Clause 9.2 of ISO 27001:2022 requires organizations to carry out regular internal audits of their information security management system (ISMS).

Doing your taxes – Photo by Dimitri Karastelev on Unsplash
These audits are essential to validate that the safety program is effective, identify weaknesses, and ensure that all requirements are met.
The difference between an internal and an external audit
Let’s start with some definitions: an internal audit is carried out by auditors who work for the organization. They report to management, but must be as independent as possible, and must not be involved in the day-to-day operations of the processes they are assessing. Their aim is to evaluate and improve safety processes on an ongoing basis.
It’s a bit like asking your accountant to check your tax returns before sending them to Revenu Québec. We might as well know what we’re doing wrong before we do it!
Internal auditing should be carried out by people with a good understanding of ISMS processes and controls, but who are independent of the activities being audited. They should possess minimum skills, such as knowledge of audit principles, a thorough understanding of ISO 27001, as well as analytical, observational and communication skills. Internal audit training and certifications such as ISO 27001 Lead Auditor or ISO 27001 Internal Auditor are also recommended.
An external audit, on the other hand, is carried out by an independent entity, such as a certification body, to verify that the organization complies with standards and regulations. External auditors are certified experts with no ties to the organization, which guarantees objectivity. They are accountable to the certification body requesting the audit. It’s a bit like Revenu Québec, which may or may not send us a notice of assessment!
Here’s a link to an article about evaluating an audit report: How to trust an auditor’s report
Clause 9.2 requires organizations to carry out internal ISMS audits to verify compliance with the requirements of the standard and the security objectives defined in clause 6.2. The clause also requires internal audits to be planned at regular intervals, according to the organization’s needs and the associated risks.
The aim is to ensure that the safety measures put in place are effective, and that any deviations are quickly rectified.
Steps for conducting internal audits
- Audit planning: Define the objectives and scope of the audit. Planning should include the audit criteria, methods and resources required, as well as the management of potential conflicts of interest. For example, the audit could focus on the compliance of security policies or the effectiveness of implemented controls (or both!).
- Selecting auditors: Choose competent, independent auditors who are ideally not directly involved in the activities being audited. For example, an auditor should not have been involved in the activities he/she is evaluating, nor should he/she be subordinate to those responsible for these activities.
- Evidence gathering: Use methods such as observation, document review and interviews to gather information on the controls in place. Evidence must be objective, verifiable and relevant to the audit objective.
- Results Analysis: Compare audit results with ISMS requirements to identify gaps and opportunities for improvement.
- Audit Report Writing: Note findings, including non-conformities and recommended corrective actions. The report should be shared with those involved, and follow-up corrective action planned.
See article: What is a listener looking for?
Table of contents of an internal audit report
An internal audit report should contain at least the following sections:
- First page: Include report title, date, and auditors’ names.
- Summary: Provide an overview of the audit objectives, key findings and conclusions.
- Introduction: Describe the context, audit objectives, scope and methodology.
- Audit Criteria and Methods: Provide information on the audit criteria used, the methods applied, and the sources of evidence.
- Follow-up on recent audits: The status of non-conformities discovered during the last audit, with a simple follow-up to check whether action plans have been carried out accordingly.
- Audit findings: Detail the results of the audit, including non-conformities, observations, and good practices identified.
- Risk Assessment: Evaluate the risks associated with identified non-conformities and their potential impact on the organization.
- Recommended corrective actions: Propose actions to correct non-conformities and improve processes.
- Follow-up plan: Describe how corrective actions will be followed up, including deadlines and those responsible.
- Appendices: Include relevant documents, such as audit questionnaires, checklists, or any other useful information.
Tips for effective internal audits
- Plan audits: Organize internal audits at regular intervals (e.g. quarterly or annually) to ensure continuous monitoring.
- Involve stakeholders: Make sure stakeholders understand the process and are involved in any necessary corrective actions.
- Training: It is important to provide ongoing training for auditors to ensure that they remain competent and up to date with developments in the standard.
- Be Objective: Auditors must remain impartial and focused on continuous improvement, rather than fault-finding.
Success Criteria
To check your compliance with clause 9.2 of ISO 27001:2022, here are some questions an auditor might ask:
- How often are internal audits carried out, and how do you decide on the frequency?
- What is the scope of your internal audits?
- How do you select auditors to guarantee their independence?
- What corrective actions have you taken following internal audits?
- How are the results of internal audits communicated to management?
Clause 9.2 verifies ISMS compliance, enhances the culture of continuous improvement and helps prepare for external audits. A well-planned and well-done audit can really help to improve information security and strengthen corporate resilience. For example, a good audit can help improve access management processes, raise security awareness among employees, or reduce the risk of security breaches.