An internal audit is a management system examining itself: systematically, independently and on the record. Its purpose is to find out whether the system also works when nobody from outside is asking. ISO/IECÂ 27001 requires it in clause 9.2 at planned intervals, and with two questions in view: does the ISMS meet the organisation's own requirements and those of the standard, and is it effectively implemented and maintained?
What the standard requires
First, an audit programme that defines frequency, methods, responsibilities and reporting lines, taking into account the importance of the processes concerned and the results of earlier audits. For each individual audit, criteria and scope have to be determined. The selection of auditors has to ensure objectivity and impartiality, the results have to be reported to relevant management, and both have to be retained as documented information.
How it runs
| Step | Content |
|---|---|
| Planning | set the audit objective, criteria, scope and dates; issue the audit plan to the auditees |
| Opening | clarify the sequence, confidentiality and how findings will be handled |
| Fieldwork | interviews, inspection of records, sampling, observation on site |
| Evaluation | hold the evidence against the criteria, classify the findings |
| Closing | discuss results and classification with the auditees |
| Report | findings, the underlying evidence, the assessment, items still open |
| Follow-up | agree corrective actions and check that they worked |
The step most often missing is the last one. An audit with no tracked actions produces documentation but no improvement.
Independence in small organisations
Nobody may audit their own work. In smaller organisations that can be solved by having departments audit each other, by a second independent role, or by engaging external auditors. The classification matters: an audit performed by an external party is still an internal audit as long as the organisation commissions it and is responsible for it. A certification audit does not replace it — the standard requires both alongside each other.
Test effectiveness, not completeness
The difference between a useful audit and one without consequence lies in the question asked. Whether a policy exists is settled in minutes. Whether it is lived shows only in samples from live operation: in approvals that were actually obtained, in access rights withdrawn after someone left, in exceptions that are documented and time-limited. ISOÂ 19011 is the established guidance for planning and performing management system audits; in an ISMS the selection of test points is usually oriented on the Statement of Applicability and on the risk treatment.
Classifying findings
The usual distinction is between major nonconformity, minor nonconformity, and observation or recommendation. A major nonconformity means a requirement is not met; a minor one describes an isolated weakness. Every finding needs the evidence it rests on, a named owner and a deadline. On classification, one rule holds: it should follow the same logic as in the certification audit, otherwise the external result comes as a surprise.
Common weaknesses
- The audit programme covers the same low-criticality areas year after year.
- Auditors examine documents rather than records from live operation.
- Findings are softened to avoid conflict.
- The audit report reaches management only together with the management review, by which point it can no longer be acted on.
- Auditors examine areas they helped build.