Independent thinking. Informed defence.

CISO Times

Intelligence for the people behind the defence.

The CISO Decision Brief

ISMS Internal Audit Programme & Procedure

Establishes an internal audit programme that satisfies Clause 9.2 and genuinely finds problems before the certification body does.

Available soon

Format
Word
Size
72 KB
Length
26 pages
Version
1.0
Updated

What's inside

  • Purpose
  • Scope
  • Roles
  • Triggers and inputs
  • The audit programme
  • Auditor independence and competence
  • Procedure steps
  • Grading findings
  • Decision points
  • Outputs and records produced
  • Timing targets
  • Escalation
  • Evidence retained
  • Worked example — the first-year programme
  • Sample audit plan
  • Finding record
  • Related documents
  • Adapting this template
  • Framework references
  • Definitions

Preview

The document from section 1, as you will receive it. Highlighted [[text]] is for you to replace; shaded guidance boxes are for you to delete before approval. The cover and document control pages are in the file.

Purpose

This procedure sets up and runs the internal audit of [[Organisation Name]]'s information security management system (ISMS): what is audited and how often, who may audit what, how one audit is carried out, how findings are graded, and how every nonconformity is taken to a cause removed and a check that it worked. It is written to satisfy clause 9.2 Internal audit of ISO/IEC 27001:2022, and to do something more useful: find the problems before the certification body does.

An internal audit that finds nothing has usually tested documents instead of practice. This procedure asks the auditor to choose the samples, follow real records from start to end, and report what was seen. A short list of honest findings, corrected before Stage 1, is worth more to a certification than a clean report.

Scope

This procedure applies to:

  • every requirement in clauses 4 to 10 of the standard, and every Annex A control the Statement of Applicability marks as applicable, within the ISMS scope (Statement of Applicability Template);
  • the organisation's own ISMS policies and procedures, which are audit criteria alongside the standard;
  • every internal audit, whether carried out by staff or by a contracted auditor, and every finding it raises;
  • nonconformities found in other ways — an incident, a complaint, a management review, a certification body audit — which follow the same corrective action steps (Stage 7).

It does not cover the certification body's Stage 1 and Stage 2 audits (see the Stage 1 and Stage 2 Audit Preparation Guide), or the management review itself (the Management Review Meeting Pack), although it feeds both.

Roles

Role

What they do in this procedure

ISMS manager

[[e.g. Head of Information Security]]

Owns the audit programme: sets it, assigns auditors, checks their independence, tracks corrective actions, and reports the programme's results to the management review. Never audits the parts of the ISMS they run or wrote (IS-07).

Internal auditor

[[independent of the area audited; internal or contracted]]

Plans and carries out each audit, grades the findings, writes the report, and checks that corrective actions worked. Independent of the area audited (IS-07).

Control owners

[[the managers who run each control]]

Are audited: send the documents asked for, answer questions, show records, agree the facts of each finding, and own the correction and corrective action for their area.

Executive sponsor

[[e.g. Chief Operating Officer]]

Approves the programme and its resources; settles a disputed grade where the ISMS manager is the auditee; is told at once of a major nonconformity.

Top management

[[e.g. Executive Committee]]

Receives the programme's results at the management review, and decides on resources and changes the results call for.

Certification body

[[an accredited certification body]]

Reviews the programme, its records and the corrective actions at Stage 1 and Stage 2. It is not part of this procedure, but it will read everything the procedure produces.

Guidance — delete before approval

In a small organisation the ISMS manager is often the only person who knows the standard well, and the one person who may not audit most of the ISMS. Use a contracted auditor for the clauses the ISMS manager runs, and train one or two managers from other teams to audit the Annex A controls. See Adapting this template.

Triggers and inputs

When this procedure runs

Event

What starts

Steps

Start of Phase 4 (Implement and operate) of the ISO 27001 Implementation Methodology & Project Plan

The first programme: one full cycle to be completed before Stage 2 (IS-06)

1 to 3

Start of each ISMS year after certification

The year's programme: its share of the [[3]]-year cycle and the yearly areas

1 to 3, then 4 to 22

An audit falls due in the programme

One audit

4 to 14

An audit report, or a nonconformity found any other way

Correction and corrective action (IS-09)

15 to 20

A major incident, a major nonconformity, or a significant change to the ISMS scope or a high-risk area

An extra audit of the area, added to the programme

1, then 4 to 14

The last audit of a cycle, and before every management review

The programme summary

21, 22

Inputs

Input

Where it comes from

Used at

The ISMS scope and the list of applicable controls

Statement of Applicability Template; the scope document (clause 4.3 Determining the scope of the information security management system)

Steps 1, 4

The organisation's policies and procedures, with owners

Your policy register (Security Policy Management pack)

Steps 4, 7

The risk assessment results: which areas carry the highest risks

Your Information Security Risk Register (Information Security Risk Management pack)

Step 1

Results of previous audits, open corrective actions, incidents and changes

Previous audit reports; the ISMS Gap & Remediation Tracker; the incident log

Steps 1, 4

The readiness position and the certification dates

Certification Readiness Self-Assessment; ISO 27001 Implementation Methodology & Project Plan

Step 1

Auditor training and independence records

Step 2 of this procedure

Steps 2, 4

The audit programme

What is audited

The programme covers the whole ISMS: every clause from 4 to 10, and every Annex A control the Statement of Applicability marks as applicable, across the 4 themes (A.5 Organizational controls, A.6 People controls, A.7 Physical controls, A.8 Technological controls). A control excluded in the Statement of Applicability is not audited as a control, but the reason for excluding it is checked when clause 6.1.3 Information security risk treatment is audited.

Each audit takes a group of requirements that are run by the same people, so the auditor can follow one thread — for example a risk in the register, the control chosen to treat it, the procedure that runs the control, and the records that show it ran.

How often

Three rules decide the frequency:

  1. Before the first certification, everything once. One full cycle — every clause and every applicable control — must be completed, reported and its nonconformities in corrective action before Stage 2 (IS-06: At least one full internal audit cycle and one management review must be completed before Stage 2). Plan it to finish before Stage 1, so the certification body sees a complete programme and the management review can use its results.
  2. After certification, everything within a [[3]]-year cycle. Every clause and applicable control is audited at least once in each cycle, spread across the years so that each year's workload is similar. [[3 years]] matches the length of a certification cycle.
  3. Higher-risk areas every year. An area is audited every year when any of these applies:
    • it is a blocking item — a requirement without which a Stage 2 audit cannot pass: 4.3 Determining the scope of the information security management system; 5.2 Policy; 6.1.2 Information security risk assessment; 6.1.3 Information security risk treatment; 6.2 Information security objectives and planning to achieve them; 9.2.2 Internal audit programme; 9.3.3 Management review results; 10.2 Nonconformity and corrective action;
    • it treats a risk rated [[High]] or above in the Information Security Risk Register;
    • it had a major nonconformity, or a significant incident, in the last 12 months;
    • it changed significantly — a new system, a new supplier for a critical service, a reorganisation;
    • its controls are new, or were not operating at the last audit.

The programme table, one row per area:

Area

Owner

Year 1

Year 2

Year 3

Yearly? Why

[[Clause or Annex A group]]

[[Role]]

[[Month]]

[[Month or —]]

[[Month or —]]

[[Yes: blocker / high risk / major finding / change — or No]]

Guidance — delete before approval

Re-rate the frequencies after every management review: a clean area can drop back to once per cycle; an area with a major finding or an incident moves to yearly. Record why, in the last column. The certification body's surveillance audits look at the blocking items every year too, so auditing them yearly is rarely wasted.

Auditor independence and competence

Independence

IS-07: Internal auditors must not audit their own work. In practice:

  • an auditor does not audit a process they run, manage, or wrote the procedure for, or a control their own team operates;
  • the ISMS manager manages the programme but does not audit clauses 4 to 10, which they run; a contracted auditor or a trained manager from another part of the organisation does;
  • nobody audits their own audits: the audit programme itself (clause 9.2) is audited by someone who did not carry out the audits reviewed;
  • each auditor signs an independence statement for every audit (in the audit plan); a conflict found later is recorded, and the affected part is audited again by someone else.

Competence

Requirement

What it means here

Evidence kept (clause 7.2)

Knows the standard

Has completed [[an ISO/IEC 27001 internal auditor course]], or is a qualified lead auditor

Certificate or course record

Knows how to audit

Has shadowed at least [[1]] audit before leading one; can plan, sample, interview and write a finding that stands on its evidence

Record of the shadowed audit; the first report, reviewed

Knows the area

Understands enough of the technology or business process to ask the right question — or audits with someone who does

Named in the audit plan

Keeps it current

Carries out at least [[2]] audits a year, or refreshes the training every [[3]] years

Audit log; training record

Guidance — delete before approval

For a contracted auditor, keep a copy of their qualification, their engagement letter, and a statement that they have not advised on, designed or run the parts of the ISMS they audit. A consultant who helped build the ISMS may not audit what they built.

Good auditors are curious, polite and specific. A manager from finance or engineering who asks 'show me' and waits for the record often finds more than a security specialist who already knows the answer.

Procedure steps

Every step names who does it and when. "Working days" are Monday to Friday excluding [[public holidays]]; "calendar days" include every day. The targets are collected in Timing targets, below.

Stage 1 — Set the programme

Step

What happens

Who

When

Output

1

List every clause 4 to 10 and every applicable Annex A control, group them into audits, and set each group's year and month using the three rules in The audit programme. Before the first certification, schedule all of them to finish before Stage 1 (IS-06).

ISMS manager

At the start of Phase 4; then at the start of each ISMS year

Draft audit programme

2

Assign an auditor to each audit. Check independence (IS-07) and competence; where no in-house auditor is independent of an area, arrange a contracted one.

ISMS manager

With step 1

Auditor assignments

3

Approve the programme and its resources: auditors' time, any contracted auditor, and the auditees' time.

Executive sponsor

Before the first notice (step 5)

Approved programme

Stage 2 — Plan one audit

Step

What happens

Who

When

Output

4

Write the audit plan (template in Sample audit plan): scope, criteria (the clauses and controls, and the organisation's own documents), auditees, dates and timetable, documents requested, and the sampling plan. Sign the independence statement.

Internal auditor

Before step 5

Audit plan

5

Send the plan to the auditees and their manager; agree the dates and who will be available.

Internal auditor

At least [[10]] working days before the audit

Audit notice

6

Send the documents asked for: procedures, the list of records from which samples will be drawn (for example all leavers in the period), previous findings.

Control owners

At least [[5]] working days before the audit

Documents received

Stage 3 — Review the documents

Step

What happens

Who

When

Output

7

Read the documents against the criteria: does what is written cover what the clause or control and our own policy require? Note what to test on site, and what records should exist if the process runs as written. Choose the samples now, from the full lists provided.

Internal auditor

Before the audit

Audit checklist and sample list

Stage 4 — Interviews and sampling

Step

What happens

Who

When

Output

8

Opening meeting ([[15]] minutes): confirm scope, timetable and who will be seen; explain how findings are graded and that the facts of every finding will be agreed before the report.

Internal auditor

First morning of the audit

Attendance noted

9

Interview the people who run each process. Ask them to show, not describe: the record, the ticket, the screen, the signed form.

Internal auditor

During the audit

Interview notes

10

Test the samples. The auditor chooses them, from the whole period, not the auditee. Record each sample's reference and what it showed. Follow at least [[one]] thread end to end: a risk → its treatment → the control → the records.

Internal auditor

During the audit

Working papers

11

Record the evidence for every conclusion — good or bad — so that another auditor could reach the same one.

Internal auditor

During the audit

Working papers

How many samples — a starting point, not a statistical method:

How often the activity happens

Samples to test

Example

Once a year

[[1]] — the latest

Annual policy review; the management review

Quarterly

[[2]]

Access reviews; supplier reassessments due in the period

Monthly

[[2 to 3]]

Vulnerability scans; backup restore tests

Weekly

[[5]]

Change approvals in a weekly change board

Daily or many times a day

[[10 to 25]]

Joiners and leavers; changes; alerts triaged

Guidance — delete before approval

If the first samples fail, take more to see whether the failure is isolated (a minor nonconformity) or systematic (a major one). If every sample passes, say so in the report: it is evidence too.

Stage 5 — Findings and closing meeting

Step

What happens

Who

When

Output

12

Write each finding: the requirement (clause or control number and title, or the organisation's own document), what was found, and the evidence; then grade it (Grading findings, below). Note good practice seen.

Internal auditor

Before the closing meeting

Draft findings

13

Closing meeting: present each finding and its grade. The auditee agrees the facts; they may dispute the grade. A disputed grade is settled by the ISMS manager — or the executive sponsor when the ISMS manager is the auditee — within [[5]] working days, and the report says so.

Internal auditor; Control owners

Last day of the audit

Findings agreed

Stage 6 — Report

Step

What happens

Who

When

Output

14

Issue the audit report: scope and criteria, who was seen, the samples tested, findings with grades, good practice, and a conclusion on whether the area meets the requirements and works. Send it to the auditees, their manager and the ISMS manager. Tell the executive sponsor of any major nonconformity at once.

Internal auditor

Within [[5]] working days of the closing meeting

Audit report

Stage 7 — Nonconformity and corrective action

IS-09: Nonconformities from audits must get a root cause, a correction, a corrective action and a check that it worked. Observations are not nonconformities: they are recorded, and considered at the management review.

Step

What happens

Who

When

Output

15

Correction: fix the immediate problem — the missing record, the leaver's account, the overdue review.

Control owners

Major: plan within [[10]] working days; fixed at once where possible

Correction recorded

16

Root cause: find why it happened, not only what. Ask 'why?' until the answer is something the organisation can change — a process step, a responsibility, a tool, a missing reminder. 'Human error' is never a root cause on its own.

Control owners with the ISMS manager

Within [[10]] working days of the report

Root cause

17

Corrective action: the change that removes the cause, with an owner and a date. Check whether the same cause could produce the same nonconformity elsewhere, and extend the action if so.

Control owners

Plan within [[10]] working days of the report; complete within [[30]] calendar days (major) or [[90]] calendar days (minor) of the report

Corrective action plan

18

Enter the finding and its actions in the ISMS Gap & Remediation Tracker (or your own corrective action log), and follow them to completion.

ISMS manager

On receipt of the plan

Tracked action

19

Effectiveness check: after the action has had time to work, take new samples from the period after it and confirm the cause is gone. Done by the auditor, or by someone else independent of the action.

Internal auditor

Within [[60]] calendar days of the action being complete

Effectiveness record

20

Close the finding if the check passes. If it does not, reopen it with a new root cause (step 16). Never close a finding on the owner's word alone.

Internal auditor

With step 19

Closed finding

Stage 8 — Report to management

Step

What happens

Who

When

Output

21

Write the programme summary: audits done against plan, findings by grade and area, repeat findings, corrective actions open and overdue, effectiveness checks passed, any independence issue, and the auditors' view of where the ISMS is weakest. It is an input to the management review.

ISMS manager

Within [[10]] working days of the cycle's last audit, and before every management review

Programme summary

22

Update the programme: move areas to or from yearly, add audits for new risks or changes, and record why.

ISMS manager

After each management review

Updated programme

Grading findings

Three grades, the same for every audit:

Grade

What it means

For example

Major nonconformity

A requirement is not met at all, or a failure is widespread or repeated enough to put in doubt whether the ISMS achieves what it is for. A certification body finding the same would normally stop or delay the certificate.

No risk treatment plan exists; no internal audit has been carried out; access reviews that the Statement of Applicability says run quarterly have not run for a year.

Minor nonconformity

A requirement is met in part: an isolated lapse, a missing record, one sample in several that fails. The system as a whole still works.

One leaver in a sample of [[10]] kept an account for three weeks; two documents past their review date.

Observation

No requirement is broken, but there is a weakness that could become a nonconformity, or a change that would make a control work better. Recorded, considered, not tracked as a nonconformity.

A measure just short of its own target; a manual step that depends on one person remembering.

Guidance — delete before approval

Grade by effect, not by embarrassment. The question is whether the requirement is met and the ISMS works, not whether the gap looks bad. When in doubt between major and minor, take more samples.

Certification bodies grade their own findings with similar words. A major nonconformity at Stage 2 normally means no certificate until it is corrected and verified, so treat every internal major as a blocker.

Decision points

Decision

Who decides

Rule

Recorded in

Which areas are yearly?

ISMS manager

The three frequency rules; re-rated after each management review

Audit programme

Who may audit this area?

ISMS manager

Not their own work (IS-07); competent

Audit plan, independence statement

Is it a finding, and which grade?

Internal auditor

Grading findings

Audit report

Disputed grade

ISMS manager; Executive sponsor if the ISMS manager is the auditee

Evidence, within [[5]] working days

Audit report

Is the root cause real?

Internal auditor, with the ISMS manager

Something the organisation can change; not 'human error' alone

Finding record

Did the corrective action work?

Internal auditor

New samples after the action (IS-09)

Finding record

Is the ISMS ready for Stage 2?

Top management

Full cycle complete; no open major; corrective actions under way (IS-06, IS-09)

Management review minutes

Outputs and records produced

Output

Produced at step

Held in

Maintained by

Audit programme, with frequencies and reasons

1 to 3, 22

[[ISMS document store]]

ISMS manager

Auditor assignments, independence statements, competence evidence

2, 4

[[ISMS document store]]; training records

ISMS manager

Audit plan and notice

4, 5

[[Audit file for the audit]]

Internal auditor

Checklist, sample list and working papers

7, 9 to 11

[[Audit file for the audit]]

Internal auditor

Audit report

14

[[Audit file]]; copy to the auditees

Internal auditor

Finding records: correction, root cause, action, effectiveness

15 to 20

Finding record; ISMS Gap & Remediation Tracker

Control owners; Internal auditor

Programme summary

21

[[ISMS document store]]; management review pack

ISMS manager

The documented information the standard requires, which these records satisfy:

Clause

Required

Kind

Records from this procedure

7.2 Competence

Evidence of competence

Record

Auditor competence evidence (step 2)

9.2.2 Internal audit programme

Internal audit programme and audit results

Record

Audit programme, plans, reports, programme summary (steps 1 to 14, 21)

10.2 Nonconformity and corrective action

Nonconformities, actions taken and results of corrective action

Record

Finding records with correction, root cause, action and effectiveness check (steps 15 to 20)

Clauses 9.2.2 Internal audit programme and 10.2 Nonconformity and corrective action are both blocking items in the Certification Readiness Self-Assessment: each must reach readiness 3 (Operating) before the Stage 2 date. The first cycle's reports and finding records are what move them there.

Timing targets

Placeholders are this template's defaults; change them to fit your organisation, and keep the order: notice, documents, audit, report, response, action, check.

Activity

Target

Basis

Audit notice and plan to the auditee

At least [[10]] working days before the audit

Step 5

Documents to the auditor

At least [[5]] working days before the audit

Step 6

Audit report

Within [[5]] working days of the closing meeting

Step 14

Executive sponsor told of a major nonconformity

At once, and within [[2]] working days of the closing meeting at the latest

Step 14

Correction, root cause and corrective action plan

Within [[10]] working days of the report

IS-09; steps 15 to 17

Major nonconformity: corrective action complete

Within [[30]] calendar days of the report, and before the Stage 1 date where there is one

IS-09

Minor nonconformity: corrective action complete

Within [[90]] calendar days of the report, and before the Stage 2 date where there is one

IS-09

Effectiveness check

Within [[60]] calendar days of the action being complete

IS-09; step 19

Programme summary

Within [[10]] working days of the cycle's last audit

Step 21

First full cycle complete

Before Stage 1; at the latest before Stage 2

IS-06

ISM-03 Gaps overdue

Zero on the critical path

ISMS Gap & Remediation Tracker; corrective actions count as gaps

Escalation

When

Escalated to

By

Basis

Auditee cannot give dates, documents or people for an audit

ISMS manager; then Executive sponsor

Internal auditor

Steps 5, 6

No independent auditor is available for an area

Executive sponsor

ISMS manager

IS-07

A major nonconformity

Executive sponsor

Internal auditor

Step 14

No correction or action plan by the deadline

ISMS manager; then Executive sponsor

Internal auditor

IS-09

A corrective action past its date

Executive sponsor; named in the monthly readiness review and the management review

ISMS manager

IS-09; IS-10; ISM-03

An effectiveness check fails twice

Top management

ISMS manager

IS-09

The first cycle will not be complete before Stage 1

Executive sponsor; Top management, with a proposal to move the Stage 1 date or re-plan

ISMS manager

IS-06

Evidence retained

Evidence

Shows

Minimum retention

Audit programmes, with reasons for frequencies

The programme is planned and risk-based (clause 9.2.2)

[[Current cycle plus one]]

Audit plans, independence statements, competence records

Auditors are independent and competent (IS-07, clause 7.2)

[[Current cycle plus one]]

Working papers and sample lists

Findings rest on evidence

[[3 years]]

Audit reports

Audits carried out and results reported (clause 9.2.2)

[[Current cycle plus one]]

Finding records with effectiveness checks

Nonconformities corrected and causes removed (clause 10.2, IS-09)

[[3 years after closure]]

Programme summaries

Results reported to management

[[Current cycle plus one]]

Guidance — delete before approval

At Stage 1 the certification body typically asks for the programme, and at Stage 2 samples an audit end to end: the plan, the report, one finding, its root cause, the corrective action and the effectiveness check. Test this yourself on one finding before Stage 1.

Worked example — the first-year programme

EXAMPLE, not part of the procedure. The organisation is the one used throughout the pack: a software services company with 240 staff in two offices, an NIS2 important entity. Its ISMS scope: the design, development, hosting and support of the company's software services, from its two offices, including the cloud platform they run on. The project started on 6 Apr 2026; Stage 1 is booked for 18 Jan 2027 and Stage 2 for 1 Mar 2027. Replace every date, role and area with your own.

Auditors

Auditor

Role

Basis

May not audit

AUD-A

Engineering quality lead (EXAMPLE)

In-house, trained as an ISO/IEC 27001 internal auditor [[in Oct 2026]]

A.8 Technological controls

AUD-B

Finance systems manager (EXAMPLE)

In-house, trained as an ISO/IEC 27001 internal auditor [[in Oct 2026]]

finance systems

AUD-C

Contracted ISO/IEC 27001 lead auditor (EXAMPLE)

External, engaged for the clauses the ISMS manager wrote or runs

Anything they advised on or designed

Audits, November 2026 to January 2027

6 audits cover every clause from 4 to 10 except 9.3, and all 4 Annex A themes, in November and December. The seventh, in January, audits the first management review, which cannot be audited before it has happened. The main cycle finishes 6 weeks before Stage 1.

Audit

Scope

Dates

Auditor

Auditees

Why this way

IA-01

Context, leadership and planning: Clause 4 Context of the organization; Clause 5 Leadership; Clause 6 Planning

Wed, 4 Nov 2026 to Thu, 5 Nov 2026

AUD-C

Executive sponsor (Chief Operating Officer); ISMS manager

The ISMS manager wrote the scope, the risk method and the Statement of Applicability, so an external auditor audits them. (EXAMPLE)

IA-02

Support and operation: Clause 7 Support; Clause 8 Operation

Wed, 11 Nov 2026

AUD-A

HR Director; ISMS manager; risk owners

Competence and awareness records, document control, and the records that risk assessment and treatment ran as planned. (EXAMPLE)

IA-03

Organisational controls: A.5 Organizational controls

Tue, 17 Nov 2026 to Thu, 19 Nov 2026

AUD-A

Control owners for A.5 (Head of IT, Head of Procurement, Head of Information Security, HR Director)

The largest theme; supplier controls are yearly because the Supplier Security Policy (P04 register SUP-001) was still awaiting approval at 30 Sept 2026. (EXAMPLE)

IA-04

People and physical controls, both offices: A.6 People controls; A.7 Physical controls

Wed, 25 Nov 2026 to Thu, 26 Nov 2026

AUD-B

HR Director; office and facilities managers at each office

One day at each office: physical controls are sampled where they are. (EXAMPLE)

IA-05

Technological controls: A.8 Technological controls

Tue, 1 Dec 2026 to Thu, 3 Dec 2026

AUD-B

Head of IT; IT Operations Manager; engineering leads

The auditor from engineering (AUD-A) may not audit the development controls, so the finance systems manager does, and does not sample finance systems. (EXAMPLE)

IA-06

Performance evaluation and improvement: Clause 9.1 Monitoring, measurement, analysis and evaluation; Clause 9.2 Internal audit; Clause 10 Improvement

Wed, 9 Dec 2026

AUD-C

ISMS manager

The ISMS manager runs measurement, the audit programme and corrective action, so an external auditor audits them; AUD-A reviews the records of IA-01, which AUD-C carried out. (EXAMPLE)

IA-07

Management review and corrective action follow-up: Clause 9.3 Management review

Tue, 12 Jan 2027

AUD-C

Executive sponsor; ISMS manager

Clause 9.3 can only be audited once the first management review has taken place (6 Jan 2027). Also checks the corrective actions from IA-01 to IA-06, and their effectiveness where they have had time to work. (EXAMPLE)

Milestones

Date

Milestone

From

[[by 14 Oct 2026]]

Programme, owned by the ISMS manager (Head of Information Security), and its auditors approved by the executive sponsor (Chief Operating Officer) (step 3) (EXAMPLE)

Step 3

21 Oct 2026

First audit notice (IA-01), 10 working days before it (EXAMPLE)

Step 5

4 Nov 2026 to 9 Dec 2026

Audits IA-01 to IA-06 (EXAMPLE)

Steps 4 to 14

18 Nov 2026

F-01 corrected: the overdue reviews done and the approval route fixed (EXAMPLE)

IS-09

23 Dec 2026

Programme summary, 10 working days after the last audit (EXAMPLE)

Step 21

6 Jan 2027

First management review, using the programme summary (Management Review Meeting Pack) (EXAMPLE)

Clause 9.3

12 Jan 2027

IA-07: the management review and corrective action progress (EXAMPLE)

Steps 4 to 14

18 Jan 2027

Stage 1 audit by the certification body

Project plan

1 Mar 2027

Stage 2 audit by the certification body

Project plan

What the first cycle found

The findings follow the example's readiness forecast (the one the Certification Readiness Self-Assessment and the ISMS Gap & Remediation Tracker use): at each audit, every requirement in scope that was not yet In place was raised — a minor nonconformity, or a major one for a blocking item still not In place by Stage 1. 15 minor and 0 major nonconformities, plus one observation (O-01). Each is corrected on the date the forecast puts it In place; the effectiveness check is at IA-07 where the action has had [[4]] weeks to work, otherwise within [[60]] calendar days.

Ref

Audit

Requirement

Grade

What was found

Owner

Corrected by

Effective-ness check

F-01

IA-02

Clause 7.5.3 Control of documented information

Minor

Overdue and unapproved documents in the policy register (record below). (EXAMPLE)

Head of Information Security

18 Nov 2026

12 Jan 2027

F-02

IA-02

Clause 8.3 Information security risk treatment

Minor

Treatment actions are under way but their completion and the residual risk are not recorded. (EXAMPLE)

Head of Information Security

2 Dec 2026

12 Jan 2027

F-03

IA-03

Annex A 5.5 Contact with authorities

Minor

No list of which authorities to contact, when, and who may do it. (EXAMPLE)

Head of Information Security

20 Jan 2027

21 Mar 2027

F-04

IA-03

Annex A 5.7 Threat intelligence

Minor

Threat information is read informally; nothing is recorded or acted on. (EXAMPLE)

Head of Information Security

3 Feb 2027

4 Apr 2027

F-05

IA-03

Annex A 5.21 Managing information security in the ICT supply chain

Minor

No check of the security of the software and cloud supply chain. (EXAMPLE)

Head of Procurement

18 Nov 2026

12 Jan 2027

F-06

IA-03

Annex A 5.22 Monitoring, review and change management of supplier services

Minor

Supplier performance and changes are not reviewed for security. (EXAMPLE)

Head of Procurement

2 Dec 2026

12 Jan 2027

F-07

IA-05

Annex A 8.10 Information deletion

Minor

Customer data is not deleted on a set schedule after contracts end. (EXAMPLE)

IT Operations Manager

2 Dec 2026

12 Jan 2027

F-08

IA-05

Annex A 8.12 Data leakage prevention

Minor

No controls to detect data leaving through email, storage or endpoints. (EXAMPLE)

Head of IT

2 Dec 2026

12 Jan 2027

F-09

IA-05

Annex A 8.16 Monitoring activities

Minor

Logs are collected but not monitored for anomalies. (EXAMPLE)

Head of IT

23 Dec 2026

21 Feb 2027

F-10

IA-05

Annex A 8.18 Use of privileged utility programs

Minor

Use of privileged utility programs is not restricted. (EXAMPLE)

Head of IT

30 Dec 2026

28 Feb 2027

F-11

IA-05

Annex A 8.23 Web filtering

Minor

Web filtering is on in the offices only, not on remote devices. (EXAMPLE)

Head of IT

6 Jan 2027

7 Mar 2027

F-12

IA-05

Annex A 8.33 Test information

Minor

No rules for selecting and protecting test data. (EXAMPLE)

Head of Engineering

9 Dec 2026

12 Jan 2027

F-13

IA-06

Clause 9.1 Monitoring, measurement, analysis and evaluation

Minor

Measures are listed but not yet collected or reported; no one analyses the results. (EXAMPLE)

Head of Information Security

23 Dec 2026

21 Feb 2027

F-14

IA-06

Clause 9.2.1 General

Minor

No check yet that each audit has set criteria and scope, an independent auditor and results reported to management. (EXAMPLE)

Head of Information Security

30 Dec 2026

28 Feb 2027

F-15

IA-06

Clause 10.1 Continual improvement

Minor

Improvements are made but not recorded as such. (EXAMPLE)

Head of Information Security

13 Jan 2027

14 Mar 2027

Years 2 and 3 of the 3-year cycle

After certification the example spreads the cycle over [[3]] years. The yearly areas are chosen by the frequency rules, from the example's own records as at 30 Sept 2026.

Area

Year 1

Year 2

Year 3

Why

Blocking clauses: 4.3, 5.2, 6.1.2, 6.1.3, 6.2, 9.2.2, 9.3.3, 10.2

Yes

Yes

Yes

Blocking items; surveillance audits look at them yearly

Other clauses 4 to 10

Yes

Clauses 4, 5, 7

Clauses 6.3, 8, 9.1, 10.1

Once per cycle

A.5.19 to A.5.23, supplier controls (from A.5.19 Information security in supplier relationships)

Yes

Yes

Yes

The Supplier Security Policy (P04 register SUP-001) was still awaiting approval at 30 Sept 2026 (EXAMPLE)

A.8.25 to A.8.34, development controls (from A.8.25 Secure development life cycle)

Yes

Yes

Yes

The services in scope are software the company builds (EXAMPLE)

A.8.13 Information backup

Yes

Yes

Yes

The Backup Standard (BKP-001) was past its review date at 30 Sept 2026 (EXAMPLE)

Other A.5 organisational controls

Yes

[[A.5.1 to A.5.18]]

[[A.5.24 to A.5.37]]

Once per cycle

A.6 people and A.7 physical controls

Yes

A.6

A.7

Once per cycle

Other A.8 technological controls

Yes

[[A.8.1 to A.8.12]]

[[A.8.14 to A.8.24]]

Once per cycle

Sample audit plan

Copy this plan for each audit. It is shown completed for audit IA-03 of the example; every entry is EXAMPLE and marked so where it is not a placeholder.

Audit plan

Audit reference

[[IA-nn]]

Programme year

[[Year 1 / 2 / 3]]

Scope

clauses and controls audited

[[Clause numbers and Annex A controls, with titles]]

Criteria

what the area is audited against

[[ISO/IEC 27001:2022 clauses and controls above; the organisation's own documents, with references]]

Auditor(s)

[[Name, role]]

Auditees

[[Names, roles]]

Independence statement

signed by each auditor

[[I have not run, managed, designed or advised on the processes and controls in this scope in the last [[12]] months. — Name, date]]

Dates

[[YYYY-MM-DD to YYYY-MM-DD]]

Notice sent

[[YYYY-MM-DD]]

Documents requested

and by when

[[List; date]]

Sampling plan

populations and sample sizes

[[Population — sample size — period]]

Timetable

[[Opening meeting; sessions by topic and person; time to prepare findings; closing meeting]]

Report due

[[YYYY-MM-DD]]

Distribution

[[Auditees, their manager, ISMS manager]]

Audit plan — IA-03 — EXAMPLE

Audit reference

IA-03

Programme year

Year 1, before certification

Scope

A.5 Organizational controls: the controls the Statement of Applicability marks as applicable. (EXAMPLE)

Criteria

ISO/IEC 27001:2022 Annex A theme A.5; the example's own documents: ISP-001 Information Security Policy; AUP-001 Acceptable Use Policy; ACP-001 Access Control Policy; INC-001 Incident Management Policy; EXC-STD Security Exception & Waiver Standard; JML-PRC Joiner, Mover, Leaver Procedure; the Supplier Security Policy (P04 register SUP-001), audited as the draft awaiting approval; and the policy register. (EXAMPLE)

Auditor(s)

AUD-A, Engineering quality lead (EXAMPLE)

Auditees

Control owners for A.5 (Head of IT, Head of Procurement, Head of Information Security, HR Director) (EXAMPLE)

Independence statement

AUD-A works in engineering and has no role in any A.5 process. Signed [[date]]. (EXAMPLE)

Dates

17 Nov 2026 to 19 Nov 2026

Notice sent

3 Nov 2026

Documents requested

The documents above; the policy register; the leaver list, access review records, supplier register, incident log and continuity plans for 18 Aug 2026 to 16 Nov 2026. By 10 Nov 2026. (EXAMPLE)

Sampling plan

Policy register: all 10 documents. Leavers: [[10]] from the period. Access reviews: every quarterly review in the period. Suppliers: [[3]] of the most critical. Incidents: [[5]] from the log. Continuity: the latest test. (EXAMPLE)

Timetable

Day 1: 09:00 opening; governance, roles and policies (A.5.1 to A.5.8); information and assets (A.5.9 to A.5.14). Day 2: access (A.5.15 to A.5.18); suppliers (A.5.19 to A.5.23). Day 3: incidents and continuity (A.5.24 to A.5.30); legal and compliance (A.5.31 to A.5.37); 15:00 prepare findings; 16:00 closing meeting. (EXAMPLE)

Report due

26 Nov 2026

Distribution

Auditees; the ISMS manager; the executive sponsor (EXAMPLE)

Finding record

One record per finding, opened by the auditor and completed by the auditee. Keep it with the audit report; it is the record clause 10.2 asks for.

Finding record

Finding reference

[[F-nn or O-nn]]

Audit

[[IA-nn]]

Grade

[[Major nonconformity / Minor nonconformity / Observation]]

Date raised

[[YYYY-MM-DD]]

Requirement

clause or control number and title, or own document

[[e.g. Annex A 5.1 Policies for information security]]

What was found

[[The facts, stated so the auditee can agree them]]

Evidence

[[Records, samples and interviews that support it]]

Facts agreed by auditee

[[Name, date]]

Report date

[[YYYY-MM-DD]]

Correction

the immediate fix

[[What, by whom, date done]]

Root cause

why it happened

[[Something the organisation can change]]

Same cause elsewhere?

[[Where else checked; result]]

Corrective action

removes the cause

[[What]]

Action owner

[[Name, role]]

Due

[[YYYY-MM-DD]]

Effectiveness check

how and when

[[New samples after the action; date; result]]

Closed by

[[Auditor, date]]

Outcome

[[Closed / Reopened]]

Finding record — F-01 — EXAMPLE

Finding reference

F-01

Audit

IA-02

Grade

Minor nonconformity

Date raised

11 Nov 2026

Requirement

Clause 7.5.3 Control of documented information

What was found

2 of the 10 documents in the policy register were past their review date — AUP-001 Acceptable Use Policy (due 1 Jul 2026) and BKP-001 Backup Standard (due 15 Aug 2026) — and the Supplier Security Policy (P04 register SUP-001) was still awaiting approval. The quarterly policy health report as at 30 Sept 2026 showed all three; none had changed on the audit date. (EXAMPLE)

Evidence

Policy register extract on the audit date; quarterly policy health report; interviews with the document owners. (EXAMPLE)

Facts agreed by auditee

Head of Information Security (register owner), 11 Nov 2026 (EXAMPLE)

Report date

18 Nov 2026

Correction

Owners review AUP-001 and BKP-001 and record the review, even where nothing changes; the Supplier Security Policy (P04 register SUP-001) goes to its approver. By 18 Nov 2026. (EXAMPLE)

Root cause

Review dates are held in the register, but nobody is told before one falls due: the quarterly report goes to management, not to the owners, and arrives after the date has passed. (EXAMPLE)

Same cause elsewhere?

Every other document in the register checked: none past its date on the audit day. (EXAMPLE)

Corrective action

The register owner sends each document owner a reminder [[30]] calendar days before the review date, and checks review dates monthly in the ISMS meeting. (EXAMPLE)

Action owner

Head of Information Security (register owner) (EXAMPLE)

Due

18 Nov 2026; latest 16 Feb 2027 (plan by 2 Dec 2026)

Effectiveness check

At IA-07, 12 Jan 2027, before Stage 1: no document past its review date in the register, and the reminders sent for every review due since the action. (EXAMPLE)

Closed by

[[AUD-C at IA-07, date]]

Outcome

[[Closed / Reopened]]

The example's other finding is an observation: O-01, raised at IA-02 — policy acknowledgement coverage was 907 of 960 person-and-policy pairs (94.5%) across the 4 policies people must acknowledge, against the organisation's own target of 95%. No requirement is broken; the gap is mostly the Acceptable Use Policy, which is also past its review date (F-01). It goes to the management review, not into corrective action.

Related documents

Document

Relationship

ISO 27001 Implementation Methodology & Project Plan

The project plan: Phase 5 (Check) is the first internal audit cycle and management review

Statement of Applicability Template

The applicable controls: the scope of the Annex A audits

Mandatory ISMS Documentation Checklist

The records this procedure produces for clauses 7.2, 9.2.2 and 10.2

Certification Readiness Self-Assessment

Readiness of clauses 9.2.2 and 10.2, both blocking items

ISMS Gap & Remediation Tracker

Where corrective actions are tracked to completion (step 18)

Management Review Meeting Pack

Receives the programme summary and the audit results (step 21)

Stage 1 and Stage 2 Audit Preparation Guide

What the certification body will ask about the audit programme at Stage 1 and Stage 2

Policy Register & Review Schedule; Policy Health & Attestation Reporting Workbook

Audit criteria and document review dates; Security Policy Management pack

Information Security Risk Register; Risk Treatment Plan

Which areas are high risk (step 1), and the thread from risk to control (step 10); Information Security Risk Management pack

Adapting this template

Guidance — delete before approval

Small organisation: the programme can be a single page and the first cycle [[four or five]] audits of a day each. Independence is the hard part: use a contracted auditor for the clauses the ISMS manager runs, and swap auditing with a manager from another team for the controls — or with a peer from another small organisation, under a confidentiality agreement. Keep the finding records complete: they are what an auditor samples.

Regulated entity: ISO/IEC 27001:2022 is the requirement this procedure meets. If you are also subject to NIS2 or DORA, the same programme can test the measures those laws expect, and the certification body's report is useful evidence to a supervisor — but a certificate is evidence, not compliance, and a law's own audit or review duties may need a function independent of management. Agree with [[legal or compliance]] whether an internal audit function already covers ICT risk, and share one programme rather than running two.

IT run by a service provider: controls the provider runs are still in your ISMS. Audit what you can see — the contract, the provider's reports and certificates, your own monitoring of the service — and use your right to audit or the provider's assurance reports for the rest. Do not let the provider audit its own work for you (IS-07).

Delete this section before approval.

Framework references

These references show where this document supports an external framework. They indicate relevance only and do not reproduce the text of any standard. Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0.

Framework

Reference

Supported by

ISO/IEC 27001:2022

Clause 9.2 — Internal audit

Whole procedure

ISO/IEC 27001:2022

Clause 9.2.1 — General

The audit programme: what is audited; auditor independence; Stages 2 to 6

ISO/IEC 27001:2022

Clause 9.2.2 — Internal audit programme

The audit programme: how often; Stage 1; Stage 8; outputs and records; worked example

ISO/IEC 27001:2022

Clause 10.2 — Nonconformity and corrective action

Stage 7: correction, root cause, corrective action, effectiveness check; finding record

ISO/IEC 27001:2022

Annex A 5.35 — Independent review of information security

Auditor independence; the audit programme as an independent review of the ISMS

NIST CSF 2.0

ID.IM-01 — “Improvements are identified from evaluations”

Stages 4 to 6: improvements identified from audits

NIST CSF 2.0

ID.IM-03 — “Improvements are identified from execution of operational processes, procedures, and activities”

Stage 7 and Stage 8: improvements from how processes actually run

Definitions

Term

Meaning in this procedure

Audit criteria

What an area is audited against: the clauses and controls in scope, and the organisation's own policies and procedures.

Audit plan

The plan for one audit: scope, criteria, auditors, auditees, dates, documents and samples.

Audit programme

The set of audits for a year and across the [[3]]-year cycle, with their frequency and the reasons for it.

Auditee

The person or team whose processes and controls are audited.

Blocking item

A requirement without which a Stage 2 audit cannot pass; the Certification Readiness Self-Assessment lists them.

Calendar day

Every day, including weekends and public holidays.

Correction

The immediate fix of a nonconformity, without addressing its cause.

Corrective action

The change that removes the cause of a nonconformity so that it does not happen again.

Effectiveness check

A later test, on new samples, that the corrective action removed the cause.

Finding

What an audit concludes about a requirement, graded as a major or minor nonconformity or an observation.

Independence

The auditor has not run, managed, designed or advised on what they audit (IS-07).

ISMS

Information security management system: the policies, processes, people and records an organisation uses to manage information security risk.

Nonconformity

A requirement not met — of the standard, or of the organisation's own ISMS documents.

Observation

A weakness or improvement noted without a requirement being broken.

Root cause

Why a nonconformity happened, stated as something the organisation can change.

Stage 1 and Stage 2

The certification body's two audits: first of readiness and documentation, then of the ISMS in operation.

Working day

Monday to Friday, excluding [[public holidays where you are]].