An ISO 27001 internal audit is a systematic, documented review of your Information Security Management System (ISMS) to verify that it is functioning as intended and conforming to the standard. It is required by clause 9.2 of ISO 27001:2022, it is a mandatory input to management review, and it is examined by your certification auditor. Getting it right is not optional — but it also does not have to be complicated.

This guide covers what an internal audit must include, the seven steps to run one, and the evidence your auditor will look for when they arrive. The stakes for getting assurance right keep rising: the ASD Annual Cyber Threat Report 2024–25 recorded over 84,700 cybercrime reports (one every 6 minutes), and data breach notifications to the OAIC hit an all-time high of 1,205 in 2025. An internal audit is how you find the gaps before an attacker or a regulator does.

What ISO 27001 Actually Requires for Internal Audits

Clause 9.2 of ISO 27001:2022 requires that internal audits are conducted at planned intervals to provide information on whether the ISMS conforms to the organisation's own requirements and to ISO 27001 requirements, and is effectively implemented and maintained.

In practical terms, this means you must:

That last point is often underweighted: the audit program itself — the plan, the schedule, the criteria — is a documented requirement, not just the findings.

The Auditor Independence Requirement

One of the most common gaps in first-time ISO 27001 internal audits is that the person who built and runs the ISMS also runs the internal audit on the ISMS. This violates the independence requirement. The standard is explicit: auditors must not audit their own work.

For most Australian SMBs, this creates a practical problem. The same person who wrote the policies is often the only person with enough context to audit them. The solutions are:

Step-by-Step: How to Run an ISO 27001 Internal Audit

1

Define the audit scope, objectives, and criteria

Decide which clauses of ISO 27001 (4–10) and which Annex A controls are in scope for this audit cycle. A risk-based audit program audits higher-risk areas more frequently — you do not need to audit everything with equal intensity every time. Document the scope in your audit plan before beginning.

2

Develop the audit checklist and interview questions

Create a structured checklist mapping each clause and control to the evidence you will seek and the questions you will ask. The checklist is not a shortcut — it is a documented audit tool and part of the audit record. Include columns for conformance status, evidence reference, and findings notes.

3

Notify stakeholders and schedule interviews

Send audit notifications to relevant process owners — typically IT, HR, legal/compliance, operations, and the ISMS owner — at least two weeks before the audit. Include the scope, what evidence will be requested, and the interview schedule. Surprises produce defensive responses; advance notice produces better evidence.

4

Conduct evidence collection and staff interviews

The audit has two components: document review and staff interviews. Document review verifies that policies, procedures, and records exist and are current. Interviews verify that the documented procedures reflect actual practice — the most common failure point. Ask process owners to walk you through what they actually do, not what the policy says.

5

Classify findings as conformance, observations, or nonconformances

Not every gap is a nonconformance. Use three categories: Conformance — the requirement is met and evidence supports it. Observation — an area for improvement that does not breach a requirement. Nonconformance — a requirement of ISO 27001 or your own ISMS is not being met. Nonconformances must further be classified as major (systemic failure) or minor (isolated failure).

6

Produce the internal audit report

The audit report documents: scope and objectives, audit methodology, who was interviewed and what evidence was reviewed, a summary of findings by clause, all nonconformances with references to the specific requirement, and the auditor's conclusion on overall conformance. This report is a mandatory input to management review and is requested by your certification auditor.

7

Track corrective actions to closure

Every nonconformance requires a documented corrective action that includes: root cause analysis, proposed fix, the person responsible, and a target completion date. The ISMS owner must track corrective actions to verified closure — not just document them and move on. Open corrective actions from internal audits are reviewed by certification auditors and will be raised if they are overdue.

What Evidence Does a Certification Auditor Examine

When your Stage 2 certification auditor (from BSI, SAI Global, Bureau Veritas, or another accredited body) arrives, they will look for specific evidence from your internal audit program:

Internal audit evidence checklist

  • Documented internal audit program (plan, schedule, criteria)
  • Internal audit checklists used for each audit
  • Audit notifications sent to process owners
  • Completed audit checklists with findings documented
  • Internal audit report with nonconformance classifications
  • Evidence of auditor independence (auditor is not the ISMS owner)
  • Corrective action records for all nonconformances
  • Evidence that corrective actions were verified as effective
  • Management review agenda and minutes referencing audit results

The Most Common Internal Audit Failures

Based on the ISO 27001 certification programs Logic Weave has run for Australian SMBs, the most common internal audit failures that lead to nonconformances at Stage 2 are:

The mindset shift: An internal audit that finds no nonconformances in a first-time ISMS is almost certainly not looking hard enough. The purpose of an internal audit is to find issues before the certification auditor does — not to confirm that everything is fine. A rigorous internal audit that surfaces genuine gaps and tracks them to resolution is a much stronger certification signal than a clean internal audit report.

Logic Weave runs ISO 27001 internal audit programs for Australian FinTech, HealthTech, and SaaS companies — including businesses going through their first certification cycle. If you want to understand what an internal audit engagement would look like for your ISMS, book a 30-minute call.

Frequently Asked Questions

How often do you need to run an ISO 27001 internal audit?

ISO 27001 requires internal audits to be conducted at planned intervals. Most Australian businesses conduct at least one full internal audit cycle per year, typically before the annual surveillance or recertification audit. Higher-risk areas may be audited more frequently. The audit program should be planned and documented — not ad hoc.

Can internal staff run an ISO 27001 internal audit?

Yes, with an important caveat: auditors must be independent of the activities they audit. This is a core requirement of ISO 27001 clause 9.2. A person cannot audit their own work. For most small Australian SMBs, this means either using a different internal team member to audit each area, or engaging an external provider to run the internal audit function.

What is the difference between an ISO 27001 internal audit and a certification audit?

An internal audit is conducted by your organisation (or an appointed external provider) to assess whether your ISMS is functioning as intended. A certification audit is conducted by an accredited external certification body (such as SAI Global, BSI, or Bureau Veritas) to independently verify conformance with the ISO 27001 standard and issue or renew your certificate. Internal audits are a mandatory prerequisite input to certification audits.

What happens if nonconformances are found in an internal audit?

Finding nonconformances is the purpose of an internal audit — it is not a failure. The requirement is that nonconformances are documented, root causes are identified, corrective actions are implemented, and the effectiveness of those corrections is verified. An internal audit that finds no nonconformances in a first-time ISMS is almost certainly not looking hard enough.