ISO 27001 practical guide
ISO 27001 Internal Audit Checklist
A useful ISO 27001 internal audit checklist is an audit plan and evidence guide, not a yes/no compliance questionnaire. It connects objective, scope, criteria and risk-based sampling to interviews, records, findings and follow-up so management can act on reliable results.
- Search intent
- Prepare and conduct a useful internal audit across Clauses 4–10.
- Guide area
- Audit
- Review status
- Practitioner reviewed
What this means in practice
Independence means the auditor can evaluate the work objectively; it does not always require an external consultant. Avoid assigning people to audit decisions or controls for which they are directly responsible.
Audit coverage may be arranged across a programme. Frequency and sampling should respond to process importance, change, previous results and risk rather than treating every control identically.
Step-by-step implementation
- Step 1. Define the audit objective, boundaries, period and criteria.
- Step 2. Confirm auditor competence and objective assignment.
- Step 3. Review prior findings, risk information, process changes and performance trends.
- Step 4. Prepare evidence-driven questions and a sampling plan.
- Step 5. Interview owners and trace samples from requirement through decision and result.
- Step 6. Classify findings against clear criteria and corroborated evidence.
- Step 7. Report conclusions, agree accountable follow-up and verify corrective-action effectiveness.
What to prepare
- audit programme and individual audit plan
- scope, criteria, timetable and process owners
- prior findings and corrective actions
- risk assessment, SoA, objectives and performance data
- sampling notes, evidence references and finding records
Documents, records and evidence
| Area or field | Example | Why it matters |
|---|---|---|
| Clauses 4–5 | How were context, interested parties, scope and responsibilities determined? | Current records plus decisions showing leadership involvement |
| Clauses 6–8 | Show the risk method, selected samples, treatments and operational controls. | Traceability from risk through action, control and retained result |
| Clause 9 | How are measures evaluated, audits programmed and management decisions retained? | Trends, audit evidence, review inputs, decisions and action follow-up |
| Clause 10 | Trace one nonconformity from correction through cause and effectiveness review. | Closure evidence demonstrates recurrence risk was addressed |
Sample trail: leaver access
Select three departures from different teams during the audit period. Compare HR termination records with identity disablement, application access removal, asset return and exception handling. Record population, sample rationale, evidence inspected and any inconsistent result.
What an auditor will look for
- A programme that covers the ISMS and reflects risk and prior results.
- Objective auditors with suitable competence.
- Reproducible samples and evidence-linked findings.
- Timely reporting and corrective-action follow-up.
An auditor may select different samples or follow unexpected evidence. Prepare authoritative records and owners who can explain normal operation, exceptions and improvement rather than rehearsed answers.
Common mistakes
- Auditing only documents and never sampling transactions.
- Letting a control owner audit their own implementation.
- Writing vague findings without criteria, evidence or affected scope.
- Closing findings when an action is promised rather than verified.
Practical checklist
- □ Objective, scope, criteria and audit period are defined.
- □ Auditor competence and objectivity are recorded.
- □ Sampling considers risk, change and previous findings.
- □ Questions ask for evidence and trace actual examples.
- □ Findings identify criteria, condition, evidence and affected scope.
- □ Corrective actions receive an effectiveness review.
Frequently asked questions
Can the security manager audit their own work?
They may audit areas they do not own, but direct responsibility creates an objectivity problem that should be addressed through another competent auditor.
Must every Annex A control be audited every year?
Plan coverage based on the audit programme, importance, risk, change and previous results; ensure the complete ISMS is covered appropriately over time.
What evidence should be retained?
Programme, plan, competence/objectivity, sampling notes, evidence references, findings, report and follow-up records.
Continue through the practical guide library
Use the topic hub to connect this task with related implementation, risk, governance, evidence and audit-preparation guidance.