ISO 27001 Audit, Internal Audit Plan & Template
Introduction
Clause 9.2 of ISO/IEC 27001:2022 requires the organization to conduct internal audits at planned intervals to obtain information about whether the ISMS conforms to the organization's own requirements and to those of the standard, and whether it is effectively implemented and maintained. The audit program is therefore not optional but a mandatory effectiveness check, and without a documented internal audit there is no Stage 2 sign-off from the external certification body.
This article covers:
- Structure of an annual audit plan (audit program per ISO/IEC 19011:2018)
- Selection and qualification of internal auditors, independence, competence, rotation
- Sampling methodology: what is checked at what depth?
- Evidence types (documents, interviews, observation, technical testing) and how to classify them
- Finding classification: Major / Minor Nonconformity, Observation, Opportunity for Improvement (OFI)
- The CAPA cycle (Corrective Action / Preventive Action) and its link to the management review
Intended audience: ISMS managers, internal auditors, CISOs, and executive sponsors building or overhauling an audit program. We show how the program can serve both the ISO 27001:2022 requirements and real risk management, rather than becoming a bureaucratic ritual.
Audit program and annual plan
The audit program defines what, when, by whom, and with which resources is audited. ISO 27001:2022, Clause 9.2.2 explicitly requires the program to take into account the importance of the processes concerned and the results of previous audits, that is, a risk-based approach, not a uniform round-robin.
Recommended structure for an annual audit plan:
- Full coverage over a three-year cycle: all of Clauses 4–10 and all 93 Annex A controls are audited at least once per three-year cycle.
- Annual mandatory areas: the highest-risk controls (e.g. A.5.7 Threat Intelligence, A.8.1 User Endpoint Devices, A.8.8 Vulnerability Management), Clause 9 (Performance Evaluation), Clause 10 (Improvement), every year.
- Event-driven audits: on new sites, significant IT changes, reported incidents, or external findings.
- Audit frequency by area: critical areas annually, medium risks every 18 months, low risks every 36 months.
- Timing: ideally 2–4 months before the external surveillance or recertification audit so that corrective actions have time to take effect.
The audit program is created annually by the ISMS manager, approved by senior management, and submitted to the external auditor for Stage 1 preparation. Anyone defining the program only as we audit the risks from list X without specifying clauses, sites, and methodology risks a minor nonconformity against Clause 9.2.2.
Audit team and qualification
Internal auditors must be competent and independent. Clause 9.2.2 c) requires selection of auditors and conduct of audits that ensure the objectivity and impartiality of the audit process. Concretely: no one audits their own work. A developer cannot audit their own team's development process; the ISMS manager cannot audit their own ISMS documentation set.
Competence requirements (oriented to ISO/IEC 19011:2018):
- Subject knowledge: the auditor knows the standard, the applicable legal requirements (e.g. DSG, FINMA circulars, NIS2 where the EU is involved), and the business context.
- Audit methodology: risk-based sampling, evidence evaluation, interview techniques, finding classification.
- Soft skills: listening without suggesting; reporting without interpreting; handling conflict factually.
- Training: ideally a recognized Lead Auditor course (PECB, BSI, TÜV) or equivalent training with examination. At minimum 16 hours of continuing education per year.
For SMEs without a dedicated internal-audit function we recommend co-sourcing: an external Lead Auditor (e.g. from SIDD) performs the audits with an internal employee shadowing (knowledge transfer). This preserves independence and accelerates the learning curve. Over the three-year cycle the internal person can gradually take over the lead role.
Sampling methodology and evidence types
An internal audit is a sampled examination, full review of every ticket and every access is neither possible nor purposeful. Sample size is determined by the risk class of the population, the variability, and the desired confidence.
Examples of typical sample plans:
- User access reviews (A.5.18): 10 % of active accounts or at least 30, whichever is higher.
- Change management tickets (A.8.32): 25 of 200 quarterly changes, of which at least 5 emergency changes.
- Incident tickets (A.5.24): all High / Critical incidents plus 20 % of those classified as Medium.
- Vendor contract review (A.5.19): 100 % of critical vendors (A class), 30 % of B class.
- Employee training (A.6.3): full reconciliation with HR roster, who completed the annual awareness module?
Evidence types:
- Document: policy, procedure, minutes, contract.
- Record: log, ticket, email, approval workflow.
- Statement: interview answer, written confirmation.
- Observation: on-site walk-through, live demonstration of a process.
- Technical test: configuration baseline, vulnerability scan, log analysis.
Rule of thumb: at least two independent evidence types per control. An interview alone is not enough, it requires documentary or technical confirmation. Audit reports that only quote statements invite the external auditor to ask about substance.
Finding classification
Classification of findings drives the response obligation and visibility toward the external auditor. ISO 27001 itself does not mandate a classification; ISO/IEC 19011:2018 and IAF guidance recommend the following scale:
- Major Nonconformity (NC): complete absence of a standard-required element (e.g. no internal audit performed) or systemic failure of a control (e.g. user access reviews not performed for 18 months). In external audit, a Major NC blocks certification until closure. Response deadline: typically 3 months.
- Minor Nonconformity (NC): isolated deviation or partial ineffectiveness (e.g. 2 of 30 sampled tickets without approval). Corrective action with deadline (typically 6 months); does not block certification but must be verified at surveillance.
- Observation: an observation not yet a breach but that could become one if intensified. No mandatory correction but mandatory assessment at the management review.
- Opportunity for Improvement (OFI): improvement suggestion without a deficiency. Often discussed in the closing meeting.
For internal audits we recommend the same scale as used by the external auditor, that avoids semantic gaps. Per finding the audit report should contain: factual statement (what was observed), evidence (document ID, ticket number, interview date), standard reference (clause / Annex A control), classification, and owner of the corrective action.
The CAPA cycle
Clauses 10.1 and 10.2 of ISO 27001:2022 require corrective actions for nonconformities. The CAPA cycle (Corrective Action / Preventive Action) is the formal process that turns every NC into a permanent improvement, and building it is the most frequent gap in practice.
CAPA cycle steps:
- Correction (immediate fix): the immediate action that eliminates the direct impact (e.g. disable the leaver's account immediately).
- Root cause analysis: why did the failure occur? Methods: 5 Whys, fishbone (Ishikawa), fault-tree analysis.
- Corrective action: the measure that prevents recurrence (e.g. extend the offboarding workflow with automatic deactivation).
- Preventive action: where the cause could affect other processes, extend the fix (e.g. the same workflow for vendor accounts).
- Verification: evidence of effectiveness after a reasonable period (e.g. sampling after 90 days).
- Closure: formal closure in the CAPA register with date and owner.
The CAPA register is a mandatory document in the external audit. We recommend a table with columns: NC ID, source (internal audit / external audit / incident / tip-off), description, classification, open date, due date, owner, status, verification date, closure date. An NC open for three years is a standard finding in external audit and typically Major, it shows that the ISMS has no effective improvement loop.
Audit report and management review
The audit report is the formal deliverable of the internal audit. Clause 9.2.2 e) requires reporting the results to the relevant management. Content of an audit report:
- Header: audit ID, date, auditor(s), auditees, scope (clauses, controls, areas), methodology.
- Summary: finding count by classification, key statements.
- Finding list: per finding: fact, evidence, standard reference, classification, recommendation, owner.
- Positive findings: good practices to be highlighted, important for auditee buy-in.
- Appendix: sample lists, interview notes, evidence references.
The management review (Clause 9.3) is the mandatory follow-up. At least annually, with the following mandatory inputs (Clause 9.3.2): status of actions from prior reviews, changes in external and internal issues, changes in interested-party needs, feedback on information security performance (nonconformities, audit results, monitoring, objectives), interested-party feedback, risk-assessment updates, improvement opportunities. Output (Clause 9.3.3): decisions on improvements, ISMS change needs, resource needs.
Sending the audit report to management without a documented management-review meeting with decisions does not satisfy Clause 9.3. The review minutes are mandatory evidence in the external audit.
How SIDD supports you
SIDD performs ISO 27001 internal audits for Swiss companies as co-sourcing or full mandate. Our Lead Auditors bring 10+ years of audit experience, know the expectations of the common Swiss certification bodies, and produce audit reports that feed into the Stage 2 or surveillance audit without rework. The mandate is part of our ISMS / ISO 27001 package or can be booked stand-alone.
For long-term anchoring of audit competence in-house, we train internal auditors on the job. Anyone looking for a dedicated ISMS owner benefits from our external CISO / ISB mandate, which includes audit program, CAPA steering, and management review as ongoing services. The CAPA register, audit program, and findings are maintained in the Priverion platform with deadline tracking and automatic escalation to the owner.
Schedule a first conversation via the contact form, we can give you a 30-minute reading of your current audit program. For a binding proposal, request a quote.
