ISO 27001 Internal Audit Checklist Template

Too many ISMS internal audits are squeezed into the month before the surveillance visit, run by the ISMS manager who wrote the controls, and check that a policy exists rather than whether the control actually operated.

Clause 9.2 of ISO/IEC 27001:2022 requires internal audits at planned intervals and an audit programme behind them. This free ISO 27001 internal audit checklist is for ISMS managers, internal auditors and audit programme owners. It runs one audit from its programme slot to a closed finding: scope and criteria, an independence sign-off before fieldwork, a risk-weighted sample of Annex A controls, graded findings, the report to management, corrective action under clause 10.2 and the input your next management review needs.

Use This Template Free See Live Example
No Credit Card Required

Last reviewed: October 2026

Building the ISMS Is Not the Same Job as Auditing It

CheckFlow has three ISO 27001 resources, each with a different job. The ISO 27001 Compliance Checklist builds the ISMS: scope, risk assessment, Statement of Applicability, control implementation and the route to certification. Our practical guide to ISO 27001 for IT teams explains the standard, the mandatory documents and how the certification audit works. This page starts where both stop: it tests whether a running ISMS still works, with an auditor independent of the area and evidence drawn from the whole audit period, not the day of the visit.

The 2022 edition split internal audit into two sub-clauses, in line with ISO’s Harmonized Structure. Clause 9.2.1 asks whether the ISMS conforms to your own requirements and to the standard, and whether it is effectively implemented and maintained. Clause 9.2.2 requires an audit programme covering frequency, methods, responsibilities, planning requirements and reporting, shaped by the importance of the processes concerned and the results of previous audits. Each audit needs defined criteria and scope, objective and impartial auditors, and results reported to relevant management, with documented information as evidence.

The method comes from guidance: ISO 19011 for auditing any management system, and ISO/IEC 27007, which adds ISMS-specific guidance on top of it. Neither is a requirement you are certified against.

Implementation checklist

Builds and certifies the ISMS

Asks: what do we need to put in place, and are we ready for Stage 1?

Annex A: all 93 controls assessed for the Statement of Applicability, then the applicable ones implemented.

Produces: a working ISMS and, if you seek it, a certificate.

Internal audit checklist (this page)

Tests the ISMS that is already running

Asks: does the ISMS conform, and did the controls operate throughout the period?

Annex A: a risk-weighted sample of the controls the Statement of Applicability marks applicable.

Produces: graded findings, verified corrective action and input to management review.

The certification body’s own audit is out of scope, although its auditors will expect to see these records at every visit.

What the ISO 27001 Internal Audit Checklist Covers

Six phases take one audit from its programme slot to a closed finding. Fieldwork waits for the programme owner’s independence approval, and corrective action opens only when a nonconformity is raised.

Phase 1

Phase 1: Programme Slot, Scope & Criteria

The first task records the audit type. A full ISMS audit switches on the management system clause task in Phase 4.

  • Open the audit from its programme slot — record the ISMS areas, sites, dates, programme owner, lead auditor and whether this is a full or partial ISMS audit
  • Note the risk reasoning behind this slot — how important the processes are, what earlier audits found, and incidents or risk changes since the last audit (clause 9.2.2)
  • Fix the objectives, criteria and scope before planning — the clauses, the Annex A controls marked applicable, your own policies, and contractual or legal security requirements
  • Confirm which versions of the ISMS documents are in force — the scope statement, risk treatment plan and Statement of Applicability this audit will test against
  • Pull every open finding against this area — from earlier internal audits, the certification body and customer audits, with the status of each action
Phase 2

Phase 2: Audit Team, Competence & Independence

The last task is an approval assigned to the programme owner named in Phase 1. Planning and fieldwork stay locked until it is approved.

  • Choose the lead auditor and any technical specialist — for example someone who can read cloud IAM policies or firewall rules when technological controls are sampled
  • Record each auditor’s competence — ISMS audit training, audit experience and knowledge of the technology in scope (clause 7.2)
  • Check each auditor against the scope for conflicts — nobody audits a control they designed, operate or manage, including the ISMS manager’s own processes
  • Agree read-only access and evidence handling — console, log and ticket access for the auditor, and where exports containing sensitive data are kept
  • Approve the audit team’s objectivity and impartiality — the programme owner approves, or replaces an auditor before any fieldwork starts (clause 9.2.2)
Phase 3

Phase 3: Audit Plan & Annex A Sampling

  • Read the ISMS records for the scope — risk register, risk treatment plan, Statement of Applicability, relevant policies and the last management review minutes
  • Select the Annex A controls to sample — weight towards high risks, recent incidents, controls changed this year and controls not yet tested in this certificate cycle
  • Define each population and sample size — for example leavers in the audit period, change tickets, privileged accounts or new supplier contracts
  • Decide how each sampled control will be tested — its design against the policy, then its operation over the period by inspection, re-performance or observation
  • Send the audit plan to auditees — timetable, interviews, systems to be demonstrated and which sessions run remotely
Phase 4

Phase 4: Fieldwork

The management system clause task appears only when Phase 1 records a full ISMS audit.

  • Open fieldwork with the auditees — walk through the plan, the grading scale, how evidence and screenshots will be handled, and the closing meeting slot
  • Full ISMS audit: test the management system clauses 4 to 10 — including the decision on whether climate change is a relevant issue (clause 4.1), risk treatment, objectives, monitoring and management review
  • Trace a sample of risks through to evidence — from the risk register through the treatment plan and Statement of Applicability to a control that is working
  • Test each sampled control’s operation over the period — tickets, logs, review sign-offs and configuration exports dated in the period, not screenshots taken on the day
  • Interview the people who operate the controls — service desk, developers, HR and facilities staff, not only the ISMS manager
  • Log every observation with an evidence reference — record ID, system, date and the clause or control it relates to, so a reviewer could re-perform the test
Phase 5

Phase 5: Findings, Report & Management Review Input

The grading task asks whether any nonconformity was raised. A yes opens Phase 6.

  • Draft each finding against its criterion — the clause or control, the sampled evidence and exactly what was missing or failed
  • Assign a grade to every finding — major or minor nonconformity, observation or improvement opportunity, on the scale your audit procedure defines
  • Run the closing meeting — take auditees through each finding, settle disputed facts and agree a response date with every finding owner
  • Send the report to the managers who own the audited areas — findings, a conclusion on conformity and effectiveness, and any limits on the sample (clause 9.2)
  • Pass the results to the next management review — audit results and trends in nonconformities and corrective actions are required inputs (clause 9.3.2)
  • Feed the results back into the programme — re-weight when this area is next audited and file the plan, evidence and report as programme records
Phase 6 — Only If a Nonconformity Is Raised

Phase 6: Clause 10.2 Follow-Up & Re-Test

Shown only when Phase 5 records a nonconformity. The re-test is assigned to the lead auditor, not to the control owner.

  • React to each nonconformity — contain and correct it and deal with the consequences, such as removing access that should already have gone (clause 10.2)
  • Find the root cause — for example a missing leaver trigger rather than one late account removal, then look for the same failure in other systems
  • Agree the corrective action, owner and due date — and update the risk assessment or Statement of Applicability if the cause sits there
  • Put the action in place — fix the procedure, configuration or tooling that let the failure happen, not only the instance the audit found
  • Re-test once the fix has had time to operate — the lead auditor samples records created after the change
  • Close the finding — keep a record of what the nonconformity was, what was done about it and whether it worked (clause 10.2)

ISO/IEC 27001:2022 Requirements Mapped to the Audit

The table maps each requirement that governs an ISMS internal audit to its clause in ISO/IEC 27001:2022, as amended in 2024, and to the phase that evidences it. Treat it as a starting point, not legal or certification advice.

Requirement Clause Evidence the audit leaves behind Evidenced in
Internal audits at planned intervals9.2.1A conclusion on conformity to your requirements and the standard, and on effective implementationPhases 1 and 5
Internal audit programme9.2.2Schedule, methods and owners, weighted by process importance and earlier resultsPhases 1 and 5
Criteria and scope for each audit9.2.2Set before fieldwork, against the Statement of Applicability in forcePhases 1 and 3
Objectivity and impartiality9.2.2Conflict check and the programme owner’s approval of the teamPhase 2
Auditor competence7.2Training, experience and technical knowledge on recordPhase 2
Applicable Annex A controls6.1.3, Annex ASampled controls operating as the Statement of Applicability claimsPhases 3 and 4
Climate change as a context issue4.1, 4.2 (Amd 1:2024)A recorded decision on whether it is relevantPhase 4
Results reported to relevant management9.2.2Report issued to the managers responsible for the audited areasPhase 5
Documented information9.2.2, 10.2Programme, audit results, nonconformities and actions retainedPhases 5 and 6
Input to management review9.3.2Audit results and nonconformity and corrective action trendsPhase 5
Nonconformity and corrective action10.2Reaction, root cause, action and a review of its effectivenessPhase 6

The standard sets no grades for findings. Certification bodies use ISO/IEC 17021-1, where a major nonconformity affects the capability of the management system to achieve its intended results and a minor one does not. Borrowing that split keeps your grades and theirs comparable.

At the time of review, ISO lists ISO/IEC 27001:2022 with its 2024 climate action amendment as the current edition, and the transition for certificates to the 2013 edition ended on 31 October 2025. ISO 19011:2026, published in May 2026, replaced the 2018 edition as a technical revision with expanded guidance on remote auditing; as guidance it applies with no transition period. ISO/IEC 27007 is being revised: the draft closed its enquiry vote on 23 September 2026 and is not yet published, so the 2020 edition remains current.

Why Run Your ISMS Internal Audits in CheckFlow?

1

Independence is a gate, not a tick box

The programme owner picked in Phase 1 gets the approval task, and enforced step order locks planning and fieldwork until the team is approved, with who and when on the activity trail.

2

Each sample keeps its evidence

A table inside the sampling task lists each control, its population, sample size and result. Log extracts, ticket exports and review sign-offs attach to the task they prove, so findings and evidence stay together.

3

The programme runs on its own schedule

Give each audit area a recurring schedule, quarterly for high-risk areas and annual for a full ISMS audit. A data set of areas and risk ratings fills Phase 1. Conditional logic opens Phase 6 only for nonconformities, and dynamic due dates run from the closing meeting.

CheckFlow is not a GRC platform, a vulnerability scanner or a certification body. It runs the audit steps and keeps the evidence with the finding. If the ISMS is still being built, start with the ISO 27001 Compliance Checklist, and read the ISO 27001 guide for IT teams for background. CheckFlow’s compliance checklist software shows how the audit fits beside the rest of your compliance calendar.

The audit method carries across management system standards. If you also hold ISO 9001, the ISO 9001 Internal Audit Checklist runs the same cycle against the quality clauses, and the two programmes can share auditors and one management review. Organisations adding an AI management system can plan its clause 9.2 audits with the ISO 42001 AI Management System Checklist.

Frequently Asked Questions

Do we have to audit all 93 Annex A controls every year?

+

No. Clause 9.2.2 asks for a programme shaped by the importance of the processes concerned and the results of earlier audits, not for every control every year. A common pattern is to audit the management system clauses annually and spread the controls your Statement of Applicability marks applicable across the three-year certificate cycle, sampling high-risk controls such as privileged access more often. Record the reasoning in the programme.

Can the ISMS manager carry out the ISO 27001 internal audit?

+

Not of their own work. Clause 9.2.2 requires auditors and audits that keep the process objective and impartial, and the ISMS manager usually designed the risk assessment, wrote the policies and runs management review. They can own the programme and audit areas they do not run. Small organisations often borrow a trained auditor from another team or buy in an external ISMS auditor for the areas the ISMS manager owns.

What is ISO/IEC 27007 and how does it relate to ISO 19011?

+

ISO 19011 is guidance on auditing any management system. The current edition, ISO 19011:2026, was published in May 2026. ISO/IEC 27007:2020 adds ISMS-specific guidance on the programme, audits and auditor competence. Both are guidance; you are certified to ISO/IEC 27001, not to them. A revised ISO/IEC 27007 is at draft stage at the time of review.

What will the certification auditor look for in our internal audit records?

+

Evidence that a programme exists and is followed: a schedule with its risk reasoning, audit plans with criteria and scope, the auditors’ competence and independence, reports issued to management, and nonconformities taken through to verified corrective action. A clean internal audit of an area where the certification body then finds a nonconformity calls the audit itself into question.

Do internal audits need to cover the 2024 climate change amendment?

+

Yes, whenever the audit covers clauses 4.1 and 4.2. Amendment 1:2024 added a requirement to determine whether climate change is a relevant issue, and a note that relevant interested parties can have requirements related to climate change. ISO and the IAF explained that the intent is to make sure climate change is considered, not that every ISMS must treat it as relevant. The auditor checks that the decision was made and the reasoning holds.

How quickly must an internal audit nonconformity be closed?

+

ISO/IEC 27001 sets no deadline. Clause 10.2 requires you to react, find the cause, act, review whether the action worked and keep records, so set response and closure targets in your audit procedure, usually tighter for a major nonconformity than a minor one. A nonconformity that is still open with no progress at the next certification body visit can turn into a finding against clause 10.2 itself.

Is CheckFlow free for this template?

+

14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.

Internal Audits That Test Whether Controls Ran, Not Just Whether Policies Exist

Free trial — no credit card required.