Independence is a gate, not a tick box
The programme owner picked in Phase 1 gets the approval task, and enforced step order locks planning and fieldwork until the team is approved, with who and when on the activity trail.
Clause 9.2 of ISO/IEC 27001:2022 requires internal audits at planned intervals and an audit programme behind them. This free ISO 27001 internal audit checklist is for ISMS managers, internal auditors and audit programme owners. It runs one audit from its programme slot to a closed finding: scope and criteria, an independence sign-off before fieldwork, a risk-weighted sample of Annex A controls, graded findings, the report to management, corrective action under clause 10.2 and the input your next management review needs.
CheckFlow has three ISO 27001 resources, each with a different job. The ISO 27001 Compliance Checklist builds the ISMS: scope, risk assessment, Statement of Applicability, control implementation and the route to certification. Our practical guide to ISO 27001 for IT teams explains the standard, the mandatory documents and how the certification audit works. This page starts where both stop: it tests whether a running ISMS still works, with an auditor independent of the area and evidence drawn from the whole audit period, not the day of the visit.
The 2022 edition split internal audit into two sub-clauses, in line with ISO’s Harmonized Structure. Clause 9.2.1 asks whether the ISMS conforms to your own requirements and to the standard, and whether it is effectively implemented and maintained. Clause 9.2.2 requires an audit programme covering frequency, methods, responsibilities, planning requirements and reporting, shaped by the importance of the processes concerned and the results of previous audits. Each audit needs defined criteria and scope, objective and impartial auditors, and results reported to relevant management, with documented information as evidence.
The method comes from guidance: ISO 19011 for auditing any management system, and ISO/IEC 27007, which adds ISMS-specific guidance on top of it. Neither is a requirement you are certified against.
Asks: what do we need to put in place, and are we ready for Stage 1?
Annex A: all 93 controls assessed for the Statement of Applicability, then the applicable ones implemented.
Produces: a working ISMS and, if you seek it, a certificate.
Asks: does the ISMS conform, and did the controls operate throughout the period?
Annex A: a risk-weighted sample of the controls the Statement of Applicability marks applicable.
Produces: graded findings, verified corrective action and input to management review.
The certification body’s own audit is out of scope, although its auditors will expect to see these records at every visit.
Six phases take one audit from its programme slot to a closed finding. Fieldwork waits for the programme owner’s independence approval, and corrective action opens only when a nonconformity is raised.
The first task records the audit type. A full ISMS audit switches on the management system clause task in Phase 4.
The last task is an approval assigned to the programme owner named in Phase 1. Planning and fieldwork stay locked until it is approved.
The management system clause task appears only when Phase 1 records a full ISMS audit.
The grading task asks whether any nonconformity was raised. A yes opens Phase 6.
Shown only when Phase 5 records a nonconformity. The re-test is assigned to the lead auditor, not to the control owner.
The table maps each requirement that governs an ISMS internal audit to its clause in ISO/IEC 27001:2022, as amended in 2024, and to the phase that evidences it. Treat it as a starting point, not legal or certification advice.
| Requirement | Clause | Evidence the audit leaves behind | Evidenced in |
|---|---|---|---|
| Internal audits at planned intervals | 9.2.1 | A conclusion on conformity to your requirements and the standard, and on effective implementation | Phases 1 and 5 |
| Internal audit programme | 9.2.2 | Schedule, methods and owners, weighted by process importance and earlier results | Phases 1 and 5 |
| Criteria and scope for each audit | 9.2.2 | Set before fieldwork, against the Statement of Applicability in force | Phases 1 and 3 |
| Objectivity and impartiality | 9.2.2 | Conflict check and the programme owner’s approval of the team | Phase 2 |
| Auditor competence | 7.2 | Training, experience and technical knowledge on record | Phase 2 |
| Applicable Annex A controls | 6.1.3, Annex A | Sampled controls operating as the Statement of Applicability claims | Phases 3 and 4 |
| Climate change as a context issue | 4.1, 4.2 (Amd 1:2024) | A recorded decision on whether it is relevant | Phase 4 |
| Results reported to relevant management | 9.2.2 | Report issued to the managers responsible for the audited areas | Phase 5 |
| Documented information | 9.2.2, 10.2 | Programme, audit results, nonconformities and actions retained | Phases 5 and 6 |
| Input to management review | 9.3.2 | Audit results and nonconformity and corrective action trends | Phase 5 |
| Nonconformity and corrective action | 10.2 | Reaction, root cause, action and a review of its effectiveness | Phase 6 |
The standard sets no grades for findings. Certification bodies use ISO/IEC 17021-1, where a major nonconformity affects the capability of the management system to achieve its intended results and a minor one does not. Borrowing that split keeps your grades and theirs comparable.
At the time of review, ISO lists ISO/IEC 27001:2022 with its 2024 climate action amendment as the current edition, and the transition for certificates to the 2013 edition ended on 31 October 2025. ISO 19011:2026, published in May 2026, replaced the 2018 edition as a technical revision with expanded guidance on remote auditing; as guidance it applies with no transition period. ISO/IEC 27007 is being revised: the draft closed its enquiry vote on 23 September 2026 and is not yet published, so the 2020 edition remains current.
The programme owner picked in Phase 1 gets the approval task, and enforced step order locks planning and fieldwork until the team is approved, with who and when on the activity trail.
A table inside the sampling task lists each control, its population, sample size and result. Log extracts, ticket exports and review sign-offs attach to the task they prove, so findings and evidence stay together.
Give each audit area a recurring schedule, quarterly for high-risk areas and annual for a full ISMS audit. A data set of areas and risk ratings fills Phase 1. Conditional logic opens Phase 6 only for nonconformities, and dynamic due dates run from the closing meeting.
CheckFlow is not a GRC platform, a vulnerability scanner or a certification body. It runs the audit steps and keeps the evidence with the finding. If the ISMS is still being built, start with the ISO 27001 Compliance Checklist, and read the ISO 27001 guide for IT teams for background. CheckFlow’s compliance checklist software shows how the audit fits beside the rest of your compliance calendar.
The audit method carries across management system standards. If you also hold ISO 9001, the ISO 9001 Internal Audit Checklist runs the same cycle against the quality clauses, and the two programmes can share auditors and one management review. Organisations adding an AI management system can plan its clause 9.2 audits with the ISO 42001 AI Management System Checklist.
No. Clause 9.2.2 asks for a programme shaped by the importance of the processes concerned and the results of earlier audits, not for every control every year. A common pattern is to audit the management system clauses annually and spread the controls your Statement of Applicability marks applicable across the three-year certificate cycle, sampling high-risk controls such as privileged access more often. Record the reasoning in the programme.
Not of their own work. Clause 9.2.2 requires auditors and audits that keep the process objective and impartial, and the ISMS manager usually designed the risk assessment, wrote the policies and runs management review. They can own the programme and audit areas they do not run. Small organisations often borrow a trained auditor from another team or buy in an external ISMS auditor for the areas the ISMS manager owns.
ISO 19011 is guidance on auditing any management system. The current edition, ISO 19011:2026, was published in May 2026. ISO/IEC 27007:2020 adds ISMS-specific guidance on the programme, audits and auditor competence. Both are guidance; you are certified to ISO/IEC 27001, not to them. A revised ISO/IEC 27007 is at draft stage at the time of review.
Evidence that a programme exists and is followed: a schedule with its risk reasoning, audit plans with criteria and scope, the auditors’ competence and independence, reports issued to management, and nonconformities taken through to verified corrective action. A clean internal audit of an area where the certification body then finds a nonconformity calls the audit itself into question.
Yes, whenever the audit covers clauses 4.1 and 4.2. Amendment 1:2024 added a requirement to determine whether climate change is a relevant issue, and a note that relevant interested parties can have requirements related to climate change. ISO and the IAF explained that the intent is to make sure climate change is considered, not that every ISMS must treat it as relevant. The auditor checks that the decision was made and the reasoning holds.
ISO/IEC 27001 sets no deadline. Clause 10.2 requires you to react, find the cause, act, review whether the action worked and keep records, so set response and closure targets in your audit procedure, usually tighter for a major nonconformity than a minor one. A nonconformity that is still open with no progress at the next certification body visit can turn into a finding against clause 10.2 itself.
14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.