What ISO 27001 requires
Internal audits must follow a planned programme that covers the whole ISMS over time. Auditors must be objective and impartial, which means people should not audit their own work. Results are reported to management, and any nonconformities are corrected.
Before certification
Certification bodies expect at least one full internal audit and a management review to be completed before the Stage 2 certification audit. Without them, the system cannot be shown to be working.
Who carries it out
It can be done by trained staff from another area of the company or by an external auditor acting on the organisation's behalf. Small companies often use an external auditor to guarantee independence.
Why it is useful
A good internal audit finds the gaps before the certification body does, when fixing them is cheaper and has no consequences for the certificate.




