ISO 27001 internal audit, a startup’s guide: the mandatory self-check that catches problems before the certification body does, and how to run it without a big team.
TL;DR
An internal audit is a mandatory ISO 27001 requirement under Clause 9. It is your own review of whether the ISMS actually works, run before the external certification body arrives, so you can fix problems on your own terms.
It must be objective: the person auditing a process should not be the one who runs it. For a startup that can mean a different team member or an external assessor. Findings feed a management review and corrective action.
On this page
ISO 27001 internal audit: what it is and why it is required
An internal audit is your organisation’s own assessment of whether the ISMS is working as intended, conducted before the external audit. ISO 27001 makes it mandatory under Clause 9, because the standard treats self-checking as a core part of a living management system. Done well, it is the dress rehearsal that turns the certification audit into a formality.
Who can run an internal audit
The one firm rule is objectivity: the person auditing a process must not be the person responsible for running it. Beyond that, ISO 27001 does not require a certified professional. For a lean team, there are two practical options.
The five-step cycle
A sound internal audit follows a clear sequence, and it is repeatable each year.
What auditors expect to see
When the certification body arrives, they will check that your internal audit was real and acted upon. They look for these.
- An audit plan and scope. Evidence you planned what to review, not just glanced over things.
- Documented findings. A record of what passed, what did not, and the evidence behind each.
- Corrective action. Proof that findings led to fixes at the root cause, not quick patches.
- A management review. Evidence leadership saw the results and made decisions on them.
Mistakes to avoid
- Auditing your own work. It breaks the objectivity requirement and auditors will flag it.
- Treating it as a formality. A rubber-stamp internal audit that finds nothing looks less credible, not more.
- Not closing findings. An open finding with no corrective action is worse than none at all.
- Skipping the management review. Clause 9 expects leadership to engage with the results.
The lean-team path to a smooth internal audit
Much of an internal audit is checking whether controls are operating and whether there is evidence to prove it. That is slow and painful when the answer lives across scattered tools and you have to chase each one down before you can even assess it.
Make your internal audit a review, not a scramble.
Osto is the one-stop cybersecurity and compliance platform built for fast-moving startups. Keep controls and their evidence in one place, so your internal audit confirms what is already there. No security team required.
Frequently asked questions
Is an internal audit mandatory for ISO 27001?
Yes. Clause 9 of ISO 27001 requires internal audits of the ISMS at planned intervals. They are a core part of the standard’s management-system requirements, and the certification body will check that you conducted and acted on them.
Who can perform an ISO 27001 internal audit?
Anyone objective enough that they are not auditing their own work. It does not require a certified professional. A startup can use an independent team member or bring in an external consultant to provide the necessary objectivity.
What is the difference between an internal audit and the certification audit?
The internal audit is your own self-assessment, run before certification, to catch and fix gaps. The certification audit is conducted by an external accredited body and determines whether you earn the certificate.
How often should internal audits happen?
At planned intervals, typically at least annually, and covering the whole ISMS over time. Many organisations audit different parts across the year so the full system is reviewed within each certification cycle.
What happens to internal audit findings?
They are documented, addressed through corrective action that fixes the root cause, and reported to leadership in a management review. The certification body looks for evidence that findings were genuinely closed, not just recorded.

