ISO 27001 Internal Audit

ISO 27001 Internal Audit 101: Catch the Gaps Before Your Auditor Does


Published 08/02/2026

Getting ISO 27001 certified, or maintaining certification once you have it, depends on one critical process: the internal audit. It's the mechanism that proves your Information Security Management System isn't just documented, but actually working as intended. Skip it, rush it, or do it poorly, and certification bodies will notice long before your customers do.

Here's what an ISO 27001 internal audit actually involves, and how to make sure yours holds up.

View Information Security Management System

What Is an ISO 27001 Internal Audit?

An ISO 27001 internal audit is a systematic, independent review of an organization's Information Security Management System to confirm it meets the requirements of the ISO/IEC 27001 standard and is functioning effectively in practice. Unlike an external certification audit, which is conducted by an accredited third party, an internal audit is typically performed by internal staff or a qualified consultant on behalf of the organization.

It's a mandatory requirement under Clause 9.2 of the standard. Organizations must conduct these audits at planned intervals to verify that security controls are properly implemented, policies are being followed, and the ISMS continues to meet its stated objectives.

Think of it as a health check. It identifies weaknesses before an external auditor does, giving the organization a chance to fix issues proactively rather than fail certification or lose it during a surveillance audit.

Why the ISO 27001 Internal Audit Matters

An internal audit isn't just a box to check for certification. It serves several important purposes.

It catches problems early. A well-run audit identifies gaps internally so they can be corrected before an external auditor flags them as nonconformities.

It confirms real-world effectiveness. Policies can look great on paper but fail in practice. The audit tests whether controls are actually being followed day to day.

It supports continuous improvement. ISO 27001 is built around the idea that an ISMS should evolve, and internal audits provide the evidence needed to refine and strengthen the system over time.

It reduces certification risk. Organizations that skip or rush this process are far more likely to encounter major nonconformities during external assessments.

It builds organizational accountability. Regular audits keep departments and employees engaged with security responsibilities instead of treating the ISMS as a one-time project.

How the ISO 27001 Internal Audit Process Works

While the specifics can vary by organization, most internal audits follow a similar structured process.

1. Audit Planning
Define the scope, objectives, and criteria for the audit. Determine which departments, processes, or controls will be reviewed and set a realistic timeline.

2. Auditor Assignment
Select auditors who are independent of the area being audited. This is a key requirement of the standard. Auditors should not review their own work to ensure objectivity.

3. Document Review
Examine existing policies, procedures, risk assessments, and records to check whether documentation aligns with actual practices and ISO 27001 requirements.

4. On-Site or Remote Assessment
Interview staff, observe processes, and test controls directly. This might include reviewing access logs, testing incident response procedures, or verifying employee training records.

5. Identifying Nonconformities
Document any gaps, weaknesses, or areas where the ISMS doesn't meet ISO 27001 requirements or internal policy commitments. These are typically categorized as major or minor nonconformities.

6. Reporting Findings
Compile a formal report outlining what was reviewed, what was found, and recommended corrective actions.

7. Corrective Action and Follow-Up
Address identified issues through a documented corrective action process, then verify the fixes were effective, often during the next audit cycle.

What ISO 27001 Auditors Typically Look For

ISO 27001 internal auditors focus on several key areas during their review:

Policy alignment. Are documented policies consistent with actual day-to-day practices across the organization?

Risk management. Has the organization properly identified, assessed, and treated information security risks?

Access controls. Are permissions granted, reviewed, and revoked appropriately, and is access limited to those who genuinely need it?

Incident management. Does the organization have a functioning process for detecting, reporting, and responding to security incidents?

Employee awareness. Do staff understand their security responsibilities, and has appropriate training been completed and documented?

Evidence and documentation. Is there sufficient evidence, such as logs, records, and reports, to demonstrate that controls are actually being followed?

How to Prepare for an ISO 27001 Internal Audit

Preparation makes the difference between a smooth audit and a stressful one. Here's how to get ready:

1. Keep documentation current. Outdated policies or unreviewed risk assessments are among the most common findings.

2. Conduct regular self-checks. Don't wait for the formal audit to review controls. Ongoing monitoring makes the real thing far less disruptive.

3. Train employees ahead of time. Make sure staff understand relevant policies and can speak confidently about their responsibilities if interviewed.

4. Address previous findings. If a prior audit identified issues, ensure corrective actions have been fully implemented and documented.

5. Use a checklist aligned with ISO 27001 clauses. Structuring your preparation around the standard's requirements helps ensure nothing is overlooked.

6. Involve leadership. Management review is a required part of ISO 27001, and leadership engagement signals that this is a genuine organizational priority, not just a formality.

Take the Next Step

An ISO 27001 internal audit doesn't have to be a stressful, once-a-year scramble. With the right tools and guidance, it can become a routine, manageable part of maintaining a strong information security program.

Sign up today and get access to internal audit templates, checklists, and expert guidance built specifically for ISO 27001, so your organization stays audit-ready all year round.

Discover our ISO Audit Management Tool


View ISMS Templates, Forms and Examples


Get Started Free
Create your first Incident Report form or choose from our form templates and start recording incidents in the field