· Guide · 7 min read
Integrated ISO 27001 and ISO 22301 Internal Audits
Plan useful integrated ISO 27001 and ISO 22301 internal audits while preserving auditor competence, impartiality and distinct audit conclusions.
Organisations that operate both an information security management system and a business continuity management system often ask whether the same people and audit programme can cover both.
The answer is usually yes—if the audit remains competent, impartial and clear about its criteria. Combining work can reduce duplicate interviews and reveal important connections between security and continuity. Poorly designed integration can instead produce a shallow review in which neither management system is tested adequately.
Some older guidance frames this question around ISO 27001 and BS 25999-2. BS 25999 was an early British management-system standard for business continuity. The relevant current international reference is ISO 22301:2019. The practical dilemma remains: how should limited audit resources be organised without weakening assurance?
What an integrated internal audit means
An integrated audit assesses more than one management system through a coordinated plan. It does not merge all requirements into one undifferentiated set.
ISO 27001 and ISO 22301 share management-system concepts such as context, leadership, competence, documented information, internal audit, management review, corrective action and continual improvement. They also address different outcomes and specialist processes.
An integrated audit should therefore:
- coordinate common interviews and evidence requests;
- test shared governance processes once where appropriate;
- retain each standard as explicit audit criteria;
- use auditors with the required combined competence; and
- report conclusions and findings with clear requirement references.
The purpose is efficient assurance, not fewer audit questions at the expense of coverage.
Where integration adds value
Information security and business continuity intersect in several operational areas.
For example, a critical cloud platform may involve:
- information security risk assessment;
- supplier security requirements;
- backup and recovery controls;
- business impact analysis;
- continuity strategy;
- incident response and crisis communication; and
- exercising and improvement.
Auditing these topics in isolation can miss contradictions. The ISMS may identify a high availability risk while the BCMS assigns a recovery objective that the supplier contract cannot support. An integrated audit can follow the dependency across both systems and reach a more useful conclusion.
Shared evidence may include organisational roles, risk governance, competence records, document control, supplier reviews, internal audit records, management-review decisions and corrective actions.
The ISO 27001 evidence register guide explains how one controlled evidence item can support several requirements without being duplicated into multiple folders.
Where the criteria must remain separate
Common structure does not mean identical requirements. The audit plan should preserve specialist coverage.
An ISO 27001 audit may need to examine risk treatment, the Statement of Applicability and selected information security controls. An ISO 22301 audit may need to examine business impact analysis, continuity strategies, response structures, plans, exercises and recovery capability.
A single management-review meeting can consider both systems, but the auditor must confirm that the necessary inputs and outputs for each are addressed. One risk register may support both systems, but the method must capture the distinct nature of information security and disruption risks.
When recording a finding, identify the applicable criterion. Avoid vague statements such as “risk management needs improvement.” State which process failed, what objective evidence was found and which requirement or internal rule was not met.
Three workable resourcing models
Model 1: one competent integrated auditor
One person plans and performs the full audit. This can work in a smaller or less complex scope when the auditor has demonstrated competence in both standards, relevant operations and audit method.
The main risks are excessive dependence on one person and insufficient technical depth. Use specialist support where the auditor cannot evaluate a complex area reliably.
Model 2: an integrated audit team
A team leader manages one coordinated audit while team members cover information security, continuity or technical specialisms. This is often the strongest model for complex organisations.
The team leader should ensure consistent evidence rules, communication and grading. Team members should understand how their areas connect so that significant cross-system issues are not lost between workstreams.
Model 3: coordinated separate audits
The organisation conducts distinct audits close together, shares planning information and avoids duplicate evidence requests. This can be useful where competence is separated or where the systems have different scopes and owners.
The programme manager should reconcile conclusions and identify issues spanning both systems.
| Model | Best fit | Main control |
|---|---|---|
| One integrated auditor | Smaller, less complex scope | Confirm combined competence and workload |
| Integrated team | Complex or technical scope | Clear leadership, allocation and consolidation |
| Coordinated separate audits | Different scopes or specialist auditors | Shared planning and cross-system review |
Protect impartiality in a small organisation
The person who built a process should not be the person who reaches the independent audit conclusion about that work.
This becomes difficult when the information security manager also coordinates continuity. Practical safeguards include cross-auditing, bringing in an external auditor for selected processes, using a peer from another business unit or assigning an impartial audit leader supported by technical specialists.
Map potential conflicts before approving the programme. Consider process ownership, design authority, operational responsibility, prior consulting work and reporting relationships.
The related guide on ISO 27001 internal auditor qualifications describes how to document competence and authorization by audit role.
Build a risk-based integrated programme
Start with the scope and objectives of both management systems. Identify shared processes, specialist processes, previous findings, material changes, incidents, exercises, supplier dependencies and areas of management concern.
Then build an audit universe showing:
- process or location;
- applicable standard and internal criteria;
- risk and significance;
- previous audit result;
- planned timing;
- required auditor competence; and
- potential independence conflict.
Do not require every clause and control to receive identical attention each year. The programme should ensure appropriate coverage across the cycle while prioritising areas where failure or uncertainty is greatest.
The ISO management-system auditing guidance identifies audits as an important way for organisations to evaluate progress and conformity. A risk-based programme makes that principle operational.
Plan interviews and sampling efficiently
Use a process trail rather than conducting two separate document tours.
For a critical service, an integrated trail might follow:
- business purpose and interested-party obligations;
- information and service dependencies;
- security and disruption risks;
- selected controls and continuity strategies;
- supplier commitments and internal resources;
- operating records, incidents and exercises;
- performance results and exceptions; and
- management decisions and improvement actions.
Define populations and samples before the audit where possible. A sample of recovery exercises does not automatically test access control, and a sample of security incidents may not test continuity activation. Share evidence only when it genuinely supports both criteria.
Report findings without losing meaning
An integrated report can be concise while keeping conclusions traceable. For each finding, record:
- the specific criterion or internal requirement;
- objective evidence and sample details;
- the observed gap;
- affected management system or systems;
- significance and agreed grading method; and
- the responsible corrective-action owner.
One underlying failure may create effects under both standards. Avoid issuing duplicate findings merely because two criteria are involved. Equally, do not hide distinct failures inside one broad statement.
For example, an untested supplier recovery arrangement may affect both security availability and business continuity. A single finding can cite the connected criteria and clearly describe both effects if the cause and corrective action are shared.
Pass, partial and fail examples
| Result | Example |
|---|---|
| Pass | The programme maps both standards, assigns competent impartial auditors, coordinates shared testing and produces conclusions traceable to each criterion. |
| Partial | Common governance processes are tested well, but specialist continuity exercises and technical security controls receive limited depth. |
| Fail | The manager responsible for both systems audits their own work, uses a generic question set and reports no sample basis or standard-specific conclusions. |
Questions management should ask
- Does the programme cover important risks and changes across both systems?
- Can the audit team evaluate the specialist processes in scope?
- Have conflicts of interest been identified and controlled?
- Are shared evidence requests genuinely shared, or merely convenient?
- Can every conclusion be traced to criteria and objective evidence?
- Are cross-system dependencies and contradictions reported?
- Do corrective actions address causes and get tested for effectiveness?
Use the ISO 27001 clause explainer to help process owners understand the ISMS side of an integrated audit. A separate authorized copy of ISO 22301 should be used for the BCMS criteria.
Final takeaway
Integrated ISO 27001 and ISO 22301 audits can be more efficient and more insightful than isolated reviews. The benefit comes from following shared processes and dependencies while preserving the competence, impartiality, sampling and criteria needed for reliable conclusions.
Choose the resourcing model that fits the scope. Where one auditor cannot provide sufficient independence or subject knowledge, build a team or coordinate separate audits. Integration should improve assurance—not simply reduce the number of audit days.