Get Demo
↑

ISO 27001 Internal Audit: Checklist, Process and Report Template

How to run ISO 27001:2022 internal audits under Clause 9.2 — programme checklist, sampling tips, and a lightweight report outline.

Published: September 2026 Compliance · ISO 27001 8–12 min read

Clause 9.2 requires internal audits at planned intervals to confirm the ISMS conforms to your requirements and to ISO/IEC 27001, and is effectively implemented and maintained. This page is a practical checklist and report outline — separate from certification-body Stage 1 / Stage 2.

Related: Stage 1 vs Stage 2 · ISMS checklist · Existing internal audit guide.

Evidence of the programme: Clause 9.2.2 expects documented information as evidence of the audit programme(s) and the audit results.

Internal Audit Process

  1. Define audit programme (scope, frequency, methods, competence).
  2. Plan each audit (criteria, evidence sources, sample size).
  3. Conduct fieldwork (interviews, records, technical sampling).
  4. Report findings (conformities, nonconformities, opportunities).
  5. Feed corrective action (Clause 10.2) and management review (9.3).

Programme Checklist

Lightweight Report Outline

Build Your ISO 27001 Programme with Continuous Evidence

CyberSilo CSA maps ISMS artefacts and Annex A control evidence; ThreatHawk supports logging and monitoring proof for technological controls.

Frequently Asked Questions

Is internal audit the same as Stage 1?

No. Clause 9.2 internal audit is your organization's programme. Stage 1/Stage 2 are certification-body audits.

Must every Annex A control be audited every year?

Audit the ISMS at planned intervals for conformity and effectiveness. Depth and sampling follow your risk-based audit programme — not a blind 93-control annual sweep unless your programme requires it.

Who can perform the internal audit?

Auditors must be objective and impartial toward the work audited. Many SMEs use trained internal staff plus external support for independence on sensitive areas.

Stage 1 vs Stage 2 · Compliance checklist · Mandatory documents

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!