ISO 27001 clause guide
ISO 27001 Clause 9.2: Internal audit
Use independent, evidence-based review to determine whether the ISMS conforms to planned arrangements and is effectively maintained. This guide explains how to turn the clause into decisions, operating evidence and a defensible audit trail.
- Clause
- 9.2
- Theme
- Performance evaluation
- Primary outcome
- Provide objective, planned assurance that the ISMS conforms to requirements and operates effectively.
What Clause 9.2 means in practice
Provide objective, planned assurance that the ISMS conforms to requirements and operates effectively. Treat the clause as part of a management system rather than an isolated document request. Its outputs should influence connected decisions, and later records should show that those decisions were carried out.
The level of formality should match risk and complexity. What matters is clarity, consistency and a traceable connection between the organization’s circumstances, chosen approach and observed result.
Step-by-step implementation
- Step 1. Establish an audit approach covering the complete ISMS over time.
- Step 2. Use competent, objective auditors and defined criteria.
- Step 3. Report results and track findings through effective follow-up.
- Final step. Test a recent example, record the result and improve weak handoffs or decisions.
Ownership
- Internal audit lead
- ISMS manager
- Independent competent auditors
Evidence and records
Implementation evidence
- internal audit procedure
- audit programme
- audit plans and reports
- auditor competence and independence records
- finding tracker
Effectiveness evidence
- audit conclusions supported by samples and evidence
- findings resolved and recurring themes influence the programme
A document can show intent. A complete sample also shows who made the decision, what happened next, whether the result was reviewed and how exceptions were handled.
How an auditor may test Clause 9.2
- Select a current business or ISMS example affected by the clause.
- Confirm the method, criteria, owner and required output.
- Trace the example through its decision records and connected processes.
- Corroborate the record with operational evidence or participant interviews.
- Follow an exception, change or adverse result to its accountable conclusion.
- Check that review and improvement occur when circumstances or results change.
Questions to prepare for
- How does the audit programme cover the whole ISMS?
- How is auditor objectivity protected?
- Show how previous findings were followed up.
Worked example
An audit samples access removal from HR termination through identity suspension and application revocation, then follows an exception to corrective action.
A strong audit trail would identify the trigger, relevant information, accountable participants, decision, resulting actions and later verification. It should be possible to explain why the approach was reasonable without reconstructing it from memory.
Smaller and mature implementation approaches
Smaller organization
Use existing leadership, service-management or risk meetings, assign a named owner and retain concise decision records. Avoid parallel governance where an established process can produce the required outcome.
Mature or complex organization
Define group-wide criteria, delegated accountabilities, integrated workflow, quality checks and consolidated performance reporting while preserving local context and evidence.
Practical implementation checklist
- □ Establish an audit approach covering the complete ISMS over time.
- □ Use competent, objective auditors and defined criteria.
- □ Report results and track findings through effective follow-up.
- □ A recent example has been traced through its connected ISMS processes.
- □ Weak results and overdue actions have accountable follow-up.
Common mistakes
- performing one annual checklist audit
- auditors reviewing their own work
- recording findings without ownership or follow-up
Frequently asked questions
Must internal audit cover everything annually?
No fixed annual coverage is prescribed; plan scope and frequency using importance, change, risk and previous results.
Can the ISMS manager audit their own work?
Objectivity must be protected; avoid self-review and use independent personnel or external support where necessary.
What makes an audit finding useful?
Clear criteria, evidence, condition, significance and enough context for accountable correction.
Explore the clause in the interactive tool
Open Clause 9.2 in the free explainer to browse its connected clauses and implementation prompts.