Table of Contents

Reach SOC 2 Compliance in 6 Weeks or Less.

  / ISO 27001 Internal Audit Explained: Key Steps and Best Practices

ISO 27001 Internal Audit Explained: Key Steps and Best Practices

Achieving ISO 27001 certification signifies excellence in information security management, demonstrating your organization’s dedication to protecting sensitive data. However, this process involves careful steps, with one of the most important being the internal audit. This crucial phase verifies that your Information Security Management System (ISMS) meets ISO 27001 standards and is strong enough to reduce risks.

Watch the Loom Video for a detailed explanation of our internal audit services, check out our Loom video, where our Principal Consultant Ali Hayat breaks down the process step-by-step and shares tips for seamless ISO 27001 compliance. Click here to watch the Loom video.

ISO 27001 Internal Audit

What is an ISO 27001 Internal Audit?

 

An ISO 27001 internal audit is a structured review of your ISMS to check its compliance with the standard’s requirements. Unlike external audits done by certification bodies, internal audits are performed by the organization itself or by a third-party auditor to find gaps, evaluate risks, and ensure readiness for certification.

The main goal of an internal audit is to ensure that your ISMS meets ISO 27001 requirements and effectively reduces risks. It also offers a chance to find areas for improvement and strengthen your organization’s security efforts. By conducting a thorough gap analysis during this stage, you help set your organization up for success in the certification process.

ISO 27001 Internal Audit Requirements: Understanding Clause 9.2

 

Clause 9.2 of ISO 27001:2022 establishes the specific requirements for internal audits, forming the backbone of audit governance. This section mandates that organizations establish and implement audit programs to evaluate the effectiveness of their ISMS at planned intervals.

The standard specifies several critical requirements within Clause 9.2:

Clause 9.2.1 – Audit Program Requirements: Organizations must define audit objectives, scope, frequency, and methodologies. Your audit program should establish criteria against which the ISMS will be evaluated, ensuring that all relevant information security controls are systematically reviewed over a defined period.

Clause 9.2.2 – Auditor Competence and Objectivity: This is perhaps the most critical requirement. Auditors must be objective, impartial, and free from conflict of interest. The standard explicitly prohibits auditors from evaluating areas for which they hold direct responsibility, as this compromises independence and undermines audit credibility.

To meet Clause 9.2.2, auditors should possess documented competence in ISO 27001 standards and audit methodologies. Many organizations require auditors to hold certifications such as Certified Information Systems Auditor (CISA) or ISO 27001 Lead Auditor. Reference to ISO 19011 – Guidelines for auditing management systems – provides additional guidance on selecting, evaluating, and managing auditors.

Who Can Perform an ISO 27001 Internal Audit?

Internal audits can be carried out by your organization’s own internal audit team or outsourced to a third-party auditor or an ISO 27001 consulting firm. Unlike external certification audits, you can choose the most suitable approach for your organization. However, it’s crucial to follow Clause 9.2(e) of the ISO 27001 standard, which stresses the importance of selecting an internal auditor who is objective and impartial. This means avoiding any potential conflicts of interest—specifically, the auditor should not have been involved in developing the ISMS or in operating or monitoring any of the controls under review. The reason for this requirement is simple: reviewing your own work can undermine objectivity and hinder a thorough evaluation.

Essential Auditor Qualifications

When selecting an auditor, ensure they meet the following criteria:

In-Depth ISO 27001 Knowledge: Auditors must understand the standard’s requirements, Annex A controls, and how they apply to your organization’s context.

Audit Methodology Expertise: Knowledge of audit planning, sampling techniques, evidence collection, and report writing.

Relevant Certifications: ISO 27001 Lead Auditor (IRCA or equivalent), CISA, or similar credentials demonstrate formal competence.

Industry Experience: Understanding of your sector’s specific security challenges and regulatory landscape adds significant value.

If internal expertise is limited, hiring an experienced third-party auditor or consulting firm can provide a fresh, unbiased perspective and valuable insights tailored to your organization’s unique environment.

Internal Audit vs External Certification Audit: Key Differences

Understanding the distinction between internal and external audits is crucial for effective compliance strategy. While both serve important roles, they differ significantly in purpose, scope, and outcome.

Aspect

Internal Audit

External Certification Audit

Conducted By

Organization (internal or contracted third party)

Accredited certification body

Primary Purpose

Identify gaps and prepare for certification

Verify compliance and issue certificate

Focus

Detailed improvement; addresses specific findings

Overall conformance; verifies readiness

Flexibility

High – customize scope and approach

Low – standardized audit procedures

 

Internal audits serve as your organization’s opportunity to address vulnerabilities proactively before the certification audit. They foster a culture of continuous improvement and ensure that any gaps are remediated well in advance. This strategic advantage makes internal audits invaluable in the certification journey.

How to Conduct an ISO 27001 Internal Audit: Key Phases

Conducting an ISO 27001 internal audit involves a series of well-defined steps to ensure that your Information Security Management System (ISMS) is thoroughly evaluated. Below is a detailed breakdown of the process:

Phase 1: Determine the Scope of the Audit

The first step is to clearly outline the audit’s scope, specifying the systems, functions, people, and processes that will be assessed. This scope ensures the audit comprehensively covers all necessary areas to meet compliance objectives. Defining the boundaries early on helps the auditor focus on the most relevant elements of the ISMS, particularly considering your organization’s specific ISMS scope boundaries and the applicability of controls.

Phase 2: Documentation Review

Before proceeding with on-site evaluations, the internal auditor will review all key ISMS documents to verify that they align with ISO 27001 requirements. An effective ISMS requires a well-defined scope, a comprehensive Statement of Applicability (SoA), a robust Information Security Policy, a thorough risk assessment and treatment plan, and clear definitions of responsibilities. Additionally, identifying individuals responsible for implementing and operating controls, and documenting evidence of control implementation, provides valuable context for the field review.

Phase 3: Management Review and Approval

The audit plan must be reviewed and approved by senior management. Regular meetings should be scheduled to set expectations, discuss timelines, and maintain open communication. Management also plays a critical role in reviewing the internal audit findings, collaborating with the auditor to assess the organization’s readiness for an external certification audit, and ensuring that all significant issues are addressed beforehand.

Phase 4: Pre-Audit Preparation

Preparation is critical for a successful audit. This phase includes developing detailed audit checklists, identifying key personnel for interviews, scheduling on-site activities, and gathering necessary documentation. A well-prepared audit checklist aligned with ISO 27001 requirements and your organization’s context ensures comprehensive coverage and consistency.

Phase 5: Conducting the Field Review

The field review is the core of the internal audit process. During this phase, the auditor evaluates the ISMS through multiple evaluation methods, gathering evidence to support findings and determine the effectiveness of controls.

Audit Tests: Assessing controls to ensure they are effectively implemented and functioning as intended. This involves testing a sample of control activities to verify control effectiveness.

Audit Evidence Collection: Reviewing documented information and audit trails to confirm compliance and identify gaps. Evidence should support all audit conclusions.

Staff Interviews: Engaging with employees to gauge their understanding of and adherence to ISMS policies. These interviews provide crucial insight into whether controls function as designed in practice.

Observations and Documentation: Recording findings, highlighting areas of non-conformity, and identifying strengths. Clear documentation enables transparent reporting and actionable recommendations.

This comprehensive review enables the auditor to pinpoint what’s working well and what needs improvement, providing a clear roadmap for corrective actions.

ISO 27001 Internal Audit Checklist: Essential Items

A well-designed audit checklist is fundamental to conducting a thorough and consistent internal audit. The checklist should cover all ISO 27001 requirements and be tailored to your organization’s context. Below are the essential categories and items to include:

Organizational Context (Clauses 4.1-4.3): Verify that the organization understands its internal and external context, interested parties, and scope of the ISMS.

Leadership and Governance (Clauses 5-6): Confirm management commitment, information security policy, allocation of roles and responsibilities, and evidence of management review.

Planning (Clause 6): Assess risk assessment methodology, risk treatment plans, and management of information security objectives.

Support and Operation (Clauses 7-8): Check resource availability, competence assessments, awareness and training programs, and operational control implementation.

Performance Evaluation (Clause 9): Review monitoring and measurement of controls, incident management procedures, and evidence that internal audit has been appropriately planned and conducted.

Improvement (Clause 10): Evaluate management of non-conformities, corrective action effectiveness, and documented information control.

Incorporating Annex A controls into your checklist ensures that all 114 control objectives are evaluated within the scope of your ISMS. Many organizations create control-specific evaluation criteria linked to this comprehensive checklist.

Addressing Non-Conformities

 

Non-conformities can range from minor documentation gaps to critical security flaws. Identifying and addressing these issues promptly is essential to maintain the integrity of your ISMS. By developing comprehensive corrective action plans and monitoring their implementation, organizations can ensure continuous improvement and long-term compliance with ISO 27001 standards.

 

Common ISO 27001 Internal Audit Findings

Understanding typical non-conformities helps organizations proactively address vulnerabilities. Here are the most frequently encountered findings:

Documentation Gaps: Missing, incomplete, or outdated policies, procedures, or records. For example, risk assessment documentation that doesn’t clearly link to implemented controls.

Access Control Deficiencies: Inadequate user access reviews, orphaned accounts, lack of segregation of duties, or insufficient multi-factor authentication implementation.

Incident Management Issues: Incomplete incident logs, lack of timely incident classification, or insufficient root cause analysis documentation.

Training and Awareness Gaps: Insufficient security awareness training records, lack of role-specific training, or no evidence of competency assessment.

Change Management Failures: Changes implemented without proper authorization, risk assessment, or documented approvals.

Backup and Recovery Defects: Untested backup procedures, unclear recovery objectives, or lack of documented restoration testing records.

The Corrective Action Process

Addressing non-conformities requires a structured, documented approach. The standard corrective action process includes:

Classification: Categorize each finding as Major (major risk or complete absence of a control) or Minor (temporary deviation or incomplete implementation that doesn’t significantly impact security).

Root Cause Analysis: Investigate why the non-conformity occurred—whether due to lack of awareness, insufficient resources, or inadequate procedures.

Corrective Action Plan: Develop specific, measurable actions with defined timelines and responsible parties. Plans should address root causes, not just symptoms.

Implementation Monitoring: Track progress toward completion and verify that actions are implemented as planned.

Effectiveness Verification: Re-audit completed actions to confirm they have resolved the non-conformity and prevented recurrence.

Major non-conformities must be resolved before certification, while minor findings require documented action plans with appropriate timelines. Organizations should also review common mistakes during ISO 27001 implementation to avoid repeating the same errors across multiple audits.

Timeline of Internal Audits

A successful ISO 27001 internal audit requires careful planning and execution. Here’s a detailed breakdown of the key phases and estimated time required for each, though actual duration depends on organization size, ISMS complexity, and control maturity.

Planning (0.5 days): Define the audit scope, objectives, and methodology. Develop an audit plan, including the schedule and resource allocation. This phase establishes the foundation for all subsequent work.

Preparation (0.5 days): Review relevant documentation, develop audit checklists, and identify key personnel to be interviewed. Preparation ensures efficiency during field activities.

Audit Execution (1-2 weeks): Conduct interviews, document reviews, and observations. Verify the implementation of controls and procedures. Identify non-conformities and opportunities for improvement. This phase is the most time-intensive and involves active on-site engagement.

Reporting (1 day): Prepare a detailed audit report, including findings, recommendations, and corrective action requirements. Review the report with management to ensure accuracy and completeness.

Closure (1 day): Finalize the audit report and distribute it to relevant stakeholders. Monitor the implementation of corrective actions. Schedule follow-up audits to verify the effectiveness of corrective actions and ensure sustainable improvement.

The audit execution timeline varies significantly based on organization size. A small organization with a well-defined scope might complete field activities in 3-5 days, while a larger enterprise with multiple business units could require 2-3 weeks. The complexity of your ISMS and the maturity of your existing controls also play significant roles in determining realistic timelines.

ISO 27001 Internal Audit Timeline

Benefits of a Well-Executed Internal Audit

Conducting a comprehensive internal audit provides key benefits for organizations aiming for ISO 27001 certification:

Certification Readiness: Identifying and fixing gaps before the certification audit greatly boosts the chances of passing on the first attempt and minimizes the need for re-audits.

Enhanced Security: Internal audits reinforce your ISMS by verifying control effectiveness, reducing weaknesses, and increasing your organization’s resilience to security risks.

Operational Efficiency: The process reveals inefficiencies and overlaps, helping you streamline workflows and better allocate resources for security efforts.

Stakeholder Trust: Showcasing strong, documented security practices through internal audits builds confidence with clients, partners, regulators, and other stakeholders. This often provides a competitive edge and supports business growth.

Culture of Improvement: Regular audits foster a mindset of continuous enhancement, motivating ongoing review and improvement of security measures beyond mere compliance.

Understanding Your Path to Certification with Axipro

 

Axipro’s internal audit services are designed to simplify the ISO 27001 compliance process. Our team of experienced auditors conducts thorough assessments, identifying gaps and providing actionable insights to strengthen your ISMS.

We tailor our approach to your organization’s unique needs, offering guidance from planning to corrective actions. With Axipro, you can streamline your internal audit process, reduce complexity, and achieve ISO 27001 certification confidently.

Conclusion

 

An ISO 27001 internal audit is a cornerstone of effective information security management. It ensures compliance, enhances security practices, and prepares your organization for certification success. By following a structured approach and leveraging expert support, you can make the audit process smooth and impactful.

Frequently Asked Questions

What is the purpose of an ISO 27001 internal audit?

The primary purpose is to verify that your ISMS aligns with ISO 27001 standards, identify gaps and non-conformities before external certification, ensure controls are effectively operating, and prepare the organization for successful certification audit.

Internal audits can be conducted by your organization’s internal audit team or outsourced to qualified third-party auditors or consulting firms. However, auditors must be objective, impartial, and free from conflicts of interest as required by Clause 9.2.

After completion, the audit report is distributed to management. Non-conformities are categorized and corrective action plans are developed. Organizations then implement and monitor these corrections. Follow-up audits verify the effectiveness of corrective actions. Once major non-conformities are resolved, the organization proceeds to schedule the external certification audit.

ISO 27001 requires audits at planned intervals, typically at least annually for certified organizations. Pre-certification organizations should conduct audits multiple times (3-6 months before certification). Focused audits can be conducted quarterly or as-needed after significant changes.

Simplify your ISO 27001 compliance journey with Axipro’s expert internal audit services.

Axipro Author

Picture of Abeera Zainab

Abeera Zainab

Blog Highlights

Explore More Articles

Most organizations think their AI governance is further along than it is. McKinsey’s 2026 AI Trust Maturity Survey of roughly 500 organizations found an average maturity score of 2.3 out of 4, and only about a third reported level three or higher in strategy, governance, and agentic AI oversight. Adoption is outpacing control, and regulators have noticed. An AI governance maturity model gives you a way to measure that gap honestly. This guide covers what a maturity model is, the six dimensions it should measure, the five levels most models use, and how to assess your own organization and build a roadmap to the next level. What Is an AI Governance Maturity Model? An AI governance maturity model is a structured framework that describes how capable an organization is at governing its AI systems, usually across five progressive levels. The concept borrows directly from the Capability Maturity Model (CMM) that software engineering has used since the early 1990s: define the capability, describe what it looks like at each stage of development, and score yourself against it. The purpose is diagnosis. A maturity model tells you where governance is strong, where it’s theater, and where it doesn’t exist at all. How It Differs from General AI Governance Frameworks Frameworks like the NIST AI Risk Management Framework or ISO/IEC 42001 tell you what good governance contains: policies, risk assessments, accountability structures, monitoring. A maturity model tells you how well you’re doing those things today. The framework is the destination. The maturity model is the odometer. That distinction matters in practice. Plenty of companies can point to an AI policy document. Far fewer can show that the policy changes what teams actually ship. Why Enterprises Need a Maturity Model Three reasons. First, budget: you can’t prioritize governance investment without knowing which dimension lags. Second, accountability: a maturity score gives boards something concrete to track quarter over quarter. Third, regulation: the EU AI Act and frameworks like ISO 42001 assume a functioning management system, and a maturity assessment is the fastest way to find out whether yours would survive scrutiny. Core Dimensions of an AI Governance Maturity Model A useful model measures more than policy coverage. Six dimensions show up consistently across the credible models, including the IEEE-USA flexible maturity model built on the NIST AI RMF. Strategy and leadership. Does the organization have a stated position on AI risk, an executive owner (increasingly a Chief AI Officer), and board visibility? Gartner’s 2025 polling found 55% of organizations now have an AI board or dedicated oversight committee, which means nearly half still govern by improvisation. Policies, standards, and accountability. Written policies mapped to regulations, a RACI matrix for AI decisions, and clear escalation paths. Many organizations adapt the three lines of defense model from financial risk: the teams building AI, the risk function overseeing them, and internal audit checking both. Data governance and model lifecycle. Training data lineage, quality controls, and lifecycle management from development through deployment, monitoring, and retirement. This is where AI governance meets MLOps, and where mature organizations maintain an AI register, a live inventory of every model and system in production. Risk, compliance, and ethics. Risk classification of AI systems, impact assessments, bias and fairness testing, and explainability requirements. Banks will recognize the DNA of model risk management under SR 11-7 here. People, skills, and culture. Training, role clarity, and whether people outside the governance team actually understand their obligations. Tools, automation, and monitoring. Drift detection, automated policy checks, audit logging, and dashboards. Governance that lives in spreadsheets caps out around level three. The 5 Levels of AI Governance Maturity Level 1: Ad Hoc / Initial AI use happens without oversight. There’s no inventory, no policy, or a policy nobody follows. Shadow AI is common, and risk surfaces only when something breaks publicly. Level 2: Developing / Repeatable Someone has been assigned responsibility. A draft policy exists, a partial inventory exists, and reviews happen for high-profile projects. The practices are repeatable but depend on specific people rather than defined processes. Level 3: Defined / Structured Governance is documented, standardized, and applied across the organization. There’s a governance committee, a risk classification scheme, defined lifecycle gates, and mandatory training. Most organizations pursuing ISO 42001 certification are working to reach and formalize this level. Level 4: Managed / Metrics-Driven Governance produces numbers. Coverage rates, review cycle times, incident counts, and risk reduction are measured and reported to leadership. Controls are enforced by tooling rather than goodwill, and audits confirm the system works as described. Level 5: Optimized / Adaptive Governance improves itself. Monitoring feeds back into policy, controls adapt to new model types (agentic systems being the current test), and the organization anticipates regulatory change rather than reacting to it. Almost nobody is here yet, and that’s fine. Level 5 is a direction, not a deadline. Insider Note: In assessments, the most common self-scoring error is claiming level 3 on the strength of documents alone. If your policy says every model gets a pre-deployment review and your inventory shows 40 models but your review log shows 6, you’re at level 2. Evidence beats paperwork every time, and auditors check the logs first. AI Governance Maturity Matrix The matrix crosses dimensions with levels so you can score each one independently. Organizations are rarely uniform: it’s normal to sit at level 3 on policy and level 1 on monitoring. For scoring, keep the rubric simple: 1 to 5 per dimension, scored on evidence you could show an auditor, not on intentions. Board-level indicators (does the board see AI risk reporting?) and operational indicators (does every production model have a completed impact assessment?) should be scored separately, because they fail independently. How to Assess Your Current AI Governance Maturity Start with a baseline self-assessment. Pull together a cross-functional group covering engineering, legal, risk, security, and the business owners of major AI use cases, and score each dimension against the matrix. Half a day is usually enough for a first pass. For each dimension, the

Most organizations get ISO 42001 certified in 2 to 9 months. Companies that already hold ISO 27001 regularly land in the 2 to 5 month range, while enterprises with sprawling AI portfolios and no existing management system can take 12 months or more. The audit itself only takes days. Almost the entire calendar goes into building and operating your AI Management System (AIMS) long enough to produce evidence an auditor can actually check. That is the short answer. The longer answer depends on your starting point, your scope, and how quickly you can get a certification body on the schedule. This article breaks down the full timeline phase by phase, the factors that stretch or compress it, and what the recertification cycle looks like once you hold the certificate. Typical ISO 42001 Certification Timeline at a Glance ISO/IEC 42001:2023 is the first international standard for AI management systems, published in December 2023. Because it follows the same harmonized structure as ISO 27001 and ISO 9001, the certification process will feel familiar to anyone who has been through a management system audit: build the system, run it, pass a Stage 1 and Stage 2 audit, then maintain it through annual surveillance. Here is how timelines typically break down by company size. Average Timeline for Small Businesses Small companies move fastest because scope stays contained. A startup with two or three AI systems, a handful of decision makers, and short approval chains can finish scoping in a week and get policies signed off in days rather than weeks. The realistic floor for a small business starting from scratch is around 3 months. With an existing ISO 27001 program and a compliance platform already collecting evidence, 2 months is achievable. Average Timeline for Mid-Sized Companies Mid-sized companies usually take 6 to 9 months. The AI inventory is growing, more departments are touching AI systems, and risk assessments have to cover more use cases. Coordination becomes the hidden cost: getting engineering, legal, and product to agree on an AI policy takes longer than writing the policy itself. Average Timeline for Enterprises Enterprises should plan for 9 to 12 months, sometimes longer. The main drivers are AI system sprawl across business units, longer procurement cycles for certification bodies, and audits that take more days. The Stage 2 audit for a large multinational can run two weeks or more on its own, and internal alignment before the audit takes far longer than the audit itself. Breakdown of the ISO 42001 Certification Timeline by Phase The phases below overlap in practice. Treat the durations as effort estimates for a reasonably resourced program, not a strict sequence. Phase 1: Scoping and Gap Analysis (2–4 Weeks) Everything starts with two questions: which AI systems are in scope, and how far is your current governance from what the standard requires? The gap analysis maps your existing policies and controls against the standard’s clauses and Annex A controls, and produces the project plan for everything that follows. Get the scope wrong here and every later phase inherits the mistake. Phase 2: AIMS Design, Leadership, and AI Policy Development (2–4 Weeks) This phase establishes the skeleton of the management system: the AI policy, governance roles, objectives, and the leadership commitments the standard requires. Executive sign-off is the gating item. The documents are not hard to write. Getting senior leadership to formally own AI governance is where programs stall. Phase 3: AI Risk and Impact Assessments (2–6 Weeks) ISO 42001 requires both AI risk assessments and AI impact assessments, and the distinction matters. Risk assessments look at what could go wrong for the organization. Impact assessments look at consequences for individuals and society, which is a newer discipline for most teams. This phase takes longer when you have many AI systems, high-risk use cases, or no prior methodology to adapt. The output feeds directly into your Statement of Applicability (SoA), the document that maps which Annex A controls you have selected and why. Insider Note: Impact assessments are where auditors probe hardest, because they are the most distinctive part of ISO 42001 compared with ISO 27001. A recycled security risk register with “AI” pasted into it will get picked apart in Stage 2. Build the impact assessment methodology properly the first time. Phase 4: Controls Implementation (2–10 Weeks) The longest phase. Here you implement the Annex A controls selected in your SoA: AI system lifecycle documentation, data governance for training data, human oversight mechanisms, transparency measures, supplier management for third-party AI, and so on. Duration depends almost entirely on the gap analysis results. Organizations with mature engineering practices often find they already do much of this and just need to document it. Organizations without formal AI development processes are building from zero. Phase 5: Documentation, Training, and Evidence Collection (2–8 Weeks) Certification requires proof that the system operates, not just that it exists on paper. That means records: training completion logs, risk assessment outputs, review meeting minutes, monitoring reports. This phase runs partly in parallel with implementation, but it cannot be compressed below a certain floor because auditors want to see evidence generated over time, not a folder of documents all created the week before Stage 1. Phase 6: Internal Audit and Management Review (2–4 Weeks) The standard requires an internal audit of the AIMS and a formal management review before the certification audit. This is your dress rehearsal. A good internal audit surfaces nonconformities while they are still cheap to fix. Skipping or rushing it is a false economy that shows up later as Stage 2 findings. Phase 7: Stage 1 Certification Audit (1–2 Weeks) The certification body reviews your documentation and assesses readiness for Stage 2. The audit itself takes 1 to 3 days for most organizations. The auditor examines your scope statement, AI policy, risk and impact assessment methodology, SoA, and internal audit results, then issues findings. The 1–2 week window covers the audit plus the report. Phase 8: Closing Nonconformities (2–4 Weeks) Almost every Stage 1 produces findings.

How Axipro Guided Technovative Solutions & DigiProd Pass to ISO 27001