ISO 27001 Clause 9.2, one full cycle

One independent internal audit. One report your certification body accepts.

A complete ISO 27001 internal audit, planned, conducted, and reported by an independent senior auditor. You get the certification-ready internal audit report Clause 9.2 requires, without hiring for a role you need a few weeks a year.

Investment  One‑time engagement, fixed scope.

The audit Clause 9.2 requires, done properly once

ISO 27001 Clause 9.2 requires your ISMS to be internally audited at planned intervals by someone objective and impartial. For most small and mid-size teams that creates an impossible staffing problem: the people who know the ISMS built it, and the standard does not allow them to audit their own work. The practical answer is an outsourced internal audit, which the standard explicitly permits.

This engagement is one full audit cycle with a single deliverable that matters: an internal audit report your certification body will accept at Stage 1, Stage 2, or surveillance. It is the standalone version of the internal audit we run inside our annual Assurance Program. If you need one credible audit before a certification deadline rather than a year-round partner, this is the offer.

What is included

  • A documented audit plan: scope, criteria, schedule, and sampling approach, agreed before fieldwork.
  • Fieldwork by a senior auditor across the ISMS clauses (4 to 10) and the Annex A controls in your Statement of Applicability.
  • Real evidence sampling, with the sampling log retained, not a walkthrough of policies.
  • Findings classified honestly: major and minor nonconformities, observations, and opportunities for improvement.
  • The internal audit report itself, written to the standard certification bodies expect, with evidence references for every finding.
  • A findings walkthrough with management, corrective action guidance for each nonconformity, and input ready for your management review.

Why the report is the product

Your certification body reads the internal audit report as a proxy for whether your ISMS actually manages itself. A two-page self-audit with zero findings tells the auditor exactly one thing: the internal audit was not real. A defensible report shows planned scope, competent and impartial execution, genuine sampling, and honestly graded findings tracked to closure. That is the difference between an internal audit that satisfies Clause 9.2 and one that becomes a Stage 2 nonconformity itself.

A certification auditor who trusts your internal audit tests lighter. One who does not trusts nothing else in the room either.

Who it is for

Companies approaching Stage 1 or Stage 2 that have no internal audit done, or one they know will not survive scrutiny. Certified companies with a surveillance audit coming and a Clause 9.2 gap since the last visit. Teams whose platform marked "internal audit" complete with a template nobody executed. If you want the audit plus continuous assurance, management-review support, and surveillance prep all year, that is the Assurance Program.

How it runs

Two to four weeks end to end, fixed scope. Planning and scoping in the first days, fieldwork and evidence sampling across one to two weeks depending on the size of your ISMS, then the report and a findings walkthrough. We audit against your Statement of Applicability and your own ISMS documents, the way a certification body will. For background, our guides to what Clause 9.2 requires, outsourcing the internal audit, and handling nonconformities cover the detail.

Questions

ISO 27001 internal audits, answered

What is an ISO 27001 internal audit report?

The documented output of the Clause 9.2 internal audit: scope and criteria, the clauses and Annex A controls examined, evidence sampled, nonconformities graded by severity, observations, and the conclusions management and the certification body rely on. It is reviewed at Stage 1, Stage 2, and every surveillance audit.

Can the internal audit be outsourced?

Yes. The standard requires objectivity and impartiality, not an employee. Auditors cannot audit their own work, so for small teams outsourcing is often the only compliant option. Our guide to outsourcing the ISO 27001 internal audit covers this in depth.

Is an internal audit required before certification?

Yes. Certification bodies expect at least one full internal audit, with results fed into management review, before Stage 2. Arriving without one is itself a nonconformity against Clause 9.2.

What does a certification body look for in the report?

A planned scope, an objective and competent auditor, coverage of the ISMS and applicable Annex A controls, real evidence sampling, honestly classified nonconformities, and corrective actions tracked to closure. A zero-findings self-audit is a red flag, not a clean bill of health.

How long does it take?

Two to four weeks end to end: planning, one to two weeks of fieldwork depending on ISMS size, then reporting and a findings walkthrough.

How much does it cost?

It is a fixed-scope, one-time engagement, priced by the size of your ISMS, locations, and the Annex A controls in your Statement of Applicability. Book a call for pricing and we will confirm a written figure within one business day.

Is this the same as the certification audit?

No. The certification audit is performed by an accredited certification body, which issues the certificate. The internal audit is your ISMS checking itself, as Clause 9.2 requires. Ledger Audits performs internal audits only and never issues certificates, which is exactly what keeps the internal audit credible.

Get the internal audit done before your auditor asks for it

Tell us your certification timeline and the size of your ISMS. We will scope the audit and send a written figure within one business day.