ISO 27001 clause guide

ISO 27001 Clause 9.2.2: Internal audit programme

Plan and manage a risk-informed programme that defines audit frequency, methods, responsibilities, scope, criteria, reporting and follow-up. This guide explains how to turn the clause into decisions, operating evidence and a defensible audit trail.

Clause
9.2.2
Theme
Performance evaluation
Primary outcome
Plan and manage a risk-informed programme that defines audit frequency, methods, responsibilities, scope, criteria, reporting and follow-up.

What Clause 9.2.2 means in practice

Plan and manage a risk-informed programme that defines audit frequency, methods, responsibilities, scope, criteria, reporting and follow-up. Treat the clause as part of a management system rather than an isolated document request. Its outputs should influence connected decisions, and later records should show that those decisions were carried out.

The level of formality should match risk and complexity. What matters is clarity, consistency and a traceable connection between the organization’s circumstances, chosen approach and observed result.

Step-by-step implementation

  1. Step 1. Build a programme that covers all ISMS areas over an appropriate cycle.
  2. Step 2. Consider process importance, change, risk and previous audit results.
  3. Step 3. Select objective auditors, define scope and criteria, report results and monitor actions.
  4. Final step. Test a recent example, record the result and improve weak handoffs or decisions.

Ownership

  • ISMS manager
  • Accountable process owner
  • Relevant leadership

Evidence and records

Implementation evidence

  • approved audit programme
  • individual audit plans
  • scope and criteria records
  • auditor assignments
  • reports and follow-up records

Effectiveness evidence

  • recent decisions demonstrate internal audit programme in operation
  • outputs connect to related ISMS processes and accountable follow-up
  • changes or weak results lead to recorded improvement

A document can show intent. A complete sample also shows who made the decision, what happened next, whether the result was reviewed and how exceptions were handled.

How an auditor may test Clause 9.2.2

  1. Select a current business or ISMS example affected by the clause.
  2. Confirm the method, criteria, owner and required output.
  3. Trace the example through its decision records and connected processes.
  4. Corroborate the record with operational evidence or participant interviews.
  5. Follow an exception, change or adverse result to its accountable conclusion.
  6. Check that review and improvement occur when circumstances or results change.

Questions to prepare for

  • How was audit frequency determined?
  • Where does the programme cover every part of the ISMS?
  • How do you prevent auditors assessing their own work?

Worked example

A current performance evaluation decision is traced through the method for internal audit programme, its accountable owner, resulting actions and later review.

A strong audit trail would identify the trigger, relevant information, accountable participants, decision, resulting actions and later verification. It should be possible to explain why the approach was reasonable without reconstructing it from memory.

Smaller and mature implementation approaches

Smaller organization

Use existing leadership, service-management or risk meetings, assign a named owner and retain concise decision records. Avoid parallel governance where an established process can produce the required outcome.

Mature or complex organization

Define group-wide criteria, delegated accountabilities, integrated workflow, quality checks and consolidated performance reporting while preserving local context and evidence.

Practical implementation checklist

  • □ Build a programme that covers all ISMS areas over an appropriate cycle.
  • □ Consider process importance, change, risk and previous audit results.
  • □ Select objective auditors, define scope and criteria, report results and monitor actions.
  • □ A recent example has been traced through its connected ISMS processes.
  • □ Weak results and overdue actions have accountable follow-up.

Common mistakes

  • programme gaps that leave parts of the ISMS unaudited
  • repeating identical scope despite changing risk
  • late reports and unmonitored findings

Frequently asked questions

What evidence supports Clause 9.2.2?

Use current records that show the method, accountable decision, resulting action and review for internal audit programme.

How does an auditor test internal audit programme?

An auditor can select a recent example and trace it across inputs, decisions, connected processes, outputs and follow-up.

Does the clause require a particular software tool?

No. The method and records should be proportionate, repeatable and effective for the organization.

Explore the clause in the interactive tool

Open Clause 9.2.2 in the free explainer to browse its connected clauses and implementation prompts.

Open Clause 9.2.2 in the clause explainer →