An ISO 27001 internal audit has two halves that behave completely differently, and treating them as one job is why so many first attempts run out of time. The management clauses are about how the information security management system is run: context, leadership, objectives, competence, monitoring, management review, and the audit and improvement machinery itself. The Annex A controls are about what you actually do to protect information, and only the ones your Statement of Applicability says apply to you. The first half is audited once for the whole organisation. The second is audited control by control, and there are far more of them than the clause count suggests.
Start from the Statement of Applicability, not from the standard
The Statement of Applicability is the document that says which Annex A controls apply to your organisation, which do not, and why. It is also your audit scope for the control half, and it is the first thing an external auditor asks for. Auditing against the full annex when your statement excludes a block of controls wastes days; auditing against a statement that has not been updated since your last system change is worse, because it audits a state of the world that no longer exists. Reconcile the statement against reality before planning a single audit day.
What evidence a control audit actually needs
For each applicable control the auditor is looking for the same chain: a decision that the control is needed, a description of how it is implemented here, evidence it operated during the audit period, and evidence that somebody checked it. Access review controls need the reviews, with dates and the accounts removed as a result. Supplier controls need the supplier assessments and the contract clauses. Logging controls need the logs and the record of a person looking at them. A control that exists in a policy and produces no periodic artefact is the classic finding, because there is nothing to sample.
Sampling that survives an external auditor
Pick records across the whole audit period rather than the last month, and pick them yourself rather than asking the owner to supply examples. A joiner, a mover and a leaver, chosen from the HR list rather than from IT, tests the access provisioning control end to end and finds the accounts that were never disabled. Three changes chosen from the change log rather than from the approved-change folder test whether the process is followed rather than whether the folder is tidy. The point of a sample is to be representative, and a sample handed to you by the person being audited is not.
The management clauses that fail most often
Objectives that are stated but not measured. A risk treatment plan whose actions have no dates or owners. Competence evidence for security roles that consists of a job title rather than training or experience. Monitoring and measurement that describes what will be measured without producing the measurements. And management review minutes that do not cover every input the clause lists. These fail together, because they all fail the same way: the system was designed properly and then not operated, and an internal audit that only reads documents cannot tell the difference.
Questions people ask about iso 27001 internal audit
Do we have to audit every Annex A control every year?
You have to cover the whole applicable scope across the audit programme, which does not mean every control in one audit. What auditors reject is a programme that leaves controls uncovered across an entire certification cycle with no risk-based reason.
Can our IT manager run the ISO 27001 internal audit?
Not for the areas they own. Impartiality is a requirement, and the auditor cannot audit their own work. Small organisations usually solve this by swapping auditors between functions, or by bringing in one external auditor for the technical controls.
How long does an ISO 27001 internal audit take?
Size it from the number of applicable controls, the checks per control and the records sampled per check rather than from a day count someone quoted. The internal audit template on this site turns those three figures into fieldwork hours and audit days.
What is the difference between the internal audit and the certification audit?
The internal audit is yours, run to your programme, and its findings are yours to close. The certification audit is a third party sampling the same system to decide whether to issue a certificate, and it will check that your internal audit happened and that the findings it raised were closed.