---
title: "ISO 27001 Internal Audits: Requirements, Auditor Selection, and Best Practice"
description: ISO 27001 Internal Audits - Key things to know
---

[Skip to content](https://knowledge.sensiba.com/iso-27001-internal-audits-key-things-to-know#main-content)

English

Show submenu for translations

- Sensiba

Open main navigation

Close main navigation

- Sensiba
- English
  
  Show submenu for translations
- [Go to sensiba.com](https://sensiba.com/)

[Go to sensiba.com](https://sensiba.com/)

 Hi There! How can we help you?

- There are no suggestions because the search field is empty.

1. [Sensiba Knowledge Base](https://knowledge.sensiba.com/?hsLang=en)
2. [ISO 27001](https://knowledge.sensiba.com/iso-27001?hsLang=en)

# ISO 27001 Internal Audits: Requirements, Auditor Selection, and Best Practice

Internal audits are a fundamental requirement of ISO/IEC 27001 and play a critical role in maintaining an effective Information Security Management System (ISMS).

Rather than being a certification exercise, an internal audit provides your organisation with an opportunity to independently assess whether your ISMS is operating as intended, identify opportunities for improvement, and address issues before they are identified during an external certification audit.

This guide explains the purpose of an ISO 27001 internal audit, who can perform one, and how to establish an effective internal audit programme.

#### **Key Takeaways**

- Internal audits are a mandatory requirement under **Clause 9.2 of ISO/IEC 27001:2022**.
- Internal audits evaluate whether your ISMS is implemented, maintained, and operating effectively.
- Certification bodies cannot perform your internal audit due to impartiality requirements.
- Internal audits may be conducted by competent internal personnel or an independent third party.
- Internal audits should be completed at planned intervals and used to drive continual improvement of your ISMS.

#### What Is an Internal Audit?

An internal audit is a documented and independent assessment of your Information Security Management System (ISMS).

Its purpose is to determine whether your ISMS:

- Conforms to your organisation's planned arrangements and the requirements of ISO/IEC 27001.
- Has been effectively implemented and maintained.
- Is capable of achieving your organisation's information security objectives.

Clause 9.2 of ISO/IEC 27001:2022 requires organisations to conduct internal audits at planned intervals. These audits provide assurance that the ISMS continues to operate effectively while identifying opportunities for improvement before external certification audits take place.

#### **Internal Audit vs External Certification Audit**

Although both audit types assess compliance against ISO 27001, they serve different purposes.

| **Internal Audit** | **External Certification Audit** |
| --- | --- |
| Conducted by your organisation or an independent third-party auditor | Conducted by an accredited certification body |
| Focuses on continual improvement and organisational readiness | Determines whether certification should be granted or maintained |
| Scope and timing are determined by your organisation | Conducted according to the certification cycle (Stage 1, Stage 2 and Surveillance Audits) |
| Identifies opportunities for improvement before certification audits | Assesses compliance against ISO 27001 requirements |
| Results are used internally to implement corrective actions | Results determine certification outcomes |

#### **Why Can't the Certification Body Perform Your Internal Audit?**

Certification bodies must remain independent and impartial.

As the organisation responsible for determining whether your ISMS meets the requirements of ISO 27001, the certification body cannot also perform activities that form part of your management system.

ISO/IEC 17021-1, the accreditation standard governing certification bodies, prohibits certification auditors from performing activities that could compromise their impartiality, including:

- Designing or implementing your ISMS
- Acting as your internal auditor
- Providing consultancy that influences certification decisions

For this reason, your internal audit must be completed independently before your certification or surveillance audit.

#### **Who Can Perform an Internal Audit?**

There are two common approaches:

##### **Option 1: Use Internal Resources**

Many organisations choose to perform internal audits using their own personnel.

However, the appointed auditor must satisfy two important requirements.

##### **Independence and Objectivity**

The internal auditor must not audit their own work or areas for which they are directly responsible.

For example, if an individual is responsible for managing the ISMS or owns controls within the Statement of Applicability (SoA), they should not be auditing those activities.

Maintaining auditor independence helps ensure objective and credible audit outcomes.

##### **Auditor Competence**

Internal auditors should possess sufficient knowledge, skills, and experience to effectively assess compliance with ISO/IEC 27001.

Competence may be demonstrated through:

- Experience managing or auditing management systems
- Formal ISO 27001 or ISO auditing training
- Practical knowledge of information security principles
- Previous audit experience

Where internal resources are used, organisations should document why the selected auditor was considered both competent and independent.

#### **Option 2: Engage an Independent Third Party**

If suitable internal resources are unavailable, many organisations choose to engage an independent third-party auditor.

This approach provides additional assurance that the audit has been conducted objectively while ensuring appropriate technical expertise.

When selecting an external provider, consider factors such as:

- Experience auditing ISO/IEC 27001 management systems
- Industry knowledge relevant to your organisation
- Auditor qualifications and experience
- Clear scope of services
- Ability to assess your ISMS against the full requirements of ISO/IEC 27001

You can also explore our trusted partner network for organisations that provide independent internal audit services. Let your CSM know, and we can arrange some introductions for you.

#### **How to Conduct an Internal Audit**

A structured audit process helps ensure your internal audit is both effective and repeatable.

##### 1. Understand the Standard

Ensure the auditor understands the requirements of ISO/IEC 27001, including the management system clauses and applicable Annex A controls.

##### 2. Define the Audit Scope

Determine which parts of the ISMS will be audited, along with the audit objectives, criteria, and timeframe.

For organisations preparing for their initial certification, we recommend auditing the entire ISMS before the Stage 1 audit.

Following certification, many organisations adopt a rolling audit programme that focuses on different areas each year. Where this approach is used, an Internal Audit Schedule should demonstrate how the entire ISMS will be audited across the three-year certification cycle.

##### 3. Select the Auditor

Appoint an auditor who is both independent of the activities being audited and competent to assess ISO 27001 requirements.

##### 4. Develop an Audit Plan

Prepare an audit plan outlining:

- Audit objectives
- Scope
- Audit criteria
- Schedule
- Methodology
- Participants

##### 5. Conduct the Audit

Perform the audit by reviewing documentation, interviewing personnel, examining records, and observing operational activities to determine whether the ISMS is functioning effectively.

##### 6. Record Audit Findings

Document all findings, including:

- Conformities
- Nonconformities
- Opportunities for improvement
- Supporting evidence

Well-documented findings make corrective actions significantly easier to manage.

##### 7. Prepare the Audit Report

Produce an audit report that clearly summarises:

- Audit scope
- Activities completed
- Findings
- Conclusions
- Recommended corrective actions

The report should provide management with sufficient information to understand the overall effectiveness of the ISMS.

##### 8. Communicate the Results

Present the audit findings to management and relevant process owners.

Where nonconformities or improvement opportunities have been identified, ensure responsibilities and timeframes for corrective actions are agreed.

##### 9. Complete Corrective Actions

Document corrective actions and monitor their implementation through to completion.

Where appropriate, verify that actions have effectively addressed the root cause rather than simply resolving the immediate issue.

##### 10. Continually Improve

Internal audits should contribute directly to continual improvement.

Review the effectiveness of your audit programme after each audit and use lessons learned to strengthen both future audits and the ISMS itself.

#### **How Often Should Internal Audits Be Conducted?**

Internal audits are an ongoing requirement throughout the lifecycle of your ISMS.

ISO/IEC 27001 requires organisations to conduct internal audits at **planned intervals**. While many organisations complete a comprehensive internal audit annually, the frequency should be determined based on factors such as organisational risk, complexity, and previous audit results.

An effective internal audit programme should:

- Be risk-based and appropriately planned
- Cover the entire scope of the ISMS over the certification cycle
- Include documented findings and corrective actions
- Support continual improvement of the ISMS

Internal audits should not be viewed solely as a certification requirement. When used effectively, they provide valuable insight into the health of your information security programme and help ensure your organisation remains prepared for ongoing certification and surveillance audits.

- [Platform](https://knowledge.sensiba.com/platform?hsLang=en#main-content)

    - [Vanta](https://knowledge.sensiba.com/platform?hsLang=en#vanta)
    - [Drata](https://knowledge.sensiba.com/platform?hsLang=en#drata)
    - [Scrut](https://knowledge.sensiba.com/platform?hsLang=en#scrut)
    - [Sprinto](https://knowledge.sensiba.com/platform?hsLang=en#sprinto)
- [Best Practices Series](https://knowledge.sensiba.com/best-practices-series?hsLang=en#main-content)

    - [Risk management & internal controls](https://knowledge.sensiba.com/best-practices-series?hsLang=en#risk-management-internal-controls)
    - [Information & communication](https://knowledge.sensiba.com/best-practices-series?hsLang=en#information-communication)
    - [Data protection](https://knowledge.sensiba.com/best-practices-series?hsLang=en#data-protection)
    - [System security](https://knowledge.sensiba.com/best-practices-series?hsLang=en#system-security)
    - [Change management](https://knowledge.sensiba.com/best-practices-series?hsLang=en#change-management)
    - [System operations](https://knowledge.sensiba.com/best-practices-series?hsLang=en#system-operations)
    - [Control environment](https://knowledge.sensiba.com/best-practices-series?hsLang=en#control-environment)
- [Consumer Data Right Guides](https://knowledge.sensiba.com/consumer-data-right-guides?hsLang=en#main-content)

    - [Network Security](https://knowledge.sensiba.com/consumer-data-right-guides?hsLang=en#network-security)
    - [Vulnerability Management](https://knowledge.sensiba.com/consumer-data-right-guides?hsLang=en#vulnerability-management)
    - [Security Awareness](https://knowledge.sensiba.com/consumer-data-right-guides?hsLang=en#security-awareness)
    - [Anti-malware](https://knowledge.sensiba.com/consumer-data-right-guides?hsLang=en#anti-malware)
    - [Information Asset Lifecycle](https://knowledge.sensiba.com/consumer-data-right-guides?hsLang=en#information-asset-lifecycle)
    - [Access Control](https://knowledge.sensiba.com/consumer-data-right-guides?hsLang=en#access-control)
    - [Governance Requirements](https://knowledge.sensiba.com/consumer-data-right-guides?hsLang=en#governance-requirements)
- [ISO 27001](https://knowledge.sensiba.com/iso-27001?hsLang=en)
- [Control Environment](https://knowledge.sensiba.com/control-environment?hsLang=en)
- [Information and Communication](https://knowledge.sensiba.com/information-and-communication?hsLang=en)
- [Risk Management](https://knowledge.sensiba.com/risk-management?hsLang=en)
- [Vendor Management](https://knowledge.sensiba.com/vendor-management?hsLang=en)
- [System Security](https://knowledge.sensiba.com/system-security?hsLang=en)
- [System Operations](https://knowledge.sensiba.com/system-operations?hsLang=en)
- [Change Management](https://knowledge.sensiba.com/change-management?hsLang=en)
- [Confidentiality](https://knowledge.sensiba.com/confidentiality?hsLang=en)
- [Privacy](https://knowledge.sensiba.com/privacy?hsLang=en)
- [CDR Reps](https://knowledge.sensiba.com/cdr-reps?hsLang=en)
- [Access reviews](https://knowledge.sensiba.com/access-reviews?hsLang=en)
- [Governance](https://knowledge.sensiba.com/governance?hsLang=en)
- [Employee management](https://knowledge.sensiba.com/employee-management?hsLang=en)
- [FAQs](https://knowledge.sensiba.com/faqs?hsLang=en)
- [Sensiba Audit Tools](https://knowledge.sensiba.com/sensiba-audit-tools?hsLang=en)

- Sensiba

[![Sensiba Logo](https://knowledge.sensiba.com/hs-fs/hubfs/Sensiba_Logo_Hubspot-01.png?width=247&height=48&name=Sensiba_Logo_Hubspot-01.png "Sensiba Logo")](https://sensiba.com/)

Copyright © 2026, Sensiba LLP