Docply Browse kits
ISO 27001

ISO 27001 Internal Audit: What to Do When Nobody Is Independent

By Alessandro Stella · · 11 min read

Every guide to the ISO 27001 internal audit recites the same thing. Clause 9.2, sub-clauses a to f. Plan the programme, define the criteria, select auditors who ensure objectivity and impartiality, report to management, retain the results.

Then they all say the auditor “should not audit their own work” and stop.

That advice is correct and, for most organisations seeking certification, unusable. In a company of thirty or sixty people, the person who understands the information security management system is the person who built it. There is no second one. Telling them to find someone independent is telling them to find someone who does not exist.

This is the real problem of the ISO 27001 internal audit, and almost nothing published addresses it. This article does: three arrangements that satisfy clause 9.2 in a small organisation, the one that does not, and what an external auditor looks at when they read your internal audit report.

The three arrangements that satisfy clause 9.2 impartiality in a small organisation, and the one that does not

Need the audit programme, the report template and the coverage check as working documents? The ISO 27001 Compliance Suite includes them, with the end-of-cycle verification that every clause and every applicable control was audited at least once. €590 excl. VAT.

What clause 9.2 actually requires

Short version, because the long version is on every other page about this.

Internal audits at planned intervals, to determine whether the ISMS conforms to your own requirements and to the standard, and whether it is effectively implemented and maintained. A programme that defines frequency, methods, responsibilities and reporting, taking into account the importance of the processes and the results of previous audits. Defined criteria and scope for each audit. Auditors selected to ensure objectivity and impartiality. Results reported to relevant management. Documented information retained as evidence.

Two words in there do the work, and they are not synonyms.

Objectivity is about the evidence: the auditor examines what is actually there, not what they expect to find. Impartiality is about the person: they have no interest in the outcome.

Most published guidance treats them as one requirement and calls it independence. The standard does not use the word independence, and that matters, because independence is what a small organisation cannot have and impartiality is what it can arrange.

The three arrangements that work

Each of these satisfies clause 9.2 in an organisation without a dedicated audit function. All three are used and accepted; the choice is about cost and about which parts of the system need the most scrutiny.

1. Cross-auditing inside the organisation

Someone who does not own the process audits it. The person who runs supplier management audits access control; the person who runs access control audits incident management.

Works when: the ISMS has several owners and the organisation is large enough that ownership is genuinely split. Cheapest option, and it builds understanding across the team.

Fails when: one person owns everything. Two people who jointly built the whole system auditing each other’s halves is a formality, and it looks like one.

What to record: who audited what, and a line confirming they do not own the process audited. The confirmation is what an external auditor looks for.

2. An external auditor for part of the programme

Bring someone in for the areas where the internal knowledge concentrates — usually risk management, the Statement of Applicability, and clauses 4 to 10 — and keep the operational controls in-house.

Works when: one or two people own the governance layer. It costs a day or two of consultancy per cycle and removes the argument entirely for the parts that matter most.

Fails when: the external auditor is the same consultant who wrote your documentation. That is the same conflict wearing a different badge, and certification bodies notice.

What to record: the engagement scope, and a statement of the auditor’s independence from the design of the system.

3. Sequencing and separation of duties

The system owner prepares the audit — programme, criteria, checklists — and a different person, briefed on what to look for, performs it and records the findings.

Works when the organisation genuinely has one person with the knowledge. The knowledge is used to design the audit; the judgement about whether the evidence satisfies the criteria belongs to someone else.

Fails when the second person rubber-stamps. The test is whether they raised anything. A second auditor who has never disagreed with the person who briefed them is decorative.

What to record: who prepared, who performed, who decided each finding. Three names, or two with the roles stated.

The arrangement that does not work

One person designs the ISMS, operates it, audits it and writes the report.

This does not satisfy clause 9.2, regardless of how carefully the audit is documented, and it is the most common finding in first certification attempts at small organisations.

The reason is not procedural pedantry. It is that a person cannot audit a system against criteria they themselves chose without the criteria being the thing that needs auditing. If the control was implemented the way they decided, and the audit criterion is the way they decided, the audit can only pass.

Declaring impartiality in the report while a single name appears in every field is worse than not declaring it, because it tells the external auditor that the organisation understood the requirement and answered it with a sentence.

The audit with no findings

This is the second most common problem, and organisations are usually proud of it when they present it.

An internal audit that raised nothing means one of three things, and only one of them is good:

An experienced external auditor treats a clean internal audit report as a prompt rather than a reassurance. They will ask how many items were sampled, how they were selected, and what the criteria were. If those answers are thin, the finding moves from your ISMS to your audit process.

A useful internal target: every audit produces at least one observation. Not because problems must be manufactured, but because a system with no observable friction is a system nobody looked at closely.

Coverage across the cycle, which is the part programmes miss

Clause 9.2 requires a programme, not a series of audits. The difference is coverage.

Over the certification cycle — three years, with surveillance in between — every clause of the standard and every control applicable in your Statement of Applicability must have been audited at least once. Not every year: at least once.

Most audit programmes are built by picking topics that felt important that year. After three years the result is that access control was audited three times and supplier security never.

Build the programme as a coverage matrix. Clauses 4 to 10 down one axis, applicable Annex A controls down the other, audit dates across. At the end of the cycle, any empty row is a gap you can see before somebody else does.

This also solves the frequency question that guides answer vaguely. The standard says planned intervals and does not say annually. What it effectively requires is that the programme covers everything within the cycle and gives more attention to processes that are important or that produced findings last time.

How to plan ISO 27001 internal audit coverage across a three-year certification cycle

What the external auditor does with your internal audit

At stage 2 and at every surveillance visit, your internal audit records are examined. Not skimmed — examined, because they tell the external auditor how seriously the organisation checks itself.

Five things they look at, in roughly this order:

Who performed it, and against what. Names and criteria. This is where the impartiality question gets settled in thirty seconds.

What was sampled, and how much. A report that says “reviewed access rights” without saying how many, from which period, and on what basis they were selected has not described an audit.

The findings, and what happened to them. Open findings from the last cycle that are still open is a much worse signal than many findings that were closed.

Whether the audit found anything the external auditor also found. If they find something obvious that your internal audit passed over, the internal audit process itself becomes the issue.

Whether the results reached management. Clause 9.2 requires reporting to relevant management, and clause 9.3 makes audit results a mandatory input to management review. If the minutes do not mention them, one of the two clauses is not satisfied.

A programme that works for a small organisation

Concretely, for a company of thirty to eighty people in its first cycle:

WhenWhatWho
Before stage 2Full audit: all clauses, all applicable controls, small samplesExternal for governance, internal for operations
Year 1 surveillanceRisk, SoA, incidents, access, supplier — plus anything with findings last timeCross-audit internally
Year 2 surveillanceThe controls not covered in year 1, plus repeat of any area with recurring findingsCross-audit internally
Before recertificationFull coverage check against the matrix, then audit whatever is uncoveredMixed

Two to four days of effort per year, which is less than most organisations expect and more than most budget for.

The five mistakes that produce findings

Auditing the documents instead of the operation. Reading the procedure and confirming it exists tests nothing. The audit question is not “is there a process for X” but “show me the last four times X happened”.

No sampling method. Records selected because they were convenient are not a sample. State how you chose: every fifth, all from one month, random from the register.

Findings without owners or dates. A finding with neither is a note. Clause 10.2 expects nonconformities to be acted on, and the audit report is where the trail starts.

The programme that is one audit. A single annual sweep of everything, done in a day, covers nothing properly and satisfies the coverage requirement only on paper.

Not auditing the management system clauses. Teams audit the Annex A controls because they are concrete and skip clauses 4 to 10 because they feel abstract. Those clauses are where certification bodies raise most major nonconformities.

Frequently asked questions

Is an ISO 27001 internal audit mandatory? Yes. Clause 9.2 requires it, and a completed internal audit — with findings, not a plan for one — must exist before the stage 2 certification audit.

How often must internal audits be conducted? The standard says at planned intervals and does not set a frequency. What it requires in practice is a programme that covers every clause and every applicable control at least once per certification cycle, weighted toward processes that are important or that produced findings previously.

Can the person who implemented the ISMS conduct the internal audit? Not alone. They can prepare the audit — programme, criteria, checklists — provided somebody else performs it and decides the findings. One name in every field does not satisfy clause 9.2.

Do we have to hire an external auditor? No. Clause 9.2 asks for objectivity and impartiality, not for an external party. Cross-auditing or separation of preparation from performance both work. An external auditor for the governance layer is a common middle option.

What if the internal audit finds nothing? Examine the sample size and the criteria before celebrating. An external auditor will. A clean report from a small sample tested against loose criteria is a finding about your audit process.

Who should receive the internal audit report? Relevant management, per clause 9.2, and it must reach management review under clause 9.3 as a mandatory input. If the review minutes do not reference audit results, the trail is broken.

Does the internal audit have to cover all 93 Annex A controls? All the controls that are applicable in your Statement of Applicability, at least once across the cycle. Excluded controls are not audited, though the justification for excluding them is.

Where to go from here

The impartiality problem has a solution in almost every organisation, and it is rarely the one the guides suggest. What it requires is separating the knowledge from the judgement: use the person who understands the system to design the audit, and someone else to decide whether the evidence meets the criteria.

Record all three roles — prepared by, performed by, decided by — and the question that consumes most of the discussion answers itself on the first page of the report.

The ISO 27001 Compliance Suite contains the audit programme and report as a single working document, with the coverage matrix across the cycle and the three impartiality arrangements written into the procedure rather than left to interpretation. 43 files, €590 excl. VAT.

If you are assembling the wider set, what ISO 27001 actually requires you to document and retain separates the seven documents from the eight records — and the audit programme and results are among the records, which is why they cannot be bought. The Statement of Applicability is what defines the control side of your audit scope, the documentation set as a whole covers the rest, and what all of this costs — including the internal audit itself, outsourced or not — is broken down separately.