Internal audit is the easiest activity in an ISMS to reduce to a formality. Once a year, an auditor walks a checklist round the departments, a report saying "no particular issues" is filed, and it is over in half a day. As a record it holds together. As an audit it found nothing.
Auditors notice. An internal audit that raised zero nonconformities, followed by a certification audit that raises several, casts doubt on the internal audit itself. The reverse — an organisation that found its own nonconformities, corrected them, and has the records — is direct evidence that the management system works. The value of an internal audit is not how many findings it produced but whether it was designed to be capable of producing them.
This article turns internal audit into practice, from programme to report, and covers the independence problem that constrains small organisations and what to watch when bringing in outside auditors. For where the requirement sits, see Clause 9: Performance Evaluation; for the standard as a whole, What Is an ISMS (ISO/IEC 27001)?.
Disclaimer: This article is general information. The authoritative texts are ISO/IEC 27001 (JIS Q 27001) itself and the publications of the accreditation and certification bodies. Base actual decisions on those.
Why This Trips People Up
Reading independence too narrowly
The standard asks for objectivity and impartiality in the audit process, and that auditors do not audit their own work. "Own work" covers not only what you personally perform but anything you are responsible for.
So an ISMS secretariat member who built the document architecture cannot independently audit document control. Likewise a system administrator auditing access management, or a development lead auditing change control.
Equally, though, auditors do not have to come from outside the organisation. Cross-departmental auditing is enough. Independence comes from not being responsible for the activity — not from being a different company.
A checklist that is the standard's clauses copied out
"7.2 Competence: has necessary competence been determined? → Yes." That checks whether a document exists, and nothing about how the work runs. A useful checklist is built from specific questions about your own procedures and records, not from clause text.
An audit that never leaves the meeting room
Documents are produced, completeness is confirmed, done. Reality is out on the floor. Without seeing the site, watching someone actually perform the task, and tracing randomly selected records, divergence between document and practice cannot surface.
Nobody wants to raise a finding
Auditor and auditee work for the same company, and the pull toward not damaging the relationship is real. The counterweight is making detection something the organisation values. Reporting to the management review that "the internal audit detected N nonconformities, of which N are corrected" makes finding things a positive.
A blurred line between nonconformity and observation
Raising every mild concern as a nonconformity makes corrective action unmanageable; downgrading a clear breach to an observation makes the audit pointless. Define the line before you start.
What You Have to Decide
1. The audit programme
The standard asks for a programme covering frequency, methods, responsibilities, planning and reporting, taking account of the importance of the processes concerned and the results of previous audits. Not every area needs the same depth every time.
| Subject | How to set frequency | Example |
|---|---|---|
| High-importance, fast-changing processes | At least annually, in depth | Change control for production, access management |
| Areas with a previous nonconformity | Always in the next cycle, including verification | Last year's missed supplier reviews |
| Stable routine activities | Annually, light sampling | Entry records, physical locking |
| Management processes of the standard | Annually, always | Document control, training, risk assessment, corrective action |
| Newly added areas | Soon after addition | New service, new site, new supplier |
Build it so the whole ISMS scope is covered at least once per year. Whether that is one audit or four quarterly ones depends on size.
2. Scope, criteria and method
- Scope: departments, processes, period (normally since the last audit)
- Criteria: the standard's requirements, your own procedures, and legal and contractual requirements
- Method: document review, interviews, record sampling, site observation, and system screens where needed
Including your own procedures in the criteria matters. Audit only against the standard and you miss the most valuable class of finding: not following the rules you wrote yourself.
3. Auditor competence and independence
Auditors need understanding of the standard, audit technique and evidence gathering. An external course certificate is the easiest evidence, but internal training is acceptable. See Designing Security Awareness Training for how to record competence.
Secure independence with an auditor-to-area assignment table fixed at planning time, verified to contain no self-assignments.
4. Defining nonconformity, observation and opportunity
| Category | Definition | Handling | Example |
|---|---|---|---|
| Major nonconformity | A requirement is unmet in a way that undermines ISMS effectiveness, or the absence of control is systemic | Corrective action, including root cause and prevention | No risk assessment performed for two years |
| Minor nonconformity | An isolated departure from a requirement, not systemic | Corrective action: correction plus cause analysis | Some training records missing in one department |
| Observation | Not a breach today, but likely to become one | Record and monitor; corrective action not mandatory | The register is updated, but always at the last moment |
| Opportunity for improvement | The requirement is met; a better way exists | Record as a suggestion; action optional | Digitising the approval flow would capture the trail automatically |
"Requirements" includes your own procedures. If the procedure says quarterly and it happened twice, that is a nonconformity even though the standard names no frequency. See Clause 10: Improvement and Writing a Corrective Action Report.
How to Do It
Step 1: Write and circulate the audit plan
Send a plan naming scope, date, auditors, auditees, criteria and method one to two weeks ahead. Surprise audits are not required — letting people prepare saves the time otherwise lost hunting for records.
Step 2: Build the checklist
This determines audit quality. Write questions about your own procedures and records, in four shapes.
| Question shape | Example |
|---|---|
| Trace forward from records | "I'll pick three access requests from the last three months. Show me the approval record and the actual permission set" |
| Trace backwards | "Show me the current list of privileged account holders. Where is the request for each of these?" |
| Hunt exceptions | "How many people left during this period? Is there an account deletion record for every one?" |
| Ask for a demonstration | "When you find an incident, where do you actually report it? Show me the screen" |
Backward tracing finds the most, in practice. Follow requests forward and everything requested was handled correctly. Permissions granted with no request at all only surface when you start from the result.
Give the checklist a column for the evidence examined — record name, date, sample reference. Without it, nothing shows what the judgement was based on.
Step 3: Hold a short opening meeting
Fifteen minutes. Say that the purpose is improvement rather than assessment, and that a finding does not attach blame to an individual. Skip this and auditees become defensive, and information stops flowing.
Step 4: Gather evidence
Combine interviews, record sampling and site observation. The principle is evidence-based: "it should be fine" is not evidence. Ask to see the record or watch the task performed.
There is no fixed sample size; three to ten items, scaled to population and importance, is the practical range. Record how you selected them (random, period edges, largest values or privileges).
Step 5: Judge, and say so at the closing meeting
Verbally, on the day. An auditee first learning of a nonconformity when the report lands damages the relationship. For each finding, state the requirement concerned (standard clause or your own procedure's article number) and the objective fact observed. Not "inadequate," but "procedure article N requires quarterly execution; two execution records exist for FY2026."
Step 6: Write the report
Include:
- Purpose, scope, criteria, dates, auditors, auditees
- Methods used (interview, document review, site observation)
- Findings list: category, requirement concerned, objective fact, evidence
- Positive observations, where they exist — useful for keeping audits non-adversarial
- Follow-up on the previous audit's findings
- Overall opinion on the effectiveness of the ISMS
Always include the previous follow-up. Whether last year's nonconformities were corrected is checked at certification audits too.
Step 7: Follow corrective actions through and report to the management review
Assign an owner and deadline for each nonconformity and confirm completion. The audit is not closed until completion is verified. Results are a mandatory management review input — see Running a Management Review.
Where It Goes Wrong
Zero nonconformities every year
The classic reason effectiveness gets questioned. It almost never means the organisation is perfect; it means the audit was not designed to find anything. Rewriting the checklist around backward tracing alone changes the detection rate.
The ISMS manager audits every department alone
Common in small organisations, but the ISMS manager owns the document architecture and the risk assessment, so independence for those processes cannot hold. At minimum, have someone else audit the management processes — document control, risk assessment, training, corrective action. See ISMS in a Small Organisation.
Checklists filled in with ticks only
No evidence recorded makes weak proof that the audit happened, and gives next year's auditor nothing to build on. Make recording the record name and date a habit.
Findings written as assessments
"Supplier management is inadequate" does not say what would close it. State the fact and the requirement and the scope of correction is settled.
A pile of observations that nobody tracks
Ten observations raised, and no record of what became of them a year later. List observations and follow them up at the next audit. If you will not track them, it is more coherent not to raise them.
No auditor signature or date on the record
A report that does not say who judged what, and when, loses evidential value. Put a signature block in the form.
Corrective action deadlines slip and are forgotten
A finding is detected and still open at the next certification audit. Making overdue corrective actions a standing management review agenda item puts them in front of executives, which is what moves them.
Handing it entirely to an outside party
Outsourcing internal audit is possible, but the responsibility stays with the organisation. Approving the programme, receiving and judging the results, and deciding corrective action remain yours. And where the person who helped build the documents would audit that same area, separate the individuals or have the organisation verify the audit conclusions. This is sometimes checked at certification audits.
Healthcare Examples
A healthcare SaaS provider
The must-audit area is control over access to production patient data, and the question should run backwards: "List the accounts that accessed the production database in the last three months. For each, where are the request and approval records?" Forward from requests, you see only what was requested.
The second is review of changes touching tenant separation. Whether "extract the changes that touched separation logic" can be answered on the spot is itself a finding. See Multi-Tenant Risk in Healthcare SaaS.
A PHR operator
Audit the path from consent withdrawal to cessation of use: "Pick three users who recently withdrew consent. Let me compare the withdrawal date with the date processing stopped." This overlaps the personal information law, so a finding here reduces legal exposure directly. See ISMS for PHR Operators.
A SaMD developer
An ISO 13485 internal audit already runs, so covering the ISMS requirements in the same audit is efficient. Add a "requirement (ISMS / QMS)" column to the plan so the report serves both certification audits — but keep the risk management checkpoints separate, since the purposes differ. See SaMD, ISMS and ISO 13485.
A development or maintenance supplier to hospitals
Audit remote maintenance work records: "Produce last month's maintenance connection log. For each session, is there both a hospital request and a work record?" Gaps here affect the hospital's own guideline compliance. See Shared Responsibility in AI EMR Security Design and The Three-Ministry Guidelines.
Conclusion
- Independence means not being responsible for the activity, not being a different company. Cross-departmental auditing works — but avoid the ISMS manager auditing the management processes they own
- Build the programme around process importance and previous results, covering the whole scope at least annually
- Include your own procedures in the audit criteria. Departing from your own rules is a nonconformity even where the standard names nothing
- Build checklists from four question shapes — trace forward, trace backwards, hunt exceptions, ask for a demonstration. Backward tracing finds the most
- Define the nonconformity/observation line in advance, and write findings as requirement plus objective fact, never as an assessment
- When outside auditors are used, approving the programme, judging the results and deciding corrective action stay with the organisation; separate the individuals where a document author would audit their own area
Pottech supports ISMS operation with a focus on healthcare, and internal audit design and delivery are part of that support. What an internal audit finds depends heavily on whether the questions reach into the healthcare-specific risk areas. See ISMS Certification Support or contact us.
References and Sources
- Information Management System Accreditation Center (ISMS-AC)
- ISO/IEC 27001 Information security management systems | ISO
- ISO 19011 Guidelines for auditing management systems | ISO
- Japanese Industrial Standards Committee (JISC)
- Guidelines for the Safe Management of Medical Information Systems | MHLW
Note: interpretation of requirements and the handling of accreditation and certification are governed by the standard itself and by the publications of the accreditation and certification bodies, and may change with revisions.