Internal Audit

Internal audit process required by ISO 27001 clause 9.2

An internal audit is the check you run on your own management system, before an external auditor runs theirs. ISO 27001 clause 9.2 requires it.

  • Glossary
  • ISO 27001

The short answer

An internal audit tests whether your controls and processes are being followed in practice, using the same evidence-sampling approach an external auditor would use. It must be planned, objective and documented, and the person auditing cannot audit their own work. You need at least one completed internal audit before Stage 1, and a continuing programme after certification.

The one thing that makes it useless: treating it as a form-filling exercise. An internal audit that finds nothing is either a perfect organisation or, far more likely, an audit that did not look.

What clause 9.2 requires

RequirementWhat it means in practice
Planned intervalsA programme with dates, not an audit done whenever someone remembers
Defined criteria and scopeEach audit states what it is testing against and which areas it covers
Objectivity and impartialityAuditors do not audit work they are responsible for
Results reported to managementFindings go to the people who can act on them, and into the management review
Documented evidenceThe programme, the plan, the findings and the corrective actions are all retained

Coverage is judged across the programme, not per audit. You can audit access control in March and supplier management in July, provided the plan shows the whole ISMS gets covered over the cycle.

How an internal audit runs

1. Plan Scope, criteria, dates, auditor 2. Gather Sample records, interview people 3. Report Findings graded and evidenced 4. Correct Root cause and owner assigned 5. Verify Closed with proof, not a tick Step 5 is the one most often skipped, and the one external auditors check hardest.

Who can perform it

Someone internal

Any competent employee, as long as they are independent of the area being audited. No formal qualification is required.

Cross-cover in a small team

Engineering audits HR processes, HR audits engineering. Objectivity comes from separation, not seniority.

An external consultant

Allowed, and common. It stays an internal audit because it is your programme. It cannot be your certification body.

Independence is the hard rule

The person who set up your access reviews cannot audit access reviews. In a ten-person company that takes planning, but it is not optional and an external auditor will ask who performed each audit.

Mistakes that become findings

MistakeWhy it fails
No findings at allReads as an audit that did not test anything, not as a clean system
Findings raised but never closedDirectly contradicts clause 10, and is trivially easy to spot
The ISMS owner audits their own ISMSBreaches the impartiality requirement in clause 9.2
A checklist with no evidence attachedNothing shows records were actually sampled, unlike proper evidence collection
Results never reach management reviewBreaks the required link between clause 9.2 and clause 9.3

How Osto supports the programme

An internal audit is only as easy as the evidence behind it. Osto keeps that evidence live: access and MFA records, endpoint state, cloud configuration, testing results and log data, all mapped to the relevant Annex A controls. Your internal auditor samples from the platform instead of chasing screenshots, and the gaps they find are the real ones rather than gaps in record keeping.

Free security assessment

Give your internal auditor something real to sample

Access records, endpoint state, cloud posture and test results, all mapped to Annex A and available without chasing screenshots.

Get a free security assessment Book a platform walkthrough

Evidence in one place · Annex A mapped · One platform, everything

Frequently asked questions

What is an internal audit in ISO 27001?

A planned, documented review of your own information security management system, testing whether controls and processes are being followed. Clause 9.2 requires it, and results feed the management review.

How often must an internal audit be done?

ISO 27001 says planned intervals rather than a fixed frequency. Most organisations run an annual programme that covers the whole ISMS across the year, sometimes split into several smaller audits.

Who can perform an internal audit?

Any competent person who is independent of the area being audited. No certification is required. Small teams often cross-cover between functions, or bring in an external consultant, who cannot be the certification body.

What is the difference between internal and external audit?

An internal audit is your own check, run by you or on your behalf, and produces no certificate. An external audit is conducted by an accredited certification body and determines whether certification is granted or maintained.

Do you need an internal audit before certification?

Yes. At least one full internal audit and one management review must be complete before Stage 1. Arriving without them is one of the most common reasons a certification audit is delayed.