ISO 27001 Internal Audit Checklist
A complete ISMS internal audit guide with verification points for every clause and control.
In short
An ISO 27001 internal audit is the audit an organisation runs against its own ISMS before the certification body arrives. Clause 9.2 requires it at planned intervals. This checklist carries audit questions per clause and per Annex A control, with columns for evidence, findings, and corrective action.
- Format
- XLSX
- Size
- 32 KB
- Price
- Free
Your data is handled in accordance with Indonesia's Personal Data Protection Law. We only send the document you requested and the occasional relevant GRC insight — no spam.
What This Document Is For
The internal audit is the only chance to find problems before an external auditor finds them. Organisations that treat it as a formality — ticking every row in two hours — typically receive a major nonconformity for something that could have been closed a month earlier.
This checklist frames questions the way auditors ask them: not 'does the control exist', but 'show me the evidence, when it last ran, and who owns it'. The findings column separates major nonconformities, minor ones, and opportunities for improvement, matching the categories certification bodies use.
Most Useful For
- Organisations running their first internal audit ahead of certification
- Internal auditors needing a consistent question set across audit cycles
- Certificate holders preparing for an annual surveillance audit
What's Inside
Clause 4–10 audit
Questions for context, leadership, planning, support, operation, performance evaluation, and improvement.
Annex A audit
Per-control questions across all four themes, filterable against the SoA so excluded controls are not audited.
Evidence column
Space to record the documents, screenshots, or interviews behind each auditor conclusion.
Finding classification
Major, minor, or opportunity for improvement, following certification body categories.
Corrective action
Root cause, action, owner, deadline, and closure verification.
Audit programme
An annual planning sheet: areas audited, schedule, auditors, and their independence.
Standards & Regulations It Helps Satisfy
| Standard / Regulation | Clause / Article | What this document covers |
|---|---|---|
| ISO/IEC 27001:2022 | Clause 9.2 | Internal audits at planned intervals with a documented programme and results. |
| ISO/IEC 27001:2022 | Clause 10.2 | Nonconformity and corrective action, including verification of effectiveness. |
| ISO 19011 | Audit guidelines | The management system auditing principles this checklist's structure follows. |
This document helps satisfy the requirements above, but does not by itself make an organisation compliant. Compliance is judged on practice in operation, not on documents held.
Questions About This Document
Who can act as internal auditor?
Anyone competent who is not auditing their own work. An IT manager may audit HR processes but not the technical controls they implemented themselves. External auditors check this independence, and breaching it produces a finding.
Must the whole ISMS be audited at once?
No. What is required is that the whole ISMS is covered across one planned cycle — commonly a year for small organisations, or three years with higher-risk areas audited more often. What matters is that the programme is written down and followed.
How does an internal audit differ from a gap assessment?
A gap assessment measures the distance to the standard before the ISMS operates. An internal audit tests whether a running ISMS is genuinely effective and conforming. Both use the same reference but answer different questions.
Related Reading
Background that helps you fill this document in correctly, rather than merely filling it in.
Documents Often Taken Together With This One
ISO 27001 Gap Assessment Checklist
Measure your organization's readiness against ISO 27001:2022 and find gaps before certification.
Free DownloadPDP Law Compliance Checklist
A compliance checklist against Law No. 27 of 2022 on Personal Data Protection (PDP Law).
Free DownloadPenetration Test Preparation Checklist
Prepare for a pentest the right way: asset scoping, test accounts, testing windows, PICs, and legal aspects — so testing runs smoothly from day one.
Free DownloadNeed guidance, not just a template?
A template speeds up producing the document. What decides whether an audit passes is whether its contents genuinely reflect how your organisation works — and that is what we support.