Home / Services / ISO 27001 Internal Audit
ISO 27001 · Clause 9.2

ISO 27001 internal audits, run independently, every year.

Clause 9.2 requires an internal audit of your ISMS at least annually, performed independently of the team being audited. We run it for you, a service the standard explicitly permits us to deliver directly, unlike the certification audit itself.

Clause 9.2 Internal AuditIndependent of your operations
Certification-body ready reports
UK · US · EU auditors
Who it's for

Who this is for

This service suits two groups. The first is companies already certified to ISO 27001 who have discovered that clause 9.2 requires an internal audit programme every year, and that running it credibly in house is harder than it looked. The second is companies heading toward first certification who need an internal audit completed before the Stage 2 audit, because a certification body will ask to see one and its absence is a straightforward nonconformity. If you have a small team where everyone owns some part of the ISMS, the independence requirement alone makes an external internal auditor the practical answer.

What's included

Scope, in plain terms.

IA-01 Scope

Full Annex A Coverage

Every applicable Annex A control tested against real evidence, not a checkbox tick: access reviews, change logs, supplier contracts, incident tickets.

IA-02 Scope

Audit Programme & Schedule

A rolling internal audit programme aligned to your certification cycle, so no domain goes untested between certification audits.

IA-03 Deliverable

Findings Register

Every nonconformity and observation logged with severity, root cause and a remediation owner, the exact format your certification body expects to see.

IA-04 Deliverable

Closing Report

A management-review-ready report summarising ISMS health, trends across audit cycles, and open corrective actions.

IA-05 Fit

Certification-Body Recognised

Reports structured to the format certification bodies expect at surveillance and recertification audits, no last-minute reformatting.

IA-06 Independence

Genuinely Independent

Performed by consultants independent of your day-to-day operations, satisfying clause 9.2's independence requirement even if we've supported other workstreams.

What clause 9.2 actually requires

ISO 27001 clause 9.2 asks you to conduct internal audits at planned intervals to check two things: that your information security management system conforms to your own documented requirements and to the requirements of the standard, and that it is effectively implemented and maintained. Those are separate tests and both matter. A control can be documented perfectly and still fail the second test if nobody follows it.

The standard also requires that auditors are objective and impartial, and that they do not audit their own work. This is the clause that catches small organisations. If the person who administers your access control process is also the person auditing it, that audit is not independent and a certification body will say so. Bringing in an external party resolves this cleanly, and the standard explicitly permits it.

Finally, clause 9.2 requires the results to be reported to relevant management and retained as documented information. In practice this means your audit output needs to be structured well enough to feed your management review, not just a list of observations in an email.

What an internal audit is not

An internal audit is not your certification audit and it does not produce a certificate. Certification audits are performed by accredited certification bodies under ISO/IEC 17021-1, and we are not one, by design. Our independence statement explains where that line sits and why we keep to it.

It is also not a gap analysis. A gap analysis asks what is missing against the standard and is most useful before you have built anything. An internal audit assumes the ISMS exists and asks whether it is working: whether the access reviews genuinely happened last quarter, whether the supplier register reflects reality, whether the incidents raised were closed the way the procedure says they should be. The two are frequently confused, and buying the wrong one wastes a cycle.

How we sample evidence

Audit findings are only as good as the evidence behind them, so we sample rather than accept assertions. If your access control policy says privileged access is reviewed quarterly, we ask to see the last four reviews, check who performed them, and look for the leavers who should have been removed. If your change management procedure requires approval before production deployment, we take a set of recent deployments and trace each one back to its approval.

This is deliberately the same approach a certification body auditor takes, which is the point. The purpose of an internal audit is to find the problems before somebody with the power to raise a nonconformity finds them. An internal audit that returns no findings at all is usually a sign the audit was too shallow, not that the ISMS is flawless.

Engagement process

How the work actually happens.

01

Audit planning

We build an audit plan against your Statement of Applicability, agreeing scope, timing and who we'll need to speak to.

02

Fieldwork

Interviews, evidence sampling and control walkthroughs, typically 2 to 4 days depending on ISMS scope.

03

Findings review

Draft findings are reviewed with your ISMS owner before anything is finalised, so there are no surprises in the closing meeting.

04

Closing meeting & report

A formal closing meeting presenting findings, followed by a written report suitable for your management review and certification body.

05

Remediation round and re-check

You get one round to apply corrective actions to what we raised. We re-check those findings and issue the final audit report for your management review and certification body.

Included as standard

One remediation cycle is built into every engagement

After the draft findings are issued, you get one round to apply corrective actions to the nonconformities and observations we raised. We then re-check those specific findings and issue the final audit report. That final report is what goes to your management review and your certification body, so it reflects the corrections you made rather than the position on the day we audited.

What goes wrong

Common mistakes we are asked to fix.

Auditing your own work

The most common cause of an internal audit being rejected. If the auditor owns any part of the process being audited, independence fails regardless of how well the audit was performed.

Confusing the internal audit with the certification audit

They are different engagements with different providers. Budgeting for one and expecting it to cover the other is a common and expensive mistake.

Auditing documents instead of practice

Reading policies and confirming they exist tells you almost nothing. The value comes from testing whether the described control actually operated over the period.

Leaving findings open until the next audit

Certification bodies look closely at corrective action tracking. An open finding from last year with no action recorded is worse than the original finding.

Timelines

Timing and what to expect

Fieldwork typically takes two to four days depending on the scope of your ISMS and how many people we need to interview, with the closing report issued within a week. Most organisations run one full internal audit cycle a year, sometimes split into two or more smaller audits covering different domains so that the whole ISMS is covered across the certification cycle. If you are working toward first certification, plan to complete your internal audit at least four to six weeks before your Stage 2 audit so there is time to close anything it surfaces.

One thing worth being clear about

We're consultants. We'll get your controls in shape and get you ready for the audit, but we don't hand out ISO 27001 certificates or sign SOC 2 reports, because the rules quite rightly don't let the firm that prepared you be the firm that passes you. That job goes to an independent certification body or CPA firm, and we'll help you find a good one. More on where exactly that line sits in our independence statement.

Offer

Your first year of service is free

Sign a 2-year agreement with pricing locked in upfront, and your first year of any one service is completely free. Adding more than one service in year one? We give you the highest-value one free and a bundle discount on the rest. See how the offer works →

Common questions

Frequently asked questions

Isn't it a conflict of interest for a consultant to run our internal audit?

No. This is one of the few places ISO 27001 explicitly allows it. Clause 9.2 requires internal audits to be independent of the process being audited, and permits a qualified external party to perform them. What we can't do is also perform your certification audit. That stays with an accredited, independent certification body. See our full independence statement for the detail.

How is this different from the certification audit?

The certification audit is performed by an accredited external certification body and results in your ISO 27001 certificate. The internal audit is an ongoing requirement of the standard itself (clause 9.2) that certified organisations must run at least annually, we perform this one directly.

Do you offer this as a free first-year service?

Yes. Internal audit is one of the services eligible for our first-year free offer, available on any service when you sign a 2-year agreement with pricing locked in upfront.

What if we already have an internal auditor?

We can run a single cycle, support your existing auditor with a co-sourced model, or take the full function. Whatever keeps your programme independent and defensible.

Will the findings be acceptable to our certification body?

Yes. Our reports are structured in the format certification bodies expect to review at surveillance and recertification audits.

Do we need an internal audit before our first certification audit?

Yes. A certification body will expect to see that at least one internal audit cycle has been completed, along with a management review, before Stage 2. Arriving without one is a predictable nonconformity.

Can we audit ourselves if we are a small team?

You can, provided the auditor is genuinely independent of the area being audited. In practice, small teams rarely have someone who is both qualified and sufficiently detached, which is why the standard allows an external party to perform the audit.

How much of the ISMS should one audit cover?

The standard requires the whole management system to be covered over a planned cycle, not necessarily in a single audit. Many organisations run a rolling programme covering different domains through the year. We will build a programme that closes the loop across your certification cycle.

What happens if you find a major nonconformity?

We tell you immediately rather than saving it for the report, and we help you get the corrective action underway. It is far better to find it in an internal audit than to have a certification body find it at Stage 2.

Will you help close the findings you raise?

We track corrective actions through to closure as part of the engagement. What we will not do is implement fixes for you and then audit those same fixes in the following cycle, because that would compromise the independence the audit depends on.

Is remediation included, or is that charged separately?

One remediation cycle is included as standard in every engagement. You get one round to apply fixes to what we raised, we re-check those specific findings, and the final report reflects your corrected state rather than the position we found at the start. What sits outside that is our engineers implementing the fixes on your behalf, rather than verifying yours, and any further rounds beyond the first. Both are quoted separately and transparently before any work starts.

Related services

Often scoped alongside this.

Ready to scope this?

Tell us your target date and current state. We'll come back with a fixed-scope proposal within two business days.

Book a discovery call