
The clause 9.2 audit your ISMS requires, run by someone genuinely independent.
ISO/IEC 27001:2022 requires internal audits carried out by someone free from bias about the area being reviewed. We deliver that independence, with findings structured to feed directly into your management review and corrective action process.
Auditing your own department rarely stands up to scrutiny.
Clause 9.2 of ISO/IEC 27001:2022 is specific: internal audits must be objective and impartial, carried out by auditors who don't audit their own work. In smaller organisations the person who manages information security is often the only one with the knowledge to audit it — which puts them in an impossible position, auditing decisions they made themselves.
Certification bodies notice this. A surveillance auditor reviewing a thin, self-marked internal audit report with no nonconformities raised, ever, tends to ask harder questions than one reviewing a properly independent audit that found and closed real issues.
There's also a competence problem. Running a credible ISMS audit means understanding the standard's clause structure, sampling technique, evidence gathering and how to write a finding that's defensible rather than vague. That's a specific skill set, distinct from managing security operations day to day.
Left unaddressed, this shows up as an internal audit programme that exists on paper — a spreadsheet with dates and a tick — but doesn't generate anything a management review can meaningfully act on. That weakens the whole continual improvement cycle the standard is built around.
The commercial risk is real too: a certification body can raise a nonconformity against the internal audit process itself if it isn't demonstrably independent and effective, which is a harder finding to explain to a customer than almost any other.
- No one internally with both the independence and the audit skill set to review the ISMS
- Internal audits that never raise nonconformities, which reads as a red flag rather than reassurance
- Findings not structured in a way management review can actually use
- Audit programme covers the same easy areas every cycle, avoiding the harder ones
- Corrective actions logged but never tracked through to verified closure
A properly planned, evidenced audit — not a box-ticking visit.
We start by agreeing the audit programme and scope with you: which clauses, which Annex A controls, and which parts of the organisation are in scope for this cycle, based on risk and what's changed since the last audit.
Fieldwork follows standard audit method — document review, sampling of records and evidence, and interviews with control owners — testing whether what's written down matches what actually happens. We're not looking to catch people out; we're testing conformity and effectiveness the same way a certification body auditor would.
Every finding is recorded with objective evidence and classified against the relevant clause or control, distinguishing genuine nonconformities from observations and opportunities for improvement. Vague findings help nobody, so we're specific about what was seen and against what requirement it falls short.
We close the audit with a meeting to walk through findings before the report is finalised, so there's no ambush and control owners understand what corrective action is expected of them.
The final report is structured to be usable directly as a management review input under clause 9.3, alongside your other required inputs, so leadership gets a coherent view of ISMS performance rather than a document that sits separately from governance.
Where you want it, we can also help set or refresh a multi-year internal audit programme so the whole ISMS scope gets covered on a sensible cycle rather than the same easy areas being revisited every year.
- Audit plan and scope agreed against risk and prior findings
- Evidence-based fieldwork: document review, sampling and interviews
- Findings classified as major nonconformity, minor nonconformity or observation
- Closing meeting before the report is finalised
- Report structured as a direct management review input
Everything in the engagement, set out up front.
Scope is agreed before fieldwork begins, whether that's the full ISMS or a focused set of clauses and controls.
Audit planning
Scope, criteria and schedule agreed with you, referencing prior audits and risk changes.
Document and record review
Policies, procedures and operational records sampled against clause and control requirements.
Control owner interviews
Structured conversations testing whether documented practice matches operational reality.
Nonconformity classification
Findings recorded with objective evidence and classified as major, minor or observation.
Closing meeting
Findings walked through with stakeholders before the report is finalised, avoiding surprises.
Corrective action support
Guidance on root cause analysis and tracking actions through to verified closure.
What you receive.
- Audit plan and criteria document
- Fieldwork evidence log
- Nonconformity and observation register
- Classified findings with clause/control references
- Closing meeting minutes
- Management review-ready summary report
- Corrective action tracking template
- Recommendations for the next audit cycle
Built for organisations that need the work done properly.
Organisations without internal audit competence
You have security capability but no one qualified or independent enough to audit it credibly.
Teams preparing for a surveillance audit
You want a realistic dry run and evidence trail before your certification body's next visit.
Businesses with a stalled audit programme
Internal audits have lapsed or become superficial, and you need to demonstrate the process is working again.
Organisations wanting objectivity on a sensitive area
You need an independent view of a specific control area — access management, supplier risk, incident response — free from internal politics.
What changes once the work is done.
An internal audit only earns its place in the ISMS if it changes something afterwards — these are the changes we aim for.
Defensible independence
An audit trail showing genuinely independent review, not a self-marked exercise.
Usable management review input
Findings structured to slot straight into your clause 9.3 process.
Real nonconformities, properly tracked
Issues surfaced and logged with a clear path to verified closure.
Stronger surveillance audit outcomes
Fewer gaps left for a certification body auditor to find first.
A credible audit programme
Coverage planned across cycles rather than repeating the same easy scope.
Confidence for leadership
A clear, evidenced view of whether the ISMS is actually working, not just documented.
How this fits with the wider ISMS audit cycle.
Clause 9.2 internal audits sit between two other mandatory activities: the risk assessment and treatment process that defines what should be controlled, and the clause 9.3 management review where leadership decides what to do about audit findings, performance data and changing risk. An internal audit that isn't connected to both ends is just a paperwork exercise.
We're careful to distinguish our role from that of an accredited certification body. Certification bodies conduct Stage 1 and Stage 2 audits and ongoing surveillance visits, and only they can issue or maintain a certificate. Our internal audits are the evidence-generating activity that happens between those visits, owned by you, delivered independently on your behalf.
Done well, a mature internal audit programme becomes one of the more persuasive pieces of evidence a certification body sees, because it demonstrates the ISMS is actively managed rather than assembled once for a certification decision and left untouched.
We typically recommend clients treat the first year or two of internal audits as a genuine capability-building exercise — refining audit criteria, sampling approach and reporting format — rather than expecting a perfect, low-friction process from the first cycle.
Questions we are asked most often.
Why does ISO 27001 require an internal audit?
Clause 9.2 requires organisations to audit their ISMS at planned intervals to check it conforms to their own requirements and to ISO/IEC 27001:2022, and that it's effectively implemented and maintained. It's a mandatory input to management review under clause 9.3 and to the certification body's ongoing surveillance audits.
Can we run internal audits ourselves?
Yes, provided the auditor is independent of the area being audited and has appropriate competence — clause 9.2 doesn't require an external party. Many smaller organisations lack the internal capacity or objectivity to audit their own security function convincingly, which is where an independent audit adds value without needing to be a permanent arrangement.
Is this the same as a certification body audit?
No. We're not a certification body and this isn't a Stage 1 or Stage 2 audit — those are carried out by an accredited certification body and result in the certification decision. Our internal audit is the clause 9.2 activity your ISMS requires you to run yourself, which then feeds evidence into the certification body's surveillance visits.
What happens if you find nonconformities?
We record them formally, classified as major or minor against the relevant clause or control, with objective evidence. Nonconformities aren't a bad outcome — a certification body expects to see your internal audit programme finding and correcting issues. What matters is that corrective action is tracked to closure, which we help structure.
How often should internal audits run?
Enough to cover the full ISMS scope within a defined cycle, typically annually, though higher-risk areas or newly implemented controls often warrant more frequent attention. We help set an audit programme and schedule proportionate to your scope and risk profile rather than defaulting to a single annual tick-box exercise.
Will the audit report feed into management review?
Yes — that's the point. We structure findings so they can be presented directly as an input to your clause 9.3 management review, alongside other required inputs such as monitoring results, risk assessment changes and prior corrective actions, so leadership sees a coherent picture rather than a standalone document.
Do you audit against specific Annex A controls or the whole ISMS?
Both, depending on scope agreed with you. Some engagements cover the full management system across clauses 4-10 and relevant Annex A controls; others focus on a subset — for example access control and supplier relationships — where you want deeper scrutiny within a shorter cycle.
How long does an internal audit take?
A full-scope audit for a single-site ISMS typically takes one to two weeks including planning, fieldwork, reporting and a closing meeting. Focused audits against a specific clause or control set can be shorter. We agree the audit plan and timeline with you before fieldwork starts.
Compliance support
Broader framework support spanning Cyber Essentials, ISO 27001, NHS DSPT and PCI DSS.
Vulnerability management
Continuous technical assurance that provides evidence for technological control testing.
Penetration testing
Independent technical testing that strengthens the evidence base behind audit findings.
Get an independent audit that actually holds up.
Tell us your ISMS scope and where you are in the audit cycle. We'll come back with a plan and realistic timeline.
Talk to a consultant