Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Compliance

ISO 27001 Clause 9.2 Internal Audit: Independence, the Audit Programme and Sampling

Direct answer: ISO 27001 clause 9.2 requires internal audits at planned intervals to check that your ISMS conforms to your own requirements and to the standard, and that it is effectively implemented and maintained. You need an audit programme, defined criteria and scope for each audit, auditors chosen so the audit is objective and impartial, results reported to management, and retained records. You do not have to audit everything every time: the programme can spread clauses and Annex A controls across the three-year certification cycle, as long as everything is covered and the riskier areas get more attention.

What clause 9.2 asks for

The clause has two parts. The first sets the purpose: audits at planned intervals that tell you whether the ISMS meets your own requirements and the standard's, and whether it is actually working. The second sets the mechanics. In our words, you must:

  • Plan, establish, implement and maintain an audit programme, covering frequency, methods, responsibilities, planning and reporting.
  • Take into account the importance of the processes concerned and the results of previous audits when you build it.
  • Define the criteria and scope of each audit.
  • Select auditors and conduct audits so the process is objective and impartial.
  • Report the results to relevant management.
  • Keep documented information as evidence of the programme and the results.

Internal audit is a management system requirement, not an Annex A control, so it cannot be excluded in your Statement of Applicability. The certification body will ask for internal audit records at the initial certification audit and at every surveillance audit after it.

Independence: the part small companies struggle with

The standard does not say "independent". It says objective and impartial. Certification bodies read that in a practical way: the person auditing an area should not be the person who designed it, operates it or is accountable for it. Nobody audits their own work objectively.

That is easy in a large company with an internal audit function. In a company of thirty people, the security lead usually wrote the policies, implemented the controls and collected the evidence, so they are the one person who cannot audit them. Workable arrangements:

  • A trained colleague from another function audits areas they do not operate, with a record of their auditor training. The head of finance auditing engineering controls is a common example.
  • Split the audit so nobody audits their own area, with two people auditing each other's.
  • An outsourced internal auditor performs the audit under your programme. This is normal and accepted. The internal audit remains yours; the auditor is an independent pair of hands.

One rule for the outsourced option: the firm that runs or built your ISMS should not also be its internal auditor, for the same reason your security lead should not be. We only take internal audit work where we have not operated the controls being audited, and we never fix what we audited.

Stage 2 or surveillance on the calendar? We run independent clause 9.2 audits, full or partial scope, and check your corrective actions before the report is final. ISO 27001 internal audit

The audit programme across the certification cycle

An ISO 27001 certificate runs on a three-year cycle: the initial certification audit, a surveillance audit in each of the following two years, and a recertification audit in the third. Your internal audit programme should be designed against that cycle rather than one audit at a time.

"Planned intervals" does not mean "everything every year". The standard asks you to decide the frequency and to weight it by the importance of the processes and the results of previous audits. A defensible programme for a smaller ISMS often looks like this:

  • Every year: the clauses that keep the system alive, such as risk assessment and treatment, the Statement of Applicability, management review, corrective action and the internal audit process itself, plus any area that had nonconformities last time.
  • Rotated across the cycle: the Annex A themes (organizational, people, physical and technological), so every applicable control is audited at least once before recertification.
  • Triggered: an extra audit after a major change, such as a new product line, an acquisition, a cloud migration or a significant incident.

Write the programme down as a simple table: each clause and Annex A theme, the year it is audited, and who audits it. Track coverage as you go. The common failure is arriving at recertification with half of Annex A never audited because each year's audit took whatever was convenient.

Free weekly email

Get The Compliance Brief every Tuesday

One email a week from Jacob Masse: the security and compliance stories that changed something that week, and what each one means if you sell software to enterprise buyers. Five stories, a take on each, five minutes to read.

Free. Unsubscribe in one click, and replies reach Jacob directly. Read the latest issue or browse the archive.

Partial-scope audits

Each audit in the programme can have its own scope. The common shapes:

  • Full: clauses 4 to 10 and every applicable Annex A control in one audit. Typical before an initial certification audit, so the certification body sees one complete internal audit.
  • Clauses only: the management system requirements without Annex A.
  • Annex A only: the controls in your Statement of Applicability without the clauses.
  • Thematic rotation: selected themes each time, chosen to complete coverage over the cycle.

Partial scope is legitimate when the programme as a whole covers everything. It is a problem only when it becomes a way of never auditing the uncomfortable areas.

Sampling

An internal audit tests what you do, not only what the policy says. That means sampling records. ISO 19011, the guidance standard for auditing management systems, describes judgement-based and statistical sampling. For most small and medium ISMS audits, judgement-based sampling is the honest choice, and the audit plan should say how samples were chosen.

Practical rules we use:

  • Sample from the full population for the period, not from a list the auditee picked.
  • Scale the sample to the frequency of the control. A quarterly access review has four instances a year; test them. A daily backup job has hundreds; sample a handful across the period, including weekends and month ends.
  • Include the edges: leavers, new starters, emergency changes, the vendor added in a hurry.
  • Record what was sampled, so the next audit can sample something else and the certification body can see the method.

Findings that hold up

Each finding should tie to the clause or control it concerns, state the requirement, describe the objective evidence, and grade it. Major nonconformities are failures of a requirement or of the system's ability to achieve its outcomes. Minor ones are isolated lapses. Observations and opportunities for improvement are not nonconformities and should not be dressed up as them.

An internal audit with no findings at all is itself a warning sign to a certification body. It suggests the audit lacked depth rather than that the ISMS is flawless.

The auditee responds to each nonconformity with a root cause and a corrective action under clause 10.2. The results go to management, and they are an input to the management review under clause 9.3. Plan the timing so the internal audit finishes before the management review, and both finish before the certification body arrives with enough time to act on what they found.

Internal audit is not a gap analysis

A gap analysis tells you what is missing before you build. An internal audit tests whether the system you already run conforms. Only an internal audit counts as clause 9.2 evidence. If the ISMS is not built yet, start with a gap analysis, then audit once it has operated long enough to produce records.

Our internal audit is from $3,000 per audit, full or partial scope, with fieldwork done remotely. Our internal audit programme guide has more on writing nonconformities, and the management review guide covers what happens with the results.

Frequently asked questions

Can our ISO 27001 consultant do our internal audit?

Not on controls they built or operate, because the audit would not be impartial. A consultant who did not build your ISMS can. Ask any firm directly whether they have operated the controls in scope.

How often do we need an internal audit?

At planned intervals that you define and justify. Most organizations audit at least part of the ISMS every year, with the full scope covered across the three-year cycle.

Does the internal auditor need to be certified?

The standard asks for competence, not a specific certificate. Keep a record of the auditor's training and experience. An ISO 27001 lead or internal auditor course is common evidence.

Does ISO 42001 have the same requirement?

Yes. ISO 42001 follows the same management system structure and has the same internal audit clause for an AI management system, so the same programme approach applies.

Need an impartial internal audit? Tell us your standard, your audit date and the scope. We confirm we are independent of your controls, then send a fixed price.

ISO 27001 internal auditOr read the programme guide

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on ISO 27001. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
Zero
Exceptions on a SOC 2 Type II built from nothing in-house

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.