ISO 27001 internal audit: what clause 9.2 requires, who can do it, and how it is checked
Each surveillance audit must include “internal audits and management review” — ISO/IEC 17021-1:2015, 9.6.2.2 a).
The internal audit is the one activity of your own that the certification body looks at every time it visits. This page sets out what the requirement says, how the programme has to work, who may and may not do it, and where it is examined.
Where the internal audit appears in the certification cycle
| Where | What is required | Source |
|---|---|---|
| Your management system | Conduct internal audits “at planned intervals” under an audit programme | Harmonized structure 9.2 |
| Stage 1 | “evaluate if the internal audits and management reviews are being planned and performed, and that the level of implementation of the management system substantiates that the client is ready for stage 2” | 17021-1, 9.3.1.2.2 g) |
| Stage 2 | Must include the auditing of “internal auditing and management review” | 17021-1, 9.3.1.3 e) |
| The certification body's report | A summary of the evidence relating to “the internal audit and management review process” | 17021-1, 9.4.8.3 a) |
| Every surveillance audit | Must include “internal audits and management review” | 17021-1, 9.6.2.2 a) |
| Who may not do it | Your certification body | 17021-1, 5.2.6 |
What clause 9.2 requires
ISO/IEC 27001:2022 applies the harmonized structure's “identical text”. That common text for internal audit reads:
“The organization shall conduct internal audits at planned intervals to provide information on whether the [information security] management system: a) conforms to: the organization’s own requirements for its [information security] management system; the requirements of this document; b) is effectively implemented and maintained.”
Harmonized structure for management system standards, 9.2.1 — the common text, not ISO/IEC 27001 itself; [information security] marks the common text's placeholder
We compared the current common text with ISO/IEC 27001:2022 where both can be read side by side (clauses 4.1 to 6.3): 79–100% of each common clause's wording appears in the standard, with small differences. The standard's own contents show the same structure here: 9.1 monitoring, measurement, analysis and evaluation; 9.2 internal audit (9.2.1 general, 9.2.2 internal audit programme); 9.3 management review (9.3.1 general, 9.3.2 inputs, 9.3.3 results).
Two tests in one audit
The requirement asks two different questions. Does the ISMS conform — to your own requirements and to the standard? And is it “effectively implemented and maintained”? An internal audit that only checks documents answers the first half.
The audit programme
“The organization shall plan, establish, implement and maintain (an) audit programme(s), including the frequency, methods, responsibilities, planning requirements and reporting.” And: “When establishing the internal audit programme(s), the organization shall consider the importance of the processes concerned and the results of previous audits.”
| The organisation shall | |
|---|---|
| a | define the audit objectives, criteria and scope for each audit |
| b | select auditors and conduct audits to ensure objectivity and the impartiality of the audit process |
| c | ensure that the results of audits are reported to relevant managers |
“Documented information shall be available as evidence of the implementation of the audit programme(s) and the audit results.”
How often
“At planned intervals” is the whole of the frequency requirement in the text. Neither the common text nor the certification body rules we have read set a number. What they do set is that every surveillance audit examines your internal audits, so a programme with nothing to show in a given year will be visible at that year's visit — our reading of how the two fit together.
Risk-based coverage
Because the programme must weigh “the importance of the processes concerned and the results of previous audits”, it does not have to audit everything with equal depth every time. What it has to do is cover the management system and the standard over the programme, and look harder where risk and past findings point.
Who can be your internal auditor
The requirement is about how the auditor stands, not what certificate they hold: the organisation shall “select auditors and conduct audits to ensure objectivity and the impartiality of the audit process”. Someone auditing their own work fails that test however qualified they are.
Not your certification body
“Therefore, the certification body and any part of the same legal entity and any entity under the organizational control of the certification body [see 9.5.1.2, bullet b)] shall not offer or provide internal audits to its certified clients. A recognized mitigation of this threat is that the certification body shall not certify a management system on which it provided internal audits for a minimum of two years following the completion of the internal audits.”
ISO/IEC 17021-1:2015, 5.2.6, quoted verbatim
A consultant, or someone in-house
Both can work. An in-house auditor from a different team knows the business; an external one brings distance. A consultancy that built your ISMS is auditing its own work if it also audits it, which is exactly the objectivity problem the text is aimed at. For what qualifications mean, see ISO 27001 lead auditor.
How the certification body examines it
At Stage 1
One of Stage 1's objectives is to “evaluate if the internal audits and management reviews are being planned and performed, and that the level of implementation of the management system substantiates that the client is ready for stage 2”. A system in which no internal audit has yet taken place is, on those words, not ready for Stage 2.
At Stage 2 and in the report
Stage 2 must include the auditing of “internal auditing and management review”, and the certification body's report must contain “a statement on the conformity and the effectiveness of the management system together with a summary of the evidence relating to: the capability of the management system to meet applicable requirements and expected outcomes; the internal audit and management review process”. See Stage 1 and Stage 2.
At every surveillance audit
The first item every surveillance audit must include is “internal audits and management review”. See surveillance audits.
What an internal audit finds
Findings from your own audit are nonconformities under your own clause 10.2 process, handled through correction and corrective action — and a nonconformity your internal audit found and closed is evidence the system works. The same issue found first by the certification body is a finding against you. See major and minor nonconformities.
If you hold more than one standard
For integrated management systems, the accreditation rules list “An integrated approach to internal audits” among the characteristics of integration that can reduce audit time. See integrated management systems.
The internal audit is also where the management review gets its input
The management review must consider trends in audit results. An internal audit that reports nothing gives the review nothing to decide on. See management review.
We do not audit, certify or consult, and are paid the same fixed fee per enquiry whichever firm you use. The requirements above are quoted from the published texts; the frequency and coverage points marked as our reading are ours.
Where this fits
Common questions
What is an ISO 27001 internal audit?
The audit your own organisation carries out of its information security management system, to find out whether it conforms to your own requirements and to the standard, and whether it is effectively implemented and maintained. It is a requirement of clause 9.2, separate from the certification body's audits.
How often do we need to do an ISO 27001 internal audit?
The requirement is “at planned intervals”; neither the harmonized-structure text nor the certification rules we have read set a number. But every surveillance audit must include internal audits, so there needs to be internal audit activity to show at each one — that is our reading of how the two fit together.
Who can carry out our internal audit?
Anyone competent who can audit with objectivity and impartiality: the text requires you to “select auditors and conduct audits to ensure objectivity and the impartiality of the audit process”. A colleague from another team, a contractor or a consultancy can all qualify. Your certification body cannot.
Can our certification body do the internal audit?
No. ISO/IEC 17021-1 5.2.6 bars the certification body from offering or providing internal audits to its certified clients, and if it did, it could not certify that management system for at least two years.
Does the internal audit need to cover all of ISO 27001?
Over the programme, the audits must tell you whether the ISMS conforms to your own requirements and to the standard. The programme must consider “the importance of the processes concerned and the results of previous audits”, so coverage can be weighted by risk across the programme rather than repeated in full each time.
What records do we need?
“Documented information shall be available as evidence of the implementation of the audit programme(s) and the audit results.” Those records are what Stage 1, Stage 2 and each surveillance audit look at.
Is an internal audit the same as the Stage 1 audit?
No. Stage 1 is carried out by your certification body and one of its objectives is to check that your internal audits are being planned and performed. The internal audit is yours.
Sources cited on this page
- ISO/IEC Harmonized structure for MSS with guidance for use (formerly Annex SL Appendix 2 of the ISO/IEC Directives, Part 1), approved 30 July 2025
- ISO/IEC 27001:2022, official preview (clauses 1 to 6.3 and contents), read first-hand
- BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text
- BS EN ISO/IEC 17021-1:2015, clauses 9.3.1.2–9.3.1.4 (initial certification audit), full text
- BS EN ISO/IEC 17021-1:2015, clauses 9.1.3, 9.5.4 and 9.6 (audit programme, surveillance, recertification, suspension), full text
- IAF MD 11:2023, Application of ISO/IEC 17021-1 for Audits of Integrated Management Systems (Issue 3)
Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.
Need an independent internal audit?
Say when your next certification or surveillance audit is, and whether anyone in-house is independent of the ISMS.
Your enquiry is ready to send
Here is what happens after you submit:
- Your answers go to ISO 27001 consultancies that advertise for your sector.
- No more than three of them may contact you, using the details you gave.
- You decide who, if anyone, you speak to. You are committed to nothing.
We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.