iso27001partnersUK certification, costed Get a cost estimate

ISO 27001 internal audit: what clause 9.2 requires, who can do it, and how it is checked

Written from the standards themselves · Editor-reviewed · Checked against the current editions on 20 September 2026
By the iso27001partners.co.uk editorial team · Published 20 September 2026 · Last reviewed 20 September 2026 · 9 min read
6 primary sources cited on this page. How we check what is on this site
Checked at every audit Stage 1, Stage 2, and every surveillance visit

Each surveillance audit must include “internal audits and management review” — ISO/IEC 17021-1:2015, 9.6.2.2 a).

The internal audit is the one activity of your own that the certification body looks at every time it visits. This page sets out what the requirement says, how the programme has to work, who may and may not do it, and where it is examined.

Where the internal audit appears in the certification cycle

The internal audit, from your management system to every certification audit
WhereWhat is requiredSource
Your management systemConduct internal audits “at planned intervals” under an audit programmeHarmonized structure 9.2
Stage 1“evaluate if the internal audits and management reviews are being planned and performed, and that the level of implementation of the management system substantiates that the client is ready for stage 2”17021-1, 9.3.1.2.2 g)
Stage 2Must include the auditing of “internal auditing and management review”17021-1, 9.3.1.3 e)
The certification body's reportA summary of the evidence relating to “the internal audit and management review process”17021-1, 9.4.8.3 a)
Every surveillance auditMust include “internal audits and management review”17021-1, 9.6.2.2 a)
Who may not do itYour certification body17021-1, 5.2.6

What clause 9.2 requires

ISO/IEC 27001:2022 applies the harmonized structure's “identical text”. That common text for internal audit reads:

“The organization shall conduct internal audits at planned intervals to provide information on whether the [information security] management system: a) conforms to: the organization’s own requirements for its [information security] management system; the requirements of this document; b) is effectively implemented and maintained.”

Harmonized structure for management system standards, 9.2.1 — the common text, not ISO/IEC 27001 itself; [information security] marks the common text's placeholder

We compared the current common text with ISO/IEC 27001:2022 where both can be read side by side (clauses 4.1 to 6.3): 79–100% of each common clause's wording appears in the standard, with small differences. The standard's own contents show the same structure here: 9.1 monitoring, measurement, analysis and evaluation; 9.2 internal audit (9.2.1 general, 9.2.2 internal audit programme); 9.3 management review (9.3.1 general, 9.3.2 inputs, 9.3.3 results).

Two tests in one audit

The requirement asks two different questions. Does the ISMS conform — to your own requirements and to the standard? And is it “effectively implemented and maintained”? An internal audit that only checks documents answers the first half.

The audit programme

“The organization shall plan, establish, implement and maintain (an) audit programme(s), including the frequency, methods, responsibilities, planning requirements and reporting.” And: “When establishing the internal audit programme(s), the organization shall consider the importance of the processes concerned and the results of previous audits.”

Internal audit programme (harmonized structure 9.2.2), verbatim
The organisation shall
adefine the audit objectives, criteria and scope for each audit
bselect auditors and conduct audits to ensure objectivity and the impartiality of the audit process
censure that the results of audits are reported to relevant managers

“Documented information shall be available as evidence of the implementation of the audit programme(s) and the audit results.”

How often

“At planned intervals” is the whole of the frequency requirement in the text. Neither the common text nor the certification body rules we have read set a number. What they do set is that every surveillance audit examines your internal audits, so a programme with nothing to show in a given year will be visible at that year's visit — our reading of how the two fit together.

Risk-based coverage

Because the programme must weigh “the importance of the processes concerned and the results of previous audits”, it does not have to audit everything with equal depth every time. What it has to do is cover the management system and the standard over the programme, and look harder where risk and past findings point.

Who can be your internal auditor

The requirement is about how the auditor stands, not what certificate they hold: the organisation shall “select auditors and conduct audits to ensure objectivity and the impartiality of the audit process”. Someone auditing their own work fails that test however qualified they are.

Not your certification body

“Therefore, the certification body and any part of the same legal entity and any entity under the organizational control of the certification body [see 9.5.1.2, bullet b)] shall not offer or provide internal audits to its certified clients. A recognized mitigation of this threat is that the certification body shall not certify a management system on which it provided internal audits for a minimum of two years following the completion of the internal audits.”

ISO/IEC 17021-1:2015, 5.2.6, quoted verbatim

A consultant, or someone in-house

Both can work. An in-house auditor from a different team knows the business; an external one brings distance. A consultancy that built your ISMS is auditing its own work if it also audits it, which is exactly the objectivity problem the text is aimed at. For what qualifications mean, see ISO 27001 lead auditor.

How the certification body examines it

At Stage 1

One of Stage 1's objectives is to “evaluate if the internal audits and management reviews are being planned and performed, and that the level of implementation of the management system substantiates that the client is ready for stage 2”. A system in which no internal audit has yet taken place is, on those words, not ready for Stage 2.

At Stage 2 and in the report

Stage 2 must include the auditing of “internal auditing and management review”, and the certification body's report must contain “a statement on the conformity and the effectiveness of the management system together with a summary of the evidence relating to: the capability of the management system to meet applicable requirements and expected outcomes; the internal audit and management review process”. See Stage 1 and Stage 2.

At every surveillance audit

The first item every surveillance audit must include is “internal audits and management review”. See surveillance audits.

What an internal audit finds

Findings from your own audit are nonconformities under your own clause 10.2 process, handled through correction and corrective action — and a nonconformity your internal audit found and closed is evidence the system works. The same issue found first by the certification body is a finding against you. See major and minor nonconformities.

If you hold more than one standard

For integrated management systems, the accreditation rules list “An integrated approach to internal audits” among the characteristics of integration that can reduce audit time. See integrated management systems.

The internal audit is also where the management review gets its input

The management review must consider trends in audit results. An internal audit that reports nothing gives the review nothing to decide on. See management review.

We do not audit, certify or consult, and are paid the same fixed fee per enquiry whichever firm you use. The requirements above are quoted from the published texts; the frequency and coverage points marked as our reading are ours.

Where this fits

Common questions

What is an ISO 27001 internal audit?

The audit your own organisation carries out of its information security management system, to find out whether it conforms to your own requirements and to the standard, and whether it is effectively implemented and maintained. It is a requirement of clause 9.2, separate from the certification body's audits.

How often do we need to do an ISO 27001 internal audit?

The requirement is “at planned intervals”; neither the harmonized-structure text nor the certification rules we have read set a number. But every surveillance audit must include internal audits, so there needs to be internal audit activity to show at each one — that is our reading of how the two fit together.

Who can carry out our internal audit?

Anyone competent who can audit with objectivity and impartiality: the text requires you to “select auditors and conduct audits to ensure objectivity and the impartiality of the audit process”. A colleague from another team, a contractor or a consultancy can all qualify. Your certification body cannot.

Can our certification body do the internal audit?

No. ISO/IEC 17021-1 5.2.6 bars the certification body from offering or providing internal audits to its certified clients, and if it did, it could not certify that management system for at least two years.

Does the internal audit need to cover all of ISO 27001?

Over the programme, the audits must tell you whether the ISMS conforms to your own requirements and to the standard. The programme must consider “the importance of the processes concerned and the results of previous audits”, so coverage can be weighted by risk across the programme rather than repeated in full each time.

What records do we need?

“Documented information shall be available as evidence of the implementation of the audit programme(s) and the audit results.” Those records are what Stage 1, Stage 2 and each surveillance audit look at.

Is an internal audit the same as the Stage 1 audit?

No. Stage 1 is carried out by your certification body and one of its objectives is to check that your internal audits are being planned and performed. The internal audit is yours.

Sources cited on this page

  1. ISO/IEC Harmonized structure for MSS with guidance for use (formerly Annex SL Appendix 2 of the ISO/IEC Directives, Part 1), approved 30 July 2025
  2. ISO/IEC 27001:2022, official preview (clauses 1 to 6.3 and contents), read first-hand
  3. BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text
  4. BS EN ISO/IEC 17021-1:2015, clauses 9.3.1.2–9.3.1.4 (initial certification audit), full text
  5. BS EN ISO/IEC 17021-1:2015, clauses 9.1.3, 9.5.4 and 9.6 (audit programme, surveillance, recertification, suspension), full text
  6. IAF MD 11:2023, Application of ISO/IEC 17021-1 for Audits of Integrated Management Systems (Issue 3)

Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.

Need an independent internal audit?

Say when your next certification or surveillance audit is, and whether anyone in-house is independent of the ISMS.

Step 1 of 6
What has made this a live question?

Almost nobody certifies for its own sake. Whatever is pushing this usually also sets the deadline, so it is worth saying first.

When do you need the certificate in your hand?

Stage 1 and Stage 2 are separate visits with a gap between them, so the certificate always lands some weeks after the last audit day. A date inside three months is a different piece of work from a date inside a year.

How many people would be inside the scope?

Not your whole payroll — everyone doing work under your control inside the certified scope, contractors included. This is the number the audit-day table in ISO/IEC 27006-1 runs on, so it decides the audit fee before anything else does.

What exists already?

There is no wrong answer here and nothing to be embarrassed about. Most enquiries are at the first option.

How do you want the work done?

The three routes cost very different amounts and suit very different teams. If you have not decided, say so — that is a useful answer too.

Where should the consultancy reach you?

This is the only step that asks you to type anything.

By clicking “Send my enquiry” I agree that iso27001partners.co.uk may pass the details above to up to three ISO 27001 consultancies that advertise for my sector, so that they can contact me at the business details I have given. Consent is not a condition of anything — every page, table and calculator on this site works without it. You can withdraw consent at any time by replying to any message you receive, or by writing to us through the enquiry form on any page. We are not a certification body, not an accreditation body and not a consultancy; the disclaimer linked in the footer sets out the whole arrangement.

  • Your details go to consultancies only, and to no more than three
  • Free to you — consultancies pay us a fixed fee per enquiry, set in advance
  • No obligation, and no certification body is involved at this stage

Your enquiry is ready to send

Here is what happens after you submit:

  1. Your answers go to ISO 27001 consultancies that advertise for your sector.
  2. No more than three of them may contact you, using the details you gave.
  3. You decide who, if anyone, you speak to. You are committed to nothing.

We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.

Free enquiryFive clicks · no obligation Start now