What must happen before, during, and after an internal audit?
Build an audit programme that states frequency, methods, responsibilities, planning requirements, and reporting. Consider the importance of each process and previous audit results rather than defaulting to equal annual coverage.
For each audit, define the and scope before testing. Collect through records, observation, interviews, demonstrations, and samples; report the results to relevant management; then handle confirmed nonconformities through the corrective-action process.
- State the audit objective, criteria, scope, method, sample basis, auditor, timing, and reporting path.
- Choose coverage using process importance, change, risk, and previous results; ISO/IEC 27001 does not prescribe an annual cycle.
- Separate audit judgment from responsibility for the activity being audited wherever needed to ensure objectivity and impartiality.
- Example: after a major identity-platform change or repeated access-review failure, bring that process forward in the programme and increase the sample. A stable low-change process with clean earlier results may be audited later, provided the programme still gives adequate ISMS coverage.
ISO/IEC 27001:2022 clauses 9.2.1 and 9.2.2 define the internal-audit purpose, programme, criteria, scope, auditor objectivity, reporting, and documented-information requirements.
ISO/IEC 27005:2022 provides risk-management guidance that can help prioritize audit coverage, while ISO/IEC 27001 remains the requirements source.