ISO 27001 Internal Audit: A Practical Checklist Before Your Certification Audit
An ISO 27001 internal audit is the last test before an external auditor arrives, and it is where most organisations discover how much of their ISMS exists only on paper. Clause 9.2 requires audits at planned intervals, b
An ISO 27001 internal audit is the last test before an external auditor arrives, and it is where most organisations discover how much of their ISMS exists only on paper. Clause 9.2 requires audits at planned intervals, but the standard says little about how to run one that is actually useful. This is the approach we use with Australian teams.
1. Fix the scope and the criteria first
Write down what the audit covers (which sites, systems, teams and processes) and what it is measured against: the ISO/IEC 27001 clauses, your own policies and the controls in your Statement of Applicability. An audit with no stated criteria produces opinions, not findings.
2. Keep the auditor independent
Auditors cannot review their own work. In a small company that usually means a different team member or an outside consultant for the areas they normally run. Record who audited what and why they were independent.
3. Work from a checklist, but sample real evidence
A checklist keeps coverage consistent. The evidence is what matters. For each control, ask to see the record, not the policy: a signed access review, a closed change ticket, a restore test log, an onboarding checklist for a recent starter. Sample a few items rather than checking every one.
Our ISO 27001 internal audit checklist lists the clause-level questions and the evidence to request for each.
4. Check the clauses people forget
Controls get the attention, but auditors also test the management system itself:
- Is the risk assessment current, and does it match the Statement of Applicability?
- Has the risk treatment plan been approved by the risk owners?
- Are security objectives measured, and who reviewed the results?
- When was the last management review, and did it produce actions?
- Are nonconformities from the last audit closed with evidence?
5. Write findings that can be fixed
Classify each finding as a major nonconformity, minor nonconformity or opportunity for improvement. State the requirement, what you saw and the evidence. "Access reviews are inadequate" cannot be fixed. "The Q2 access review for the finance system was not performed, contrary to the access control policy" can.
6. Finish the fixes before the external audit
Assign an owner and a due date to each finding, track root cause rather than just the symptom, and keep the corrective action records. Certification bodies often ask to see the last internal audit report and how its findings were handled, so complete this before Stage 2.
Timing
Most organisations run the internal audit and management review a few weeks before the certification audit, which leaves time to fix findings. If you are still planning the certification itself, see the ISO 27001 certification overview for the typical stages.
If you would like an independent review of your ISMS before the external audit, contact Cyber Compliance Pro.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.