Auditor reviewing evidence logs during an ISMS internal audit
ISO 27001 internal audit

The clause 9.2 audit your ISMS requires, run by someone genuinely independent.

ISO/IEC 27001:2022 requires internal audits carried out by someone free from bias about the area being reviewed. We deliver that independence, with findings structured to feed directly into your management review and corrective action process.

Clauses & controls in scope
Full ISMS
Typical nonconformities
3-8
Fieldwork duration
5-10
Illustrative figures
The challenge

Auditing your own department rarely stands up to scrutiny.

Clause 9.2 of ISO/IEC 27001:2022 is specific: internal audits must be objective and impartial, carried out by auditors who don't audit their own work. In smaller organisations the person who manages information security is often the only one with the knowledge to audit it — which puts them in an impossible position, auditing decisions they made themselves.

Certification bodies notice this. A surveillance auditor reviewing a thin, self-marked internal audit report with no nonconformities raised, ever, tends to ask harder questions than one reviewing a properly independent audit that found and closed real issues.

There's also a competence problem. Running a credible ISMS audit means understanding the standard's clause structure, sampling technique, evidence gathering and how to write a finding that's defensible rather than vague. That's a specific skill set, distinct from managing security operations day to day.

Left unaddressed, this shows up as an internal audit programme that exists on paper — a spreadsheet with dates and a tick — but doesn't generate anything a management review can meaningfully act on. That weakens the whole continual improvement cycle the standard is built around.

The commercial risk is real too: a certification body can raise a nonconformity against the internal audit process itself if it isn't demonstrably independent and effective, which is a harder finding to explain to a customer than almost any other.

  • No one internally with both the independence and the audit skill set to review the ISMS
  • Internal audits that never raise nonconformities, which reads as a red flag rather than reassurance
  • Findings not structured in a way management review can actually use
  • Audit programme covers the same easy areas every cycle, avoiding the harder ones
  • Corrective actions logged but never tracked through to verified closure
Our approach

A properly planned, evidenced audit — not a box-ticking visit.

We start by agreeing the audit programme and scope with you: which clauses, which Annex A controls, and which parts of the organisation are in scope for this cycle, based on risk and what's changed since the last audit.

Fieldwork follows standard audit method — document review, sampling of records and evidence, and interviews with control owners — testing whether what's written down matches what actually happens. We're not looking to catch people out; we're testing conformity and effectiveness the same way a certification body auditor would.

Every finding is recorded with objective evidence and classified against the relevant clause or control, distinguishing genuine nonconformities from observations and opportunities for improvement. Vague findings help nobody, so we're specific about what was seen and against what requirement it falls short.

We close the audit with a meeting to walk through findings before the report is finalised, so there's no ambush and control owners understand what corrective action is expected of them.

The final report is structured to be usable directly as a management review input under clause 9.3, alongside your other required inputs, so leadership gets a coherent view of ISMS performance rather than a document that sits separately from governance.

Where you want it, we can also help set or refresh a multi-year internal audit programme so the whole ISMS scope gets covered on a sensible cycle rather than the same easy areas being revisited every year.

  • Audit plan and scope agreed against risk and prior findings
  • Evidence-based fieldwork: document review, sampling and interviews
  • Findings classified as major nonconformity, minor nonconformity or observation
  • Closing meeting before the report is finalised
  • Report structured as a direct management review input
What's included

Everything in the engagement, set out up front.

Scope is agreed before fieldwork begins, whether that's the full ISMS or a focused set of clauses and controls.

Audit planning

Scope, criteria and schedule agreed with you, referencing prior audits and risk changes.

Document and record review

Policies, procedures and operational records sampled against clause and control requirements.

Control owner interviews

Structured conversations testing whether documented practice matches operational reality.

Nonconformity classification

Findings recorded with objective evidence and classified as major, minor or observation.

Closing meeting

Findings walked through with stakeholders before the report is finalised, avoiding surprises.

Corrective action support

Guidance on root cause analysis and tracking actions through to verified closure.

Deliverables

What you receive.

  • Audit plan and criteria document
  • Fieldwork evidence log
  • Nonconformity and observation register
  • Classified findings with clause/control references
  • Closing meeting minutes
  • Management review-ready summary report
  • Corrective action tracking template
  • Recommendations for the next audit cycle
Who it suits

Built for organisations that need the work done properly.

Organisations without internal audit competence

You have security capability but no one qualified or independent enough to audit it credibly.

Teams preparing for a surveillance audit

You want a realistic dry run and evidence trail before your certification body's next visit.

Businesses with a stalled audit programme

Internal audits have lapsed or become superficial, and you need to demonstrate the process is working again.

Organisations wanting objectivity on a sensitive area

You need an independent view of a specific control area — access management, supplier risk, incident response — free from internal politics.

Outcomes & benefits

What changes once the work is done.

An internal audit only earns its place in the ISMS if it changes something afterwards — these are the changes we aim for.

Defensible independence

An audit trail showing genuinely independent review, not a self-marked exercise.

Usable management review input

Findings structured to slot straight into your clause 9.3 process.

Real nonconformities, properly tracked

Issues surfaced and logged with a clear path to verified closure.

Stronger surveillance audit outcomes

Fewer gaps left for a certification body auditor to find first.

A credible audit programme

Coverage planned across cycles rather than repeating the same easy scope.

Confidence for leadership

A clear, evidenced view of whether the ISMS is actually working, not just documented.

How this fits with the wider ISMS audit cycle.

Clause 9.2 internal audits sit between two other mandatory activities: the risk assessment and treatment process that defines what should be controlled, and the clause 9.3 management review where leadership decides what to do about audit findings, performance data and changing risk. An internal audit that isn't connected to both ends is just a paperwork exercise.

We're careful to distinguish our role from that of an accredited certification body. Certification bodies conduct Stage 1 and Stage 2 audits and ongoing surveillance visits, and only they can issue or maintain a certificate. Our internal audits are the evidence-generating activity that happens between those visits, owned by you, delivered independently on your behalf.

Done well, a mature internal audit programme becomes one of the more persuasive pieces of evidence a certification body sees, because it demonstrates the ISMS is actively managed rather than assembled once for a certification decision and left untouched.

We typically recommend clients treat the first year or two of internal audits as a genuine capability-building exercise — refining audit criteria, sampling approach and reporting format — rather than expecting a perfect, low-friction process from the first cycle.

Frequently asked questions

Questions we are asked most often.

Why does ISO 27001 require an internal audit?

Clause 9.2 requires organisations to audit their ISMS at planned intervals to check it conforms to their own requirements and to ISO/IEC 27001:2022, and that it's effectively implemented and maintained. It's a mandatory input to management review under clause 9.3 and to the certification body's ongoing surveillance audits.

Can we run internal audits ourselves?

Yes, provided the auditor is independent of the area being audited and has appropriate competence — clause 9.2 doesn't require an external party. Many smaller organisations lack the internal capacity or objectivity to audit their own security function convincingly, which is where an independent audit adds value without needing to be a permanent arrangement.

Is this the same as a certification body audit?

No. We're not a certification body and this isn't a Stage 1 or Stage 2 audit — those are carried out by an accredited certification body and result in the certification decision. Our internal audit is the clause 9.2 activity your ISMS requires you to run yourself, which then feeds evidence into the certification body's surveillance visits.

What happens if you find nonconformities?

We record them formally, classified as major or minor against the relevant clause or control, with objective evidence. Nonconformities aren't a bad outcome — a certification body expects to see your internal audit programme finding and correcting issues. What matters is that corrective action is tracked to closure, which we help structure.

How often should internal audits run?

Enough to cover the full ISMS scope within a defined cycle, typically annually, though higher-risk areas or newly implemented controls often warrant more frequent attention. We help set an audit programme and schedule proportionate to your scope and risk profile rather than defaulting to a single annual tick-box exercise.

Will the audit report feed into management review?

Yes — that's the point. We structure findings so they can be presented directly as an input to your clause 9.3 management review, alongside other required inputs such as monitoring results, risk assessment changes and prior corrective actions, so leadership sees a coherent picture rather than a standalone document.

Do you audit against specific Annex A controls or the whole ISMS?

Both, depending on scope agreed with you. Some engagements cover the full management system across clauses 4-10 and relevant Annex A controls; others focus on a subset — for example access control and supplier relationships — where you want deeper scrutiny within a shorter cycle.

How long does an internal audit take?

A full-scope audit for a single-site ISMS typically takes one to two weeks including planning, fieldwork, reporting and a closing meeting. Focused audits against a specific clause or control set can be shorter. We agree the audit plan and timeline with you before fieldwork starts.

Get an independent audit that actually holds up.

Tell us your ISMS scope and where you are in the audit cycle. We'll come back with a plan and realistic timeline.

Talk to a consultant