An internal audit is the check you run on your own management system, before an external auditor runs theirs. ISO 27001 clause 9.2 requires it.
The short answer
An internal audit tests whether your controls and processes are being followed in practice, using the same evidence-sampling approach an external auditor would use. It must be planned, objective and documented, and the person auditing cannot audit their own work. You need at least one completed internal audit before Stage 1, and a continuing programme after certification.
The one thing that makes it useless: treating it as a form-filling exercise. An internal audit that finds nothing is either a perfect organisation or, far more likely, an audit that did not look.
On this page
What clause 9.2 requires
| Requirement | What it means in practice |
|---|---|
| Planned intervals | A programme with dates, not an audit done whenever someone remembers |
| Defined criteria and scope | Each audit states what it is testing against and which areas it covers |
| Objectivity and impartiality | Auditors do not audit work they are responsible for |
| Results reported to management | Findings go to the people who can act on them, and into the management review |
| Documented evidence | The programme, the plan, the findings and the corrective actions are all retained |
Coverage is judged across the programme, not per audit. You can audit access control in March and supplier management in July, provided the plan shows the whole ISMS gets covered over the cycle.
How an internal audit runs
Who can perform it
Someone internal
Any competent employee, as long as they are independent of the area being audited. No formal qualification is required.
Cross-cover in a small team
Engineering audits HR processes, HR audits engineering. Objectivity comes from separation, not seniority.
An external consultant
Allowed, and common. It stays an internal audit because it is your programme. It cannot be your certification body.
Independence is the hard rule
The person who set up your access reviews cannot audit access reviews. In a ten-person company that takes planning, but it is not optional and an external auditor will ask who performed each audit.
Mistakes that become findings
| Mistake | Why it fails |
|---|---|
| No findings at all | Reads as an audit that did not test anything, not as a clean system |
| Findings raised but never closed | Directly contradicts clause 10, and is trivially easy to spot |
| The ISMS owner audits their own ISMS | Breaches the impartiality requirement in clause 9.2 |
| A checklist with no evidence attached | Nothing shows records were actually sampled, unlike proper evidence collection |
| Results never reach management review | Breaks the required link between clause 9.2 and clause 9.3 |
How Osto supports the programme
An internal audit is only as easy as the evidence behind it. Osto keeps that evidence live: access and MFA records, endpoint state, cloud configuration, testing results and log data, all mapped to the relevant Annex A controls. Your internal auditor samples from the platform instead of chasing screenshots, and the gaps they find are the real ones rather than gaps in record keeping.
Free security assessment
Give your internal auditor something real to sample
Access records, endpoint state, cloud posture and test results, all mapped to Annex A and available without chasing screenshots.
Get a free security assessment Book a platform walkthroughEvidence in one place · Annex A mapped · One platform, everything
Frequently asked questions
What is an internal audit in ISO 27001?
A planned, documented review of your own information security management system, testing whether controls and processes are being followed. Clause 9.2 requires it, and results feed the management review.
How often must an internal audit be done?
ISO 27001 says planned intervals rather than a fixed frequency. Most organisations run an annual programme that covers the whole ISMS across the year, sometimes split into several smaller audits.
Who can perform an internal audit?
Any competent person who is independent of the area being audited. No certification is required. Small teams often cross-cover between functions, or bring in an external consultant, who cannot be the certification body.
What is the difference between internal and external audit?
An internal audit is your own check, run by you or on your behalf, and produces no certificate. An external audit is conducted by an accredited certification body and determines whether certification is granted or maintained.
Do you need an internal audit before certification?
Yes. At least one full internal audit and one management review must be complete before Stage 1. Arriving without them is one of the most common reasons a certification audit is delayed.

