ISO 27001 practical guide

ISO 27001 Internal Audit Checklist

A useful ISO 27001 internal audit checklist is an audit plan and evidence guide, not a yes/no compliance questionnaire. It connects objective, scope, criteria and risk-based sampling to interviews, records, findings and follow-up so management can act on reliable results.

Search intent
Prepare and conduct a useful internal audit across Clauses 4–10.
Guide area
Audit
Review status
Practitioner reviewed

What this means in practice

Independence means the auditor can evaluate the work objectively; it does not always require an external consultant. Avoid assigning people to audit decisions or controls for which they are directly responsible.

Audit coverage may be arranged across a programme. Frequency and sampling should respond to process importance, change, previous results and risk rather than treating every control identically.

Step-by-step implementation

  1. Step 1. Define the audit objective, boundaries, period and criteria.
  2. Step 2. Confirm auditor competence and objective assignment.
  3. Step 3. Review prior findings, risk information, process changes and performance trends.
  4. Step 4. Prepare evidence-driven questions and a sampling plan.
  5. Step 5. Interview owners and trace samples from requirement through decision and result.
  6. Step 6. Classify findings against clear criteria and corroborated evidence.
  7. Step 7. Report conclusions, agree accountable follow-up and verify corrective-action effectiveness.

What to prepare

  • audit programme and individual audit plan
  • scope, criteria, timetable and process owners
  • prior findings and corrective actions
  • risk assessment, SoA, objectives and performance data
  • sampling notes, evidence references and finding records

Documents, records and evidence

Area or fieldExampleWhy it matters
Clauses 4–5How were context, interested parties, scope and responsibilities determined?Current records plus decisions showing leadership involvement
Clauses 6–8Show the risk method, selected samples, treatments and operational controls.Traceability from risk through action, control and retained result
Clause 9How are measures evaluated, audits programmed and management decisions retained?Trends, audit evidence, review inputs, decisions and action follow-up
Clause 10Trace one nonconformity from correction through cause and effectiveness review.Closure evidence demonstrates recurrence risk was addressed

Sample trail: leaver access

Select three departures from different teams during the audit period. Compare HR termination records with identity disablement, application access removal, asset return and exception handling. Record population, sample rationale, evidence inspected and any inconsistent result.

What an auditor will look for

  • A programme that covers the ISMS and reflects risk and prior results.
  • Objective auditors with suitable competence.
  • Reproducible samples and evidence-linked findings.
  • Timely reporting and corrective-action follow-up.

An auditor may select different samples or follow unexpected evidence. Prepare authoritative records and owners who can explain normal operation, exceptions and improvement rather than rehearsed answers.

Common mistakes

  • Auditing only documents and never sampling transactions.
  • Letting a control owner audit their own implementation.
  • Writing vague findings without criteria, evidence or affected scope.
  • Closing findings when an action is promised rather than verified.

Practical checklist

  • □ Objective, scope, criteria and audit period are defined.
  • □ Auditor competence and objectivity are recorded.
  • □ Sampling considers risk, change and previous findings.
  • □ Questions ask for evidence and trace actual examples.
  • □ Findings identify criteria, condition, evidence and affected scope.
  • □ Corrective actions receive an effectiveness review.

Frequently asked questions

Can the security manager audit their own work?

They may audit areas they do not own, but direct responsibility creates an objectivity problem that should be addressed through another competent auditor.

Must every Annex A control be audited every year?

Plan coverage based on the audit programme, importance, risk, change and previous results; ensure the complete ISMS is covered appropriately over time.

What evidence should be retained?

Programme, plan, competence/objectivity, sampling notes, evidence references, findings, report and follow-up records.

Continue through the practical guide library

Use the topic hub to connect this task with related implementation, risk, governance, evidence and audit-preparation guidance.

Browse all ISO 27001 practical guides →