An ISO 27001 internal audit checklist is a working document that lists, for every clause and applicable Annex A control, the question the auditor asks, the record that answers it, and the conformity decision that follows. Clause 9.2 does not require a checklist. It requires an audit program that reaches an objective conclusion about whether your ISMS conforms to ISO/IEC 27001:2022 and is effectively implemented and maintained.
That distinction is the reason most internal audits produce nothing useful. A checklist with 153 rows of yes and no boxes can be completed in a day without a single record being examined, and it will still look complete to anyone who has not audited before. What follows is the program, not the artifact: what to ask, what to demand as objective evidence, and how to write the finding when the evidence is not there.
What does Clause 9.2 of ISO 27001 actually require?
Clause 9.2 of ISO/IEC 27001:2022 splits into two parts. Clause 9.2.1 requires internal audits at planned intervals that establish whether the ISMS conforms both to the organization's own requirements for the ISMS and to the requirements of the standard, and whether it is effectively implemented and maintained. Clause 9.2.2 sets out what the audit program must contain.
The program obligations are specific, and each one is separately auditable by your certification body:
- Plan, establish, implement, and maintain an audit program covering frequency, methods, responsibilities, planning requirements, and reporting
- Consider the importance of the processes concerned and the results of previous audits when setting the program
- Define audit criteria and scope for each individual audit
- Select auditors and conduct audits in a way that ensures objectivity and impartiality
- Report results to relevant management
- Retain documented information as evidence of both the program and the results
Two of these are where organizations most often fail. Impartiality means the person auditing a process cannot be the person who owns or operates it. The security lead cannot audit the access control process they designed. Considering previous results means the program must visibly change in response to what the last audit found, and a program that audits the same clauses in the same order every year with no reference to prior findings does not meet that requirement.
Note what the standard does not require. It does not require a documented internal audit procedure. It does not prescribe a checklist format. It does not require every clause and all 93 Annex A controls in every audit, provided the program covers the full scope across a defined cycle and the sampling rationale is documented. Certification bodies see far more findings against the audit program design than against the audit execution.
What do you need before the audit starts?
Five inputs, and an ISO 27001 internal audit program that is missing any of them will produce a document rather than an audit. An internal audit that begins with the checklist is already compromised. Collect these first, because they define what conformity means for your organization specifically:
- The ISMS scope statement. Everything you audit sits inside it, and anything outside it is not your finding to raise.
- The Statement of Applicability. Required under Clause 6.1.3(d). It tells you which of the 93 Annex A controls are in play and what the organization claimed about each one.
- The risk register and risk treatment plan. The SoA has to be traceable back to these. Where it is not, you have a finding before you interview anyone.
- The previous internal audit report and the status of its findings. Open findings from last cycle are the single highest-yield place to start.
- The last management review minutes. Clause 9.3 outputs feed Clause 9.2 planning, and vice versa.
Read all five before you write a single audit question. If the SoA and the risk register contradict each other, that inconsistency is your first line of inquiry and it will run through the whole audit.
The ISO 27001 internal audit checklist: Clauses 4 through 10
This is the ISMS audit proper. For each clause, the table gives the question to ask, the objective evidence to request, and the wording of the nonconformity when the evidence does not exist.
A finding written as an opinion gets argued with. A finding written as a statement of fact against a clause requirement gets fixed.
Clause 4: Context of the organization
| Sub-clause | What the auditor asks | Record requested | Typical nonconformity wording |
|---|---|---|---|
| 4.1 | How were internal and external issues relevant to the ISMS determined, and when were they last reviewed? | Context analysis or equivalent record, with a date and an owner | The organization has not determined external and internal issues relevant to the purpose of the ISMS as required by Clause 4.1. No record of context determination was available. |
| 4.2 | Who are the interested parties and what are their information security requirements? | Interested party register mapping each party to specific requirements | Interested parties were identified but their information security requirements were not determined, contrary to Clause 4.2. |
| 4.3 | What is in scope, what is excluded, and what justifies the exclusion? | Approved scope statement listing interfaces and dependencies | The ISMS scope does not address interfaces and dependencies with activities performed by other organizations, as required by Clause 4.3. |
| 4.4 | Can you show the ISMS processes and their interactions? | Process map or documented ISMS framework | No finding available on 4.4 in isolation. Weakness here surfaces as findings elsewhere. |
What auditors actually find here: a scope statement that names the product but not the supporting infrastructure, the offices, or the remote workforce. Ask whether a laptop used by a contractor in a third country is inside the scope. If nobody can answer without checking, the scope is not defined well enough to audit against.
Clause 5: Leadership
| Sub-clause | What the auditor asks | Record requested | Typical nonconformity wording |
|---|---|---|---|
| 5.1 | How does top management demonstrate commitment, and where is the evidence? | Management review attendance and decisions, approved resource allocation, security objectives signed by leadership | Top management has not demonstrated leadership and commitment with respect to the ISMS. Management review records for the period contain no evidence of resource decisions or direction. |
| 5.2 | Is there an information security policy, is it available to interested parties, and when was it last approved? | Approved policy with version history and evidence of communication | The information security policy has not been reviewed or approved since [date] and does not include a commitment to continual improvement of the ISMS, contrary to Clause 5.2. |
| 5.3 | Who is responsible for ISMS conformity and who reports on performance to top management? | Documented roles and responsibilities, with named individuals | Responsibilities and authorities for reporting on ISMS performance to top management have not been assigned, contrary to Clause 5.3. |
What auditors actually find here: a policy signed by a CEO who left two years ago. Version control on the policy is the cheapest thing to fix and one of the most common findings.
Clause 6: Planning
This is the highest-yield clause in the entire audit. Most major nonconformities trace back here.
| Sub-clause | What the auditor asks | Record requested | Typical nonconformity wording |
|---|---|---|---|
| 6.1.1 | What risks and opportunities to the ISMS itself have been determined? | Documented determination, distinct from information security risk | The organization has not determined risks and opportunities that need to be addressed to ensure the ISMS can achieve its intended outcomes, contrary to Clause 6.1.1. |
| 6.1.2 | What is the documented risk assessment methodology, including risk acceptance criteria? Show me it applied consistently. | Risk methodology plus the current risk register | Risk acceptance criteria have not been established and the risk assessment process does not produce consistent, valid, and comparable results, contrary to Clause 6.1.2. |
| 6.1.3 | For a given accepted risk, show me the treatment option chosen, the controls determined, and the risk owner's approval. | Risk treatment plan, SoA, and documented risk owner approval of residual risk | Residual information security risks have not been approved by risk owners, contrary to Clause 6.1.3(f). |
| 6.1.3(d) | Does the Statement of Applicability list all 93 Annex A controls with justification for inclusion and exclusion? | The current SoA | The Statement of Applicability does not include justification for the exclusion of [n] Annex A controls, contrary to Clause 6.1.3(d). |
| 6.2 | What are the information security objectives, how are they measured, and what is current performance? | Objectives with metrics, targets, owners, and current measured results | Information security objectives have been established but are not measurable and no results have been monitored, contrary to Clause 6.2. |
| 6.3 | When the organization last changed something material to the ISMS, how was that change planned? | Change record showing ISMS impact assessment | Changes to the ISMS were not carried out in a planned manner, contrary to Clause 6.3. |
The single test that finds the mostPick one high-rated risk from the register. Trace it forward to the treatment decision, to the controls selected in the SoA, to the policy that describes the control, to the record that proves the control operated last month. Then pick one Annex A control marked applicable in the SoA and trace it backward to the risk that justifies it. In most first internal audits, at least one of those two traces breaks. That break is the audit's most valuable output.
Clause 7: Support
| Sub-clause | What the auditor asks | Record requested | Typical nonconformity wording |
|---|---|---|---|
| 7.1 | What resources have been determined and provided for the ISMS? | Budget, headcount, or tooling decisions attributable to the ISMS | Resources needed for the establishment and maintenance of the ISMS have not been determined and provided, contrary to Clause 7.1. |
| 7.2 | How was competence determined for people whose work affects information security, and how was it verified? | Competence criteria per role, plus training or qualification records | The organization has not retained documented information as evidence of competence, contrary to Clause 7.2. |
| 7.3 | Show me evidence that personnel are aware of the policy and their contribution to ISMS effectiveness. | Awareness training completion records covering the full in-scope population | Awareness records show [n] of [m] in-scope personnel completed security awareness training in the period, contrary to Clause 7.3. |
| 7.4 | What is communicated about information security, to whom, when, and by whom? | Communication plan and examples of actual communications | Communication requirements have not been determined, contrary to Clause 7.4. |
| 7.5 | How is documented information controlled for approval, version, distribution, and retention? | Document register showing version, owner, approver, and review date | Documented information of external origin is not identified and controlled, contrary to Clause 7.5.3. |
Sampling note for 7.3: get the full population of in-scope personnel from HR, not from the training platform. The training platform only knows about people who were enrolled. The gap between the HR list and the enrolled list is where the finding lives, and it is the most reliable awareness finding in any internal audit.
Clause 8: Operation
| Sub-clause | What the auditor asks | Record requested | Typical nonconformity wording |
|---|---|---|---|
| 8.1 | How is it demonstrated that ISMS processes were carried out as planned? | Records of process execution across the period | Documented information is not retained to the extent necessary to have confidence that ISMS processes have been carried out as planned, contrary to Clause 8.1. |
| 8.2 | When was the risk assessment last performed, and what triggered it? | Dated risk assessment results, plus records of trigger-based reassessment | Information security risk assessments have not been performed at planned intervals or when significant changes occurred, contrary to Clause 8.2. |
| 8.3 | Show me the risk treatment plan implemented, with status per action. | Risk treatment plan with dated implementation evidence | The information security risk treatment plan has not been implemented and [n] treatment actions remain overdue with no revised target date, contrary to Clause 8.3. |
Clause 9: Performance evaluation
| Sub-clause | What the auditor asks | Record requested | Typical nonconformity wording |
|---|---|---|---|
| 9.1 | What is monitored and measured, by what method, when, and who evaluates the results? | Defined metrics with method, frequency, and evaluated results | The organization has not determined the methods for monitoring, measurement, analysis, and evaluation, and no evaluation of results was retained, contrary to Clause 9.1. |
| 9.2 | Show me the audit program, the criteria and scope of each audit, and the impartiality basis of the auditor. | Audit program, individual audit plans, auditor independence statement | The internal audit was conducted by the owner of the processes audited, and objectivity and impartiality of the audit process was therefore not ensured, contrary to Clause 9.2.2(b). |
| 9.3 | Do management review records address every required input, and do they contain decisions? | Management review minutes with agenda mapped to 9.3.2 inputs | Management review did not consider [specific inputs], contrary to Clause 9.3.2, and the record contains no decisions related to continual improvement opportunities. |
The management review test: take the required inputs in Clause 9.3.2 and check each one off against the minutes: status of prior actions, changes in external and internal issues, changes in interested party needs, feedback on information security performance including nonconformities, monitoring results, audit results, and fulfillment of objectives, feedback from interested parties, risk assessment results and treatment plan status, and opportunities for continual improvement. Minutes that do not visibly cover all of them produce a finding almost every time, and this is one of the two or three most common nonconformities certification bodies raise at Stage 2.
Clause 10: Improvement
| Sub-clause | What the auditor asks | Record requested | Typical nonconformity wording |
|---|---|---|---|
| 10.1 | How is the ISMS continually improved, and what changed as a result? | Improvement register or equivalent showing implemented changes | No evidence of continual improvement of the suitability, adequacy, or effectiveness of the ISMS was available, contrary to Clause 10.1. |
| 10.2 | For a closed nonconformity, show me the cause analysis, the correction, the corrective action, and the effectiveness check. | Corrective action record with all four elements | Corrective action records document the correction applied but contain no review of the cause of the nonconformity or determination of whether similar nonconformities exist, contrary to Clause 10.2(b). |
The most common Clause 10.2 failure: a corrective action record that says "access removed" and closes. Correction fixes the instance. Corrective action addresses the cause so the instance does not recur. If the record does not distinguish the two, it does not satisfy 10.2, and this is worth checking on every closed finding you sample.
How do you audit the 93 Annex A controls?
ISO/IEC 27001:2022 Annex A contains 93 controls in four themes: 37 organizational (A.5), 8 people (A.6), 14 physical (A.7), and 34 technological (A.8). The 2022 revision introduced 11 controls that did not exist in the 2013 structure, including threat intelligence, information security for use of cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering, and secure coding.
You do not have to test all 93 in one audit, and pretending otherwise is why so many internal audits are shallow. What you must do is document a sampling rationale that a certification body will accept. A defensible approach:
- Test every control linked to a high-rated risk. Non-negotiable. The SoA gives you the mapping.
- Test all 11 controls new in the 2022 revision for at least the first two audit cycles. These are the ones organizations transitioned onto paper without implementing.
- Test every control where the previous audit raised a finding. Verification of effectiveness is a Clause 10.2 requirement, not an optional courtesy.
- Test every control the SoA marks as applicable but for which the SoA cites no implementing document. The absence of a reference is itself the signal.
- Rotate the remainder so that all applicable controls are covered across a defined cycle, usually one year for small organizations and up to three for large ones, and state the cycle in the audit program.
For each control selected, the test is the same three steps and takes ten minutes when the evidence exists:
- Design. Does a documented process exist that would achieve the control objective if followed?
- Implementation. Does the responsible person describe doing it that way, unprompted?
- Effectiveness. Pull a sample of records from the period and confirm the control operated. One record is not a sample. For a monthly control across twelve months, two to four months is the usual minimum. For an event-driven control such as onboarding, get the full population from HR and sample from it.
Step three is the one that gets skipped, and skipping it is what makes an internal audit worthless as preparation for Stage 2. Your certification body will do step three. If your internal audit did not, your first real test of operating effectiveness happens in front of the person who decides whether you get certified.
Which ISO 27001 internal audit questions produce findings?
A Clause 9.2 checklist tells you what to look at. The questions below are what turn looking into evidence. Closed questions produce the answer the interviewee thinks you want. Open questions produce the process as it actually runs. Ask the person who does the work, not the person who wrote the policy.
To an engineer, on access control: Walk me through what happened the last time someone joined your team. Who requested their access, who approved it, and where would I see that? Now the last person who left. When did their access go, and how do you know?
To an engineer, on change management: Show me the last change you deployed to production. Who reviewed it? Has anything gone out without review in the last three months, and what happened in that case?
To the person running access reviews: Show me the last review. Who performed it and who reviewed the result? What did you find, and what happened to what you found? A review that never removes anything is usually not a review.
To an incident responder: Tell me about the last security incident. Not the worst, the last. Where is the record? Who was notified, and when? Was a lesson recorded and did anything change?
To a new joiner: What security training did you get and when? What would you do if you got an email asking you to move money urgently?
To the vendor owner: How was the last new supplier assessed before we sent them data? Show me the assessment. What is the review cycle and when was the last review done?
To top management: What are the current information security objectives and how are we performing against them? If the answer is a policy statement rather than a number, note it against Clause 6.2 and 9.1.
How do you classify and write a nonconformity?
Certification bodies distinguish major nonconformities, minor nonconformities, and opportunities for improvement. Your internal audit should use the same vocabulary so that findings translate directly.
Major nonconformity. The absence or total breakdown of a required part of the ISMS, or a failure that raises significant doubt about the ISMS achieving its intended outcomes. A missing risk assessment, an internal audit that was never conducted, a management review that has never happened, or a systemic failure of a control across the whole period. At Stage 2, a major must be closed before a certificate is issued.
Minor nonconformity. A single lapse or isolated failure that does not represent a systemic breakdown. One termination where access was removed six days late against a documented one-day requirement.
Opportunity for improvement. Conformity is met, but the practice is fragile or inefficient. Do not use OFIs as a way to avoid raising a nonconformity. Softening a real finding is the most damaging thing an internal auditor can do, because it moves the discovery from your report to the certification body's.
Every finding needs four elements. Missing any one of them makes the finding arguable:
- The requirement. The clause or control reference, quoted or closely paraphrased.
- The objective evidence. What was examined, with dates and identifiers. "Access review records for Q1 and Q2 2026" is evidence. "Access reviews seemed inconsistent" is not.
- The statement of nonconformity. One sentence, factual, no adjectives.
- The classification and the response due date.
Four findings written the way a certification body writes them
These are illustrative examples, structured the way a defensible finding should read. Substitute your own once you have run the audit.
Finding 1, minor, Clause 9.3.2. Requirement: management review shall consider the specified inputs. Evidence: management review minutes dated 14 February 2026 and 8 August 2026 were examined. Nonconformity: neither record addresses the results of the information security risk assessment or the status of the risk treatment plan, and the February minutes contain no reference to the status of actions from previous management reviews.
Finding 2, minor, control A.5.15 and Clause 8.1. Requirement: rules for physical and logical access control shall be established and implemented. Evidence: the population of 23 terminations between 1 January and 30 June 2026 was obtained from the HR system, and a sample of 8 was tested. Nonconformity: in 2 of 8 sampled terminations, access to the production environment was revoked 6 and 11 calendar days after the termination date, against the 24-hour requirement stated in the Access Control Policy version 3.1.
Finding 3, major, Clause 6.1.3(d). Requirement: the organization shall produce a Statement of Applicability containing the necessary controls, justification for inclusion, whether they are implemented, and justification for exclusion of Annex A controls. Evidence: Statement of Applicability version 1.0 dated 3 November 2025 was examined. Nonconformity: the document lists 61 of the 93 Annex A controls. No determination or justification has been documented for the remaining 32 controls.
Finding 4, minor, Clause 10.2. Requirement: on detecting a nonconformity, the organization shall review the nonconformity, determine its causes, and determine whether similar nonconformities exist or could potentially occur. Evidence: corrective action records CA-2026-03 and CA-2026-07 were examined. Nonconformity: both records document the correction applied and the closure date but contain no cause analysis and no determination of whether similar nonconformities exist elsewhere.
Notice what none of these say. None of them says the organization should do something. A nonconformity states what was found against what was required. The corrective action is the auditee's to determine, and an internal auditor who writes the corrective action has stopped being impartial.
What must the ISO 27001 internal audit report contain?
Clause 9.2.2(d) requires retained documented information as evidence of the audit results. In practice, a report a certification body will accept as evidence of a functioning Clause 9.2 process contains:
- Audit scope and criteria for this specific audit, referencing the ISMS scope and the version of the SoA used
- Audit dates, auditor name, and the basis for the auditor's impartiality
- Method, including which clauses and controls were tested and the sampling rationale for those that were not
- Who was interviewed, by role
- Documents and records examined, identified specifically enough to be retrieved
- Findings, classified, each with requirement, evidence, and statement of nonconformity
- Status of findings from the previous audit
- A conclusion that answers the Clause 9.2.1 question directly: does the ISMS conform, and is it effectively implemented and maintained
- Distribution to relevant management, as required by Clause 9.2.2(c)
The conclusion is where most internal audit reports go quiet. It should state a position. An internal audit that finds nothing and concludes everything is fine, submitted by the person who runs the ISMS, is the pattern certification bodies have learned to distrust, and after 2026 so have enterprise buyers.
Eight mistakes that make an ISO 27001 internal audit worthless
- Auditing the documents instead of the operation. Reading the policy is Stage 1. Sampling records is the audit.
- Using a purchased checklist as the audit. A generic checklist does not know your SoA, your risks, or your scope, and cannot ask the follow-up question.
- No impartiality. The single most avoidable major finding available.
- Sample sizes of one. One record does not evidence operation across a period.
- Populations pulled from the tool being audited. Get the termination list from HR, not from the identity provider whose provisioning process you are testing.
- No trace test. Risk to treatment to SoA to policy to record is the test that finds structural problems. Control-by-control checking never will.
- Findings written as opinions. They get negotiated away and nothing changes.
- No verification of prior findings. Clause 10.2 requires you to confirm corrective action was effective, and a finding closed without verification is still open.
How this connects to Stage 1 and Stage 2
Your certification body will audit your Clause 9.2 process as a control in its own right. At Stage 1 they will ask for the audit program and the last internal audit report, and they use both to judge whether Stage 2 is worth scheduling. At Stage 2 they will sample the same records you sampled, and they will notice if your internal audit found nothing where they find something.
That is the actual purpose of an internal audit. Not to produce a clean report, but to find everything the certification body would find, early enough that you can fix it.
An internal audit that raises fifteen findings twelve weeks before Stage 2 has done its job. One that raises none has told you nothing about your ISMS and something worrying about your auditor.
A control matrix that ties each Annex A control to the risk it treats and the evidence behind it is what makes an audit like this fast instead of forensic. If you would rather have an independent, impartial team run this program for you, on a defined cycle, with findings you can hand straight to your certification body, that is exactly what the Assurance Program is for.
Primary source: the standard itself, ISO/IEC 27001:2022, published by ISO. This guide paraphrases clause requirements for educational purposes and is not a substitute for the licensed text.
Frequently asked questions
Is an ISO 27001 internal audit checklist mandatory?
No. ISO/IEC 27001:2022 Clause 9.2 requires an audit program with defined criteria, scope, frequency, methods, responsibilities, and reporting, and it requires retained documented information as evidence of the program and the results. It does not require a checklist, and it does not prescribe a format. A checklist is a tool for consistency, not a requirement.
How often must ISO 27001 internal audits be conducted?
Clause 9.2 requires internal audits at planned intervals, without specifying a frequency. In practice most organizations run at least one full audit cycle per year, because Clause 9.3 management review needs audit results as an input annually and certification bodies expect audit coverage since the last surveillance visit. Larger organizations commonly run a rolling program covering the full scope across a defined cycle rather than auditing everything at once.
Do all 93 Annex A controls need to be audited every year?
No, provided the audit program documents a sampling rationale and the full applicable scope is covered across a stated cycle. What is difficult to defend is omitting controls linked to high-rated risks, controls where a previous finding was raised, or the 11 controls introduced in the 2022 revision.
Who is allowed to conduct an ISO 27001 internal audit?
Anyone competent to do so, provided objectivity and impartiality are ensured under Clause 9.2.2(b). The practical constraint is that auditors cannot audit their own work. That is why many small organizations use an external firm, staff from an unrelated department, or a reciprocal arrangement with another team. Using an external auditor to perform the internal audit is fully compliant, because Clause 9.2 governs the purpose of the audit and not who is on the payroll.
Can you fail an ISO 27001 internal audit?
There is no pass or fail. The internal audit is a management tool that reports whether the ISMS conforms and is effective. Findings are the expected output. An audit that raises no findings in a young ISMS is more concerning than one that raises a dozen, because it usually indicates the audit did not examine records.
What is the difference between a major and a minor nonconformity?
A major nonconformity is the absence or total breakdown of a required element, or a failure that casts significant doubt on the ISMS achieving its intended outcomes. A minor is an isolated lapse against a requirement that is otherwise implemented. At Stage 2 a major must be resolved before certification is granted, whereas minors are usually resolved through an agreed corrective action plan.
How long does an ISO 27001 internal audit take?
For a company of 30 to 80 people with a single product and a cloud environment, a thorough first internal audit covering all clauses plus a risk-based Annex A sample typically takes three to five auditor days including report writing. Subsequent cycles are faster because the trace work is already mapped. Anything completed in a few hours is a document review, not an audit.
Related reading: what Clause 9.2 requires of an internal audit program, what is a nonconformity in ISO 27001, can you outsource your ISO 27001 internal audit, and how to build a control matrix for SOC 2 or ISO 27001.