How to Run an ISO 27001 Internal Audit, Step by Step
Learning how to run an ISO 27001 internal audit is easier when you break it into clear steps. This guide covers planning, evidence, findings and follow-up, so your certification audit holds no surprises.
Closing Actions
Corrective actions, management review and keeping the cycle going.
Read SectionIf you are wondering how to run an ISO 27001 internal audit, start with the purpose. Clause 9.2 of the standard requires you to check at planned intervals that your information security management system works and meets both your own requirements and the standard.
Many teams treat this as a box to tick before the certification body arrives. Done well, it is your best chance to find problems on your own terms. The steps below work for small and mid-sized Australian organisations alike.
How to Run an ISO 27001 Internal Audit: Scope and Programme
First, confirm the scope of your information security management system. The audit must cover every area in that scope, including sites, teams and key suppliers.
Next, build an audit programme. List the clauses and Annex A controls to be reviewed, assign an auditor to each and set dates. You do not have to audit everything at once. Many organisations split the work across the year, as long as the whole system is covered within the certification cycle.
Risk should guide the order. Areas with recent incidents, major changes or earlier findings deserve earlier and deeper attention.
Step 3: Choose Auditors Who Are Independent
ISO 27001 expects objectivity and impartiality. In practice, that means auditors must not review their own work. An engineer who configured the firewall should not be the person who signs it off.
Small teams often struggle with this. In that case, borrow a trained colleague from another department or bring in an external specialist. Auditors need a working knowledge of the standard, plus enough technical understanding to ask sensible questions.
Need a ready-made structure? Use our internal audit checklist for ISO 27001 to keep each review consistent.
Step 4 and 5: Gather Evidence and Test the Controls
The core of how to run an ISO 27001 internal audit is evidence, not opinion. For each control, ask three questions: is it documented, is it in place and is it working? Then collect proof for each answer.
Good evidence comes in several forms. Interviews show whether staff understand their duties. Records, such as access reviews and training logs, show that activities actually happen. Direct observation and system configuration checks confirm that technical controls behave as described.
Sample sensibly. Instead of reading every record, choose a representative set across teams and time periods, and note exactly what you examined so another person could repeat the check.
Step 6: Record Findings and Grade Them Clearly
Write each finding so that a reader who was not in the room can follow it. State the requirement, the evidence and the gap. Then grade it, using a simple scale such as major nonconformity, minor nonconformity or opportunity for improvement.
Also record what works well. Positive observations help management see where the system is strong and give your certification auditor useful context. Share the draft report with control owners before it is final, so factual errors are fixed early.
Step 7: Close Corrective Actions and Feed Management Review
However, an audit only helps if findings lead to change. For every nonconformity, record the root cause, the corrective action, the owner and a due date. After the fix, verify it worked rather than assuming it did.
The results then go to top management as an input to the management review required by clause 9.3. Keep the audit report, the programme and the corrective action records, because certification auditors will ask to see them. For the full requirements, refer to the ISO 27001 standard.
If your next step is certification, our ISO 27001 certification support page explains how internal audits fit into the wider process.
Common Mistakes to Avoid
Several problems appear again and again. Teams audit only documents and never test real behaviour. Others use the same checklist every year without adjusting for changes in risk. Some leave findings open for months, which a certification auditor will notice.
When you review how to run an ISO 27001 internal audit next year, a simple remedy is to ask what the last audit missed, and adjust the next programme accordingly. A short cyber compliance assessment can also give an outside view of gaps your own team may overlook.
Audits come in several forms, which our cyber security audit guide compares.
Want an expert to run or review your internal audit?
Get in TouchFrequently Asked Questions
At planned intervals. Most organisations audit the full system at least once a year, often splitting the work into smaller reviews across the year.
Anyone competent and impartial. Auditors must not review their own work, so small teams often use a colleague from another department or an external specialist.
Yes. A checklist keeps reviews consistent, but it should be adapted to your scope and risks and supported by real evidence, not tick marks alone.
Record it, find the root cause, assign a corrective action with an owner and date, and verify the fix. Report it to management as part of the review.
The internal audit is your own check of the system. The certification audit is carried out by an accredited external body that decides whether you meet the standard.