Skip to main content

ISO 27001 CLAUSE 9.2

The ISO 27001 internal audit has to be independent of the people who built it.

Clause 9.2 requires internal audits at planned intervals, conducted by auditors selected to ensure objectivity and impartiality of the audit process. If the people who wrote your management system also audit it, that requirement is not met, and it is one of the first things a certification body checks.

Book the Free DiagnosticSame-week availability

Loading the calendar

Open the booking page

Calendar not loading? Open Calendly directly

What happens

PHASE 01

Audit programme and scope

What is being audited, against which clauses and controls, over what period, and why that programme is risk based.

  • Audit programme
  • Scope statement
  • Audit plan

PHASE 02

Fieldwork

Interviews, document review and evidence sampling against the clauses and the controls in your Statement of Applicability.

  • Interview notes
  • Evidence samples
  • Working papers

PHASE 03

Findings

Nonconformities, observations and opportunities for improvement, each written against the clause it fails and each with an owner.

  • Nonconformity reports
  • Findings register
  • Owner and date per finding

PHASE 04

Report and management review input

A report your certification body will accept, and the input clause 9.3 requires for management review.

  • Internal audit report
  • Management review input
  • Corrective action tracker

The impartiality rule, and why it is a feature

Goldline does not sell implementation and internal audit to the same organisation for the same scope. If Goldline built your management system, someone else audits it, and we will introduce an independent credentialled auditor or brief a competent person inside your own organisation. That restriction is written into the engagement. It is the reason the audit report holds up.

Who this is for

  • You built the management system yourself, or a platform built it, and clause 9.2 is now due.

  • Your certification body has asked for the internal audit report before Stage 1.

  • A previous internal audit was carried out by the people who wrote the policies.

  • Surveillance is due and the audit programme has not run this cycle.

Delivered by a PECB ISO 27001 Lead Auditor and ISO 27001 Senior Lead Implementer, CISSP.

The audit samples the controls recorded in your ISO 27001 Statement of Applicability.

Send that document for a free review instead, back within 48 hours.

Check your audit position, and size it

Five questions on how your last internal audit was run, then a sizing step that estimates the audit effort for your scope.

01

Who carried out your most recent internal audit?

02

Does a written audit programme cover the whole standard and the applicable Annex A controls across the certification cycle?

03

Did the last audit produce a written report with findings classified and corrective actions dated?

04

When is your next certification body visit?

05

Was the ISMS implemented with outside help?

Result

Answer the questions and the result updates here as you go.

Four more questions and it tells you how many audit days this needs and what the programme has to cover.

Book the internal audit scoping call

A free 45 minute diagnostic with the practitioner who would do the work. Bring your scope, your Statement of Applicability and the last audit programme if there is one.

45 minutes, video, with the practitioner who would do the work. No sales pitch.

We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.