Internal Audit

An internal audit is the systematic, independently conducted and documented examination of whether a management system meets the organisation’s own requirements and those of the underlying standard, and is effectively implemented. ISO/IEC 27001 requires it in clause 9.2 at planned intervals. The organisation itself is responsible for it, not the certification body.

ISO 27001Last reviewed:

An internal audit is a management system examining itself: systematically, independently and on the record. Its purpose is to find out whether the system also works when nobody from outside is asking. ISO/IEC 27001 requires it in clause 9.2 at planned intervals, and with two questions in view: does the ISMS meet the organisation's own requirements and those of the standard, and is it effectively implemented and maintained?

What the standard requires

First, an audit programme that defines frequency, methods, responsibilities and reporting lines, taking into account the importance of the processes concerned and the results of earlier audits. For each individual audit, criteria and scope have to be determined. The selection of auditors has to ensure objectivity and impartiality, the results have to be reported to relevant management, and both have to be retained as documented information.

How it runs

StepContent
Planningset the audit objective, criteria, scope and dates; issue the audit plan to the auditees
Openingclarify the sequence, confidentiality and how findings will be handled
Fieldworkinterviews, inspection of records, sampling, observation on site
Evaluationhold the evidence against the criteria, classify the findings
Closingdiscuss results and classification with the auditees
Reportfindings, the underlying evidence, the assessment, items still open
Follow-upagree corrective actions and check that they worked

The step most often missing is the last one. An audit with no tracked actions produces documentation but no improvement.

Independence in small organisations

Nobody may audit their own work. In smaller organisations that can be solved by having departments audit each other, by a second independent role, or by engaging external auditors. The classification matters: an audit performed by an external party is still an internal audit as long as the organisation commissions it and is responsible for it. A certification audit does not replace it — the standard requires both alongside each other.

Test effectiveness, not completeness

The difference between a useful audit and one without consequence lies in the question asked. Whether a policy exists is settled in minutes. Whether it is lived shows only in samples from live operation: in approvals that were actually obtained, in access rights withdrawn after someone left, in exceptions that are documented and time-limited. ISO 19011 is the established guidance for planning and performing management system audits; in an ISMS the selection of test points is usually oriented on the Statement of Applicability and on the risk treatment.

Classifying findings

The usual distinction is between major nonconformity, minor nonconformity, and observation or recommendation. A major nonconformity means a requirement is not met; a minor one describes an isolated weakness. Every finding needs the evidence it rests on, a named owner and a deadline. On classification, one rule holds: it should follow the same logic as in the certification audit, otherwise the external result comes as a surprise.

Common weaknesses

  • The audit programme covers the same low-criticality areas year after year.
  • Auditors examine documents rather than records from live operation.
  • Findings are softened to avoid conflict.
  • The audit report reaches management only together with the management review, by which point it can no longer be acted on.
  • Auditors examine areas they helped build.
Browse all entriesBack to top

Frequently asked questions

See compliance run on your real assets

Rizzqo turns framework requirements into owned tasks on the assets you already have, and prices the risk in real money.

Made in GermanyEU-hostedMulti-framework