Certification bodies read your internal audit report the way a lender reads bank statements: not for what it claims, but for what it proves. ISO 27001 Clause 9.2 requires the internal audit, and Clause 9.2 plus your certification body's expectations effectively dictate what the report must contain. This article lays out the required contents section by section, how nonconformities should be graded, and the failures that make certification auditors stop trusting the whole ISMS.

Why the Report Carries So Much Weight

The internal audit is the ISMS checking itself. At Stage 1, the certification body verifies one exists. At Stage 2 and at every surveillance visit, they read it to decide how much they can rely on your own oversight, and they calibrate their own sampling accordingly. A credible report earns you a lighter audit. A hollow one earns you a deeper dig and, frequently, a nonconformity against Clause 9.2 itself. We cover the requirement in full in our Clause 9.2 guide; here we focus on the document.

What the Report Must Contain

1. Scope, criteria, and objectives

State what was audited: which parts of the ISMS, which locations, which Annex A controls from your Statement of Applicability, and against what criteria, meaning the standard itself plus your own policies and procedures. If this cycle covered only part of the ISMS, reference the audit programme showing when the rest is covered, because Clause 9.2 requires the programme to reach everything over time.

2. Auditor identity and impartiality

Name the auditor and state the basis of their objectivity. Auditors cannot audit their own work, which is why outsourcing the internal audit is both permitted and, for small teams, usually the only compliant option. A report signed by the person who built the ISMS is the fastest way to lose a certification auditor's trust.

3. Methodology and sampling

Describe how the audit was actually performed: documents reviewed, interviews conducted, systems observed, and how samples were selected. Keep the sampling log. "Reviewed the access control policy" is not evidence of an audit; "sampled 25 access grants from the period and traced each to an approval ticket" is.

4. Findings, graded honestly

Each finding needs a classification, a statement of the requirement, the evidence observed, and the gap. Use the standard grading: a major nonconformity is a total breakdown of a requirement or a systemic failure; a minor nonconformity is an isolated lapse that does not undermine the ISMS; observations and opportunities for improvement capture weaknesses that are not yet breaches. Grading everything as an observation to keep the report clean is transparent to a certification auditor and discredits the audit.

5. Evidence references

Every finding, and every conclusion of conformity, should cite the evidence behind it: the ticket numbers, log extracts, interview notes, and sampled records. This is what separates an audit report from an opinion document, and it is the first thing a certification body probes.

6. Conclusion and distribution

Close with an overall conclusion on ISMS conformity and effectiveness, the corrective action expectations with owners and timeframes, and confirmation the report was reported to relevant management, because Clause 9.2 requires exactly that, and the results must feed the management review under Clause 9.3.

From Findings to Closure

The report does not end the process. Each nonconformity flows into corrective action under Clause 10.1: containment, root cause, corrective action, and verification of effectiveness. Certification bodies check that the loop closed, not just that a plan was written. Our guide to handling nonconformities covers how to write corrective action plans that survive verification.

The credibility testA certification auditor asks four questions of an internal audit report: Was the auditor impartial? Was real evidence sampled? Were findings graded honestly? Were corrective actions tracked to closure? Zero findings from a self-audit answers all four, badly.

If You Need the Audit Done, Not Just Described

Writing the report presumes someone competent and impartial performed the audit behind it. If your certification deadline is close and Clause 9.2 is still open, our ISO 27001 internal audit report service delivers the full cycle: plan, fieldwork, evidence sampling, graded findings, and a certification-ready report, typically in two to four weeks. If you want internal audit covered permanently alongside surveillance prep and management review, that is the Assurance Program.