ISO/IEC 27001:2022

ISO 27001 Internal Audit Checklist: What to Audit Before Certification

Internal audit is one of the most important activities before an ISO 27001 certification audit. It helps verify whether the Information Security Management System has been properly implemented, whether controls are operating as intended, and whether documented information is sufficient to demonstrate conformity.

This guide explains what an ISO 27001 internal audit checklist should cover, how to structure the audit by process and clause, and what auditors typically expect to see before certification.

11 min read Internal Audit Guide

Key Takeaways

  • An ISO 27001 internal audit should verify both conformity to the standard and effective implementation of the ISMS.
  • The internal audit checklist should cover Clauses 4–10, relevant Annex A controls and key operational processes within the ISMS scope.
  • Audit evidence should include interviews, documented information, records, operational practices and objective evidence of control implementation.
  • The audit should be risk-based and aligned with the organization’s scope, risks and applicable controls.
  • Internal audit findings should be resolved before certification readiness is declared.

In This Article

What is an ISO 27001 Internal Audit? Why Internal Audit Matters Before Certification What an ISO 27001 Internal Audit Checklist Should Cover Clause 4–10 Internal Audit Checklist Areas Audit Checklist by Process / Department Evidence to Verify During the Audit How to Plan the Internal Audit Common ISO 27001 Internal Audit Findings What Certification Auditors Will Expect FAQ

What is an ISO 27001 Internal Audit?

An ISO 27001 internal audit is a systematic review conducted by the organization, or on its behalf, to determine whether the ISMS conforms to planned arrangements, conforms to ISO/IEC 27001 requirements, and is effectively implemented and maintained.

It is not only a document review. A good internal audit evaluates whether the organization’s information security processes and controls are operating as intended and whether there is sufficient evidence to support certification readiness.

Conformity Check

Verifies whether the ISMS meets ISO 27001 Clause 4–10 requirements and the organization’s own ISMS arrangements.

Implementation Check

Verifies whether procedures, controls, registers and records are actually being used and maintained.

Improvement Input

Identifies nonconformities, weaknesses, gaps and improvement opportunities before certification audit.

Why Internal Audit Matters Before Certification

Clause 9.2 requires organizations to conduct internal audits at planned intervals. In practice, the internal audit is one of the strongest indicators of whether the ISMS is mature enough for certification.

Before certification, the internal audit should help confirm whether:

  • The ISMS scope, policy, objectives and responsibilities are established and communicated.
  • Risk assessment, risk treatment and Statement of Applicability are complete and aligned.
  • Operational controls are implemented and supported by records.
  • Incidents, changes, supplier arrangements and access controls are being managed as planned.
  • Management review has been conducted and corrective actions are being followed up.

What an ISO 27001 Internal Audit Checklist Should Cover

A practical internal audit checklist should not be limited to clause wording copied from the standard. It should reflect how the organization’s ISMS actually operates.

Management System

Clauses 4–10

Context, leadership, planning, support, operation, performance evaluation and improvement.

Operational Controls

Applicable Processes

Asset management, access control, backup, incident management, supplier security, change management and business continuity.

Annex A

Applicable Controls

Only the controls determined applicable through the Statement of Applicability need to be audited for implementation.

Records

Objective Evidence

Registers, logs, reports, training records, audit reports, review minutes, test results and corrective action evidence.

Clause 4–10 Internal Audit Checklist Areas

Clause What to Audit Typical Evidence
Clause 4 – Context ISMS scope, internal and external issues, interested parties and relevant requirements. ISMS scope statement, issues register, interested parties register.
Clause 5 – Leadership Policy, roles, responsibilities, authorities and management commitment. Information Security Policy, roles matrix, meeting records, approvals.
Clause 6 – Planning Risk assessment methodology, risk assessment results, Risk Treatment Plan, SoA and objectives. Risk register, risk treatment plan, SoA, objectives register.
Clause 7 – Support Competence, awareness, communication and control of documented information. Training records, awareness records, communication records, document control arrangements.
Clause 8 – Operation Implementation of operational controls and ISMS processes. Access records, backup logs, incident records, supplier evaluations, change records.
Clause 9 – Performance Evaluation Monitoring, internal audit programme, internal audit results and management review. Monitoring register, audit programme, audit report, management review minutes.
Clause 10 – Improvement Nonconformities, corrective actions and improvement actions. Corrective action records, updated documents, closure evidence.

Download the Free ISO 27001 Starter Pack

Includes implementation checklist, documented information list, information asset register sample and risk assessment sample.

Download Starter Pack

Audit Checklist by Process / Department

In addition to clause-based audit questions, the internal audit checklist should be adapted to the organization’s actual processes and departments. This makes the audit more meaningful and helps connect the ISMS to business operations.

IT / Infrastructure

Access control, patching, backup, logging, vulnerability management, incident response and restoration testing.

Human Resources

Competence, awareness, confidentiality arrangements, onboarding and employee exit controls.

Procurement / Vendor Management

Supplier security requirements, cloud service assessment, contracts and third-party evaluations.

Business Functions

Asset ownership, information classification, operational handling of information, incident reporting and compliance with ISMS rules.

Evidence to Verify During the Audit

Internal audit should be evidence-based. Auditors should verify not only whether documents exist, but whether the organization can demonstrate implementation and control.

Typical evidence includes:

  • Approved policy and ISMS documented information
  • Internal and external issues register, interested parties register and roles matrix
  • Risk assessment register, Risk Treatment Plan and Statement of Applicability
  • Information asset register and classification records
  • User access approvals, access review records and privileged access records
  • Backup logs, restoration test results, vulnerability register and patch records
  • Incident reports, investigation records and corrective actions
  • Training and awareness records
  • Internal audit programme, internal audit checklist and internal audit report
  • Management review minutes and follow-up actions

How to Plan the Internal Audit

Internal audit should be planned rather than improvised. The audit programme and audit plan should consider risk, importance of processes, previous audit results, changes affecting the ISMS and certification timing.

Planning Element What to Define
Audit Scope Which locations, departments, processes and controls will be audited.
Audit Criteria ISO/IEC 27001 requirements, internal procedures, SoA controls and organizational requirements.
Audit Methods Interviews, document review, record review, observation and sampling.
Audit Team Competent auditors who are objective and independent from the activities being audited where practicable.
Audit Schedule Planned timing, departments, process owners and duration.

Common ISO 27001 Internal Audit Findings

  • Scope not clearly aligned with actual business operations or systems.
  • Internal and external issues or interested parties not maintained or not linked to the ISMS.
  • Risk assessment not updated after changes, incidents or new systems.
  • Statement of Applicability not aligned with Risk Treatment Plan or actual controls.
  • Evidence of awareness or competence not retained.
  • Access approvals and access reviews not consistently maintained.
  • Backup restoration testing not evidenced.
  • Supplier security evaluation not performed for relevant third parties.
  • Management review not covering required inputs or not conducted at all.
  • Corrective actions not effectively closed.

What Certification Auditors Will Expect

Internal audit programme established and implemented.
Audit scope covers the ISMS and relevant processes.
Internal audit checklist and audit report retained as evidence.
Audit findings clearly recorded and communicated.
Nonconformities and corrective actions followed up to closure.
Audit conclusions support management review and certification readiness.
Auditors are competent and sufficiently objective.
Internal audit is more than a superficial document check.

Frequently Asked Questions (FAQ)

Yes. ISO/IEC 27001 requires internal audit to be conducted at planned intervals, and certification bodies will expect evidence that internal audit has been completed before the certification audit.

Ideally both. The checklist should ensure Clause 4–10 coverage while also being adapted to the organization’s actual processes, departments and applicable controls.

Internal auditors should be objective and impartial. Where possible, they should not audit activities for which they are directly responsible. Smaller organizations may need practical arrangements, but objectivity should still be maintained.

The checklist is used during the audit to guide verification of requirements and evidence. The audit report records the audit summary, findings, conclusions and any nonconformities or opportunities for improvement.

Need ISO 27001 Internal Audit Templates?

Access the complete ISO 27001 Document Kit with internal audit programme, internal audit plan, internal audit checklist by process, internal audit report, management review records and full ISMS templates.

View ISO 27001 Document Kit