Internal audit is where you find your problems before someone else does - which means an internal audit that finds nothing has failed at its only job. ISO 27001 makes it mandatory; most other frameworks expect it in substance. Done well it is the cheapest assurance you will buy.
What the requirement actually says
ISO 27001 requires internal audits at planned intervals to determine whether the ISMS conforms to your own requirements and to the standard, and whether it is effectively implemented and maintained. It requires an audit programme, defined criteria and scope per audit, auditor objectivity and impartiality, reporting to relevant management, and retained evidence.
Note what it does not require: a dedicated internal audit department, or an external firm. It requires independence from the area being audited - which is achievable in small organisations with some thought.
Building the programme
An audit programme is a plan across a cycle, not a single event. Over a certification cycle every clause and every applicable control should be covered - but not necessarily every year.
- Risk-based frequency. Audit high-risk and previously-failing areas more often; low-risk stable areas less.
- Trigger-based additions - a new system, a significant incident, a major process change, or a customer escalation.
- Coverage tracking so you can show the full scope was addressed across the cycle.
A common finding is a programme that audits the same comfortable areas each year while something material has never been examined. Track coverage explicitly rather than assuming it.
Plan and evidence your internal audits
GRC Copilot tracks audit coverage across your control set, records findings against controls, and keeps the corrective action trail auditors ask for.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
Solving independence when you are small
The requirement is that auditors do not audit their own work. Practical options:
- Cross-audit internally. The engineering lead audits HR security controls; the operations manager audits change management. Neither audits their own area.
- Use a different function - finance, legal or quality often have audit-capable people.
- Engage externally. A consultant or an audit firm performs the internal audit - permitted, and common for first certifications.
- Rotate so the same person does not audit the same area repeatedly.
What does not work: the person who wrote the policy and operates the control auditing it and declaring it effective. That is the exact self-assessment the requirement exists to prevent.
Conducting an audit
- Define criteria and scope in writing - which clauses, which controls, which period.
- Prepare by reading the procedure, prior findings and the control description.
- Sample the population. Do not accept a curated example - ask for the full list and choose from it yourself.
- Interview the person who performs the control, not their manager.
- Trace end to end. Follow one instance from trigger through to record and outcome.
- Test the exception path - what happens when the process cannot be followed.
- Record evidence examined, not just conclusions.
Writing findings that get fixed
A finding should be evidenced, specific and actionable. Classify consistently:
- Major nonconformity - a requirement is not implemented, or a systemic failure.
- Minor nonconformity - an isolated lapse against a requirement.
- Observation or opportunity for improvement - not a breach, but worth addressing.
State the requirement, the evidence, and the gap. "Access reviews are weak" is not actionable. "The Q2 review for System X was not performed; the policy requires quarterly review (Standard 4.2); no record exists for the period" is.
Closing the loop
An audit that produces findings nobody fixes is worse than no audit, because it evidences known-and-ignored gaps. Every finding needs an owner, a root cause, a corrective action, a due date and verified closure. Your external auditor will read the internal audit report and check what happened next.
What certification auditors look for
- The audit programme and its risk basis.
- Evidence of auditor independence for each audit.
- Audit reports with scope, criteria, evidence and findings.
- Findings tracked to closure with verification.
- Results reported into management review.
- Coverage across the cycle.
Frequently asked questions
How often must we audit?
At planned intervals determined by risk - not necessarily annually per area, provided the full scope is covered across the cycle and you can evidence the plan.
Can a consultant perform our internal audit?
Yes, and it is common. Ensure they are independent of any implementation work they did for you.
Is it a problem if we find a lot?
No - it is the point. What concerns a certification auditor is finding nothing, or finding things that were never closed.
Can internal audit replace external audit?
No. Certification requires an accredited external body. Internal audit is your own assurance, and a prerequisite.
Key takeaways
- An internal audit that finds nothing has not done its job.
- Independence means not auditing your own work - achievable without a department.
- Sample from the full population yourself; do not accept curated examples.
- Unclosed findings are worse than no audit - track them to verified closure.