How to do ISO 27001 Internal Audit [+ Templates]

 

ISO 27001 Internal Audit

In this guide, you will learn directly from ISO 27001 Lead Auditor with over 30 years industry experience, exactly how to do an ISO 27001 Internal Audit.

The same process is applied when you do an ISO 27001 Gap Analysis.

I have conducted hundreds of audits and taught consultants how to audit. Now, I’m giving you the exact templates, walkthroughs, and practical examples you need to do your own ISO 27001 Internal Audits.

I am Stuart Barker, the ISO 27001 Ninja and author of the Ultimate ISO 27001 Toolkit.

What is an ISO 27001 Internal Audit?

ISO 27001 internal audit is the process of internally independently verifying the effectiveness of the information security management system and information security controls.

Why do ISO 27001 Internal Audits?

Internal audit is a requirement of the ISO 27001 standard and covered explicitly in ISO 27001 Clause 9.2 Internal Audit.

These audits are designed to help you improve the information security management system and ensure that it still meets the requirements of the ISO 27001 standard. It helps you spot weak spots in your security before a real problem happens. It’s like a fire drill for your data.

Who should conduct an ISO 27001 Internal Audit?

Internal audits should be performed by employees of the organisation. The caveat is that the person must have the experience and skills required to conduct an audit and be independent of the area being audited. If you do not have the competence or skills then an internal audit can be outsourced to an experienced ISO 27001 Consultant.

Being independent of the area being audited means that you must not be accountable, responsible or operate the area that is audited.

In this article I show you how you can conduct the internal as an internal employee.

The 3 Types of Internal Audit

Audit MethodDescriptionBest PracticeWhen to Use & Why
InterviewSpeaking directly to control owners to verify understanding and implementation of specific controls.Send the interview notes back to the interviewee to confirm accuracy and avoid misrepresentation.Assess Knowledge & Culture: Use when checking if staff understand their responsibilities (e.g., asking “Who do you report incidents to?”). It reveals if security is embedded in the culture.
ObservationWitnessing a process or system activity in real-time (e.g., watching a user log in or a developer commit code).Follow the same recording protocols as an interview (date, time, location) to ensure the evidence is traceable.Verify Real-World Execution: Use for physical security or manual processes (e.g., Clear Desk Policy). It confirms that written procedures are actually followed in practice, not just on paper.
Review of DocumentsExamining static evidence such as logs, screenshots, policies, and configuration files to prove a control operated as intended.Verify the dates on records to ensure they fall within the specific audit period (not historical or future-dated).Validate Historical Compliance: Use to prove consistency over time (e.g., checking Access Logs from 6 months ago). It provides the concrete “audit trail” required for certification.

ISO 27001 Audit Toolkit

Before we look at the step by step guide lets consider some helpful templates.

The best way to do this is to get a copy of the Ultimate ISO 27001 Toolkit of which the ISO 27001 Audit Toolkit is a part. We have made the ISO 27001 Audit Toolkit available standalone.

The ISO 27001 Audit Toolkit includes everything you need to conduct ISO 27001 audits and ISO 27001 gap analysis.

ISO 27001 Gap Analysis and Audit Toolkit - ISO 27001 Internal Audit Templates
ISO 27001 Gap Analysis and Audit Toolkit

The ISO 27001 Internal Audit Process Flow

ISO 27001 Internal Audit Process Flow Diagram
ISO 27001 Internal Audit Process Flow Diagram

When do you do an ISO 27001 internal audit?

You should do an internal audit at least once a year. It’s a good idea to do it before your ISO 27001 certification audit. The certification audit will be done by an accredited certification body. You can read the Top 10 ISO 27001 Certification Bodies Guide to find a certification body if you do not have one already.

You can also do one after a major change in your business, like launching a new product or moving to a new office.

There are typical 4 scenarios when an internal audit will be conducted:

How to conduct an ISO 27001 Internal Audit: The Information Security Managers Guide

Creating your audit plan

The audit plan document allows you to plan both the internal and external audits for the year and to record when those audits took place. 

You will complete the audit plan for the year ahead. Remembering that audit is based on risk the following are considerations when planning audits:

  • Plan your external audits first. These represent anchor points and give you a goal and target by which your internal audits should have completed. 
  • The entire ISMS and the Annex A / ISO 27002 controls require auditing at least once in a 12-month period.
  • When considering if an area requires auditing more than once consider if the control represents a high-risk area or a significant incident or failing has occurred with the control in the last 12 months.
  • Update your document version control. 
  • Remember to audit both the ISMS and the ANNEX A controls

The following are the high-level areas that require audit. In the audit working document these are both tabs.

  • The Information Security Management System
  • Context
  • Leadership
  • Planning
  • Support
  • Operation
  • Performance evaluation
  • Improvement
  • The Annex A Control Areas
  • Information security policies
  • Organisation of information security
  • Human resource security
  • Asset management
  • Access control
  • Cryptography
  • Physical and environmental security
  • Operations security
  • Communications security
  • System acquisition, development, and maintenance
  • Supplier Relationships
  • Information security incident management
  • Information security aspects of business continuity management
  • Compliance

Conducting an ISO 27001 internal audit is a mandatory requirement under ISO 27001 Clause 9.2 Internal Audit of the standard. It serves as the primary mechanism to verify that your Information Security Management System (ISMS) conforms to its own requirements and is effectively implemented and maintained. The following process moves beyond basic checking to establish a risk-based, rigorous audit cycle that satisfies external auditors.

ISO 27001 Audit Plan Example

Updating the audit plan

The audit plan is updated based on changes and scheduling requirements. The following are usual scenarios when the audit plan will require updating.

  • Staff availability changes. 
  • Your audit plan slips.
  • You have a significant incident. 

When the audit plan changes it should be presented at the next Management Review Team Meeting and recorded in the minutes of the meeting.

Note: Remember to update your document version control 

ISO 27001 Audit Plan Example 2

Conducting the internal audits

Identify the control owners

The RASCI document is used to record who is accountable and who is responsible for the controls. Using this document, you will have recorded the people to speak to. There may be others since the document was created so now is a good time to update the RASCI if needed. 

ISO 27001 RASCI Matrix Example

Decide on your audit approach

Audit is based on ‘If it is not written down it does not exist’. Your audit will look for evidence of documents, files, records. You have 3 main options in conducting an audit and you can choose one or a combination of the following:

Interview

Speaking to people and seeking answers to questions on controls. Be sure to record the date, time, location and who as well as the notes from the interview. It is best practice though not essential to send the record of the interview to the interviewee stating that if you have misunderstood or misrepresented for them to send you back the changes. 

Observation of process and activity

Like an interview you will sit with the person and observe either the systems they use or the operation of the process as they perform it. Follow the same guidelines as for interview. 

Review of documents and records

Speaking to control owners you will ask them to send you links to or copies of the documentation and records that make up the control. It can include screenshots. You are looking for the evidence of the operation of the process and control. 

Contact the Control Owners

Make contract with the person or persons that you are going to audit. Introduce yourself and explain the context of what you are going to do, what you are going to cover in the audit and what the outcome will be. Explain to them your approach to the audit based on the 3 options discussed when deciding your audit approach. Ask them for the best times and dates for holding a 1-hour meeting to conduct the audit and be flexible to their schedule. You want the person onside and comfortable.

Arrange the Audit Meeting

Your audit meeting can take from 10 minutes up to 1 hour depending on the maturity of the process and the availability of the evidence. Schedule your first meeting for 1 hour. 

Create and send an agenda that covers:

  • The time, location, and attendees 
  • The details of the control objectives you will cover.
  • The list of documents or types of documents and records you would like access to 

Send the agenda and the meeting request in good time and be prepared to reschedule based on people’s availability.

Save a copy of the agenda in the audit folder for your records.

For a face-to-face meeting ensure that the meeting takes place in location with a screen on which the person can display any relevant documents.

For a web-based meeting ensure your environment is set up for a professional level meeting and your technology is properly configured. If sharing a desktop be sure that no confidential documents are open, that notifications are disabled, that chat is disabled. 

Conduct your first meeting

Introduce yourself and explain the context of what you are doing, the agenda and what you are hoping to achieve. Explain the audit approach that you have decide to take.  Explain that this is not a test, that not knowing an answer is perfectly acceptable and that a follow up meeting can be arranged for any gaps or documents can be shared after the meeting. 

Perform the audit

Document: Audit Compliance Report. – Base Template xlsx

Maintaining one document through out the year that you add to with each consecutive audit is good practice. Within a 12-month period you will have completed all audits, with the dates of each audit recorded next to each control. Be sure to keep version control and update the version control section.

Go to the section of the document that relates to the audit you are conducting. 

For each control 

  • Read the control objective. 
  • Clarify what the control objective is hoping to achieve.
  • Gain comfort that there is an understanding what the control objective is hoping to achieve.
  • Consider verbally providing examples of the types of documents, records, processes that typically satisfy this control as a guide. 
  • Update the Date Last Assessed Column to the date the audit.
  • Update the Evaluation Method Column to the Audit Approach you are taking. 
  • Complete the positive and negative columns with comments on the findings that you are presented with and can evidence. Where you are provided documents record the name, version, and location.
  • Make your assessment and record your Rating. 
ISO 27001 Audit Worksheet Example

After the Audit Meeting

If there are items that were not able to be covered and require follow up repeat the above process until you are satisfied you have covered all control objectives and reviewed all available evidence.

Report your audit findings

To Auditee

Either in person or digitally present your audit findings to the person (s) audited.  Seek agreement that it represents what was discussed and the reality as they see it or clarifications they would wish to make. It may be that you have misunderstood something or that further evidence is available but was not provided on the day. 

Be clear that the findings are not a reflection on any individual or their role and are not a comment on the operation in either a positive or negative way. Explain the findings are objective based on evidence provided. Where there is a request to provide additional supporting evidence consider setting a time limit.

To Management Review Team

Document: Audit Report – TEMPLATE

Complete the audit summary report for management. 

Audit reports are presented to the Management Review Team and the Management Review Team Meeting. 

Ensure that the agenda and the minutes of the Management Review Team Meeting reflect the audit that you conducted and are reporting out.

Update the Incident and Corrective Action Log

Update the Incident and Corrective Actions Log with nonconformities and the corrective actions. 

ISO27001-Incident-and-Corrective-Action-Log-Example

Update the Risk Register

Consider if a new risk is required on the risk register and to be managed as part of the risk management process

ISO 27001 Risk Register Example 2
ISO 27001 Risk Register Example 2

Update the Audit Schedule

Update the audit schedule to show that the audit that was conduct. 

Update the forward schedule for future audits as required based on the outcome of this audit. If Non-Conformities were observed, consider scheduling a reaudit in 3 months time. 

Update all document version control information.

Step-by-Step Guide to ISO 27001 Internal Audit

Time needed: 4 hours and 30 minutes

How to conduct an ISO 27001 Internal Audit

  1. Update your audit plan for the yearThe audit plan is based on risk and also availability. This is an admin step that is required. Consider which areas are the most risky to your business and plan to audit them more than once. Be sure to plan all your audits for the year so that you have done at least one pass of all controls before your external audit happens. Add the external audit to the plan.
  2. Identify the control ownersTo be able to conduct an audit you need to know who to audit. The RASCI matrix is a great tool to record this but if you do not have one then list the control areas in a spreadsheet and record who is responsible for them. 
  3. Decide on your audit approachWe work on the principle that if it is not written down it does not exist or did not happen. Consider the approach you will take. You can review records and documents, you can interview people, you can observe people operating a process or you can do a combination.
  4. Contact the Control OwnersSpeak to the people that own the controls and take time to explain what you are going to do, why you are going to do it and what they can expect. 
  5. Arrange the audit meetingArrange the audit meeting at a time to suit everyone. 
  6. Conduct Your First MeetingAt your first meeting you will introduce yourself and explain what you are doing, why you are doing and what they can expect.
  7. Conduct the auditUsing the audit work sheet it is good practice to maintain one working sheet for the entire year. Conduct the audit and record the results in the audit sheet including dates.
  8. Create your audit reportTaking the raw data from the audit worksheet create a management report of your audit findings. Include key findings and observations. It may be appropriate to put forward recommendations for improvement if you know them or record there is a gap that needs to be addressed.
  9. Report your audit findingsThe cycle of reporting is to first send the report to the person that you audited. This allows for them to provide additional information if your results are in dispute. Once the final report is created then this is shared at the next management review meeting and the process of continual improvement starts.
  10. Update the audit planUpdate the audit plan to show that the audit was conducted. Update any document version control.

Applicability of internal audit to Small Businesses, Tech Startups, and AI Companies

Internal audit is useful for any size company, no matter how big or small you are. Here’s how it applies:

Organisation TypeWhy Internal Audit MattersExamples of Audit Activities
Small BusinessesBuilds Trust & Competitiveness.
Shows customers you take data seriously and differentiates you from less secure competitors.
  • Verifying payment system security.
  • Ensuring old customer credit card numbers are not stored.
  • Enforcing strong password policies for employees.
Tech StartupsInvestor Confidence & Growth.
Demonstrates maturity to investors and prepares operations for secure scaling.
  • Checking code for security bugs during development.
  • Testing new features for safety before launch.
  • Auditing intellectual property protection measures.
AI CompaniesEthics & Model Safety.
Ensures massive datasets are handled responsibly and proprietary algorithms are secure.
  • Auditing data collection and storage for training models.
  • Verifying data anonymisation and privacy compliance.
  • Testing defences against model theft or manipulation.

Where do you need it?

You need to do the audit everywhere in your company where you handle information. That means you should check your computers, your servers, your cloud storage, and even how your employees handle paper documents.

Watch the YouTube tutorial How to implement ISO 27001 Clause 9.2 Internal Audit

Which information security standards need Internal Audit?

The internal audit is a key part of the ISO 27001 standard. It’s how you prove to the auditors that you’ve been doing the right things to protect your information.

Other standards that need internal audit include:

StandardFull NameRelevance to Internal AuditISO 27001:2022 Mapping
ISO 27001International Organization for Standardization 27001Key Component: Mandatory requirement to prove protective measures work effectively.Clause 9.2 (Internal Audit)
GDPRGeneral Data Protection RegulationRequired to ensure ongoing compliance with data privacy laws for EU citizens.Control 5.34 (Privacy and protection of PII)
CCPACalifornia Consumer Privacy ActRequired to verify compliance with privacy rights for California residents.Control 5.34 (Privacy and protection of PII)
DORADigital Operational Resilience ActEssential for testing operational resilience in the financial sector.Control 5.30 (ICT readiness for business continuity)
NIS2Network and Information Security DirectiveNeeded to verify cybersecurity risk management measures.Control 5.36 (Compliance with policies, rules and standards)
SOC 2Service Organisation Control 2Specific audit reports are required to attest to the trustworthiness of services provided.Control 5.35 (Independent review of information security)
NISTNational Institute of Standards and TechnologyPeriodic assessments are required to measure adherence to the cybersecurity framework.Control 5.36 (Compliance with policies, rules and standards)
HIPAAHealth Insurance Portability and Accountability ActAudits are necessary to ensure the protection of sensitive patient health information.Control 5.34 (Privacy and protection of PII)

Audit differences between ISO 27001 and SOC 2

FeatureISO 27001SOC 2 (System and Organization Controls)ISO 27001:2022 Mapping
Primary GoalTo certify you have a functioning Management System (ISMS) to manage risk.To attest that your specific Controls work effectively to protect client data.Clause 4.4 (Information security management system)
The OutputA Certificate.
It is a pass/fail outcome. The final document is usually a 1-page certificate.
An Attestation Report.
A detailed (often 100+ page) report containing the auditor’s opinion and descriptions of your tests.
Clause 9.1 (Monitoring, measurement, analysis and evaluation)
Who Audits You?An ISO Certification Body (Registrar).A licensed CPA Firm (Certified Public Accountant).Clause 9.2 (Internal audit) / ISO/IEC 27006 Requirements
Geographic FocusGlobal. Recognized internationally.North America. predominantly (though growing globally).Clause 4.1 (Understanding the organization and its context)
Scope FlexibilityRigid. You must address the standard’s clauses and usually most of the 93 controls in Annex A.Flexible. You select which “Trust Services Criteria” apply to you (Security is mandatory; Availability, Privacy, etc., are optional).Clause 4.3 (Determining the scope of the information security management system)
Renewal Cycle3-Year Cycle.
(Initial certification → Year 1 Surveillance → Year 2 Surveillance → Recertification).
Annual.
Most companies get a new SOC 2 report every 12 months to cover the previous year’s period.
Clause 10.1 (Continual improvement)

About the author

Stuart Barker
🎓 MSc Security 🛡️ Lead Auditor 30+ Years Exp 🏢 Ex-GE Leader

Stuart Barker

ISO 27001 Ninja

Stuart Barker is a veteran practitioner with over 30 years of experience in systems security and risk management. Holding an MSc in Software and Systems Security, he combines academic rigor with extensive operational experience, including a decade leading Data Governance for General Electric (GE).

As a qualified ISO 27001 Lead Auditor, Stuart possesses distinct insight into the specific evidence standards required by certification bodies. His toolkits represent an auditor-verified methodology designed to minimise operational friction while guaranteeing compliance.

Shopping Basket
Scroll to Top