ISO 27001 Internal Audit Checklist: ISMS Audit Guide
An ISO 27001 internal audit checklist helps you verify that your Information Security Management System (ISMS) conforms to the standard and operates effectively. With cyber threats growing across the Middle East, a thorough internal audit is your first line of defence. This guide covers Clauses 4–10, Annex A controls, evidence collection, reporting, and the key differences between internal and external audits.
Internal auditing is a mandatory requirement of ISO 27001:2022 Clause 9.2. It provides independent assurance that your ISMS is working as intended and that your security controls are effectively protecting information assets. Without a robust internal audit programme, your organisation cannot know whether its information security investments are delivering the expected results.
What Is an ISO 27001 Internal Audit Checklist?
An ISO 27001 internal audit checklist is a structured tool that guides auditors through each clause and control of the standard. It contains audit questions, document requests, and evidence collection criteria. The checklist ensures consistency across audits, helps less experienced auditors perform thorough reviews, and provides a complete record of what was examined for external auditors and certification bodies.
A good ISO 27001 checklist goes beyond yes-or-no questions. It prompts the auditor to verify implementation through interviews, observation, and system testing. The checklist should be updated before each audit cycle to reflect changes in the ISMS, new threats, and findings from previous audits.
ISMS Audit Planning
Effective ISMS audits start with proper planning. The audit programme must be risk-based, meaning high-risk areas are audited more frequently and more thoroughly than low-risk areas. Confirm the following before each audit cycle:
| Planning Activity | Details | Responsible |
|---|---|---|
| Define audit scope | Identify departments, processes, locations, and outsourced services in scope | Audit programme manager |
| Select audit criteria | ISO 27001:2022 clauses, Annex A controls, legal/regulatory requirements, contractual obligations | Lead auditor |
| Risk-based scheduling | Prioritise high-risk areas (network security, access control, third-party management, business continuity) | ISMS team |
| Assemble audit team | Trained ISO 27001 internal auditors, independent of audited areas and processes | Audit programme manager |
| Notify auditees | Send audit schedule, scope, and document requests at least two weeks in advance | Lead auditor |
| Review previous reports | Analyse findings from last internal audit, management review, and any external audits | Lead auditor |
| Prepare audit checklist | Tailor the checklist to the specific scope, processes, and risks of the audit | Audit team |
Clauses 4–10 Audit Checklist
Below is the complete clause-by-clause ISO 27001 internal audit checklist covering Clauses 4 through 10. Each table includes audit questions, documents to request, and evidence to examine.
Clause 4 – Context of the Organisation
The auditor must verify that the organisation understands its internal and external context, the needs and expectations of interested parties, and the scope of the ISMS. This is the foundation upon which the entire ISMS is built.
| Audit Question | Documents to Request | Evidence to Examine |
|---|---|---|
| Have external and internal issues affecting the ISMS been identified? | Context analysis, business environment assessment, PESTLE analysis | Documented issues with relevance to information security and risk assessment |
| Are interested parties and their information security requirements documented? | Interested party register, stakeholder requirements log | Legal, regulatory, and contractual security requirements mapped to controls |
| Is the ISMS scope defined and documented with exclusions justified? | ISMS scope document | Boundaries, applicability, exclusions, and justification for each exclusion |
| Does the ISMS include all necessary processes and their interactions? | ISMS process map, process interaction diagrams | Inputs, outputs, sequence, and interfaces with other management systems |
Clause 5 – Leadership
Top management must demonstrate active leadership and commitment to the ISMS. This is one of the most important clauses because without management commitment, the ISMS will lack resources, authority, and visibility.
| Audit Question | Documents to Request | Evidence to Examine |
|---|---|---|
| Has top management demonstrated leadership and commitment for the ISMS? | ISMS policy signed by top management, strategic plans | Policy communication evidence, resource allocation decisions, budget approvals |
| Is the information security policy appropriate, communicated, and reviewed? | Information security policy document, review records | Policy awareness survey results, intranet postings, induction materials |
| Have information security objectives been established at relevant functions? | ISMS objectives register | Measurable objectives with KPIs, targets, progress reports, and review dates |
| Are information security roles and responsibilities defined and assigned? | RACI matrix, role descriptions, ISMS committee charter | Named information security officer, defined escalation paths |
Clause 6 – Planning
Planning is the heart of the ISMS. The auditor must verify that risk assessment and risk treatment processes are properly defined, executed, and maintained. The Statement of Applicability (SoA) must be complete and accurate.
| Audit Question | Documents to Request | Evidence to Examine |
|---|---|---|
| How does the organisation assess information security risks? | Risk assessment methodology, risk criteria, risk scales | Completed risk assessment with risk owners, scores, and prioritisation |
| How are risk treatment options selected and applied? | Statement of Applicability (SoA), risk treatment plan (RTP) | SoA matched to Annex A, treatment deadlines, resource commitments, status updates |
| How are changes to the ISMS managed? | ISMS change management procedure | Change records, impact assessments, approval evidence, communication of changes |
| Are information security objectives planned and monitored? | Objectives planning document | Objective achievement status, variance analysis, corrective actions for missed targets |
Clause 7 – Support
Support covers resources, competence, awareness, communication, and documented information. Weaknesses in this clause undermine the entire ISMS because even the best policies fail without competent, aware personnel.
| Audit Question | Documents to Request | Evidence to Examine |
|---|---|---|
| How are ISMS resources determined and provided? | ISMS budget, staffing plans, security tool inventory | Allocated personnel, security tools, infrastructure budget, MSSP contracts |
| Are information security roles and responsibilities defined and understood? | ISMS roles matrix, job descriptions, employment contracts | Role assignments, authority levels for security decisions, committee memberships |
| Are personnel competent in information security? | Competence records, training matrix, certification register | Security training attendance, professional certifications, competence assessment results |
| Is documented information controlled per ISO 27001 requirements? | Document control procedure, record control procedure, document inventory | Document approval records, versioning, distribution lists, retention and disposal practices |
Clause 8 – Operation
This clause requires the organisation to plan, implement, and control its information security processes. The auditor must verify that risk treatment plans are being executed and that operational controls are effective.
| Audit Question | Documents to Request | Evidence to Examine |
|---|---|---|
| How are information security risks assessed and treated operationally? | Operational risk treatment plans, project risk assessments | Risk assessments for new projects, systems, changes, and third-party engagements |
| Are third-party services assessed for information security? | Supplier security assessment reports, due diligence records | Supplier evaluations, contractual security clauses, ongoing monitoring evidence |
| How does the organisation manage information security incidents? | Incident response procedure, incident register | Incident reports, response times, root cause analysis, lessons learned documentation |
Clause 9 – Performance Evaluation
The organisation must evaluate ISMS performance through monitoring, measurement, analysis, internal audit, and management review. This clause closes the PDCA cycle and drives improvement.
| Audit Question | Documents to Request | Evidence to Examine |
|---|---|---|
| How is ISMS performance monitored, measured, analysed, and evaluated? | ISMS KPI dashboard, monitoring plan, metric definitions | Security metrics, trend analysis, action triggers, threshold alerts, incident statistics |
| What is the internal audit programme for the ISMS? | Internal audit procedure, audit schedule, audit checklists | Completed audit reports, checklist evidence, auditor qualifications, nonconformity closure |
| Does top management review the ISMS at planned intervals? | Management review procedure, agenda template | Management review minutes covering all required inputs, decisions, resource allocations |
| How is compliance with legal and regulatory requirements evaluated? | Legal register, compliance evaluation records | Compliance evaluation reports, regulatory correspondence, license renewals |
Clause 10 – Improvement
The final clause addresses nonconformity handling, corrective actions, and continual improvement. This is where the ISMS demonstrates whether it is a mature, self-correcting system.
| Audit Question | Documents to Request | Evidence to Examine |
|---|---|---|
| How are nonconformities and corrective actions managed in the ISMS? | Corrective action procedure, nonconformity log, root cause analysis records | Root cause analysis quality, corrective action completion rates, effectiveness verification |
| How does the organisation drive continual improvement of the ISMS? | Improvement register, lessons learned database, security roadmap | Improvement projects, implemented recommendations, before/after metrics |
Annex A Control Audit Checklist
ISO 27001:2022 defines 93 controls across 4 themes. Your internal audit must verify that applicable controls from the Statement of Applicability (SoA) are implemented and effective. This is where the internal audit differs most from a clause-level audit, because each control requires specific verification techniques.
| Annex A Theme | Control Count | Key Controls to Audit | Verification Approach |
|---|---|---|---|
| Organisational controls | 37 | Information security policies, roles and responsibilities, incident management, business continuity, supplier security | Policy review, role definition documents, incident response drills, BCP tabletop exercises |
| People controls | 8 | Screening, terms and conditions, awareness and training, disciplinary process, remote working | Background check records, training completion rates, signed NDAs, remote work policy implementation |
| Physical controls | 14 | Physical security perimeter, entry controls, equipment security, clear desk and clear screen, secure disposal | Site walkthroughs, access badge logs, CCTV footage review, visitor register checks |
| Technological controls | 34 | Access control, user access reviews, cryptography, network security, malware protection, logging and monitoring, backup management | User access reviews, encryption configuration audits, SIEM log analysis, backup restore test results, patch management reports |
Internal Audit vs External Certification Audit
Understanding the differences between internal and external audits helps you prepare for both. Internal audits are a management tool; external audits are a certification requirement. Both are necessary for a mature ISMS.
| Aspect | Internal Audit | External Certification Audit |
|---|---|---|
| Purpose | Verify ISMS conformance and drive improvement | Grant or maintain ISO 27001 certification |
| Auditors | Internal staff or hired specialists | Accredited certification body auditors (third party) |
| Frequency | At least annually; more often for high-risk areas | Stage 1 (initial), Stage 2 (initial), surveillance (annual), recertification (every 3 years) |
| Scope | Full or partial ISMS (risk-based, rolling) | Full ISMS scope as stated in the certification scope document |
| Outcome | Nonconformities, observations, improvement actions | Certification decision: grant, maintain, suspend, or withdraw |
| Report audience | Management, ISMS team, process owners | Certification body, registrar, top management, customers (if requested) |
| Flexibility | High; schedules can be adjusted | Fixed schedule agreed in advance |
Evidence Collection Best Practices for ISO 27001 Audits
Collecting strong evidence during an ISO 27001 internal audit is critical. Weak evidence leads to disputed findings and missed risks. Use these methods to gather reliable, objective evidence:
- Interviews – Speak with process owners, IT staff, security personnel, and end users to verify awareness and implementation. Ask open-ended questions that require demonstration, not just confirmation
- Document review – Examine policies, procedures, work instructions, and records for adequacy, conformance, and consistency. Check that documents are approved, current, and accessible
- Observation – Walk through facilities, server rooms, data centres, and work areas. Verify physical controls such as locks, access badges, clear desk compliance, and CCTV coverage
- System testing – Verify access controls, authentication mechanisms, backup restoration procedures, antivirus updates, and logging configurations. Use screenshots and logs as evidence
- Sampling – Use a representative sample for high-volume controls. For user access reviews, sample across departments and roles. For training records, sample recent hires and role changes
- Third-party verification – Where controls are outsourced (e.g. cloud services, managed SOC), request SOC 2 reports, ISO 27001 certificates, or contractual SLAs as evidence
Frequently Asked Questions
Can I perform ISO 27001 internal audits without an external consultant?
Yes, provided your internal auditors are trained in ISO 27001 auditing techniques and remain independent of the areas they audit. Consider ISO 27001 internal auditor training (IRCA certified) for your team. For smaller organisations with limited internal resources, outsourcing the internal audit is a practical alternative.
How many Annex A controls must an internal audit cover?
Your audit must cover all controls listed in your Statement of Applicability (SoA). If a control is marked as applicable, it must be audited. For a typical organisation, that is 60–80 controls. Controls marked as not applicable must be justified in the SoA.
What is the biggest mistake in ISMS internal auditing?
Treating the audit as a paperwork exercise. Auditors who only review documents without verifying implementation through interviews, observation, and system testing will miss critical gaps. Real evidence comes from people and systems, not just policies and procedures.
How do I prepare for an ISO 27001 external audit using internal audits?
Run a full-scope internal audit two to three months before the external audit. Close all nonconformities, address observations, and verify corrective actions. Present the internal audit report during the external audit as evidence of a mature, self-correcting ISMS.
What is the difference between an ISMS internal audit and a vulnerability scan?
A vulnerability scan is a technical assessment of IT systems for known vulnerabilities. An ISMS internal audit is a broader evaluation of management systems, policies, processes, and controls. Both are important for information security, but they serve different purposes and neither replaces the other.
How long does an ISO 27001 internal audit take?
For a small organisation (20–50 employees), a full ISMS audit including Annex A controls takes 3–5 days. Mid-size organisations typically need 5–10 days, split across multiple weeks to minimise disruption. Allow additional time for report preparation and the closing meeting.
Do I need to audit all Annex A controls every year?
You can use a risk-based approach. High-risk controls (e.g. access control, malware protection, incident management) should be audited annually. Lower-risk controls may be audited on a rolling basis, provided every applicable control is covered within a three-year cycle.
What qualifications should an ISO 27001 internal auditor have?
At minimum, an internal auditor should have completed an ISO 27001 internal auditor training course (preferably IRCA recognised) and have a good understanding of information security concepts. For technical Annex A controls, domain expertise (e.g. network security, access management) is beneficial.
Internal Audit Report Format for ISO 27001
Your internal audit report must provide a clear and complete picture of ISMS health. A well-structured report helps management make informed decisions and provides evidence for external auditors. Include the following sections in every report:
- Audit reference number, title, date, and audit team members
- Scope and criteria (clauses audited, Annex A controls covered, documents referenced)
- Executive summary of findings, including overall ISMS effectiveness rating
- Positive findings and best practices observed during the audit
- Nonconformities listed with clause references, severity classification, and evidence references
- Observations and opportunities for improvement
- Process performance data and KPI trends reviewed
- Conclusions on ISMS conformity and effectiveness
- Corrective action plan with responsible owners and target dates
- Distribution list and confidentiality markings
Get ISO 27001 Internal Audit Support
Bitrixme specialises in ISO 27001 ISMS implementation, internal audits, and certification support across the Middle East. Our experienced lead auditors can conduct your internal audit, train your team, or help you build your internal audit checklist and audit programme.
We work with organisations across banking, healthcare, government, technology, and professional services to strengthen their information security posture and achieve ISO 27001 certification. Our services include gap analysis, risk assessment facilitation, documentation development, internal audit execution, and external audit support.
Contact Bitrixme for ISO 27001 ISMS audit services or send us a message on WhatsApp to discuss your requirements.