In this article:

ISO 27001 Clause 9.2: Internal Audit Requirements Explained

Compliance
/
July 16, 2026
ISO 27001 Clause 9.2: Internal Audit Requirements Explained

ISO 27001 Clause 9.2 requires you to audit your own information security management system at planned intervals, to confirm two things: that the ISMS conforms to your own documented requirements and to the standard, and that it is effectively implemented and maintained. The clause has two parts. Clause 9.2.1 states that objective. Clause 9.2.2 sets the mechanics: plan and maintain an audit program covering frequency, methods, responsibilities, planning requirements, and reporting; define criteria and scope for each audit; select auditors and run audits so objectivity and impartiality are assured; report results to relevant management; and retain documented information as evidence of both the program and the results. Most organizations meet it with one annual cycle, and certification auditors examine the program, the competence records, and the independence arrangement before they read a single finding.

What the clause actually asks for

Read literally, Clause 9.2.2 contains five obligations, and each one produces a distinct artifact. The audit program is the first and the one most often missing. It is a standing document, not a single audit, and it has to say how often audits occur, what methods will be used, who is responsible, how audits are planned, and how results get reported. It should also explain why the schedule looks the way it does, since the standard expects the program to consider the importance of the processes involved and the results of previous audits.

The second obligation is criteria and scope for each individual audit. Criteria means what you are auditing against, normally the relevant clauses of ISO 27001, the applicable Annex A controls, your own policies, and any contractual or regulatory commitments in scope. Scope means which parts of the ISMS, which locations, which systems, and which time period. Auditors who arrive without either write reports that read like opinion pieces.

The third is objectivity and impartiality in auditor selection, which is the requirement that causes the most trouble in smaller organizations and gets its own section below. The fourth is reporting results to relevant management, which in practice means the results reach the people who can act on them and then feed into the Clause 9.3 management review as a required input. The fifth is retention: the program, the plans, the working papers, the reports, and the resulting corrective actions all need to be kept as documented information.

How often, in practice

The standard says planned intervals, not annually. Certification practice has converged on annual anyway, for two structural reasons. First, Clause 9.3 management review needs internal audit results as an input, and management review is expected at least yearly. Second, certification bodies conduct surveillance audits in each of the two years between certification and recertification, and each of those expects to see a completed internal audit cycle since the last visit.

What varies is how the year is arranged. A small single-site ISMS is usually audited in one pass of three to six auditor-days. Larger or multi-site systems are better served by a rolling program: a few audits a year, each covering a slice, with all clauses 4 through 10 and all applicable Annex A controls covered across a defined cycle, commonly 12 months and at most the three years of the certification cycle for the lowest-risk controls. Higher-risk areas earn more frequent attention, and access control, supplier management, and change management are the usual candidates for a second look. Multi-site programs of 8 to 20 auditor-days a year are normal at 500 people and above.

Competence and objectivity

Two separate tests apply to whoever performs the audit. Competence means knowledge of the standard's requirements, knowledge of auditing technique, and enough understanding of the technology in scope to tell a real control from a screenshot. Formal internal auditor or lead auditor training costs $1,500 to $3,500 a seat and is the usual way organizations evidence the auditing side.

Objectivity means the auditor is not auditing their own work. ISO 19011, the guidance standard for auditing management systems, treats independence as a core principle, and while ISO 19011 is guidance rather than a requirement of ISO 27001, certification auditors expect the underlying discipline. In a 1,000-person company objectivity is arrangeable: internal audit, risk, or quality functions can audit the ISMS, or auditors from one business unit can audit another. In an 80-person company the arithmetic usually fails, because the one person who understands the ISMS well enough to audit it is the person who built it.

Why the implementer usually cannot audit the implementation

This is not a bureaucratic technicality. The person who wrote the access control policy, chose the review cadence, and set up the evidence collection has already decided what good looks like. Asked to audit it, they will test against their own design rather than against the standard.

Three workable options exist. Assign the audit to a competent person in a different function with no role in the ISMS. Set up a cross-audit arrangement inside a group, where the ISMS manager at one entity audits another entity's scope. Or engage an external provider to perform the internal audit, which is the most common answer below roughly 250 employees and costs $5,000 to $15,000 for a typical single-site scope, rising to $15,000 to $40,000 for multi-site programs. Our breakdown of ISO 27001 certification cost puts that spend in the context of the full first cycle.

What certification auditors look for in your evidence

  • A program document, not just a report. Frequency, methods, responsibilities, planning requirements, and reporting lines, with a schedule showing coverage of clauses 4 through 10 and the applicable Annex A controls across the cycle.
  • Criteria and scope for each audit. Written before the audit, naming the clauses and controls in scope, the locations, the systems, and the period examined.
  • Competence and objectivity records. The auditor's qualifications and training, plus a written statement of independence from the areas audited. Certification auditors ask for this by name.
  • Working papers that show sampling. Which records were examined, how many, chosen how, and who was interviewed. A report with conclusions and no visible sample is treated as an opinion.
  • Findings routed into corrective action. Every nonconformity linked to the Clause 10.2 process with a root cause, a corrective action, an owner, a date, and a later effectiveness check.
  • Proof of reporting. Minutes, a distribution record, or a management review agenda showing that results reached management and were considered as a Clause 9.3 input.

The nonconformities that come up most

The single most common finding is that an audit happened but no program exists. There is a report from last spring and nothing that describes frequency, methods, responsibilities, or how the schedule was decided, which fails 9.2.2 on its face even though the audit itself may have been competent.

Coverage gaps come second. Clauses 4 through 10 get audited and Annex A does not, or a batch of controls has not been examined since the initial certification two years ago.

Third is the independence failure: the ISMS manager audited the ISMS they built, with no compensating arrangement documented. Fourth is corrective action that stops halfway. Findings are raised, actions are recorded, and nothing shows root cause analysis or a later check that the fix worked, which converts an internal audit finding into a Clause 10.2 nonconformity as well.

Fifth, and easy to fix, is the reporting gap: a good audit report that never reached management and never appeared as a management review input. Sixth is the audit that finds nothing. Zero findings across an entire ISMS is read as evidence that the audit was superficial rather than that the system is flawless, and experienced certification auditors will probe the working papers hard when they see it. A credible first-year internal audit on a mid-sized ISMS typically raises 5 to 15 observations and one to four minor nonconformities.

Last is timing. An internal audit completed two weeks before the certification audit leaves no room to remediate anything it found, and one completed after the management review cannot have fed into it. Schedule the internal audit two to four months ahead of the certification or surveillance visit, and ahead of the management review, and both problems disappear.

Where internal audit ends and certification begins

Three roles keep the system credible and they are deliberately separate. An implementer builds the ISMS. An internal auditor checks it independently under Clause 9.2. An accredited certification body audits it and issues the certificate. Accredited registrars are barred from consulting for the clients they certify, which is why your certification body cannot perform your internal audit.

BD Emerson sits on the first two of those three. We perform Clause 9.2 internal audits, and we are not a certification body: we do not issue ISO certificates, and the certificate comes from an accredited registrar such as one under ANAB or UKAS. Where we have done implementation work for a client and internal audit is also in play, we keep the teams separate so the objectivity requirement is met in substance rather than on paper.

Where BD Emerson fits

Our ISO 27001 internal audit service delivers the full 9.2 package: an audit program you can hand to a certification auditor, per-audit criteria and scope, working papers that show the sampling, a report with findings classified and routed into corrective action, and the competence and independence records that get asked for first. If the ISMS itself still needs building or repairing before it can be audited usefully, our ISO 27001 consulting practice handles scoping, the risk assessment, the Statement of Applicability, and the evidence cadence. The internal audit is the cheapest place to find your Stage 2 problems while they are still yours to fix quietly.

About the author

Leslie Sakal is a Managing Director at BD Emerson focused on cybersecurity, enterprise risk management, and regulatory compliance. She brings over a decade of experience advising organizations across technology, financial services, education, and other regulated industries on implementing organization-wide goals and programs that align with their broader business objectives.
Leslie Sakal
Leslie Sakal
Managing Director