ISO 27001 Internal Audit
In this guide, you will learn directly from ISO 27001 Lead Auditor with over 30 years industry experience, exactly how to do an ISO 27001 Internal Audit.
The same process is applied when you do an ISO 27001 Gap Analysis.
I have conducted hundreds of audits and taught consultants how to audit. Now, I’m giving you the exact templates, walkthroughs, and practical examples you need to do your own ISO 27001 Internal Audits.
I am Stuart Barker, the ISO 27001 Ninja and author of the Ultimate ISO 27001 Toolkit.
Table of contents
- ISO 27001 Internal Audit
- What is an ISO 27001 Internal Audit?
- Why do ISO 27001 Internal Audits?
- Who should conduct an ISO 27001 Internal Audit?
- The 3 Types of Internal Audit
- ISO 27001 Audit Toolkit
- The ISO 27001 Internal Audit Process Flow
- When do you do an ISO 27001 internal audit?
- How to conduct an ISO 27001 Internal Audit: The Information Security Managers Guide
- Conducting the internal audits
- Applicability of internal audit to Small Businesses, Tech Startups, and AI Companies
- Where do you need it?
- Which information security standards need Internal Audit?
- Audit differences between ISO 27001 and SOC 2
- About the author
What is an ISO 27001 Internal Audit?
ISO 27001 internal audit is the process of internally independently verifying the effectiveness of the information security management system and information security controls.
Why do ISO 27001 Internal Audits?
Internal audit is a requirement of the ISO 27001 standard and covered explicitly in ISO 27001 Clause 9.2 Internal Audit.
These audits are designed to help you improve the information security management system and ensure that it still meets the requirements of the ISO 27001 standard. It helps you spot weak spots in your security before a real problem happens. It’s like a fire drill for your data.
Who should conduct an ISO 27001 Internal Audit?
Internal audits should be performed by employees of the organisation. The caveat is that the person must have the experience and skills required to conduct an audit and be independent of the area being audited. If you do not have the competence or skills then an internal audit can be outsourced to an experienced ISO 27001 Consultant.
Being independent of the area being audited means that you must not be accountable, responsible or operate the area that is audited.
In this article I show you how you can conduct the internal as an internal employee.
The 3 Types of Internal Audit
| Audit Method | Description | Best Practice | When to Use & Why |
|---|---|---|---|
| Interview | Speaking directly to control owners to verify understanding and implementation of specific controls. | Send the interview notes back to the interviewee to confirm accuracy and avoid misrepresentation. | Assess Knowledge & Culture: Use when checking if staff understand their responsibilities (e.g., asking “Who do you report incidents to?”). It reveals if security is embedded in the culture. |
| Observation | Witnessing a process or system activity in real-time (e.g., watching a user log in or a developer commit code). | Follow the same recording protocols as an interview (date, time, location) to ensure the evidence is traceable. | Verify Real-World Execution: Use for physical security or manual processes (e.g., Clear Desk Policy). It confirms that written procedures are actually followed in practice, not just on paper. |
| Review of Documents | Examining static evidence such as logs, screenshots, policies, and configuration files to prove a control operated as intended. | Verify the dates on records to ensure they fall within the specific audit period (not historical or future-dated). | Validate Historical Compliance: Use to prove consistency over time (e.g., checking Access Logs from 6 months ago). It provides the concrete “audit trail” required for certification. |
ISO 27001 Audit Toolkit
Before we look at the step by step guide lets consider some helpful templates.
The best way to do this is to get a copy of the Ultimate ISO 27001 Toolkit of which the ISO 27001 Audit Toolkit is a part. We have made the ISO 27001 Audit Toolkit available standalone.
The ISO 27001 Audit Toolkit includes everything you need to conduct ISO 27001 audits and ISO 27001 gap analysis.

The ISO 27001 Internal Audit Process Flow

When do you do an ISO 27001 internal audit?
You should do an internal audit at least once a year. It’s a good idea to do it before your ISO 27001 certification audit. The certification audit will be done by an accredited certification body. You can read the Top 10 ISO 27001 Certification Bodies Guide to find a certification body if you do not have one already.
You can also do one after a major change in your business, like launching a new product or moving to a new office.
There are typical 4 scenarios when an internal audit will be conducted:
- Prior to the ISO 27001 certification audit
- At least once annually
- After an incident
- After a significant change
How to conduct an ISO 27001 Internal Audit: The Information Security Managers Guide
Creating your audit plan
The audit plan document allows you to plan both the internal and external audits for the year and to record when those audits took place.
You will complete the audit plan for the year ahead. Remembering that audit is based on risk the following are considerations when planning audits:
- Plan your external audits first. These represent anchor points and give you a goal and target by which your internal audits should have completed.
- The entire ISMS and the Annex A / ISO 27002 controls require auditing at least once in a 12-month period.
- When considering if an area requires auditing more than once consider if the control represents a high-risk area or a significant incident or failing has occurred with the control in the last 12 months.
- Update your document version control.
- Remember to audit both the ISMS and the ANNEX A controls
The following are the high-level areas that require audit. In the audit working document these are both tabs.
- The Information Security Management System
- Context
- Leadership
- Planning
- Support
- Operation
- Performance evaluation
- Improvement
- The Annex A Control Areas
- Information security policies
- Organisation of information security
- Human resource security
- Asset management
- Access control
- Cryptography
- Physical and environmental security
- Operations security
- Communications security
- System acquisition, development, and maintenance
- Supplier Relationships
- Information security incident management
- Information security aspects of business continuity management
- Compliance
Conducting an ISO 27001 internal audit is a mandatory requirement under ISO 27001 Clause 9.2 Internal Audit of the standard. It serves as the primary mechanism to verify that your Information Security Management System (ISMS) conforms to its own requirements and is effectively implemented and maintained. The following process moves beyond basic checking to establish a risk-based, rigorous audit cycle that satisfies external auditors.
ISO 27001 Audit Plan Example
Updating the audit plan
The audit plan is updated based on changes and scheduling requirements. The following are usual scenarios when the audit plan will require updating.
- Staff availability changes.
- Your audit plan slips.
- You have a significant incident.
When the audit plan changes it should be presented at the next Management Review Team Meeting and recorded in the minutes of the meeting.
Note: Remember to update your document version control

Conducting the internal audits
Identify the control owners
The RASCI document is used to record who is accountable and who is responsible for the controls. Using this document, you will have recorded the people to speak to. There may be others since the document was created so now is a good time to update the RASCI if needed.

Decide on your audit approach
Audit is based on ‘If it is not written down it does not exist’. Your audit will look for evidence of documents, files, records. You have 3 main options in conducting an audit and you can choose one or a combination of the following:
Interview
Speaking to people and seeking answers to questions on controls. Be sure to record the date, time, location and who as well as the notes from the interview. It is best practice though not essential to send the record of the interview to the interviewee stating that if you have misunderstood or misrepresented for them to send you back the changes.
Observation of process and activity
Like an interview you will sit with the person and observe either the systems they use or the operation of the process as they perform it. Follow the same guidelines as for interview.
Review of documents and records
Speaking to control owners you will ask them to send you links to or copies of the documentation and records that make up the control. It can include screenshots. You are looking for the evidence of the operation of the process and control.
Contact the Control Owners
Make contract with the person or persons that you are going to audit. Introduce yourself and explain the context of what you are going to do, what you are going to cover in the audit and what the outcome will be. Explain to them your approach to the audit based on the 3 options discussed when deciding your audit approach. Ask them for the best times and dates for holding a 1-hour meeting to conduct the audit and be flexible to their schedule. You want the person onside and comfortable.
Arrange the Audit Meeting
Your audit meeting can take from 10 minutes up to 1 hour depending on the maturity of the process and the availability of the evidence. Schedule your first meeting for 1 hour.
Create and send an agenda that covers:
- The time, location, and attendees
- The details of the control objectives you will cover.
- The list of documents or types of documents and records you would like access to
Send the agenda and the meeting request in good time and be prepared to reschedule based on people’s availability.
Save a copy of the agenda in the audit folder for your records.
For a face-to-face meeting ensure that the meeting takes place in location with a screen on which the person can display any relevant documents.
For a web-based meeting ensure your environment is set up for a professional level meeting and your technology is properly configured. If sharing a desktop be sure that no confidential documents are open, that notifications are disabled, that chat is disabled.
Conduct your first meeting
Introduce yourself and explain the context of what you are doing, the agenda and what you are hoping to achieve. Explain the audit approach that you have decide to take. Explain that this is not a test, that not knowing an answer is perfectly acceptable and that a follow up meeting can be arranged for any gaps or documents can be shared after the meeting.
Perform the audit
Document: Audit Compliance Report. – Base Template xlsx
Maintaining one document through out the year that you add to with each consecutive audit is good practice. Within a 12-month period you will have completed all audits, with the dates of each audit recorded next to each control. Be sure to keep version control and update the version control section.
Go to the section of the document that relates to the audit you are conducting.
For each control
- Read the control objective.
- Clarify what the control objective is hoping to achieve.
- Gain comfort that there is an understanding what the control objective is hoping to achieve.
- Consider verbally providing examples of the types of documents, records, processes that typically satisfy this control as a guide.
- Update the Date Last Assessed Column to the date the audit.
- Update the Evaluation Method Column to the Audit Approach you are taking.
- Complete the positive and negative columns with comments on the findings that you are presented with and can evidence. Where you are provided documents record the name, version, and location.
- Make your assessment and record your Rating.

After the Audit Meeting
If there are items that were not able to be covered and require follow up repeat the above process until you are satisfied you have covered all control objectives and reviewed all available evidence.
Report your audit findings
To Auditee
Either in person or digitally present your audit findings to the person (s) audited. Seek agreement that it represents what was discussed and the reality as they see it or clarifications they would wish to make. It may be that you have misunderstood something or that further evidence is available but was not provided on the day.
Be clear that the findings are not a reflection on any individual or their role and are not a comment on the operation in either a positive or negative way. Explain the findings are objective based on evidence provided. Where there is a request to provide additional supporting evidence consider setting a time limit.
To Management Review Team
Document: Audit Report – TEMPLATE
Complete the audit summary report for management.
Audit reports are presented to the Management Review Team and the Management Review Team Meeting.
Ensure that the agenda and the minutes of the Management Review Team Meeting reflect the audit that you conducted and are reporting out.
Update the Incident and Corrective Action Log
Update the Incident and Corrective Actions Log with nonconformities and the corrective actions.

Update the Risk Register
Consider if a new risk is required on the risk register and to be managed as part of the risk management process.

Update the Audit Schedule
Update the audit schedule to show that the audit that was conduct.
Update the forward schedule for future audits as required based on the outcome of this audit. If Non-Conformities were observed, consider scheduling a reaudit in 3 months time.
Update all document version control information.
Step-by-Step Guide to ISO 27001 Internal Audit
Time needed: 4 hours and 30 minutes
How to conduct an ISO 27001 Internal Audit
- Update your audit plan for the yearThe audit plan is based on risk and also availability. This is an admin step that is required. Consider which areas are the most risky to your business and plan to audit them more than once. Be sure to plan all your audits for the year so that you have done at least one pass of all controls before your external audit happens. Add the external audit to the plan.
- Identify the control ownersTo be able to conduct an audit you need to know who to audit. The RASCI matrix is a great tool to record this but if you do not have one then list the control areas in a spreadsheet and record who is responsible for them.
- Decide on your audit approachWe work on the principle that if it is not written down it does not exist or did not happen. Consider the approach you will take. You can review records and documents, you can interview people, you can observe people operating a process or you can do a combination.
- Contact the Control OwnersSpeak to the people that own the controls and take time to explain what you are going to do, why you are going to do it and what they can expect.
- Arrange the audit meetingArrange the audit meeting at a time to suit everyone.
- Conduct Your First MeetingAt your first meeting you will introduce yourself and explain what you are doing, why you are doing and what they can expect.
- Conduct the auditUsing the audit work sheet it is good practice to maintain one working sheet for the entire year. Conduct the audit and record the results in the audit sheet including dates.
- Create your audit reportTaking the raw data from the audit worksheet create a management report of your audit findings. Include key findings and observations. It may be appropriate to put forward recommendations for improvement if you know them or record there is a gap that needs to be addressed.
- Report your audit findingsThe cycle of reporting is to first send the report to the person that you audited. This allows for them to provide additional information if your results are in dispute. Once the final report is created then this is shared at the next management review meeting and the process of continual improvement starts.
- Update the audit planUpdate the audit plan to show that the audit was conducted. Update any document version control.
Applicability of internal audit to Small Businesses, Tech Startups, and AI Companies
Internal audit is useful for any size company, no matter how big or small you are. Here’s how it applies:
| Organisation Type | Why Internal Audit Matters | Examples of Audit Activities |
|---|---|---|
| Small Businesses | Builds Trust & Competitiveness. Shows customers you take data seriously and differentiates you from less secure competitors. |
|
| Tech Startups | Investor Confidence & Growth. Demonstrates maturity to investors and prepares operations for secure scaling. |
|
| AI Companies | Ethics & Model Safety. Ensures massive datasets are handled responsibly and proprietary algorithms are secure. |
|
Where do you need it?
You need to do the audit everywhere in your company where you handle information. That means you should check your computers, your servers, your cloud storage, and even how your employees handle paper documents.
Watch the YouTube tutorial How to implement ISO 27001 Clause 9.2 Internal Audit
Which information security standards need Internal Audit?
The internal audit is a key part of the ISO 27001 standard. It’s how you prove to the auditors that you’ve been doing the right things to protect your information.
Other standards that need internal audit include:
| Standard | Full Name | Relevance to Internal Audit | ISO 27001:2022 Mapping |
|---|---|---|---|
| ISO 27001 | International Organization for Standardization 27001 | Key Component: Mandatory requirement to prove protective measures work effectively. | Clause 9.2 (Internal Audit) |
| GDPR | General Data Protection Regulation | Required to ensure ongoing compliance with data privacy laws for EU citizens. | Control 5.34 (Privacy and protection of PII) |
| CCPA | California Consumer Privacy Act | Required to verify compliance with privacy rights for California residents. | Control 5.34 (Privacy and protection of PII) |
| DORA | Digital Operational Resilience Act | Essential for testing operational resilience in the financial sector. | Control 5.30 (ICT readiness for business continuity) |
| NIS2 | Network and Information Security Directive | Needed to verify cybersecurity risk management measures. | Control 5.36 (Compliance with policies, rules and standards) |
| SOC 2 | Service Organisation Control 2 | Specific audit reports are required to attest to the trustworthiness of services provided. | Control 5.35 (Independent review of information security) |
| NIST | National Institute of Standards and Technology | Periodic assessments are required to measure adherence to the cybersecurity framework. | Control 5.36 (Compliance with policies, rules and standards) |
| HIPAA | Health Insurance Portability and Accountability Act | Audits are necessary to ensure the protection of sensitive patient health information. | Control 5.34 (Privacy and protection of PII) |
Audit differences between ISO 27001 and SOC 2
| Feature | ISO 27001 | SOC 2 (System and Organization Controls) | ISO 27001:2022 Mapping |
|---|---|---|---|
| Primary Goal | To certify you have a functioning Management System (ISMS) to manage risk. | To attest that your specific Controls work effectively to protect client data. | Clause 4.4 (Information security management system) |
| The Output | A Certificate. It is a pass/fail outcome. The final document is usually a 1-page certificate. | An Attestation Report. A detailed (often 100+ page) report containing the auditor’s opinion and descriptions of your tests. | Clause 9.1 (Monitoring, measurement, analysis and evaluation) |
| Who Audits You? | An ISO Certification Body (Registrar). | A licensed CPA Firm (Certified Public Accountant). | Clause 9.2 (Internal audit) / ISO/IEC 27006 Requirements |
| Geographic Focus | Global. Recognized internationally. | North America. predominantly (though growing globally). | Clause 4.1 (Understanding the organization and its context) |
| Scope Flexibility | Rigid. You must address the standard’s clauses and usually most of the 93 controls in Annex A. | Flexible. You select which “Trust Services Criteria” apply to you (Security is mandatory; Availability, Privacy, etc., are optional). | Clause 4.3 (Determining the scope of the information security management system) |
| Renewal Cycle | 3-Year Cycle. (Initial certification → Year 1 Surveillance → Year 2 Surveillance → Recertification). | Annual. Most companies get a new SOC 2 report every 12 months to cover the previous year’s period. | Clause 10.1 (Continual improvement) |
