GlossaryISO 27001

Internal audit

Short answer

An internal audit is a planned, independent review that an organisation carries out on its own management system to check that it meets the requirements of a standard such as ISO 27001 and works as intended. It is mandatory before certification.

What ISO 27001 requires

Internal audits must follow a planned programme that covers the whole ISMS over time. Auditors must be objective and impartial, which means people should not audit their own work. Results are reported to management, and any nonconformities are corrected.

Before certification

Certification bodies expect at least one full internal audit and a management review to be completed before the Stage 2 certification audit. Without them, the system cannot be shown to be working.

Who carries it out

It can be done by trained staff from another area of the company or by an external auditor acting on the organisation's behalf. Small companies often use an external auditor to guarantee independence.

Why it is useful

A good internal audit finds the gaps before the certification body does, when fixing them is cheaper and has no consequences for the certificate.

Related terms

Keep reading on this topic

ISO 27001 information security management: scope, risk treatment, Annex A controls, internal audit and the certification audit process, explained.

Go to the topic hub