Skip to content
Back to Knowledge Base
ISO 27001

How to Conduct an ISO 27001 Internal Audit Before Certification

19 August 20266 min read
How to Conduct an ISO 27001 Internal Audit Before Certification

The internal audit is where most ISO 27001 certification efforts either settle down or fall apart. Done well, it is a dress rehearsal that exposes weak controls while there is still time to fix them. Done poorly — or skipped — it leaves the external auditor to find your gaps for you, and that rarely ends happily. This guide walks through how to plan and run an internal audit that covers the whole Information Security Management System (ISMS) at least once before your certification audit.


Why the Internal Audit Matters

Clause 9.2 of ISO 27001:2022 makes internal audit a mandatory part of the standard, not a nice-to-have. Beyond compliance, it serves three practical purposes:
  • It tests conformity: confirming your ISMS meets the requirements of the standard and your own documented policies.
  • It tests effectiveness: a control that exists on paper but is not followed in practice is a finding, not a pass.
  • It creates evidence: external auditors want to see that your audit programme runs, findings are recorded, and corrective actions are tracked to closure.
Think of it as a fire drill for your certification. It is far better to raise a nonconformity internally in March than to have the certification body raise it in June.

When to Audit — and How Often

The certification auditors will expect to see a completed internal audit cycle covering the full ISMS scope before they arrive. In practice:
  • Before certification: audit every clause of the standard (Clauses 4–10) and every applicable Annex A control at least once. You do not have to do it all in one sitting — a staged programme over two to three months is fine — but nothing in scope can be left unaudited.
  • Ongoing: at least annually thereafter, with the full cycle repeated across the certification period.
  • After triggers: a security incident, a major organisational change, or a new product launch should prompt a targeted audit of the affected areas.
Aim to finish the pre-certification audit four to six weeks before the external Stage 1 and Stage 2 audits. That window gives you time to implement corrective actions and show evidence that they worked.

Choosing the Auditor

The golden rule is independence: whoever audits an area must not own, operate, or be accountable for it. The IT manager cannot audit the access control process they administer themselves.
  • Competence matters too: the auditor needs to understand the standard, audit techniques, and the evidence to look for. Formal lead auditor training helps but is not strictly required for internal work.
  • Small teams have options: in a small business where true internal independence is impossible, swap roles between departments (have operations audit IT and vice versa) or bring in an external consultant. A short, fixed-price engagement such as an internal audit service gives you genuine independence and findings an external auditor will respect.
---

A Step-by-Step Approach

1. Build a Risk-Based Audit Programme

  • Prioritise by risk: schedule high-risk areas — access control, supplier relationships, incident management, and the controls your risk treatment plan leans on most heavily — early and often.
  • Cover everything eventually: the programme must demonstrate that all ISMS clauses and applicable Annex A controls are audited across the cycle, even if low-risk areas appear less frequently.
  • Document it: the programme itself is auditable evidence. Record scope, criteria, schedule, and assigned auditors.

2. Prepare the Audit

  • Review the documents first: read the policies, procedures, and the Statement of Applicability for the area you are auditing so you know what the control is supposed to look like.
  • Write a checklist: turn each clause or control into specific questions and evidence requests. Good checklists keep audits consistent when different people run them.

3. Gather Evidence Using Three Methods

  • Interviews: talk to control owners and the people who follow the process day to day. Ask open questions ("Walk me through what happens when a new starter joins") and send interview notes back afterwards to confirm accuracy.
  • Observation: watch the process happen — a visitor sign-in, a code deployment, a screen-lock culture on the office floor. Reality often differs from the procedure document.
  • Records review: examine logs, tickets, training records, screenshots, and configuration exports. Check dates carefully — evidence must fall within the audit period, and it should show the control operating consistently over time, not once.

4. Report Findings Honestly

  • Classify each finding: a nonconformity is a requirement not met; an observation or opportunity for improvement is a weakness worth fixing before it becomes one. Do not soften real nonconformities into observations to keep the report tidy — the external auditor will spot it.
  • Write findings clearly: state the requirement, the evidence seen, and why it falls short. Vague findings produce vague fixes.
  • Link back to risk: where a finding touches a risk in your risk register, update the register so the ISMS stays coherent.

5. Track Corrective Actions to Closure

  • Assign owners and deadlines: every finding needs a named owner and a realistic due date.
  • Fix the cause, not the symptom: root-cause analysis matters. Re-training one person does not fix a broken onboarding process.
  • Verify the fix: confirm the corrective action actually works before closing the finding, and keep the evidence. Management review should see the audit results and the status of open actions.
---

Common Mistakes to Avoid

  • Auditing only IT: the ISMS covers people, physical security, HR processes, and suppliers — not just firewalls and passwords.
  • Treating it as a checkbox exercise: if nobody expects findings, the audit is not being done properly. A clean report with zero findings is a red flag to an experienced certification auditor.
  • Leaving it too late: an internal audit finished the week before Stage 2 leaves no time to close corrective actions.
  • Failing to act on findings: raising issues without tracking them to closure is worse than not auditing at all — it shows the improvement cycle is broken.
---

An internal audit that covers your entire ISMS before certification is the single best predictor of a smooth external audit. Plan it around risk, keep the auditor independent, gather real evidence, and close out what you find. If you would rather have an experienced practitioner run it — or sanity-check your readiness first — a structured ISO 27001 gap assessment is a fast way to see where you stand.

Check your certification readiness with our FREE ISO 27001 Gap Assessment Tool — instant results, no sign-up required.

ISO 27001

Need Help With Your Security?

Our team of experts can guide you through implementation and certification. Start with a free assessment.

Start Free Assessment