iso-27001-internal-audit-checklist

By July 25th, 2026ISO Audit And Certificate13 min read

ISO 27001 Internal Audit Checklist: ISMS Audit Guide

An ISO 27001 internal audit checklist helps you verify that your Information Security Management System (ISMS) conforms to the standard and operates effectively. With cyber threats growing across the Middle East, a thorough internal audit is your first line of defence. This guide covers Clauses 4–10, Annex A controls, evidence collection, reporting, and the key differences between internal and external audits.

Internal auditing is a mandatory requirement of ISO 27001:2022 Clause 9.2. It provides independent assurance that your ISMS is working as intended and that your security controls are effectively protecting information assets. Without a robust internal audit programme, your organisation cannot know whether its information security investments are delivering the expected results.

What Is an ISO 27001 Internal Audit Checklist?

An ISO 27001 internal audit checklist is a structured tool that guides auditors through each clause and control of the standard. It contains audit questions, document requests, and evidence collection criteria. The checklist ensures consistency across audits, helps less experienced auditors perform thorough reviews, and provides a complete record of what was examined for external auditors and certification bodies.

A good ISO 27001 checklist goes beyond yes-or-no questions. It prompts the auditor to verify implementation through interviews, observation, and system testing. The checklist should be updated before each audit cycle to reflect changes in the ISMS, new threats, and findings from previous audits.

ISMS Audit Planning

Effective ISMS audits start with proper planning. The audit programme must be risk-based, meaning high-risk areas are audited more frequently and more thoroughly than low-risk areas. Confirm the following before each audit cycle:

Planning ActivityDetailsResponsible
Define audit scopeIdentify departments, processes, locations, and outsourced services in scopeAudit programme manager
Select audit criteriaISO 27001:2022 clauses, Annex A controls, legal/regulatory requirements, contractual obligationsLead auditor
Risk-based schedulingPrioritise high-risk areas (network security, access control, third-party management, business continuity)ISMS team
Assemble audit teamTrained ISO 27001 internal auditors, independent of audited areas and processesAudit programme manager
Notify auditeesSend audit schedule, scope, and document requests at least two weeks in advanceLead auditor
Review previous reportsAnalyse findings from last internal audit, management review, and any external auditsLead auditor
Prepare audit checklistTailor the checklist to the specific scope, processes, and risks of the auditAudit team

Clauses 4–10 Audit Checklist

Below is the complete clause-by-clause ISO 27001 internal audit checklist covering Clauses 4 through 10. Each table includes audit questions, documents to request, and evidence to examine.

Clause 4 – Context of the Organisation

The auditor must verify that the organisation understands its internal and external context, the needs and expectations of interested parties, and the scope of the ISMS. This is the foundation upon which the entire ISMS is built.

Audit QuestionDocuments to RequestEvidence to Examine
Have external and internal issues affecting the ISMS been identified?Context analysis, business environment assessment, PESTLE analysisDocumented issues with relevance to information security and risk assessment
Are interested parties and their information security requirements documented?Interested party register, stakeholder requirements logLegal, regulatory, and contractual security requirements mapped to controls
Is the ISMS scope defined and documented with exclusions justified?ISMS scope documentBoundaries, applicability, exclusions, and justification for each exclusion
Does the ISMS include all necessary processes and their interactions?ISMS process map, process interaction diagramsInputs, outputs, sequence, and interfaces with other management systems

Clause 5 – Leadership

Top management must demonstrate active leadership and commitment to the ISMS. This is one of the most important clauses because without management commitment, the ISMS will lack resources, authority, and visibility.

Audit QuestionDocuments to RequestEvidence to Examine
Has top management demonstrated leadership and commitment for the ISMS?ISMS policy signed by top management, strategic plansPolicy communication evidence, resource allocation decisions, budget approvals
Is the information security policy appropriate, communicated, and reviewed?Information security policy document, review recordsPolicy awareness survey results, intranet postings, induction materials
Have information security objectives been established at relevant functions?ISMS objectives registerMeasurable objectives with KPIs, targets, progress reports, and review dates
Are information security roles and responsibilities defined and assigned?RACI matrix, role descriptions, ISMS committee charterNamed information security officer, defined escalation paths

Clause 6 – Planning

Planning is the heart of the ISMS. The auditor must verify that risk assessment and risk treatment processes are properly defined, executed, and maintained. The Statement of Applicability (SoA) must be complete and accurate.

Audit QuestionDocuments to RequestEvidence to Examine
How does the organisation assess information security risks?Risk assessment methodology, risk criteria, risk scalesCompleted risk assessment with risk owners, scores, and prioritisation
How are risk treatment options selected and applied?Statement of Applicability (SoA), risk treatment plan (RTP)SoA matched to Annex A, treatment deadlines, resource commitments, status updates
How are changes to the ISMS managed?ISMS change management procedureChange records, impact assessments, approval evidence, communication of changes
Are information security objectives planned and monitored?Objectives planning documentObjective achievement status, variance analysis, corrective actions for missed targets

Clause 7 – Support

Support covers resources, competence, awareness, communication, and documented information. Weaknesses in this clause undermine the entire ISMS because even the best policies fail without competent, aware personnel.

Audit QuestionDocuments to RequestEvidence to Examine
How are ISMS resources determined and provided?ISMS budget, staffing plans, security tool inventoryAllocated personnel, security tools, infrastructure budget, MSSP contracts
Are information security roles and responsibilities defined and understood?ISMS roles matrix, job descriptions, employment contractsRole assignments, authority levels for security decisions, committee memberships
Are personnel competent in information security?Competence records, training matrix, certification registerSecurity training attendance, professional certifications, competence assessment results
Is documented information controlled per ISO 27001 requirements?Document control procedure, record control procedure, document inventoryDocument approval records, versioning, distribution lists, retention and disposal practices

Clause 8 – Operation

This clause requires the organisation to plan, implement, and control its information security processes. The auditor must verify that risk treatment plans are being executed and that operational controls are effective.

Audit QuestionDocuments to RequestEvidence to Examine
How are information security risks assessed and treated operationally?Operational risk treatment plans, project risk assessmentsRisk assessments for new projects, systems, changes, and third-party engagements
Are third-party services assessed for information security?Supplier security assessment reports, due diligence recordsSupplier evaluations, contractual security clauses, ongoing monitoring evidence
How does the organisation manage information security incidents?Incident response procedure, incident registerIncident reports, response times, root cause analysis, lessons learned documentation

Clause 9 – Performance Evaluation

The organisation must evaluate ISMS performance through monitoring, measurement, analysis, internal audit, and management review. This clause closes the PDCA cycle and drives improvement.

Audit QuestionDocuments to RequestEvidence to Examine
How is ISMS performance monitored, measured, analysed, and evaluated?ISMS KPI dashboard, monitoring plan, metric definitionsSecurity metrics, trend analysis, action triggers, threshold alerts, incident statistics
What is the internal audit programme for the ISMS?Internal audit procedure, audit schedule, audit checklistsCompleted audit reports, checklist evidence, auditor qualifications, nonconformity closure
Does top management review the ISMS at planned intervals?Management review procedure, agenda templateManagement review minutes covering all required inputs, decisions, resource allocations
How is compliance with legal and regulatory requirements evaluated?Legal register, compliance evaluation recordsCompliance evaluation reports, regulatory correspondence, license renewals

Clause 10 – Improvement

The final clause addresses nonconformity handling, corrective actions, and continual improvement. This is where the ISMS demonstrates whether it is a mature, self-correcting system.

Audit QuestionDocuments to RequestEvidence to Examine
How are nonconformities and corrective actions managed in the ISMS?Corrective action procedure, nonconformity log, root cause analysis recordsRoot cause analysis quality, corrective action completion rates, effectiveness verification
How does the organisation drive continual improvement of the ISMS?Improvement register, lessons learned database, security roadmapImprovement projects, implemented recommendations, before/after metrics

Annex A Control Audit Checklist

ISO 27001:2022 defines 93 controls across 4 themes. Your internal audit must verify that applicable controls from the Statement of Applicability (SoA) are implemented and effective. This is where the internal audit differs most from a clause-level audit, because each control requires specific verification techniques.

Annex A ThemeControl CountKey Controls to AuditVerification Approach
Organisational controls37Information security policies, roles and responsibilities, incident management, business continuity, supplier securityPolicy review, role definition documents, incident response drills, BCP tabletop exercises
People controls8Screening, terms and conditions, awareness and training, disciplinary process, remote workingBackground check records, training completion rates, signed NDAs, remote work policy implementation
Physical controls14Physical security perimeter, entry controls, equipment security, clear desk and clear screen, secure disposalSite walkthroughs, access badge logs, CCTV footage review, visitor register checks
Technological controls34Access control, user access reviews, cryptography, network security, malware protection, logging and monitoring, backup managementUser access reviews, encryption configuration audits, SIEM log analysis, backup restore test results, patch management reports

Internal Audit vs External Certification Audit

Understanding the differences between internal and external audits helps you prepare for both. Internal audits are a management tool; external audits are a certification requirement. Both are necessary for a mature ISMS.

AspectInternal AuditExternal Certification Audit
PurposeVerify ISMS conformance and drive improvementGrant or maintain ISO 27001 certification
AuditorsInternal staff or hired specialistsAccredited certification body auditors (third party)
FrequencyAt least annually; more often for high-risk areasStage 1 (initial), Stage 2 (initial), surveillance (annual), recertification (every 3 years)
ScopeFull or partial ISMS (risk-based, rolling)Full ISMS scope as stated in the certification scope document
OutcomeNonconformities, observations, improvement actionsCertification decision: grant, maintain, suspend, or withdraw
Report audienceManagement, ISMS team, process ownersCertification body, registrar, top management, customers (if requested)
FlexibilityHigh; schedules can be adjustedFixed schedule agreed in advance

Evidence Collection Best Practices for ISO 27001 Audits

Collecting strong evidence during an ISO 27001 internal audit is critical. Weak evidence leads to disputed findings and missed risks. Use these methods to gather reliable, objective evidence:

  • Interviews – Speak with process owners, IT staff, security personnel, and end users to verify awareness and implementation. Ask open-ended questions that require demonstration, not just confirmation
  • Document review – Examine policies, procedures, work instructions, and records for adequacy, conformance, and consistency. Check that documents are approved, current, and accessible
  • Observation – Walk through facilities, server rooms, data centres, and work areas. Verify physical controls such as locks, access badges, clear desk compliance, and CCTV coverage
  • System testing – Verify access controls, authentication mechanisms, backup restoration procedures, antivirus updates, and logging configurations. Use screenshots and logs as evidence
  • Sampling – Use a representative sample for high-volume controls. For user access reviews, sample across departments and roles. For training records, sample recent hires and role changes
  • Third-party verification – Where controls are outsourced (e.g. cloud services, managed SOC), request SOC 2 reports, ISO 27001 certificates, or contractual SLAs as evidence

Frequently Asked Questions

Can I perform ISO 27001 internal audits without an external consultant?

Yes, provided your internal auditors are trained in ISO 27001 auditing techniques and remain independent of the areas they audit. Consider ISO 27001 internal auditor training (IRCA certified) for your team. For smaller organisations with limited internal resources, outsourcing the internal audit is a practical alternative.

How many Annex A controls must an internal audit cover?

Your audit must cover all controls listed in your Statement of Applicability (SoA). If a control is marked as applicable, it must be audited. For a typical organisation, that is 60–80 controls. Controls marked as not applicable must be justified in the SoA.

What is the biggest mistake in ISMS internal auditing?

Treating the audit as a paperwork exercise. Auditors who only review documents without verifying implementation through interviews, observation, and system testing will miss critical gaps. Real evidence comes from people and systems, not just policies and procedures.

How do I prepare for an ISO 27001 external audit using internal audits?

Run a full-scope internal audit two to three months before the external audit. Close all nonconformities, address observations, and verify corrective actions. Present the internal audit report during the external audit as evidence of a mature, self-correcting ISMS.

What is the difference between an ISMS internal audit and a vulnerability scan?

A vulnerability scan is a technical assessment of IT systems for known vulnerabilities. An ISMS internal audit is a broader evaluation of management systems, policies, processes, and controls. Both are important for information security, but they serve different purposes and neither replaces the other.

How long does an ISO 27001 internal audit take?

For a small organisation (20–50 employees), a full ISMS audit including Annex A controls takes 3–5 days. Mid-size organisations typically need 5–10 days, split across multiple weeks to minimise disruption. Allow additional time for report preparation and the closing meeting.

Do I need to audit all Annex A controls every year?

You can use a risk-based approach. High-risk controls (e.g. access control, malware protection, incident management) should be audited annually. Lower-risk controls may be audited on a rolling basis, provided every applicable control is covered within a three-year cycle.

What qualifications should an ISO 27001 internal auditor have?

At minimum, an internal auditor should have completed an ISO 27001 internal auditor training course (preferably IRCA recognised) and have a good understanding of information security concepts. For technical Annex A controls, domain expertise (e.g. network security, access management) is beneficial.

Internal Audit Report Format for ISO 27001

Your internal audit report must provide a clear and complete picture of ISMS health. A well-structured report helps management make informed decisions and provides evidence for external auditors. Include the following sections in every report:

  • Audit reference number, title, date, and audit team members
  • Scope and criteria (clauses audited, Annex A controls covered, documents referenced)
  • Executive summary of findings, including overall ISMS effectiveness rating
  • Positive findings and best practices observed during the audit
  • Nonconformities listed with clause references, severity classification, and evidence references
  • Observations and opportunities for improvement
  • Process performance data and KPI trends reviewed
  • Conclusions on ISMS conformity and effectiveness
  • Corrective action plan with responsible owners and target dates
  • Distribution list and confidentiality markings

Get ISO 27001 Internal Audit Support

Bitrixme specialises in ISO 27001 ISMS implementation, internal audits, and certification support across the Middle East. Our experienced lead auditors can conduct your internal audit, train your team, or help you build your internal audit checklist and audit programme.

We work with organisations across banking, healthcare, government, technology, and professional services to strengthen their information security posture and achieve ISO 27001 certification. Our services include gap analysis, risk assessment facilitation, documentation development, internal audit execution, and external audit support.

Contact Bitrixme for ISO 27001 ISMS audit services or send us a message on WhatsApp to discuss your requirements.