ISO 27001 CLAUSE 9.2
The ISO 27001 internal audit has to be independent of the people who built it.
Clause 9.2 requires internal audits at planned intervals, conducted by auditors selected to ensure objectivity and impartiality of the audit process. If the people who wrote your management system also audit it, that requirement is not met, and it is one of the first things a certification body checks.
Loading the calendar
Open the booking pageCalendar not loading? Open Calendly directly
What happens
PHASE 01
Audit programme and scope
What is being audited, against which clauses and controls, over what period, and why that programme is risk based.
- Audit programme
- Scope statement
- Audit plan
PHASE 02
Fieldwork
Interviews, document review and evidence sampling against the clauses and the controls in your Statement of Applicability.
- Interview notes
- Evidence samples
- Working papers
PHASE 03
Findings
Nonconformities, observations and opportunities for improvement, each written against the clause it fails and each with an owner.
- Nonconformity reports
- Findings register
- Owner and date per finding
PHASE 04
Report and management review input
A report your certification body will accept, and the input clause 9.3 requires for management review.
- Internal audit report
- Management review input
- Corrective action tracker
The impartiality rule, and why it is a feature
Goldline does not sell implementation and internal audit to the same organisation for the same scope. If Goldline built your management system, someone else audits it, and we will introduce an independent credentialled auditor or brief a competent person inside your own organisation. That restriction is written into the engagement. It is the reason the audit report holds up.
Who this is for
You built the management system yourself, or a platform built it, and clause 9.2 is now due.
Your certification body has asked for the internal audit report before Stage 1.
A previous internal audit was carried out by the people who wrote the policies.
Surveillance is due and the audit programme has not run this cycle.
Delivered by a PECB ISO 27001 Lead Auditor and ISO 27001 Senior Lead Implementer, CISSP.
The audit samples the controls recorded in your ISO 27001 Statement of Applicability.
Send that document for a free review instead, back within 48 hours.
Check your audit position, and size it
Five questions on how your last internal audit was run, then a sizing step that estimates the audit effort for your scope.
Result
Answer the questions and the result updates here as you go.
Four more questions and it tells you how many audit days this needs and what the programme has to cover.
Book the internal audit scoping call
A free 45 minute diagnostic with the practitioner who would do the work. Bring your scope, your Statement of Applicability and the last audit programme if there is one.
45 minutes, video, with the practitioner who would do the work. No sales pitch.
