Building an ISO 27001 Internal Audit Programme

Clause 9.2 requires internal audits of the ISMS at planned intervals. Certification bodies rarely fail organisations for a weak finding — they fail them for a programme that cannot show planned, independent, complete coverage.

Plan a cycle, not a single audit

The programme should cover the whole ISMS across a defined cycle, usually annual or biennial, with higher-risk areas audited more often. Record when each area was last audited; that history is the first thing an external auditor asks for.

Define scope and criteria per audit

Each audit in the programme needs its own scope (which parts of the ISMS), criteria (the standard clauses, Annex A controls, and internal policies being audited against), and method. Vague scope is what produces audits that cannot demonstrate coverage.

Cover the clauses, not just Annex A

Annex A control testing is the visible part, but clauses 4–10 — context, leadership, planning, support, operation, performance evaluation, improvement — are equally auditable and commonly under-covered.

Protect auditor independence

Auditors must not audit their own work. In small teams that means documenting who audited what and, where independence is not achievable internally, using an external party for that area. Certification bodies check this.

Raise nonconformities with corrective action

A nonconformity needs the requirement breached, the evidence, a correction, a root cause analysis, and corrective action with an owner and date — then verification that the action worked. Closing without verification is itself a common audit failure.

Feed management review

Audit results are a required input to management review. The programme should produce a summary of audits performed, nonconformities raised, and corrective action status in a form the review can consume directly.

Keep reading

More internal audit guides