ISO 27001 internal audit: Meaning, process, checklist

Getting ISO 27001 certified is a big win, but the real challenge is keeping it. ISO 27001 requires you to regularly check if your information security practices still hold up. That's where the internal audit comes in.
In this guide, we'll break down what an ISO 27001 internal audit involves, how often to run it, and what steps to follow  plus a checklist to help you stay on track.
Note: This blog focuses on ISO/IEC 27001:2022, which marks the end of its transition period on October 31, 2025â€â€future-proofing your compliance efforts while remaining relevant to organizations still aligned with the 2013 version.
What is an ISO 27001 audit?
An ISO 27001 audit is a formal review of your organization's Information Security Management System (ISMS) to verify whether it meets the requirements of the ISO/IEC 27001 standard. In simple terms, it's a way to confirm that your security policies, controls, and processes are not just well-documented but actually working to protect sensitive data and manage risks effectively.
There are three types of ISMS audits:
- Internal audits are required at least once a year to identify gaps, assess effectiveness, and get ready for certification.
- External audits are carried out by accredited certification bodies to certify your ISMS or maintain that certification through annual surveillance and triennial recertification.
- Third-party audits are less common and usually performed by customers or partners to assess your security practices as part of vendor evaluations or contract obligations.
What is an ISO 27001 internal audit?
An ISO 27001 internal audit is an in-house review of an organization's Information Security Management System (ISMS) to ensure compliance with ISO/IEC 27001:2022 and internal security objectives.
Conducted within the organization by trained staff or hired auditors, it identifies risks and gaps in the ISMS. Its goal is to spot any gaps, non-conformities, or improvement areas before certification or a surveillance audit.
Required at least annually, these audits prepare you for external certification. It's a critical step to keep your security practices sharp and compliant.
Who is responsible for the ISO 27001 internal audit?
While top management is accountable for the overall effectiveness of the ISMS as outlined in Clause 5, Clause 9.2 of ISO/IEC 27001:2022 places the responsibility for planning and conducting internal audits on the organization.
Per ISO/IEC 27001:2022, Clause 9.2, they must ensure audits occur at planned intervals and are impartial to verify compliance. This keeps the ISMS effective and ready for certification.
What are the ISO 27001 internal audit requirements?
Here's a comprehensive rundown of what you need to nail an ISO 27001 internal audit, per ISO/IEC 27001:2022:
- Audit methodology: Follow a documented process to ensure consistent, repeatable ISMS audits.
- Scope and objectives: Define the audit's focus, covering specific ISMS areas and goals.
- Audit team: Use qualified auditors (internal or third-party) with ISO 27001 expertise.
- Audit program: Plan audits with clear frequency, methods, and assigned responsibilities.
- Documentation: Record all audit processes, evidence, and findings for traceability.
- Reporting: Share results with management to drive corrective actions and improvements.
- Continual improvement: Use audit findings to enhance the ISMS over time.
- Objectivity and impartiality: Ensure auditors are independent, free from conflicts.
- ISO 27001 knowledge: Auditors must be competent as per Clause 7.2, which includes appropriate education, training, and experience to understand and assess the standard's requirements effectively.
What is the 27001 internal audit process?
ISO/IEC 27001:2022 lays out a clear process to ensure your ISMS is up to standard. Here's the five-step process to get it right:
1. Define audit scope and plan:
Create an audit plan detailing scope, objectives, and schedule, focusing on relevant ISMS assets, Clauses 4–10, and Annex A controls listed in your Statement of Applicability.
2. Collect evidence and review documents:
Examine key ISMS documents like the Scope Statement, Risk Assessment, and Information Security Policy to verify compliance and control effectiveness.
3. Conduct the audit:
Perform assessments through interviews, control observations, and document reviews to evaluate ISMS performance against ISO 27001 requirements and identify gaps.
4. Prepare audit report:
Summarize findings in a report, including scope, non-conformities, corrective actions, and recommendations, ensuring clarity for management review.
5. Management review and follow-up:
Present findings to management, address non-conformities per Clause 10.1, and plan improvements to ensure readiness for certification audits.
Who can conduct internal audits under ISO 27001?
Per Clause 9.2.2, internal audits must be conducted by individuals who are both competent and impartial. Competencyâ€â€as defined in Clause 7.2â€â€includes appropriate education, training, or experience. While some organizations engage certified internal staff (e.g., those with Lead Auditor training) or independent third-party consultants, ISO 27001 does not mandate certifications. Software tools, such as compliance platforms, can assist with evidence collection and reporting, but they do not replace the need for qualified human auditors.
What is the importance of ISO 27001 internal audits?
Internal audits, mandated by Clause 9.2 of ISO/IEC 27001:2022, are critical for keeping your ISMS robust and compliant. They help identify weaknesses before external audits and drive continuous improvement. Here's why they matter:
- Ensure compliance: Internal audits verify that your ISMS aligns with ISO 27001 requirements and your organization's security policies, reducing the risk of certification failures.
- Identify risks and gaps: Audits uncover vulnerabilities and non-conformities, enabling proactive risk management before they become costly issues.
- Drive improvement: By addressing audit findings, organizations strengthen their ISMS, enhancing security and operational efficiency over time.
How to avoid common ISO 27001 internal audit mistakes?
Internal audits require a methodical approach, but common pitfalls can undermine your efforts. Here's how to steer clear of three frequent mistakes:
- Lack of auditor independence: Using auditors involved in ISMS operations risks bias. Choose impartial auditors with no direct responsibility for audited processes.
- Poor planning: Vague scope or objectives can lead to incomplete audits. Define clear goals, covering relevant clauses and Annex A controls, in your audit plan.
- Ignoring follow-up: Failing to act on audit findings wastes the process. Ensure that management reviews and implements corrective actions promptly.

FAQs
Do all internal auditors need to undergo training?
Internal auditors must be competent as required by Clause 9.2.2 of ISO/IEC 27001:2022. Competency is defined in Clause 7.2 and may be achieved through a combination of education, training, or relevant experience.
While formal trainingâ€â€such as ISO 27001 internal auditor or lead auditor coursesâ€â€can help build this competency, such certifications are not explicitly required by the standard. What matters is that auditors understand the standard, audit methodology, and can assess the ISMS impartially and effectively.
What are some important audits for ISO 27001 certification?
Key audits include internal audits (Clause 9.2), which are conducted objectively and impartially to evaluate ISMS compliance; surveillance audits, typically held annually after certification, to monitor ongoing adherence; and recertification audits every three years to renew certification. Together, these audits ensure that your ISMS continues to meet ISO/IEC 27001:2022 requirements.
Can ISO 27001 auditors carry out internal audits as well?
External consultants with ISO 27001 expertise, who are not affiliated with your certification body, can be engaged to conduct internal audits, as long as they are independent of the areas being audited. Certification auditors, however, are not allowed to perform internal audits for the same client due to conflict-of-interest rules.
Are the internal audit requirements the same as ISO 27001 after 2013?
Yes, the core internal audit requirements in ISO/IEC 27001:2022 are essentially the same as those in the 2013 version. Organizations are still required to conduct internal audits at planned intervals to evaluate ISMS conformity and effectiveness. The 2022 update includes minor wording improvements for clarity but does not change the intent or expectations under Clause 9.2.
What do you do with the findings of the ISO 27001 internal audit?
After the internal audit, organizations must document the findings, report them to relevant management, and take corrective actions where necessary. Non-conformities should be analyzed to determine root causes, followed by implementing and tracking appropriate measures.
These actions are not only essential for preparing for external audits but are also critical for maintaining and continually improving the ISMS, as required by Clause 10.1 of ISO/IEC 27001:2022.
What are some common non-conformities found in an internal audit?
Frequent issues include:
1. Incomplete risk assessments (Clause 6.1.2)  missing risk criteria or outdated evaluations
2. Outdated documentation (Clause 7.5)  policies not reviewed or aligned with current practices
3. Access control gaps (Annex A.9)  shared credentials or lack of user access reviews
These usually stem from poor planning or lack of follow-up on past audit findings.
How often should an ISO 27001 internal audit be conducted?
Clause 9.2 requires internal audits at least annually, though frequency may increase based on risk assessments or significant ISMS changes. Regular audits ensure ongoing compliance and readiness for certification.
Ready to see what security-first GRC really looks like?
Ready to see what security-first GRC really looks like?
Ready to see what security-first GRC really looks like?
See what a real security- first GRC platform looks like
Ready to see what security-first GRC really looks like?
Focus on the traveler experience. We’ll handle the regulations.
Get Scrut. Achieve and maintain compliance without the busywork.
Choose risk-first compliance that’s always on, built for you, and never in your way.
Ready to see what security-first GRC
One platform, every framework. No more duplicate work.
You can’t manage user access if you’re always playing catch-up.
Explore the future of enterprise GRC
Tired of chasing vendors for risk assessments?
Join the thousands of companies automating their compliance with Scrut.
The right partner makes all the difference. Let’s grow together.
Make your business easy to trust, put security transparency front and center.
Risk-first security starts with risk-first visibility.
Secure your team from the inside out.
Don't settle for slow, expensive compliance. Get Scrut instead.
Risk-first compliance for forward-thinking teams.
Audits without the back-and-forth. Just seamless collaboration.
Scale fast. Stay compliant. Automate the rest.
Compliance? Done and dusted, in half the time.
Get ahead of GDPR compliance before it becomes a problem.
Outgrowing table-stakes compliance? Create custom frameworks with ease.
Navigate SOC 2 compliance, minus the stress.
PCI DSS compliance, minus the panic.
Take the wheel of your HIPAA certification journey today.
We’ve got what you need to fast-track your ISO 27001 certification.
Make your NIST AI RMF journey as smooth as possible.
Your GRC team, multiplied and AI-backed.
Modern compliance for the evolving education landscape.
Ready to simplify healthcare compliance?
Don’t let compliance turn into a bottleneck in your SaaS growth.
Find the right compliance frameworks for your business in minutes
Ready to see what security-first GRC really looks like?
Real-time visibility into every asset
Ready to simplify fintech compliance?
The Scrut Platform helps you move fast, stay compliant, and build securely from the start.
Scrut helps you set up a security program that scales with your business and stands up to audits. Without last-minute chaos.
Scrut helps you streamline audits, close deals faster, and stay ahead of risk without slowing down your team. Because trust shouldn’t take months to earn.
Scrut helps you set up a security program that scales with your business and stands up to audits. Without last-minute chaos.
Tag, classify, and monitor assets in real time—without the manual overhead.
Whether you're entering new markets or launching new products, Scrut helps you stay compliant without slowing down.
Scrut pulls compliance data straight from the tools you already use—so you don’t have to dig for evidence, chase approvals, or manually track controls.
Less manual work, more customizability. The Scrut Platform gives you everything you need to align your compliance to your business’s priorities.
With Scrut, you’re not just adding a tool to your offering—you’re adding a competitive edge. Join our Partner Network and help your clients streamline their GRC program.
Gaining trust is your first step to growing and cracking better deals. The Scrut Platform comes pre-built with all the tools you need to showcase a firm security posture and build confidence.
Don’t settle for rigid systems—Scrut ensures your risk management strategy is as flexible as your business needs.
Start building a security-first culture. Save your operations from improper training and a lack of compliance awareness.
Scrut fast-tracks compliance so you can focus on scaling, not scrambling. Automate compliance tasks and accelerate enterprise deals—without the grind.
Automate assessments, track compliance, and get full visibility into third-party risk—all in one place.
Scrut automates compliance tasks, supports proactive risk management, and saves you time, so you can focus on growing your business. Start building trust with customers and scaling confidently.
Leave legacy GRC behind. Meet the AI-powered platform built for teams managing risk and compliance in real time.
Give auditors direct access, keep track of every request, and manage audits effortlessly—all in one place.
Scrut ensures access permissions are correct, up-to-date, and fully compliant.
Whether you need fast results or a fully tailored program mapped to your risks and needs, Scrut delivers exactly what you need, when you need it. Ready to start?
Scrut unifies compliance across all your frameworks, so you can stop juggling systems and start scaling securely.
Manually managing your compliance processes and audits can get inefficient and overwhelming. Scrut automates these outdated, manual processes and eliminates your last-minute worries.
Access automated compliance, real-time risk tracking, and expert-backed support—all in one platform. Get started with Scrut!
Less manual work, more customizability. The Scrut Platform gives you everything you need to align your compliance to your business’s priorities.
The Scrut Platform helps you move fast, stay compliant, and build securely from the start.
Earn trust and back it up with solid evidence. Scrut takes you through the SOC 2 compliance journey step-by-step, navigating every complexity you face.
Manage your PCI DSS compliance with real-time monitoring and effortless automation. Get started with Scrut today!
Securing your PHI shouldn’t be a constant hassle. Scrut automates your workflows—from risk assessments to monitoring—so you can put your compliance worries on the back burner.
Automate security controls, simplify audits, and keep your ISMS aligned with the latest standards. Get started with Scrut!
Tackle potential AI risks with NIST AI RMF-compliant controls and get expert support every step of the way.
Offload the grunt compliance work to us. Execute manual, draining GRC tasks with the reliable AI-powered Scrut Teammates without switching contexts or bottlenecks.
Whether you're managing student data, partnering with educational institute, or expanding to new geographies—Scrut gives you the tools to stay compliant, manage risk, and build trust at every step.
Scaling healthcare doesn’t have to come at the cost of security. Scrut keeps your organization compliant, audit-ready, and protected—no matter how fast you grow.
Scrut automates the hard parts of compliance and security so you can move fast and stay ahead of risks from day one.
The Scrut Platform helps you move fast, stay compliant, and build securely from the start.
Growth in fintech comes with heavy scrutiny. Scrut helps you stay compliant, audit-ready, and secure—without slowing down your momentum.



