Internal audit is one of the most important activities before an ISO 27001 certification audit. It helps verify whether the Information Security Management System has been properly implemented, whether controls are operating as intended, and whether documented information is sufficient to demonstrate conformity.
This guide explains what an ISO 27001 internal audit checklist should cover, how to structure the audit by process and clause, and what auditors typically expect to see before certification.
An ISO 27001 internal audit is a systematic review conducted by the organization, or on its behalf, to determine whether the ISMS conforms to planned arrangements, conforms to ISO/IEC 27001 requirements, and is effectively implemented and maintained.
It is not only a document review. A good internal audit evaluates whether the organization’s information security processes and controls are operating as intended and whether there is sufficient evidence to support certification readiness.
Verifies whether the ISMS meets ISO 27001 Clause 4–10 requirements and the organization’s own ISMS arrangements.
Verifies whether procedures, controls, registers and records are actually being used and maintained.
Identifies nonconformities, weaknesses, gaps and improvement opportunities before certification audit.
Clause 9.2 requires organizations to conduct internal audits at planned intervals. In practice, the internal audit is one of the strongest indicators of whether the ISMS is mature enough for certification.
Before certification, the internal audit should help confirm whether:
A practical internal audit checklist should not be limited to clause wording copied from the standard. It should reflect how the organization’s ISMS actually operates.
Context, leadership, planning, support, operation, performance evaluation and improvement.
Asset management, access control, backup, incident management, supplier security, change management and business continuity.
Only the controls determined applicable through the Statement of Applicability need to be audited for implementation.
Registers, logs, reports, training records, audit reports, review minutes, test results and corrective action evidence.
| Clause | What to Audit | Typical Evidence |
|---|---|---|
| Clause 4 – Context | ISMS scope, internal and external issues, interested parties and relevant requirements. | ISMS scope statement, issues register, interested parties register. |
| Clause 5 – Leadership | Policy, roles, responsibilities, authorities and management commitment. | Information Security Policy, roles matrix, meeting records, approvals. |
| Clause 6 – Planning | Risk assessment methodology, risk assessment results, Risk Treatment Plan, SoA and objectives. | Risk register, risk treatment plan, SoA, objectives register. |
| Clause 7 – Support | Competence, awareness, communication and control of documented information. | Training records, awareness records, communication records, document control arrangements. |
| Clause 8 – Operation | Implementation of operational controls and ISMS processes. | Access records, backup logs, incident records, supplier evaluations, change records. |
| Clause 9 – Performance Evaluation | Monitoring, internal audit programme, internal audit results and management review. | Monitoring register, audit programme, audit report, management review minutes. |
| Clause 10 – Improvement | Nonconformities, corrective actions and improvement actions. | Corrective action records, updated documents, closure evidence. |
Includes implementation checklist, documented information list, information asset register sample and risk assessment sample.
Download Starter PackIn addition to clause-based audit questions, the internal audit checklist should be adapted to the organization’s actual processes and departments. This makes the audit more meaningful and helps connect the ISMS to business operations.
Access control, patching, backup, logging, vulnerability management, incident response and restoration testing.
Competence, awareness, confidentiality arrangements, onboarding and employee exit controls.
Supplier security requirements, cloud service assessment, contracts and third-party evaluations.
Asset ownership, information classification, operational handling of information, incident reporting and compliance with ISMS rules.
Internal audit should be evidence-based. Auditors should verify not only whether documents exist, but whether the organization can demonstrate implementation and control.
Typical evidence includes:
Internal audit should be planned rather than improvised. The audit programme and audit plan should consider risk, importance of processes, previous audit results, changes affecting the ISMS and certification timing.
| Planning Element | What to Define |
|---|---|
| Audit Scope | Which locations, departments, processes and controls will be audited. |
| Audit Criteria | ISO/IEC 27001 requirements, internal procedures, SoA controls and organizational requirements. |
| Audit Methods | Interviews, document review, record review, observation and sampling. |
| Audit Team | Competent auditors who are objective and independent from the activities being audited where practicable. |
| Audit Schedule | Planned timing, departments, process owners and duration. |
Yes. ISO/IEC 27001 requires internal audit to be conducted at planned intervals, and certification bodies will expect evidence that internal audit has been completed before the certification audit.
Ideally both. The checklist should ensure Clause 4–10 coverage while also being adapted to the organization’s actual processes, departments and applicable controls.
Internal auditors should be objective and impartial. Where possible, they should not audit activities for which they are directly responsible. Smaller organizations may need practical arrangements, but objectivity should still be maintained.
The checklist is used during the audit to guide verification of requirements and evidence. The audit report records the audit summary, findings, conclusions and any nonconformities or opportunities for improvement.
Access the complete ISO 27001 Document Kit with internal audit programme, internal audit plan, internal audit checklist by process, internal audit report, management review records and full ISMS templates.
View ISO 27001 Document Kit