Home / Resources / Internal Audit Checklist
Free checklist

Internal Audit
Checklist.

ISO 27001 · ISM

Use this internal audit checklist for ISO 27001 to run consistent internal compliance reviews, with a structured, ready-to-use set of audit questions.

Quick answer: An internal audit checklist for ISO 27001 lists the clauses and Annex A controls an auditor should test, so reviews are consistent and evidence is ready before the certification audit. ISO/IEC 27001 requires internal audits at planned intervals.
A hand marking off items on a checklist, representing an internal compliance audit
Structured & ready-to-use
ISO 27001 · ISM ALIGNED
Why It Matters

An internal audit checklist that actually holds up.

A structured checklist keeps your internal reviews consistent, thorough, and easy to evidence.

Consistent Coverage

Work through every control area the same way, every time — nothing gets missed between reviews.

ISO 27001 & ISM Aligned

Mapped to the control structure of ISO 27001 and the Australian Government Information Security Manual.

Ready For External Audit

Catch gaps internally first, with a documented trail you can hand straight to an external auditor.

Guide

What an internal audit checklist for ISO 27001 should cover

An ISO 27001 checklist turns the standard's internal audit requirement into repeatable steps: what to test, what evidence to collect and who is responsible.

Clause 9.2 of ISO/IEC 27001 requires an organisation to audit its information security management system (ISMS) at planned intervals. A good ISO 27001 checklist covers the management clauses as well as the Annex A controls, so nothing is left to memory. The ISO/IEC 27001 standard sets out the requirements each item maps back to.

What to include in an ISO 27001 internal audit checklist

  • Scope, context and interested parties (clause 4)
  • Leadership, policy and roles (clause 5)
  • Risk assessment, risk treatment and the Statement of Applicability (clauses 6 and 8)
  • Support, competence and documented information (clause 7)
  • Monitoring, internal audit and management review (clause 9)
  • Nonconformities and corrective action (clause 10)
  • Annex A control testing

How often should you run an internal audit?

Most organisations audit each part of the ISMS at least once a year, review higher-risk areas more often, and complete the internal audit and management review before the certification body's surveillance or recertification audit.

FAQ

Internal audit checklist ISO 27001 questions

Is an internal audit required for ISO 27001 certification?

Yes. Clause 9.2 of ISO/IEC 27001 requires internal audits of the ISMS at planned intervals, and certification bodies expect an internal audit and a management review to be complete before the Stage 2 audit.

Who can carry out an ISO 27001 internal audit?

Anyone who is competent, objective and impartial, which means they do not audit their own work. Many organisations use a trained auditor from another team or an external consultant.

What evidence should an ISO 27001 internal audit collect?

Records that show controls operate in practice, such as policies and approvals, access reviews, risk registers, incident logs, training records and earlier audit findings, each dated and traceable to the clause or control tested.

Do you provide a ready-made internal audit checklist for ISO 27001?

Yes. Our internal audit checklist for ISO 27001 covers every management clause and Annex A control area, so your reviewer works through the same list every time and nothing gets missed before the certification body arrives.

How often should an ISO 27001 internal audit be carried out?

ISO/IEC 27001 requires internal audits at planned intervals, and most organisations audit each part of the ISMS at least once a year. Higher-risk areas are often reviewed more frequently, and the internal audit and management review should be complete before the certification body's Stage 2, surveillance or recertification audit.

Standard

Why an internal audit checklist needs real evidence

An internal audit checklist is only as good as the evidence behind each tick, and that's usually where an ISO 27001 internal audit either holds up or falls apart under a certification body's questions.

A checklist item marked complete needs something to point to. For access control, that might be a quarterly access review with sign-off. For patch management, a patch log showing time-to-patch against your own policy target. ISO/IEC 27001 doesn't specify the evidence format, but it does expect it to exist and to be dated.

Common gaps an internal audit checklist exposes

  • A policy exists but nobody can produce a record showing it's followed
  • Risk treatment decisions were made verbally and never logged in the risk register
  • Access reviews happen irregularly instead of on the schedule the policy states
  • Training records exist for new starters but not for annual refreshers

How this feeds the certification audit

A well-run internal audit, with findings closed out before the external auditor arrives, is one of the clearest signals of a maturing ISMS. Certification bodies notice when internal audit findings repeat year over year with no resolution — it suggests the internal audit checklist is being run as a formality rather than a real check.

Get access to our Internal Audit Checklist

Fill in your details and we'll send the checklist straight to your inbox.

Thanks — check your inbox for a message from Cyber Compliance Pro with your Internal Audit Checklist.

We may occasionally send you helpful updates — no spam, no mass emails, just relevant insights you'll appreciate.

Need Help With Your Audit?

Want a second pair of eyes?

Our consultants can run your internal audit for you, or review your findings before you take them to certification.

New to auditing? Our step-by-step guide on how to run an ISO 27001 internal audit explains planning, evidence and findings.