What Happens During an ISO 27001 Internal Audit?
An internal audit tests whether the ISMS and selected controls conform to criteria and operate as intended.
Planning comes first
The auditor defines objectives, scope, criteria, schedule, control owners and sampling approach. Audit criteria may include ISO/IEC 27001 requirements, the organisation's own policies, contractual obligations and control procedures.
Evidence is sampled
Auditors rarely inspect every transaction. They select evidence that is sufficient to support a conclusion. The sample might cover access reviews, user lifecycle events, changes, incidents, backup tests, supplier reviews or security training across the review period.
Interviews are not evidence by themselves
Interviews explain how a process is supposed to operate and help locate evidence. A strong conclusion usually requires corroboration such as system records, approvals, logs, tickets, reports or completed review artefacts.
Findings need criteria and condition
A finding should show what requirement or control expectation applies, what evidence showed, why the difference matters, and what needs to be corrected. The classification of a finding should follow the audit methodology rather than the auditor's mood.
Follow-up matters
The audit is not complete merely because the report was issued. Corrective actions need owners, due dates, remediation evidence and a closure or retest decision.
Use the Readiness Review to define scope and the first assessment.