Back to Columns
ISMS & Certification14 min read

Running an Internal Audit: Plan, Checklist, Report

September 14, 2026

Running an Internal Audit: Plan, Checklist, Report
Share this article

Internal audit is the easiest activity in an ISMS to reduce to a formality. Once a year, an auditor walks a checklist round the departments, a report saying "no particular issues" is filed, and it is over in half a day. As a record it holds together. As an audit it found nothing.

Auditors notice. An internal audit that raised zero nonconformities, followed by a certification audit that raises several, casts doubt on the internal audit itself. The reverse — an organisation that found its own nonconformities, corrected them, and has the records — is direct evidence that the management system works. The value of an internal audit is not how many findings it produced but whether it was designed to be capable of producing them.

This article turns internal audit into practice, from programme to report, and covers the independence problem that constrains small organisations and what to watch when bringing in outside auditors. For where the requirement sits, see Clause 9: Performance Evaluation; for the standard as a whole, What Is an ISMS (ISO/IEC 27001)?.

Disclaimer: This article is general information. The authoritative texts are ISO/IEC 27001 (JIS Q 27001) itself and the publications of the accreditation and certification bodies. Base actual decisions on those.

Why This Trips People Up

Reading independence too narrowly

The standard asks for objectivity and impartiality in the audit process, and that auditors do not audit their own work. "Own work" covers not only what you personally perform but anything you are responsible for.

So an ISMS secretariat member who built the document architecture cannot independently audit document control. Likewise a system administrator auditing access management, or a development lead auditing change control.

Equally, though, auditors do not have to come from outside the organisation. Cross-departmental auditing is enough. Independence comes from not being responsible for the activity — not from being a different company.

A checklist that is the standard's clauses copied out

"7.2 Competence: has necessary competence been determined? → Yes." That checks whether a document exists, and nothing about how the work runs. A useful checklist is built from specific questions about your own procedures and records, not from clause text.

An audit that never leaves the meeting room

Documents are produced, completeness is confirmed, done. Reality is out on the floor. Without seeing the site, watching someone actually perform the task, and tracing randomly selected records, divergence between document and practice cannot surface.

Nobody wants to raise a finding

Auditor and auditee work for the same company, and the pull toward not damaging the relationship is real. The counterweight is making detection something the organisation values. Reporting to the management review that "the internal audit detected N nonconformities, of which N are corrected" makes finding things a positive.

A blurred line between nonconformity and observation

Raising every mild concern as a nonconformity makes corrective action unmanageable; downgrading a clear breach to an observation makes the audit pointless. Define the line before you start.

What You Have to Decide

1. The audit programme

The standard asks for a programme covering frequency, methods, responsibilities, planning and reporting, taking account of the importance of the processes concerned and the results of previous audits. Not every area needs the same depth every time.

SubjectHow to set frequencyExample
High-importance, fast-changing processesAt least annually, in depthChange control for production, access management
Areas with a previous nonconformityAlways in the next cycle, including verificationLast year's missed supplier reviews
Stable routine activitiesAnnually, light samplingEntry records, physical locking
Management processes of the standardAnnually, alwaysDocument control, training, risk assessment, corrective action
Newly added areasSoon after additionNew service, new site, new supplier

Build it so the whole ISMS scope is covered at least once per year. Whether that is one audit or four quarterly ones depends on size.

2. Scope, criteria and method

  • Scope: departments, processes, period (normally since the last audit)
  • Criteria: the standard's requirements, your own procedures, and legal and contractual requirements
  • Method: document review, interviews, record sampling, site observation, and system screens where needed

Including your own procedures in the criteria matters. Audit only against the standard and you miss the most valuable class of finding: not following the rules you wrote yourself.

3. Auditor competence and independence

Auditors need understanding of the standard, audit technique and evidence gathering. An external course certificate is the easiest evidence, but internal training is acceptable. See Designing Security Awareness Training for how to record competence.

Secure independence with an auditor-to-area assignment table fixed at planning time, verified to contain no self-assignments.

4. Defining nonconformity, observation and opportunity

CategoryDefinitionHandlingExample
Major nonconformityA requirement is unmet in a way that undermines ISMS effectiveness, or the absence of control is systemicCorrective action, including root cause and preventionNo risk assessment performed for two years
Minor nonconformityAn isolated departure from a requirement, not systemicCorrective action: correction plus cause analysisSome training records missing in one department
ObservationNot a breach today, but likely to become oneRecord and monitor; corrective action not mandatoryThe register is updated, but always at the last moment
Opportunity for improvementThe requirement is met; a better way existsRecord as a suggestion; action optionalDigitising the approval flow would capture the trail automatically

"Requirements" includes your own procedures. If the procedure says quarterly and it happened twice, that is a nonconformity even though the standard names no frequency. See Clause 10: Improvement and Writing a Corrective Action Report.

How to Do It

Step 1: Write and circulate the audit plan

Send a plan naming scope, date, auditors, auditees, criteria and method one to two weeks ahead. Surprise audits are not required — letting people prepare saves the time otherwise lost hunting for records.

Step 2: Build the checklist

This determines audit quality. Write questions about your own procedures and records, in four shapes.

Question shapeExample
Trace forward from records"I'll pick three access requests from the last three months. Show me the approval record and the actual permission set"
Trace backwards"Show me the current list of privileged account holders. Where is the request for each of these?"
Hunt exceptions"How many people left during this period? Is there an account deletion record for every one?"
Ask for a demonstration"When you find an incident, where do you actually report it? Show me the screen"

Backward tracing finds the most, in practice. Follow requests forward and everything requested was handled correctly. Permissions granted with no request at all only surface when you start from the result.

Give the checklist a column for the evidence examined — record name, date, sample reference. Without it, nothing shows what the judgement was based on.

Step 3: Hold a short opening meeting

Fifteen minutes. Say that the purpose is improvement rather than assessment, and that a finding does not attach blame to an individual. Skip this and auditees become defensive, and information stops flowing.

Step 4: Gather evidence

Combine interviews, record sampling and site observation. The principle is evidence-based: "it should be fine" is not evidence. Ask to see the record or watch the task performed.

There is no fixed sample size; three to ten items, scaled to population and importance, is the practical range. Record how you selected them (random, period edges, largest values or privileges).

Step 5: Judge, and say so at the closing meeting

Verbally, on the day. An auditee first learning of a nonconformity when the report lands damages the relationship. For each finding, state the requirement concerned (standard clause or your own procedure's article number) and the objective fact observed. Not "inadequate," but "procedure article N requires quarterly execution; two execution records exist for FY2026."

Step 6: Write the report

Include:

  • Purpose, scope, criteria, dates, auditors, auditees
  • Methods used (interview, document review, site observation)
  • Findings list: category, requirement concerned, objective fact, evidence
  • Positive observations, where they exist — useful for keeping audits non-adversarial
  • Follow-up on the previous audit's findings
  • Overall opinion on the effectiveness of the ISMS

Always include the previous follow-up. Whether last year's nonconformities were corrected is checked at certification audits too.

Step 7: Follow corrective actions through and report to the management review

Assign an owner and deadline for each nonconformity and confirm completion. The audit is not closed until completion is verified. Results are a mandatory management review input — see Running a Management Review.

Where It Goes Wrong

Zero nonconformities every year

The classic reason effectiveness gets questioned. It almost never means the organisation is perfect; it means the audit was not designed to find anything. Rewriting the checklist around backward tracing alone changes the detection rate.

The ISMS manager audits every department alone

Common in small organisations, but the ISMS manager owns the document architecture and the risk assessment, so independence for those processes cannot hold. At minimum, have someone else audit the management processes — document control, risk assessment, training, corrective action. See ISMS in a Small Organisation.

Checklists filled in with ticks only

No evidence recorded makes weak proof that the audit happened, and gives next year's auditor nothing to build on. Make recording the record name and date a habit.

Findings written as assessments

"Supplier management is inadequate" does not say what would close it. State the fact and the requirement and the scope of correction is settled.

A pile of observations that nobody tracks

Ten observations raised, and no record of what became of them a year later. List observations and follow them up at the next audit. If you will not track them, it is more coherent not to raise them.

No auditor signature or date on the record

A report that does not say who judged what, and when, loses evidential value. Put a signature block in the form.

Corrective action deadlines slip and are forgotten

A finding is detected and still open at the next certification audit. Making overdue corrective actions a standing management review agenda item puts them in front of executives, which is what moves them.

Handing it entirely to an outside party

Outsourcing internal audit is possible, but the responsibility stays with the organisation. Approving the programme, receiving and judging the results, and deciding corrective action remain yours. And where the person who helped build the documents would audit that same area, separate the individuals or have the organisation verify the audit conclusions. This is sometimes checked at certification audits.

Healthcare Examples

A healthcare SaaS provider

The must-audit area is control over access to production patient data, and the question should run backwards: "List the accounts that accessed the production database in the last three months. For each, where are the request and approval records?" Forward from requests, you see only what was requested.

The second is review of changes touching tenant separation. Whether "extract the changes that touched separation logic" can be answered on the spot is itself a finding. See Multi-Tenant Risk in Healthcare SaaS.

A PHR operator

Audit the path from consent withdrawal to cessation of use: "Pick three users who recently withdrew consent. Let me compare the withdrawal date with the date processing stopped." This overlaps the personal information law, so a finding here reduces legal exposure directly. See ISMS for PHR Operators.

A SaMD developer

An ISO 13485 internal audit already runs, so covering the ISMS requirements in the same audit is efficient. Add a "requirement (ISMS / QMS)" column to the plan so the report serves both certification audits — but keep the risk management checkpoints separate, since the purposes differ. See SaMD, ISMS and ISO 13485.

A development or maintenance supplier to hospitals

Audit remote maintenance work records: "Produce last month's maintenance connection log. For each session, is there both a hospital request and a work record?" Gaps here affect the hospital's own guideline compliance. See Shared Responsibility in AI EMR Security Design and The Three-Ministry Guidelines.

Conclusion

  1. Independence means not being responsible for the activity, not being a different company. Cross-departmental auditing works — but avoid the ISMS manager auditing the management processes they own
  2. Build the programme around process importance and previous results, covering the whole scope at least annually
  3. Include your own procedures in the audit criteria. Departing from your own rules is a nonconformity even where the standard names nothing
  4. Build checklists from four question shapes — trace forward, trace backwards, hunt exceptions, ask for a demonstration. Backward tracing finds the most
  5. Define the nonconformity/observation line in advance, and write findings as requirement plus objective fact, never as an assessment
  6. When outside auditors are used, approving the programme, judging the results and deciding corrective action stay with the organisation; separate the individuals where a document author would audit their own area

Pottech supports ISMS operation with a focus on healthcare, and internal audit design and delivery are part of that support. What an internal audit finds depends heavily on whether the questions reach into the healthcare-specific risk areas. See ISMS Certification Support or contact us.

References and Sources

Note: interpretation of requirements and the handling of accreditation and certification are governed by the standard itself and by the publications of the accreditation and certification bodies, and may change with revisions.

Share this article

Related Articles

ISMS & Certification

Reading the 37 Organizational Controls

The 37 organizational controls of Annex A.5, grouped into eight clusters rather than translated one by one: policy and governance, assets and classification, access policy, suppliers and cloud, threat intelligence, incident management, continuity, and compliance. What each cluster is asking for, and what you end up producing.

September 14, 2026
ISMS & Certification

Annex A 2022: 93 Controls Across Four Themes

A map of the 93 Annex A controls in ISO/IEC 27001:2022 across four themes — 37 organizational, 8 people, 14 physical, 34 technological. Why there is no duty to implement all 93, how inclusion and exclusion are justified in the Statement of Applicability, what the attributes are for, and the order a healthcare company should work in.

September 14, 2026
ISMS & Certification

Reading the 8 People Controls

The 8 people controls of Annex A.6, grouped into entry, employment, exit, where people work, and reporting culture. How they connect to existing employment rules, how to handle segregation of duties when the team is too small for it, and how far to go on remote working — written for healthcare companies.

September 14, 2026
ISMS & Certification

Reading the 14 Physical Controls

The 14 physical controls of Annex A.7 in five clusters, with a concrete treatment of what a fully remote, cloud-only organisation can exclude and what must be reassigned to home-working rules and supplier management — data centres, media and disposal, and equipment off premises.

September 14, 2026
AI Karte

Explore AI Karte

An AI-native EHR connecting reception, documentation, accounting, claims, and analytics into one cycle.

View the product page

ISMS Certification Support as an Option

From scope design and documentation to training, internal audit, and dealing with the certification body. Pottech supports healthcare companies through ISO/IEC 27001 certification end to end.