are planning estimates for an ISMS covering roughly 5 to 50 people, not quoted prices, and sit separately from the certification body's fee.

Cost itemWho paysPlanning estimate, September 2026
Audit programme and first audit planYour teamHalf a day once, then reused
A first full scope internal auditYour team2 to 4 days of auditor time, plus half a day per area owner
Report writing and grading findingsYour teamHalf a day to one day
Fixing the nonconformities foundYour teamVariable, budget one to two weeks
External consultant to audit insteadYou, optionalQuoted per day, varies widely by market, get two quotes
Internal auditor training courseYou, optionalVendor priced. Not required by Clause 9.2
Tool holding the controls, evidence and audit trailYouCertAssist is US$225 per month on the launch price, normally US$375 per month, or US$3,999 per year
The certification auditCertification bodySeparate cost, quoted by the body

For what the certificate costs beyond the internal audit, see the CertAssist guide to ISO 27001 certification cost.

What is the difference between a major and a minor nonconformity?

Grading is where internal audits go soft, and a soft internal audit is worse than none, because it tells your certification body that your audit programme does not work. ISO 27001 does not define the grades. The grading below is the convention certification bodies apply.

GradeWhat it meansEffect at certification
Major nonconformityA requirement is not implemented, or the failure is so widespread the ISMS cannot be relied onCertification withheld until corrected and verified
Minor nonconformityA single lapse against a requirement otherwise in place, such as one leaver removed lateCertificate can still issue, with a corrective action plan
ObservationConformant today, heading towards a problemNo action required, but repeats become findings
Opportunity for improvementA suggestion, with no requirement breachedNone. Do not use it to soften a real nonconformity

Every nonconformity needs a root cause, a correction, a corrective action and a closure date. Correction fixes the instance, corrective action fixes the reason. An audit that closes ten findings by fixing ten instances raises the same ten next year.

What goes in an ISO 27001 internal audit report?

An ISO 27001 internal audit report has no prescribed format. Keep it to a few pages covering the scope and criteria, the dates, the auditor and why they were impartial, the records examined, what was sampled and how many items, the findings with grades, and an explicit conclusion on whether the ISMS conforms and is effectively implemented. That conclusion is what Clause 9.2.1 asks for, so write it. The common weakness is a report listing what was reviewed but never what was sampled. "Reviewed the access control policy" is not evidence of an audit. "Sampled six accounts against the approved access list, two discrepancies found" is. ISO 19011, the guidelines for auditing management systems, comes from ISO/TC 176/SC 3.

What do certification auditors check about your internal audit?

At certification, the internal audit is itself an audited area. The certification auditor asks for the programme and checks it covers the whole ISMS across the cycle, tests the auditor's independence, reads the report to confirm findings were graded and closed with evidence, and checks the results reached management review. They also look for a plausible balance of findings: a first internal audit raising zero nonconformities reads as a sign the audit was not real. The CertAssist guide on what auditors really look for in your evidence sets out the same standard of proof.

When running your own ISO 27001 internal audit is the wrong call

Bring in an external auditor if your scope includes a regulated activity you have no internal expertise in, if a previous certification audit raised a major nonconformity against Clause 9.2 itself, if the ISMS is run by one person with no impartial colleague available, or if a customer has contractually specified an independent internal audit.

CertAssist is also not right for everyone. CertAssist has no integrations by design, so it does not connect to your cloud, identity provider or code repository and will not collect evidence automatically. If continuous monitoring across hundreds of assets saves you more than it costs, a platform built around integrations fits better. CertAssist includes an ISO 27001 Internal Audit framework alongside ISO 27001:2022, so you can record conformity, raise findings and track them to closure where your controls already sit. No tool replaces the certification body, and no tool conducts your internal audit for you.

Frequently asked questions

What is an ISO 27001 internal audit?

An ISO 27001 internal audit is an examination of your own information security management system against ISO/IEC 27001:2022 and your own documented policies, carried out by someone impartial. Clause 9.2 requires it. Its purpose is to confirm the ISMS conforms and is effectively implemented, and to raise nonconformities before a certification body finds them.

Who can be an ISO 27001 internal auditor?

Anyone competent and impartial, including your own staff. ISO 27001 requires only that auditors are selected to ensure objectivity and impartiality, which means nobody audits their own work. In a small organisation that usually means a colleague from another function, a peer swap with another company, or a contractor for two or three days.

How often are ISO 27001 internal audits required?

ISO 27001 requires internal audits at planned intervals and names no frequency. Certification bodies expect at least one audit covering the full ISMS scope before your stage 2 certification audit, then continued audits so the whole scope is covered across the three year cycle. Most small organisations run one full audit a year, or four quarterly ones.

What is the difference between an ISO 27001 internal auditor and a lead auditor?

An ISO 27001 internal auditor audits your own ISMS on your organisation's behalf and needs no formal certificate. A lead auditor is trained to a recognised course and, working for a certification body, leads the audit team and can recommend certification. Internal auditing is a role you can fill in house, provided the person does not audit their own work.

Run the internal audit where your controls already live

CertAssist lays out every ISO 27001 control and the ISO 27001 Internal Audit framework side by side, with editable policy and evidence templates and read-only auditor access. CertAssist has no integrations and no system access, and costs US$225 a month.

See pricing Frameworks

← Back to the blog

Powerful in its simplicity.

Flat US$225 a month launch price (normally US$375), or US$3,999 a year (12 months for the price of 11). All prices in USD.