FAQGlobalISO/IEC 27001

ISO/IEC 27001 FAQ Internal Audit

How should teams run Internal Audits under ISO/IEC 27001:2022 Information Security Management System?

Plan the programme around process importance and earlier results, protect auditor objectivity, report results to relevant management, and retain the programme and audit results.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Questions
4

Structured answer sets in this page tree.

Primary sources
5

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

An ISO/IEC 27001 checks whether the ISMS conforms to the organization's own requirements and ISO/IEC 27001, and whether it is effectively implemented and maintained. The organization must run audits at planned intervals, define criteria and scope for each audit, protect objectivity and impartiality, report results to relevant management, and retain evidence of the programme and results.

Search this module

Find a question or answer quickly

4 of 4 questions
Question 1

What must happen before, during, and after an internal audit?

Build an audit programme that states frequency, methods, responsibilities, planning requirements, and reporting. Consider the importance of each process and previous audit results rather than defaulting to equal annual coverage.

For each audit, define the and scope before testing. Collect through records, observation, interviews, demonstrations, and samples; report the results to relevant management; then handle confirmed nonconformities through the corrective-action process.

  • State the audit objective, criteria, scope, method, sample basis, auditor, timing, and reporting path.
  • Choose coverage using process importance, change, risk, and previous results; ISO/IEC 27001 does not prescribe an annual cycle.
  • Separate audit judgment from responsibility for the activity being audited wherever needed to ensure objectivity and impartiality.
  • Example: after a major identity-platform change or repeated access-review failure, bring that process forward in the programme and increase the sample. A stable low-change process with clean earlier results may be audited later, provided the programme still gives adequate ISMS coverage.
Citations
ISO/IEC 27001:2022 standard page

ISO/IEC 27001:2022 clauses 9.2.1 and 9.2.2 define the internal-audit purpose, programme, criteria, scope, auditor objectivity, reporting, and documented-information requirements.

ISO/IEC 27005:2022 standard page

ISO/IEC 27005:2022 provides risk-management guidance that can help prioritize audit coverage, while ISO/IEC 27001 remains the requirements source.

Question 2

What evidence makes an internal audit auditable?

Retain evidence that the audit programme was implemented and the audit results. A usable audit file identifies the criteria and scope, auditor, dates, methods, samples, evidence examined, conclusions, and reported findings.

A finding should distinguish a from an observation or improvement suggestion. ISO/IEC 27001 requires action on nonconformities; labels such as observation or opportunity for improvement come from the organization's audit method and should not be used to weaken a failure to meet a requirement. For a nonconformity, link the unmet requirement and evidence to correction, cause analysis, , and the later effectiveness review required by Clause 10.2.

  • Keep the approved programme, audit plan, working papers needed to support conclusions, report, and distribution record.
  • Record enough sample detail to reproduce the test without copying sensitive logs or personal data unnecessarily.
  • Track each confirmed to the requirement, evidence, owner, correction, cause, , due date, and effectiveness result.
Citations
ISO/IEC 27002:2022 standard page

ISO/IEC 27002:2022 can help auditors understand control intent and implementation guidance, but audit criteria must come from the defined ISMS requirements and audit scope.

ISO/IEC 27001:2022 standard page

ISO/IEC 27001:2022 clauses 9.2.2 and 10.2 require evidence of the audit programme and results and define the response to nonconformity and corrective action.

Question 3

Who should review and approve internal-audit findings?

The auditor forms and reports the audit conclusion; relevant management receives the results. The process owner normally owns correction and , while someone able to make an objective judgment verifies completion and effectiveness under the organization's procedure.

Do not close a because a due date passed or a document was uploaded. Confirm the immediate correction, assess the cause and whether the issue could exist elsewhere, implement any needed , and review its effectiveness. For example, correcting one missing approval fixes the sampled record; changing the workflow and then testing later approvals may address and verify the systemic cause.

  • Record each finding with owner, risk impact, decision date, and remediation proof.
  • Separate independent audit team responsibilities from implementation ownership.
  • Include audit-result trends and material unresolved findings in management-review inputs.
Citations
ISO/IEC 27001:2022 standard page

ISO/IEC 27001:2022 requires audit results to be reported to relevant management, corrective-action effectiveness to be reviewed, and audit-result trends to be considered in management review.

Question 4

How often should internal audits and their outcomes be rechecked?

ISO/IEC 27001 requires internal audits at planned intervals but sets no universal annual frequency. Set the programme so the organization can judge conformity and effective implementation across the ISMS, using process importance and previous results to decide timing and coverage.

A major change, incident, repeated failure, overdue , or new risk may justify an additional or earlier audit. That is a risk-based programme decision, not a separate fixed timetable imposed by the standard.

  • Use calendar review dates plus change-trigger reviews for incidents, context shifts, or contractual scope changes.
  • Re-verify closed findings after remediation evidence is produced, not after the target date alone.
  • Track all unresolved findings in governance to prevent drift between audit cycles.
Citations
Primary sources

References and citations

iafcertsearch.org
Referenced sections
  • Public IAF certification database used to verify and monitor management-system certifications.
"verify and monitor certifications"
iso.org
Referenced sections
  • This source is the governing requirements context for ISO/IEC 27001 scope, control governance, and review cadence in ISMS operations.
"Information security management systems — Requirements"
iso.org
Referenced sections
  • This source supports control implementation guidance and control-implementation expectations supporting ISO/IEC 27001 governance.
"Information security controls"
iso.org
Referenced sections
  • ISO/IEC 27005:2022 provides risk-management guidance that can help prioritize audit coverage, while ISO/IEC 27001 remains the requirements source.
"Guidance on managing information security risks"
iso.org
Referenced sections
  • Primary ISO listing for requirements that apply to bodies auditing and certifying ISO/IEC 27001 information security management systems.
"audit and certification"
Related guides

Explore more topics

ISO/IEC 27001 Annex A Control Evidence Guide
Build useful ISO/IEC 27001:2022 Annex A control evidence: selected controls, SoA rationale, owners, implementation proof, effectiveness checks, audit records, and improvement actions.
ISO/IEC 27001 Annex A Control Ownership FAQ
How to assign practical owners for ISO/IEC 27001 Annex A controls without confusing control ownership with the standard's required risk-owner accountability.
ISO/IEC 27001 Audit Readiness Guide
Prepare ISO/IEC 27001 audit evidence across ISMS scope, risk assessment, risk treatment, Statement of Applicability, Annex A controls, internal audit, management review, and corrective actions.
ISO/IEC 27001 Certification Body Evidence FAQ
What ISO/IEC 27001 certification auditors may sample, how to connect requirements to operating evidence, and what the certification body does not own.
ISO/IEC 27001 Certification Stage Workflow
Plan optional ISO/IEC 27001 certification from scope readiness through Stage 1, Stage 2, findings, certification decision, surveillance, and recertification.
ISO/IEC 27001 Compliance Guide: ISMS Evidence
Build ISO/IEC 27001:2022 conformity evidence for ISMS scope, leadership, risk assessment and treatment, the Statement of Applicability, operations, audits, management review, and corrective action.
ISO/IEC 27001 FAQ: ISMS Scope, Risk and SoA
Practical ISO/IEC 27001 FAQ covering ISMS scope, risk assessment, risk treatment, Statement of Applicability, Annex A controls, certification evidence, audits, management review, and surveillance readiness.
ISO/IEC 27001 Implementation Roadmap Guide
A practical ISO/IEC 27001:2022 roadmap from context and scope through risk treatment, the SoA, control operation, internal audit, management review, corrective action, and optional certification.
ISO/IEC 27001 Internal Audit and Management Review Guide
Keep ISO/IEC 27001 internal audit and management review distinct and connected: independent audit evidence, top-management decisions, corrective actions, resources, and improvement records.
ISO/IEC 27001 Management Review FAQ
What ISO/IEC 27001 management review must consider, what top management must decide, what evidence to retain, and how to set the cadence.
ISO/IEC 27001 Requirements Guide
Plain-language guide to ISO/IEC 27001:2022 Clauses 4-10: context, leadership, planning, support, operation, performance evaluation, improvement, and Annex A control selection.
ISO/IEC 27001 Risk Acceptance FAQ
How ISO/IEC 27001 risk acceptance works: criteria, risk-owner approval, residual-risk evidence, external obligations, and reassessment triggers.
ISO/IEC 27001 Risk Treatment and Residual Risk Guide
Connect ISO/IEC 27001 risk-treatment choices, necessary controls, the treatment plan, Statement of Applicability, residual-risk acceptance, owners, evidence, and review triggers.
ISO/IEC 27001 Risk Treatment Register Workflow
Build an ISO/IEC 27001 risk-treatment register that links assessed risks to treatment options, controls, SoA entries, actions, owners, residual-risk approval, evidence, and review triggers.
ISO/IEC 27001 SoA Exclusions FAQ
How should teams justify Statement of Applicability exclusions under ISO/IEC 27001? Practical answer with owners, evidence, review triggers, and external source references.
ISO/IEC 27001 SoA: workflow for gathering and documenting control evidence
Operate the ISO/IEC 27001 Statement of Applicability as a live evidence index linking necessary controls, Annex A inclusion and exclusion rationale, implementation status, owners, and proof.
ISO/IEC 27001 Statement of Applicability template: Annex A control selection and justification
Practical ISO/IEC 27001:2022 Statement of Applicability template fields for necessary controls, Annex A applicability, inclusion and exclusion rationale, status, owners, evidence, and review history.
ISO/IEC 27001 Surveillance Audits FAQ
What ISO/IEC 27001 surveillance audits check, how they differ from internal audit and recertification, and what evidence to maintain between audits.
ISO/IEC 27001 vs NIS2 Comparison
Compare voluntary ISO/IEC 27001 ISMS conformity and optional certification with NIS2 legal duties, entity scope, management accountability, incident reporting, supervision, and penalties.
ISO/IEC 27001 vs NIST CSF 2.0 Comparison
Compare ISO/IEC 27001:2022's certifiable ISMS requirements with NIST CSF 2.0's cybersecurity outcomes, Profiles, Tiers, Functions, evidence uses, and adoption choices.
ISO/IEC 27001 vs SOC 2 Comparison
Compare ISO/IEC 27001 certification with SOC 2 examination reports: criteria, scope, assurance period, auditor and certification-body roles, deliverables, evidence reuse, and claim limits.