ISO 27001 Internal Audit: A Plain-English Guide for UK SMBs

By Brian Crocker · Published 19 July 2026

ISO 27001 Clause 9.2 makes one thing mandatory: internal audits, conducted at planned intervals, to confirm your Information Security Management System (ISMS) is working. Not a one-off event before your certification audit — a regular programme you run throughout the three-year certification cycle.

Most UK SMBs treat internal audits as a checkbox before Stage 2. Auditors know this and probe for it. A well-run internal audit programme is one of the clearest signals that your ISMS is genuine, not a paper exercise.

This guide covers what Clause 9.2 actually requires, how to plan a proportionate internal audit programme for a 10–100 person business, and what a solid audit report looks like.

What Clause 9.2 requires

ISO 27001:2022 splits Clause 9.2 into two parts:

Clause 9.2.1 requires that you conduct internal audits at planned intervals to confirm your ISMS: (a) conforms to your own ISMS requirements and to ISO 27001's requirements; and (b) is effectively implemented and maintained.

Clause 9.2.2 requires that you plan, establish, implement, and maintain an audit programme — covering frequency, methods, responsibilities, and reporting — that takes into account the importance of the relevant processes and the results of previous audits.

Two things are notable. First, the standard does not set a fixed frequency. "Planned intervals" means you decide — based on risk, changes in your business, and audit history. Annually is the minimum most certification bodies expect; high-risk areas should be audited more often. Second, the programme must evolve: last year's findings should inform this year's scope and depth.

Who can conduct internal audits

Auditors must be objective and impartial (Clause 9.2.2). This means the person who designed or operates a control cannot audit it. For most SMBs, complete staff separation is unrealistic — common approaches that satisfy the standard:

  • Cross-department swap. The finance manager audits IT processes; the IT manager audits HR processes. Works well if both receive auditor training first.
  • Rotating external specialist. A freelance ISO 27001 consultant runs your internal audit, documents findings, and produces the formal report. Costs £500–1,500 per audit day but removes the independence problem entirely.
  • Peer audit between certified businesses. Two SMBs with ISMS programmes audit each other under a confidentiality agreement. Common in professional services networks.

Whatever route you choose, document auditor qualifications or training records. Your certification auditor will ask.

Planning your audit programme

For a first-year certification cycle, plan a minimum of two internal audits before your Stage 2 assessment:

  1. Gap audit (month 3–4 of implementation). Scope: all ISMS clauses and a representative sample of Annex A controls. Purpose: identify gaps while there is time to close them before certification. This often doubles as your first documented internal audit.

  2. Pre-certification audit (month 8–10). Scope: same coverage, focusing on controls where the gap audit raised findings. Purpose: verify corrective actions are closed and your ISMS is ready for Stage 2 scrutiny.

After certification, plan at least one internal audit per year. Audit higher-risk areas and any Annex A controls with open findings from your last surveillance audit more frequently.

Your audit programme document should record: dates, scope, auditor name, methodology (document review, interviews, observation), and planned reporting format. This is the document your certification auditor reviews first.

Structuring your audit checklist

An ISO 27001 internal audit covers two areas: the ISMS clauses (4–10) and the applicable Annex A controls from your Statement of Applicability.

ISMS clause checklist structure (Clauses 4–10):

Clause Key questions
4.1 Understanding the organisation Are internal/external issues documented and reviewed?
4.2 Interested parties Are stakeholder requirements documented? Are security needs of clients/regulators captured?
4.3 Scope Is the ISMS scope documented? Does it cover all relevant assets and processes?
5.2 Information security policy Is the policy approved by top management? Do employees know its content?
6.1.2 Risk assessment Is the methodology documented? Has it been applied to all in-scope assets? Are results current?
6.1.3 Risk treatment Is the risk treatment plan current? Is the SoA complete with justifications?
7.2 Competence Are training records maintained? Is competence verified, not just training attendance?
7.5 Documented information Is version control active? Are records retrievable on demand?
8.1 Operational planning Are processes controlled? Do process owners understand their ISMS responsibilities?
9.1 Monitoring and measurement Are security objectives tracked? Is there a defined monitoring programme?
9.3 Management review Have management reviews been held? Are all required inputs covered? Are outputs actioned?
10.2 Corrective actions Are nonconformities logged? Is root cause addressed? Is effectiveness verified?

Annex A control sampling approach:

With 93 controls across 4 categories, auditing every applicable control in one session is impractical for most SMBs. Use a risk-based sampling approach:

  • Audit all controls rated high-risk in your risk assessment every cycle
  • Rotate medium-risk controls across audit cycles so all are covered over 3 years
  • Prioritise controls in categories A.5 (organisational) and A.8 (technological) — these carry the highest evidence burden
  • After a cyber incident or near-miss, advance the audit of relevant controls regardless of schedule

Our ISO 27001 Annex A Controls Checklist maps all 93 controls to the standard's four categories with evidence prompts for each.

Conducting the audit

A well-run internal audit has four stages:

1. Preparation (1–2 days). Define scope and criteria. Notify auditees at least 1 week in advance. Request document evidence: current policy versions, risk register, SoA, training records, incident log, previous audit reports. Review these before the fieldwork day.

2. Fieldwork (0.5–2 days depending on scope). Combine document review, interviews, and observation. For ISMS audits, interviews are critical — paper policies must be backed by staff who understand and follow them. Ask open questions: "Walk me through what happens when you onboard a new supplier" rather than "Do you follow the supplier vetting procedure?"

3. Reporting (0.5–1 day). Classify findings into three categories:

  • Nonconformity (NC): A requirement of the standard or your ISMS is not met. Major NC = missing entirely. Minor NC = partial implementation.
  • Observation / opportunity for improvement (OFI): Not a breach, but a weakness worth addressing.
  • Positive finding: Evidence of strong practice, worth sharing across the business.

4. Follow-up. For each nonconformity, the responsible process owner must: identify root cause, implement corrective action, set a target closure date. Track corrective actions in a log. Your next internal audit should verify all major NCs are closed.

What a finding looks like

Weak finding: "Access controls need improvement."

Strong finding: "Clause 9.2.2 / Annex A.8.2 (Privileged access rights): Review found 4 former employees still had active VPN credentials at the audit date. Access termination procedure exists (v1.2, dated 2025-04-01) but was not followed for leavers in Q1 2026. Root cause: offboarding checklist does not assign VPN revocation to a named owner. Corrective action: revoke credentials by 2026-07-25; update offboarding checklist to name IT administrator as owner. Target closure: 2026-08-01."

The difference: specificity, evidence, clause reference, root cause, named action, date. Certification auditors will read your internal audit reports during Stage 2 and look for exactly this.

Records to retain

Clause 9.2.2 requires you to retain documented information as evidence of the audit programme and audit results. Keep:

  • Audit programme (schedule for the year)
  • Individual audit plans (scope, criteria, auditor, dates)
  • Audit checklists used
  • Audit reports with classified findings
  • Corrective action log with closure evidence

Retain for at least the current certification cycle (3 years). Many organisations retain indefinitely — audit history is useful context for management reviews and surveillance audits.

Common reasons internal audits fail certification scrutiny

  1. Auditor not independent. A process owner audits their own process. Documenting auditor roles and independence is the fix.
  2. Scope too narrow. "We only audited Annex A.8 controls" when the risk assessment showed significant organisational and people controls. Cover all clauses every cycle.
  3. No corrective action follow-up. Findings without documented closure actions signal the audit was a paper exercise.
  4. Report filed and forgotten. Management review inputs must include internal audit results (Clause 9.3.2). If there is no evidence the MD saw the report, it is a finding.
  5. First audit done the week before Stage 2. Certification bodies expect at least two audits before Stage 2. One last-minute audit raises questions about programme credibility.

The ISO 9001 parallel

If you already hold ISO 9001 or are pursuing both standards together, your internal audit programme structure can be integrated. ISO 9001 Clause 9.2 has an identical structure — same planning requirement, same independence rule, same record-keeping obligation. Run combined audits covering both standards' clauses and Annex A controls in one visit: more efficient and aligns the evidence record. The ISO 9001 Internal Audit Checklist covers the QMS clause sequence if you need to run the standards separately first.

Practical starting point

If you have not run an ISO 27001 internal audit before, start here:

  1. Appoint your auditor — confirm independence meets Clause 9.2.2
  2. Draft an audit programme for the next 12 months with at least 2 scheduled audit dates
  3. Build your checklist from the ISMS clause table above plus your SoA controls list
  4. Request documents 1 week before fieldwork; review before the audit day
  5. Write findings with clause reference, evidence, root cause, and corrective action
  6. Present the report at your next management review — keep the minutes as evidence

A first-rate internal audit programme will not guarantee certification, but a poor one will derail it. The Stage 2 auditor will read your reports.

This article is for general informational purposes only and does not constitute legal, regulatory, or professional compliance advice. ISO certification requirements vary by scope, sector, and certification body. Always verify requirements with your UKAS-accredited certification body or a qualified consultant before making compliance decisions.

ClauseWise is coming soon

Generate your ISO 9001 and ISO 27001 documentation without consultant fees.