ISO 27001 internal audit: checklist, template and process for the entire ISMS
The internal audit is a mandatory part of every ISMS according to ISO/IEC 27001:2022. The frequent question about a PDF checklist shortens the requirement. The article provides structure, questions per Annex A chapter and a flowchart that holds up in the recertification audit.
According to Section 9.2 of ISO/IEC 27001:2022, the internal audit is a mandatory part of every information security management system (ISMS). The standard requires that the organisation conducts internal audits at scheduled intervals to determine whether the ISMS meets the requirements of the standard and the organisation's own requirements and is effectively implemented and maintained. The transition period for the 2022 version runs until October 31, 2026. Anyone who has not converted by then will lose the certification and have to restart the recertification, which can mean months of delay and a loss of trust with customers and regulators.
The search for a finished PDF checklist is understandable, but it falls short: an internal audit is a process, not a document. This article provides the structure that an internal audit must have according to ISO/IEC 27001:2022, the questions per Annex A chapter with reference to the 93 controls of the new version, a flowchart from the audit program to the final report and the link to the management review according to Section 9.3. You get a pragmatic framework that works regardless of industry and see how a compliance platform and officer-as-a-service like CIVAC centrally manages the audit program instead of letting it fail in a PDF attachment to email traffic. The auditing of cloud services and supply chains receives particular emphasis in the 2022 version.
Key Takeaways
- The ISO/IEC 27001:2022 internal audit is a Section 9.2 process, not a one-time checklist.
- The 93 controls in Annex A 2022 are structured into four topics: organisational, personnel, physical, technological.
- Audit findings, corrective measures and effectiveness monitoring must be fully documented and dealt with in the management review.
What Section 9.2 Really Requires
Section 9.2.1 of ISO/IEC 27001:2022 requires that the organisation conducts internal audits at scheduled intervals to obtain information on whether the ISMS meets its own requirements and the requirements of the standard and is effectively implemented and maintained. Section 9.2.2 requires an audit program that takes into account the importance of the affected processes, the results of previous audits and changes in the environment. The audit criteria and scope of each audit must be determined, the auditors selected, objectivity and impartiality ensured.
On a practical level, this means: an internal audit is not a one-time event, but a recurring process. Most organisations carry out an annual full audit and supplement it with topic-related partial audits, for example on supplier management, cryptography or physical security. The Information Security Officer is responsible for the audit program; operational implementation is carried out either by internal auditors with a certificate (e.g. according to ISO/IEC 19011) or by external service providers who are not involved in the area being audited.
The audit provides findings that must be made available to the responsible management in accordance with 9.2.2 e). Anyone who sees the audit as pure preparation for the external certification body is giving away the most important function: the honest inside view of their own ISMS. Audit-proof, documented, § 9.2-proof begins with a realistic audit program. An audit program that only exists on paper will be assessed as non-compliant in the external certification. The certification body auditor requires evidence of implementation, findings and completed measures. Anyone who cannot show these documents will lose their certification. The operational responsibility for this lies with the information security officer. A written task description with authorities, reporting channels and representation regulations protects against later ambiguities and is particularly valuable when there is a change in personnel.
Audit program: planning, cycle, responsibilities
The audit program is the overarching planning. It covers a period of one to three years and describes which areas, processes and controls are audited and at what frequency. The following rhythm has proven successful in a medium-sized organisation: all 93 controls in Annex A once per recertification cycle (three years), the mandatory sections 4 to 10 of the standard once a year, risky topics such as cloud, suppliers and identity management every six months.
For each audit, the audit program names the responsible auditor, the area audited, the audit date, the audit criteria and the intended audit procedure (document review, interview, sample, technical exam). The selection of auditors is a recurring point of contention. A person may not audit their own work. In small organisations, this leads to external auditors being commissioned, for example via CIVAC in the Officer-as-a-Service model. The external auditor brings the objectivity that is lacking internally and knows industry-specific focal points.
The audit program is approved by top management in accordance with Section 5.1 and reviewed at least annually. Changes in risks (new cloud services, new suppliers, new business areas) trigger an adjustment. In the CIVAC workspace, the audit program is linked to the risk register so that shifts in the risk profile automatically influence the audit frequency. If you run the program in a single Excel file, you will lose track every time you rotate staff. A link to the risk register, the list of measures and the management review keeps the program alive. Versioning with a time stamp and author creates the necessary traceability in external audits. If you also maintain a preview list for the next twelve months, you will have a concrete basis for discussion in the management review instead of just talking about the past.
Audit preparation: documents, samples, interview guide
The preparation begins with the audit announcement to the audited area, typically two to four weeks before the audit date. The announcement names the audit criteria (relevant sections of the standard and Annex A controls), the scope of application, the schedule and the required documents. The mandatory documents include the ISMS manual, the risk assessment and risk treatment according to Section 6.1, the Statement of Applicability (SoA), the information security policy according to Section 5.2 and the documented procedures for personnel, suppliers, incidents and emergencies.
The auditor creates an interview guide with open questions. Closed yes-no questions are unsuitable in internal audits because they put the person being audited on the defensive and do not provide any insight. Example of a good question for Control A.5.7 (Threat Intelligence): "Describe which sources you use for current threat intelligence and how this is incorporated into your risk assessment." Samples are defined before the audit and are not drawn ad hoc. For authorisation management, for example: ten randomly selected employees, of which at least two have administrative rights and at least one has changed functions in the last twelve months.
There are 490 audit templates available in the CIVAC workspace, several of which are for ISO/IEC 27001:2022 with questionnaires per Annex A chapter. These templates do not replace the auditor's expertise, but they structure the preparation. The auditor adapts the questions to the specific organisation and supplements them with sampling plans. The appointment certificate, signed, filed, verifiable also applies to the appointment of the internal auditor. A written appointment with authority, reporting channel and confidentiality obligation protects against later discussions about the scope of the audit. This appointment is standard equipment for every audit program in the CIVAC workspace.
Annex A 2022: The 93 controls in four subject areas
The Annex A controls of ISO/IEC 27001:2022 have been restructured compared to the 2013 version: 93 controls in four subject areas instead of 114 controls in 14 areas. The four areas are A.5 Organizational Controls (37 Controls), A.6 Personnel Controls (8 Controls), A.7 Physical Controls (14 Controls) and A.8 Technological Controls (34 Controls). Eleven controls have been added, such as A.5.7 Threat Intelligence, A.5.23 Information Security for Cloud Services, A.5.30 ICT Readiness for Business Continuity, A.8.9 Configuration Management, A.8.10 Information Deletion, A.8.11 Data Masking, A.8.12 Data Leakage Prevention.
In the internal audit, the auditor checks for each control: Is there documented implementation? Is this implementation marked as applicable in the SoA? Is it lived in practice? How is effectiveness measured? The central pitfall in transition audits is the SoA. If the SoA still references the old structure or new controls are marked as "not applicable" even though they actually should be, this is immediately noticeable in the audit.
The audit report includes: audit question, checked document, observation, evaluation (compliant, minor deviation, major deviation, suggestion for improvement) for each control. The compliance function has an accompanying effect here because Annex A controls and general compliance requirements often overlap, for example in data protection, confidentiality protection and whistleblower protection. An integrated view saves double audits of the same documents. Anyone who interviews the same employee twice for the ISMS and the GDPR, using different sets of questions, wastes time and creates gaps between the two reports. Consolidated audit planning with common samples for overlapping topics significantly reduces the effort. It is particularly useful if the organisation is additionally regulated under NIS-2 and the information security officer coordinates both the ISO duty and the NIS-2 oversight duty.
Audit execution: opening, survey, closing
The audit implementation follows a fixed structure. The opening meeting typically lasts thirty minutes and states the goal, scope, methodology, confidentiality and reporting path. The auditor, the audited department manager and, if necessary, other key people are present. The opening is recorded and the minutes are archived. In the survey phase, the auditor conducts interviews, looks at documents and checks samples.
The survey phase lasts from half a day to several days, depending on the scope. Important rule: Every audit finding is supported by at least one piece of objective evidence (document, screen capture, evaluation, written statement). Assumptions are not recorded as findings, they are noted as indications and, if necessary, expanded upon in the next audit. The auditor prioritises the findings according to severity: major deviation (significant violation of the norm), minor deviation (partial violation of the norm), observation (notice without violation of the norm), suggestion for improvement (recommendation without obligation).
The final meeting follows immediately after the survey. The auditor presents the findings, the audited area comments, and the assessment is agreed upon together. A major deviation may not be discussed in the final meeting; it remains a major deviation. In the CIVAC workspace, the findings are transferred directly from the audit log to the measures register, with the responsible person, deadlines and effectiveness control. The auditor calls, the evidence is ready. and this also applies to the final report: it is finalized no later than ten working days after the audit. If you take longer, you lose the relevance of your memory of the interviews and the samples. The report then becomes a mandatory task, not a tool. A standardised report template in the workspace with pre-populated sections significantly reduces creation time without flattening the content. The final assessment is made by the auditor; the template only provides the framework.
Audit report: content, structure, addressees
The audit report is the central result document. It contains at least: audit framework (date, auditor, scope, criteria), audit methodology (interviews, documents, samples), audit findings per audited chapter with evidence and assessment, summary of major deviations and minor deviations, recommendations and suggestions for improvement. A pure PDF table is not enough. The report explains the findings in such a way that even someone who was not present at the audit can understand and understand them.
The addressee is primarily the top management, which deals with the findings in the management review according to Section 9.3. The area manager receives the report for information and to initiate corrective measures. Major deviations are responded to with an action plan within a short period of time (typically two to six weeks), minor deviations by the next audit date. Suggestions for improvement are voluntary, but should be checked in a documented manner so that they can be found in the next audit program.
The report is saved in the ISMS document management. Versioning, access rights and retention period (typically six years after the audit date, but at least a full certification cycle plus two years) must be determined. The CIVAC platform stores audit reports in the EU data residency, with read access for the external certification body during the next round of audits. Anyone who keeps audit reports in shared email inboxes will lose them the first time there is a change in personnel in the area. A central storage system with clear roles is also preferable from a data protection perspective because audit reports can contain personal samples. Access rights are limited to the need-to-know principle, with a traceable audit trail. Anyone who comes for recertification as an external auditor receives temporary reading access to the relevant reports instead of sending PDFs as email attachments. This practice also meets the requirements of Annex A 8.3 (restricted access) and reduces the risk of uncontrolled disclosure.
Corrective measures and effectiveness control
Section 10.1 of ISO/IEC 27001:2022 regulates continuous improvement, Section 10.2 regulates non-conformity and corrective action. Every audit finding in the sense of a deviation must be transferred into a corrective action process. This process includes: root cause analysis (why did the deviation arise?), measure (what exactly is being changed?), responsibility, deadline, effectiveness control (how is it determined that the measure is effective?).
The root cause analysis is the most common weak point. Anyone who simply notes “employees were not reminded” as the cause of a lack of safety training is not providing a cause analysis, but rather a subsequent description. A true root cause analysis asks: Why is there no automated reminder mechanism? Why wasn't the annual requirement included in the onboarding? Why wasn't the omission recognised in the quarterly report? Only this depth prevents repetition.
The effectiveness check is carried out at the earliest three months after the measure has been implemented. It shows whether the correction is actually effective or whether a new audit is necessary. In the CIVAC workspace, corrective actions are directly linked to the original audit finding. The effectiveness control is planned as a separate process, with a deadline, responsibility and result. Others run compliance like a filing cabinet. We run it like software. In concrete terms, this means: An audit finding will not be closed if the measure has only been implemented but its effect has not been confirmed. This discipline pays off in the external audit because the certification body also checks the effectiveness and no open points are allowed to remain. A closed measure that is not recognised as effective in the external audit is considered a major deviation. Anyone who works thoroughly in the internal audit will avoid this discovery. If in doubt, a measure should be kept open longer and confirmed more thoroughly than closed prematurely.
Management review according to Section 9.3 and linking to the ISMS
The management review according to Section 9.3 of ISO/IEC 27001:2022 is the place where the audit results are politically assessed. Top management evaluates the ISMS at scheduled intervals, at least annually. The mandatory input variables are listed in 9.3.2 and include, among other things, the status of the measures from previous reviews, changes to external and internal topics, feedback on information security services, audit results, results of the risk assessment, status of risk treatment and opportunities for continuous improvement.
The output variables are regulated in 9.3.3 and include decisions on opportunities for improvement, adjustments to the ISMS, resource requirements. These decisions are recorded and transferred to the subsequent program. A management review that only consists of a PowerPoint presentation and does not produce any documented decisions is normatively incomplete.
The link to the internal audit is bidirectional. The audit provides input variables for the review, the review provides focal points for the next audit program. In the CIVAC workspace, the management review and audit program are managed in the same system, with versioning over at least six years. The reporting line to the management is not a PowerPoint once a year, but a living process with comprehensible decisions. Anyone who licences the workspace receives the templates for the review protocol. Licence the workspace for your internal representatives, or have our representatives order it. The templates are adapted to the 2022 version of the standard and will be updated as soon as the standards group at ISO issues a new update. The appointment certificate, signed, filed, verifiable also applies to external orders. When in doubt, the external auditor is the most effective answer to the conflict between objectivity and proximity in small organisations.
From the desire for a PDF checklist to a reliable audit process
Looking for an ISO 27001 audit checklist in PDF is understandable. But it doesn't solve the problem. A PDF checklist is static, it becomes outdated with the next standard update, it is not linked to the risk register, and there is no effectiveness control. An internal audit according to ISO/IEC 27001:2022 is a living process that actively develops the ISMS. Anyone who sees it as a compulsory exercise is giving away the actual tool for continuous improvement.
CIVAC works as a compliance platform and officer-as-a-service. The platform manages the audit program, the templates for 93 controls in Annex A, the catalogue of measures and the management review in a common workspace with EU data residency. Licence the workspace for your internal representatives, or have our representatives order it. In the Officer-as-a-Service variant, the external information security officer takes over the appointment certificate, maintaining the ISMS, carrying out the internal audit and preparing the external certification. The order is usually placed within two working days of placing the order.
Turn reading into a mandate. A short email to info@civac.de with the industry, certification status and existing ISMS is enough for the first appointment. If you prefer to use the contact form, you can find it linked via the FAQ page. What you don't get: a generic audit PDF. What you get: concrete feedback on what gaps exist in your ISMS, what the next internal audit should look like and what corrective measures need to be closed before re-certification in October 2026. Deadline expires when we know: If you haven't initiated the transition yet, you shouldn't wait any longer. An initial, reliable gap analysis is available within a week; the elimination of the most common gaps takes four to twelve weeks, depending on the initial situation.
FAQ
How often does an internal audit according to ISO/IEC 27001:2022 have to take place?
The standard requires planned distances, but does not prescribe a specific frequency. An annual full audit is usual, supplemented by topic-specific partial audits every six months. All mandatory sections and all applicable Annex A controls must have been audited once over the three-year recertification cycle. Risky topics such as cloud services and supplier management are usually reviewed more frequently, at least every six months.
Can a PDF checklist replace the internal audit?
No. A PDF checklist can serve as preparation, but does not replace interviews, spot checks, document checking and the auditor's individual assessment of the findings. The standard requires an audit process, not a checked-off document. A PDF checklist that is used without reference to your own risk register and your own statement of applicability will be noticed in an external audit.
Who is allowed to carry out the internal audit?
The auditor must be objective and impartial. He is not allowed to audit the area in which he himself works or has had direct influence. A qualification according to ISO/IEC 19011 or a comparable certification is recommended. In small organisations, external auditors are commissioned, for example via CIVAC in the officer-as-a-service model, to reliably meet the objectivity requirement.
What happens to major deviations in internal audit?
Major deviations are responded to with an action plan within a few weeks. The measure includes root cause analysis, concrete correction, responsibility, deadline and effectiveness control. A major deviation that is not closed by the next external audit immediately jeopardizes certification. In the follow-up audit, the external certification body checks whether the measure was actually effective and not just formally implemented.
Which new controls from 2022 are particularly relevant to audits?
The new controls A.5.7 Threat Intelligence, A.5.23 Information Security for Cloud Services, A.5.30 ICT Readiness for Business Continuity, A.8.9 Configuration Management, A.8.10 Information Deletion, A.8.11 Data Masking and A.8.12 Data Leakage Prevention are particularly relevant to audits. These controls are not included in the 2013 version or are only included indirectly and lead to most of the findings in the transition audit.
How is the effectiveness of a corrective action confirmed?
The effectiveness check takes place at the earliest three months after implementation. It checks whether the original deviation does not occur again and whether the actual goal (e.g. complete training quota) is achieved. It is documented with date, method and result. The audit finding is only closed after a positive effectiveness check, not after the measure has been implemented.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.