ChecklistsFree

ISO 27001 Internal Audit Checklist

A complete ISMS internal audit guide with verification points for every clause and control.

In short

An ISO 27001 internal audit is the audit an organisation runs against its own ISMS before the certification body arrives. Clause 9.2 requires it at planned intervals. This checklist carries audit questions per clause and per Annex A control, with columns for evidence, findings, and corrective action.

Format
XLSX
Size
32 KB
Price
Free

Your data is handled in accordance with Indonesia's Personal Data Protection Law. We only send the document you requested and the occasional relevant GRC insight — no spam.

What This Document Is For

The internal audit is the only chance to find problems before an external auditor finds them. Organisations that treat it as a formality — ticking every row in two hours — typically receive a major nonconformity for something that could have been closed a month earlier.

This checklist frames questions the way auditors ask them: not 'does the control exist', but 'show me the evidence, when it last ran, and who owns it'. The findings column separates major nonconformities, minor ones, and opportunities for improvement, matching the categories certification bodies use.

Most Useful For

  • Organisations running their first internal audit ahead of certification
  • Internal auditors needing a consistent question set across audit cycles
  • Certificate holders preparing for an annual surveillance audit

What's Inside

01

Clause 4–10 audit

Questions for context, leadership, planning, support, operation, performance evaluation, and improvement.

02

Annex A audit

Per-control questions across all four themes, filterable against the SoA so excluded controls are not audited.

03

Evidence column

Space to record the documents, screenshots, or interviews behind each auditor conclusion.

04

Finding classification

Major, minor, or opportunity for improvement, following certification body categories.

05

Corrective action

Root cause, action, owner, deadline, and closure verification.

06

Audit programme

An annual planning sheet: areas audited, schedule, auditors, and their independence.

Standards & Regulations It Helps Satisfy

Standard / RegulationClause / ArticleWhat this document covers
ISO/IEC 27001:2022Clause 9.2Internal audits at planned intervals with a documented programme and results.
ISO/IEC 27001:2022Clause 10.2Nonconformity and corrective action, including verification of effectiveness.
ISO 19011Audit guidelinesThe management system auditing principles this checklist's structure follows.

This document helps satisfy the requirements above, but does not by itself make an organisation compliant. Compliance is judged on practice in operation, not on documents held.

Questions About This Document

Who can act as internal auditor?

Anyone competent who is not auditing their own work. An IT manager may audit HR processes but not the technical controls they implemented themselves. External auditors check this independence, and breaching it produces a finding.

Must the whole ISMS be audited at once?

No. What is required is that the whole ISMS is covered across one planned cycle — commonly a year for small organisations, or three years with higher-risk areas audited more often. What matters is that the programme is written down and followed.

How does an internal audit differ from a gap assessment?

A gap assessment measures the distance to the standard before the ISMS operates. An internal audit tests whether a running ISMS is genuinely effective and conforming. Both use the same reference but answer different questions.

Related Reading

Background that helps you fill this document in correctly, rather than merely filling it in.

Need guidance, not just a template?

A template speeds up producing the document. What decides whether an audit passes is whether its contents genuinely reflect how your organisation works — and that is what we support.