An internal audit ISO 27001 is your own check on your own security system, done before anyone external looks at it. You choose the timing, the depth, and the areas to test. That control is exactly why it is the most useful audit you will run all year.
The standard requires internal audits at planned intervals, covering both the management system clauses and the controls you declared applicable. But the requirement is the floor, not the goal. A well-planned internal audit ISO 27001 gives you months of warning before a certification body finds the same gap, which is the difference between a quiet fix and a nonconformity on record.
This page covers how to plan the audit, how to sample sensibly, what evidence to gather, and how to write findings that people can actually act on. It sits within the wider information security management system framework and links closely to the broader ISMS audits picture.
What an Internal ISO 27001 Audit Tests
Two questions run through every audit.
Does the system meet the requirements - the clauses of the standard, your own documented procedures, and any contractual security obligations you have signed up to?
Does the system work - are those procedures producing the results they were designed for? A quarterly access review that happens but never removes an account is technically performed and practically useless.
Auditors who only test the first question produce clean reports and surprised organisations. The second question is where value hides.
Planning the Internal Audit

Define Scope and Objectives First
Write down what is in scope before you build a checklist. Scope means departments, locations, systems, processes, and the specific clauses or controls under review. Objectives explain why - post-incident verification, pre-certification readiness, or routine cycle coverage.
Vague scope is the most common planning failure. "Audit information security" produces a shallow sweep. "Audit access provisioning and revocation for the three production systems" produces findings.
Set the Audit Frequency
You are not required to audit everything at once. Cover the full system across the certification cycle and weight the frequency by risk. Areas with recent change, past findings, high-value assets, or heavy third-party involvement deserve more visits. Stable, low-risk processes can wait.
Practical guidance on setting cadence is covered in this piece on internal audit frequency for ISO compliance.
Choose the Auditor
Two rules apply. The auditor must be competent, with recorded training and enough technical familiarity to interrogate the area properly. And the auditor must be independent of the work being audited.
Small teams struggle with the second rule. Workable options are cross-auditing between departments, swapping auditors with a peer organisation, or contracting an external auditor for areas your own staff own. Whatever you choose, record the reasoning - auditors will ask how independence was maintained.
Running the Audit
Prepare a Working Checklist
Build the checklist from your own documents, not a generic template. Pull the actual control statements from your Statement of Applicability and your information security policies, then write the question you would need to answer to prove each one operates.
Leave space for what you find rather than only tick boxes. A checklist with no notes column produces reports nobody trusts.
Sample Properly
Sampling decides audit quality more than anything else. Two habits weaken it: always sampling the same well-run areas, and letting the process owner choose the records.
Pick your own sample, cover the whole period rather than the last two weeks, and deliberately include awkward cases - the contractor who joined mid-project, the emergency change made at midnight, the leaver who returned. Approaches that hold up under scrutiny are set out in this guide to internal audit sampling methods.
Gather Evidence, Not Opinions
Evidence is records, screenshots, logs, tickets, signed forms, and system exports. "The team says they do this monthly" is not evidence. Ask for the last three months of records instead.
Trace forwards and backwards. Take a live user account and trace back to the approval that created it. Take an approved access request and check whether the account was actually created with the rights specified. Gaps show up in the gap between the two directions.
Interview With Open Questions
Ask people to describe what they do rather than confirm what the policy says. "Walk me through what happens when someone leaves" reveals far more than "Do you revoke access when someone leaves?" The second question has only one socially acceptable answer.
Interviews also test awareness, which connects directly to your security awareness programme. If three people describe three different processes, you have found something whether or not the records look clean.
Writing Findings and Reports
A finding needs four parts: the requirement, the evidence, the gap, and the classification. Missing any one makes it arguable.

Weak: "Access reviews are not adequate." Usable: "Clause requires periodic access review. Records exist for Q1 and Q4 only. Q2 and Q3 reviews were not performed for the finance system."
Classify consistently. A systemic breakdown or absent requirement is major. An isolated lapse in an otherwise working process is minor. Anything worth improving but not required is an observation.
Keep the report short and specific. Long reports with vague findings get filed. Short reports with three concrete, evidenced gaps get acted on.
Closing Findings Properly
Fixing the single example the auditor found is not closure. Closure means understanding why the gap existed, correcting the underlying cause, and proving the fix holds over time.
That sequence needs real root cause analysis followed by corrective action with an owner, a date, and verification evidence. Where a finding relates to identified risk, the fix usually feeds back into your risk treatment records rather than sitting alone.
One timing insight that saves trouble: verification evidence often needs time to accumulate. If the fix is a monthly control, you need at least two or three months of records before you can honestly mark it closed. Build that lead time into your deadlines instead of closing findings on the strength of a single corrected instance.
Common Weaknesses in Internal Audits
Across compliance reviews, four patterns repeat.
All audits crammed into the weeks before the external visit, which removes any early warning value. Checklists copied from generic sources that never touch your actual controls. Findings marked closed with no verification evidence attached. And audit records kept as loose spreadsheets, so nobody can answer "what is still open?" without an afternoon of digging.
The first two cost nothing but planning discipline. The last two are structural and usually need a system rather than a stronger reminder.
Managing Internal ISO 27001 Audits in Effivity
Effivity's information security management software covers the full internal audit lifecycle. You can build a multi-year audit programme, assign auditors with recorded competence and independence notes, run checklists on mobile or tablet during fieldwork, attach evidence directly to each question, raise findings against specific clauses and controls, and route corrective actions to owners with due dates and verification steps.
Dashboards show open findings by area and age, so nothing quietly slips past its deadline. Everything is timestamped and version-controlled, which is why teams using it treat external audit prep as filtering records rather than rebuilding a paper trail.
If you would like to see it against your own scope, Get a Free Personalized Demo with your real departments and controls.
Frequently Asked Questions
It is a review carried out by your own organisation to test whether your security controls meet ISO 27001 and work in practice. You control the scope and timing.
The full system should be covered across each certification cycle, with higher-risk areas audited more frequently. Many organisations run audits quarterly by area.
Anyone competent and independent of the area being audited. Recorded training and relevant technical knowledge are both needed.
Yes, by cross-auditing between departments or appointing an external auditor for areas your own staff manage. Record how independence was achieved.
Internal audits are yours, run to find problems early. Certification audits are run by an accredited body and decide whether your certificate is issued or kept.
The audit plan, checklist with notes, evidence samples, findings, and closure records with verification. Reports without evidence do not stand up externally.