ISMS audits are planned checks that test whether your security controls exist, work, and are being followed. They are the only reliable way to know if your written policies match daily practice. Without them, an organisation runs on assumption.
There are several kinds of ISMS audits, run by different people for different reasons - your own team, your certification body, and sometimes your customers. Each one looks at the same information security management system but with a different lens and a different level of formality.
The value of ISMS audits sits less in the certificate and more in what they surface. A well-run audit finds the access review nobody completed, the supplier assessment that expired, the backup restore test that was never documented. Those findings are cheap to fix in an audit and expensive to fix after an incident.
What ISMS Audits Cover
Two things get tested, and people often forget the second one.
The first is conformity - does your system meet the requirements of the standard and your own documented procedures? The second is effectiveness - are those procedures actually achieving anything? A password policy can be fully documented, approved, and ignored by half the company. That passes a document check and fails an effectiveness test.
Scope typically includes management system clauses, the controls you declared applicable in your Statement of Applicability, the Annex A controls themselves, and any legal or contractual security obligations you have taken on.
Types of ISMS Audits
Internal Audits
Run by your own organisation, or by a contractor on your behalf. These are the most frequent and the most useful because you control the timing and depth. Internal audits are where problems should be found first.
Certification Audits
Carried out by an accredited certification body. These follow a fixed structure and lead to the certificate itself. The auditor works to a time budget based on your headcount and complexity, which means they sample rather than review everything.
Surveillance Audits
Shorter visits between certification cycles, usually annual. They confirm the system is still running and check that previous findings were closed properly. Surveillance audits are where lapsed discipline shows up most clearly.
Second-Party and Customer Audits
Your clients may audit you directly, particularly in finance, healthcare, and government supply chains. These follow the client's agenda rather than a standard, and the same evidence you prepare for your certification body covers most of what they ask. If you also assess your own suppliers, the mirror image of this is your vendor security review process.
The Certification Audit Cycle
The cycle runs over three years and follows a predictable rhythm.

Stage 1 is a readiness review. The auditor checks your documented system, scope definition, risk assessment, and Statement of Applicability. The output is usually a list of gaps to close before Stage 2. Treat this as a genuine opportunity, not a formality.
Stage 2 is the full implementation audit. Here the auditor tests evidence across the whole system - interviews, records, screenshots, logs, and walkthroughs. Certification is recommended on the strength of this visit.
Surveillance years one and two revisit a portion of the system, always including previous findings, internal audits, management review, and any changes to scope or infrastructure.
Recertification in year three repeats a fuller audit and renews the certificate. A useful reference point on how this plays out in practice is this guide to the ISO 27001 audit process.
Building an ISMS Audit Programme
A programme is a plan across time, not a single audit date. Two decisions shape it.
Schedule by Risk, Not by Calendar Convenience
Every area does not need equal attention. Weight your programme towards areas with high-value assets, recent change, past findings, or heavy third-party involvement. A stable HR filing process can be audited every second cycle. A newly migrated cloud environment deserves attention within months.
Cover the full system across the cycle, but vary the depth. This is also where your risk treatment records help - open treatment actions are natural audit targets.
Auditor Competence and Independence
Auditors must not audit their own work. In small teams this is the hardest rule to honour, and the usual workaround is cross-auditing between departments or bringing in an external auditor for the areas your own staff own.
Competence needs recording too. Keep evidence of training, prior audit experience, and technical familiarity with the areas being audited. An auditor who cannot read a firewall rule set will struggle to test network controls meaningfully.
What Auditors Actually Ask For
Experienced auditors follow evidence trails rather than checklists. Common requests include:
- Internal audit reports with dates, findings, and closure records
- Management review minutes showing decisions, not just attendance
- Risk assessment and treatment records with named owners
- Access review records for critical systems
- Incident logs with resolution and lessons learned
- Training completion and awareness records
- Change and patch records for in-scope systems
- Supplier assessments and current certificates
A pattern worth knowing: auditors rarely accept a policy as evidence. They accept records that show the policy was followed. Ten well-kept records beat a hundred pages of procedure.
How Findings Are Classified and Closed
Most certification bodies use three levels. A major nonconformity means a requirement is absent or has broken down systemically, and it blocks certification until fixed. A minor nonconformity is an isolated lapse. An observation or opportunity for improvement carries no obligation but is worth acting on.
Closure is where organisations lose marks. A finding is not closed by fixing the single example the auditor found. It is closed by identifying why the gap existed, correcting it, and showing the fix holds. That means genuine root cause analysis followed by a documented corrective action plan with an owner, a date, and verification evidence.
Practical guidance: give yourself an internal deadline well before the certification body's, because verification evidence often needs time to accumulate. A monthly access review fix needs at least two months of records to prove it works.
Where ISMS Audits Commonly Fall Down
Across compliance work, the same four weaknesses appear again and again.

The first is a compressed internal audit programme - all audits crammed into the month before the external visit, which produces no useful early warning. The second is sampling that always lands on the same well-run areas, a problem addressed well in this piece on internal audit sampling methods.
The third is findings that get "closed" with no verification evidence attached. The fourth is scope drift - a new office, product, or cloud region joins the business, and nobody updates the audit scope to match.
Fixing the first two costs nothing but discipline. Fixing the last two usually needs a system that tracks status rather than a folder that stores files.
Managing ISMS Audits in Effivity
Effivity's information security management software handles the audit lifecycle end to end. You can build a multi-year audit programme, assign auditors with recorded competence, run checklists on mobile during fieldwork, raise findings against specific clauses or controls, route corrective actions to owners with due dates, and track closure with verification evidence attached. Dashboards show open findings by area and age, so nothing quietly ages past its deadline.
Everything is timestamped and version-controlled, which turns audit preparation into filtering records rather than reconstructing history.
If you want to see how your own audit programme would sit inside it, Get a Free Personalized Demo using your real scope and departments.
Frequently Asked Questions
They are planned reviews that test whether information security controls are in place, working, and followed. They check both conformity to the standard and real effectiveness.
Internal audits should cover the full system across each certification cycle, with higher-risk areas reviewed more often. External surveillance audits usually happen once a year.
Internal audits are run by your own organisation to find problems early. Certification audits are run by an accredited body and decide whether your certificate is issued or maintained.
Yes, a major nonconformity must be corrected and verified before the certificate is granted. Minor findings usually allow certification with an agreed closure timeline.
Anyone with recorded competence who is independent of the area being audited. Small teams often cross-audit between departments or appoint an external auditor.
Access reviews, incident logs, training records, risk treatment updates, and closure evidence for past findings. Records matter more than policy documents.