An ISO 27001 internal audit is a systematic, documented review of your Information Security Management System (ISMS) to verify that it is functioning as intended and conforming to the standard. It is required by clause 9.2 of ISO 27001:2022, it is a mandatory input to management review, and it is examined by your certification auditor. Getting it right is not optional — but it also does not have to be complicated.
This guide covers what an internal audit must include, the seven steps to run one, and the evidence your auditor will look for when they arrive. The stakes for getting assurance right keep rising: the ASD Annual Cyber Threat Report 2024–25 recorded over 84,700 cybercrime reports (one every 6 minutes), and data breach notifications to the OAIC hit an all-time high of 1,205 in 2025. An internal audit is how you find the gaps before an attacker or a regulator does.
What ISO 27001 Actually Requires for Internal Audits
Clause 9.2 of ISO 27001:2022 requires that internal audits are conducted at planned intervals to provide information on whether the ISMS conforms to the organisation's own requirements and to ISO 27001 requirements, and is effectively implemented and maintained.
In practical terms, this means you must:
- Establish, implement, and maintain an audit program — not just conduct audits ad hoc.
- Define audit criteria, scope, frequency, and methods for each audit.
- Select auditors who are independent of the activities being audited.
- Report audit results to relevant management.
- Retain documented information as evidence of the audit program and results.
That last point is often underweighted: the audit program itself — the plan, the schedule, the criteria — is a documented requirement, not just the findings.
The Auditor Independence Requirement
One of the most common gaps in first-time ISO 27001 internal audits is that the person who built and runs the ISMS also runs the internal audit on the ISMS. This violates the independence requirement. The standard is explicit: auditors must not audit their own work.
For most Australian SMBs, this creates a practical problem. The same person who wrote the policies is often the only person with enough context to audit them. The solutions are:
- Rotate responsibilities: Have different team members audit different areas, even if it requires some cross-training.
- Engage an external auditor: An external provider who runs the internal audit function satisfies independence requirements while bringing framework expertise. This is the approach most Logic Weave clients take — we run the internal audit so the in-house team is not marking its own homework.
Step-by-Step: How to Run an ISO 27001 Internal Audit
Define the audit scope, objectives, and criteria
Decide which clauses of ISO 27001 (4–10) and which Annex A controls are in scope for this audit cycle. A risk-based audit program audits higher-risk areas more frequently — you do not need to audit everything with equal intensity every time. Document the scope in your audit plan before beginning.
Develop the audit checklist and interview questions
Create a structured checklist mapping each clause and control to the evidence you will seek and the questions you will ask. The checklist is not a shortcut — it is a documented audit tool and part of the audit record. Include columns for conformance status, evidence reference, and findings notes.
Notify stakeholders and schedule interviews
Send audit notifications to relevant process owners — typically IT, HR, legal/compliance, operations, and the ISMS owner — at least two weeks before the audit. Include the scope, what evidence will be requested, and the interview schedule. Surprises produce defensive responses; advance notice produces better evidence.
Conduct evidence collection and staff interviews
The audit has two components: document review and staff interviews. Document review verifies that policies, procedures, and records exist and are current. Interviews verify that the documented procedures reflect actual practice — the most common failure point. Ask process owners to walk you through what they actually do, not what the policy says.
Classify findings as conformance, observations, or nonconformances
Not every gap is a nonconformance. Use three categories: Conformance — the requirement is met and evidence supports it. Observation — an area for improvement that does not breach a requirement. Nonconformance — a requirement of ISO 27001 or your own ISMS is not being met. Nonconformances must further be classified as major (systemic failure) or minor (isolated failure).
Produce the internal audit report
The audit report documents: scope and objectives, audit methodology, who was interviewed and what evidence was reviewed, a summary of findings by clause, all nonconformances with references to the specific requirement, and the auditor's conclusion on overall conformance. This report is a mandatory input to management review and is requested by your certification auditor.
Track corrective actions to closure
Every nonconformance requires a documented corrective action that includes: root cause analysis, proposed fix, the person responsible, and a target completion date. The ISMS owner must track corrective actions to verified closure — not just document them and move on. Open corrective actions from internal audits are reviewed by certification auditors and will be raised if they are overdue.
What Evidence Does a Certification Auditor Examine
When your Stage 2 certification auditor (from BSI, SAI Global, Bureau Veritas, or another accredited body) arrives, they will look for specific evidence from your internal audit program:
Internal audit evidence checklist
- Documented internal audit program (plan, schedule, criteria)
- Internal audit checklists used for each audit
- Audit notifications sent to process owners
- Completed audit checklists with findings documented
- Internal audit report with nonconformance classifications
- Evidence of auditor independence (auditor is not the ISMS owner)
- Corrective action records for all nonconformances
- Evidence that corrective actions were verified as effective
- Management review agenda and minutes referencing audit results
The Most Common Internal Audit Failures
Based on the ISO 27001 certification programs Logic Weave has run for Australian SMBs, the most common internal audit failures that lead to nonconformances at Stage 2 are:
- No documented audit program. Running an audit without a documented plan is itself a nonconformance against clause 9.2.1.
- Auditor auditing their own work. The most common independence violation — addressed above.
- Audit that only reviews documents, not practice. ISO 27001 requires that the ISMS is effectively implemented — document review alone cannot verify this.
- Nonconformances with no corrective actions. Finding a gap without tracking a fix is not a complete internal audit.
- Corrective actions that address symptoms, not root causes. Clause 10.1 requires root cause analysis. Updating a policy without understanding why the gap occurred is unlikely to prevent recurrence.
- Internal audit results not presented to management review. Clause 9.3 requires management review to consider internal audit results. The link between the two must be documented.
The mindset shift: An internal audit that finds no nonconformances in a first-time ISMS is almost certainly not looking hard enough. The purpose of an internal audit is to find issues before the certification auditor does — not to confirm that everything is fine. A rigorous internal audit that surfaces genuine gaps and tracks them to resolution is a much stronger certification signal than a clean internal audit report.
Logic Weave runs ISO 27001 internal audit programs for Australian FinTech, HealthTech, and SaaS companies — including businesses going through their first certification cycle. If you want to understand what an internal audit engagement would look like for your ISMS, book a 30-minute call.
Frequently Asked Questions
How often do you need to run an ISO 27001 internal audit?
ISO 27001 requires internal audits to be conducted at planned intervals. Most Australian businesses conduct at least one full internal audit cycle per year, typically before the annual surveillance or recertification audit. Higher-risk areas may be audited more frequently. The audit program should be planned and documented — not ad hoc.
Can internal staff run an ISO 27001 internal audit?
Yes, with an important caveat: auditors must be independent of the activities they audit. This is a core requirement of ISO 27001 clause 9.2. A person cannot audit their own work. For most small Australian SMBs, this means either using a different internal team member to audit each area, or engaging an external provider to run the internal audit function.
What is the difference between an ISO 27001 internal audit and a certification audit?
An internal audit is conducted by your organisation (or an appointed external provider) to assess whether your ISMS is functioning as intended. A certification audit is conducted by an accredited external certification body (such as SAI Global, BSI, or Bureau Veritas) to independently verify conformance with the ISO 27001 standard and issue or renew your certificate. Internal audits are a mandatory prerequisite input to certification audits.
What happens if nonconformances are found in an internal audit?
Finding nonconformances is the purpose of an internal audit — it is not a failure. The requirement is that nonconformances are documented, root causes are identified, corrective actions are implemented, and the effectiveness of those corrections is verified. An internal audit that finds no nonconformances in a first-time ISMS is almost certainly not looking hard enough.