ISMS Internal Audit Programme & Procedure
Establishes an internal audit programme that satisfies Clause 9.2 and genuinely finds problems before the certification body does.
Available soon
- Format
- Word
- Size
- 72 KB
- Length
- 26 pages
- Version
- 1.0
- Updated
What's inside
- Purpose
- Scope
- Roles
- Triggers and inputs
- The audit programme
- Auditor independence and competence
- Procedure steps
- Grading findings
- Decision points
- Outputs and records produced
- Timing targets
- Escalation
- Evidence retained
- Worked example — the first-year programme
- Sample audit plan
- Finding record
- Related documents
- Adapting this template
- Framework references
- Definitions
Preview
The document from section 1, as you will receive it. Highlighted [[text]] is for you to replace; shaded guidance boxes are for you to delete before approval. The cover and document control pages are in the file.
Purpose
This procedure sets up and runs the internal audit of [[Organisation Name]]'s information security management system (ISMS): what is audited and how often, who may audit what, how one audit is carried out, how findings are graded, and how every nonconformity is taken to a cause removed and a check that it worked. It is written to satisfy clause 9.2 Internal audit of ISO/IEC 27001:2022, and to do something more useful: find the problems before the certification body does.
An internal audit that finds nothing has usually tested documents instead of practice. This procedure asks the auditor to choose the samples, follow real records from start to end, and report what was seen. A short list of honest findings, corrected before Stage 1, is worth more to a certification than a clean report.
Scope
This procedure applies to:
- every requirement in clauses 4 to 10 of the standard, and every Annex A control the Statement of Applicability marks as applicable, within the ISMS scope (Statement of Applicability Template);
- the organisation's own ISMS policies and procedures, which are audit criteria alongside the standard;
- every internal audit, whether carried out by staff or by a contracted auditor, and every finding it raises;
- nonconformities found in other ways — an incident, a complaint, a management review, a certification body audit — which follow the same corrective action steps (Stage 7).
It does not cover the certification body's Stage 1 and Stage 2 audits (see the Stage 1 and Stage 2 Audit Preparation Guide), or the management review itself (the Management Review Meeting Pack), although it feeds both.
Roles
Role | What they do in this procedure |
|---|---|
ISMS manager [[e.g. Head of Information Security]] | Owns the audit programme: sets it, assigns auditors, checks their independence, tracks corrective actions, and reports the programme's results to the management review. Never audits the parts of the ISMS they run or wrote (IS-07). |
Internal auditor [[independent of the area audited; internal or contracted]] | Plans and carries out each audit, grades the findings, writes the report, and checks that corrective actions worked. Independent of the area audited (IS-07). |
Control owners [[the managers who run each control]] | Are audited: send the documents asked for, answer questions, show records, agree the facts of each finding, and own the correction and corrective action for their area. |
Executive sponsor [[e.g. Chief Operating Officer]] | Approves the programme and its resources; settles a disputed grade where the ISMS manager is the auditee; is told at once of a major nonconformity. |
Top management [[e.g. Executive Committee]] | Receives the programme's results at the management review, and decides on resources and changes the results call for. |
Certification body [[an accredited certification body]] | Reviews the programme, its records and the corrective actions at Stage 1 and Stage 2. It is not part of this procedure, but it will read everything the procedure produces. |
Guidance — delete before approval
In a small organisation the ISMS manager is often the only person who knows the standard well, and the one person who may not audit most of the ISMS. Use a contracted auditor for the clauses the ISMS manager runs, and train one or two managers from other teams to audit the Annex A controls. See Adapting this template.
Triggers and inputs
When this procedure runs
Event | What starts | Steps |
|---|---|---|
Start of Phase 4 (Implement and operate) of the ISO 27001 Implementation Methodology & Project Plan | The first programme: one full cycle to be completed before Stage 2 (IS-06) | 1 to 3 |
Start of each ISMS year after certification | The year's programme: its share of the [[3]]-year cycle and the yearly areas | 1 to 3, then 4 to 22 |
An audit falls due in the programme | One audit | 4 to 14 |
An audit report, or a nonconformity found any other way | Correction and corrective action (IS-09) | 15 to 20 |
A major incident, a major nonconformity, or a significant change to the ISMS scope or a high-risk area | An extra audit of the area, added to the programme | 1, then 4 to 14 |
The last audit of a cycle, and before every management review | The programme summary | 21, 22 |
Inputs
Input | Where it comes from | Used at |
|---|---|---|
The ISMS scope and the list of applicable controls | Statement of Applicability Template; the scope document (clause 4.3 Determining the scope of the information security management system) | Steps 1, 4 |
The organisation's policies and procedures, with owners | Your policy register (Security Policy Management pack) | Steps 4, 7 |
The risk assessment results: which areas carry the highest risks | Your Information Security Risk Register (Information Security Risk Management pack) | Step 1 |
Results of previous audits, open corrective actions, incidents and changes | Previous audit reports; the ISMS Gap & Remediation Tracker; the incident log | Steps 1, 4 |
The readiness position and the certification dates | Certification Readiness Self-Assessment; ISO 27001 Implementation Methodology & Project Plan | Step 1 |
Auditor training and independence records | Step 2 of this procedure | Steps 2, 4 |
The audit programme
What is audited
The programme covers the whole ISMS: every clause from 4 to 10, and every Annex A control the Statement of Applicability marks as applicable, across the 4 themes (A.5 Organizational controls, A.6 People controls, A.7 Physical controls, A.8 Technological controls). A control excluded in the Statement of Applicability is not audited as a control, but the reason for excluding it is checked when clause 6.1.3 Information security risk treatment is audited.
Each audit takes a group of requirements that are run by the same people, so the auditor can follow one thread — for example a risk in the register, the control chosen to treat it, the procedure that runs the control, and the records that show it ran.
How often
Three rules decide the frequency:
- Before the first certification, everything once. One full cycle — every clause and every applicable control — must be completed, reported and its nonconformities in corrective action before Stage 2 (IS-06: At least one full internal audit cycle and one management review must be completed before Stage 2). Plan it to finish before Stage 1, so the certification body sees a complete programme and the management review can use its results.
- After certification, everything within a [[3]]-year cycle. Every clause and applicable control is audited at least once in each cycle, spread across the years so that each year's workload is similar. [[3 years]] matches the length of a certification cycle.
- Higher-risk areas every year. An area is audited every year when any of these applies:
- it is a blocking item — a requirement without which a Stage 2 audit cannot pass: 4.3 Determining the scope of the information security management system; 5.2 Policy; 6.1.2 Information security risk assessment; 6.1.3 Information security risk treatment; 6.2 Information security objectives and planning to achieve them; 9.2.2 Internal audit programme; 9.3.3 Management review results; 10.2 Nonconformity and corrective action;
- it treats a risk rated [[High]] or above in the Information Security Risk Register;
- it had a major nonconformity, or a significant incident, in the last 12 months;
- it changed significantly — a new system, a new supplier for a critical service, a reorganisation;
- its controls are new, or were not operating at the last audit.
The programme table, one row per area:
Area | Owner | Year 1 | Year 2 | Year 3 | Yearly? Why |
|---|---|---|---|---|---|
[[Clause or Annex A group]] | [[Role]] | [[Month]] | [[Month or —]] | [[Month or —]] | [[Yes: blocker / high risk / major finding / change — or No]] |
Guidance — delete before approval
Re-rate the frequencies after every management review: a clean area can drop back to once per cycle; an area with a major finding or an incident moves to yearly. Record why, in the last column. The certification body's surveillance audits look at the blocking items every year too, so auditing them yearly is rarely wasted.
Auditor independence and competence
Independence
IS-07: Internal auditors must not audit their own work. In practice:
- an auditor does not audit a process they run, manage, or wrote the procedure for, or a control their own team operates;
- the ISMS manager manages the programme but does not audit clauses 4 to 10, which they run; a contracted auditor or a trained manager from another part of the organisation does;
- nobody audits their own audits: the audit programme itself (clause 9.2) is audited by someone who did not carry out the audits reviewed;
- each auditor signs an independence statement for every audit (in the audit plan); a conflict found later is recorded, and the affected part is audited again by someone else.
Competence
Requirement | What it means here | Evidence kept (clause 7.2) |
|---|---|---|
Knows the standard | Has completed [[an ISO/IEC 27001 internal auditor course]], or is a qualified lead auditor | Certificate or course record |
Knows how to audit | Has shadowed at least [[1]] audit before leading one; can plan, sample, interview and write a finding that stands on its evidence | Record of the shadowed audit; the first report, reviewed |
Knows the area | Understands enough of the technology or business process to ask the right question — or audits with someone who does | Named in the audit plan |
Keeps it current | Carries out at least [[2]] audits a year, or refreshes the training every [[3]] years | Audit log; training record |
Guidance — delete before approval
For a contracted auditor, keep a copy of their qualification, their engagement letter, and a statement that they have not advised on, designed or run the parts of the ISMS they audit. A consultant who helped build the ISMS may not audit what they built.
Good auditors are curious, polite and specific. A manager from finance or engineering who asks 'show me' and waits for the record often finds more than a security specialist who already knows the answer.
Procedure steps
Every step names who does it and when. "Working days" are Monday to Friday excluding [[public holidays]]; "calendar days" include every day. The targets are collected in Timing targets, below.
Stage 1 — Set the programme
Step | What happens | Who | When | Output |
|---|---|---|---|---|
1 | List every clause 4 to 10 and every applicable Annex A control, group them into audits, and set each group's year and month using the three rules in The audit programme. Before the first certification, schedule all of them to finish before Stage 1 (IS-06). | ISMS manager | At the start of Phase 4; then at the start of each ISMS year | Draft audit programme |
2 | Assign an auditor to each audit. Check independence (IS-07) and competence; where no in-house auditor is independent of an area, arrange a contracted one. | ISMS manager | With step 1 | Auditor assignments |
3 | Approve the programme and its resources: auditors' time, any contracted auditor, and the auditees' time. | Executive sponsor | Before the first notice (step 5) | Approved programme |
Stage 2 — Plan one audit
Step | What happens | Who | When | Output |
|---|---|---|---|---|
4 | Write the audit plan (template in Sample audit plan): scope, criteria (the clauses and controls, and the organisation's own documents), auditees, dates and timetable, documents requested, and the sampling plan. Sign the independence statement. | Internal auditor | Before step 5 | Audit plan |
5 | Send the plan to the auditees and their manager; agree the dates and who will be available. | Internal auditor | At least [[10]] working days before the audit | Audit notice |
6 | Send the documents asked for: procedures, the list of records from which samples will be drawn (for example all leavers in the period), previous findings. | Control owners | At least [[5]] working days before the audit | Documents received |
Stage 3 — Review the documents
Step | What happens | Who | When | Output |
|---|---|---|---|---|
7 | Read the documents against the criteria: does what is written cover what the clause or control and our own policy require? Note what to test on site, and what records should exist if the process runs as written. Choose the samples now, from the full lists provided. | Internal auditor | Before the audit | Audit checklist and sample list |
Stage 4 — Interviews and sampling
Step | What happens | Who | When | Output |
|---|---|---|---|---|
8 | Opening meeting ([[15]] minutes): confirm scope, timetable and who will be seen; explain how findings are graded and that the facts of every finding will be agreed before the report. | Internal auditor | First morning of the audit | Attendance noted |
9 | Interview the people who run each process. Ask them to show, not describe: the record, the ticket, the screen, the signed form. | Internal auditor | During the audit | Interview notes |
10 | Test the samples. The auditor chooses them, from the whole period, not the auditee. Record each sample's reference and what it showed. Follow at least [[one]] thread end to end: a risk → its treatment → the control → the records. | Internal auditor | During the audit | Working papers |
11 | Record the evidence for every conclusion — good or bad — so that another auditor could reach the same one. | Internal auditor | During the audit | Working papers |
How many samples — a starting point, not a statistical method:
How often the activity happens | Samples to test | Example |
|---|---|---|
Once a year | [[1]] — the latest | Annual policy review; the management review |
Quarterly | [[2]] | Access reviews; supplier reassessments due in the period |
Monthly | [[2 to 3]] | Vulnerability scans; backup restore tests |
Weekly | [[5]] | Change approvals in a weekly change board |
Daily or many times a day | [[10 to 25]] | Joiners and leavers; changes; alerts triaged |
Guidance — delete before approval
If the first samples fail, take more to see whether the failure is isolated (a minor nonconformity) or systematic (a major one). If every sample passes, say so in the report: it is evidence too.
Stage 5 — Findings and closing meeting
Step | What happens | Who | When | Output |
|---|---|---|---|---|
12 | Write each finding: the requirement (clause or control number and title, or the organisation's own document), what was found, and the evidence; then grade it (Grading findings, below). Note good practice seen. | Internal auditor | Before the closing meeting | Draft findings |
13 | Closing meeting: present each finding and its grade. The auditee agrees the facts; they may dispute the grade. A disputed grade is settled by the ISMS manager — or the executive sponsor when the ISMS manager is the auditee — within [[5]] working days, and the report says so. | Internal auditor; Control owners | Last day of the audit | Findings agreed |
Stage 6 — Report
Step | What happens | Who | When | Output |
|---|---|---|---|---|
14 | Issue the audit report: scope and criteria, who was seen, the samples tested, findings with grades, good practice, and a conclusion on whether the area meets the requirements and works. Send it to the auditees, their manager and the ISMS manager. Tell the executive sponsor of any major nonconformity at once. | Internal auditor | Within [[5]] working days of the closing meeting | Audit report |
Stage 7 — Nonconformity and corrective action
IS-09: Nonconformities from audits must get a root cause, a correction, a corrective action and a check that it worked. Observations are not nonconformities: they are recorded, and considered at the management review.
Step | What happens | Who | When | Output |
|---|---|---|---|---|
15 | Correction: fix the immediate problem — the missing record, the leaver's account, the overdue review. | Control owners | Major: plan within [[10]] working days; fixed at once where possible | Correction recorded |
16 | Root cause: find why it happened, not only what. Ask 'why?' until the answer is something the organisation can change — a process step, a responsibility, a tool, a missing reminder. 'Human error' is never a root cause on its own. | Control owners with the ISMS manager | Within [[10]] working days of the report | Root cause |
17 | Corrective action: the change that removes the cause, with an owner and a date. Check whether the same cause could produce the same nonconformity elsewhere, and extend the action if so. | Control owners | Plan within [[10]] working days of the report; complete within [[30]] calendar days (major) or [[90]] calendar days (minor) of the report | Corrective action plan |
18 | Enter the finding and its actions in the ISMS Gap & Remediation Tracker (or your own corrective action log), and follow them to completion. | ISMS manager | On receipt of the plan | Tracked action |
19 | Effectiveness check: after the action has had time to work, take new samples from the period after it and confirm the cause is gone. Done by the auditor, or by someone else independent of the action. | Internal auditor | Within [[60]] calendar days of the action being complete | Effectiveness record |
20 | Close the finding if the check passes. If it does not, reopen it with a new root cause (step 16). Never close a finding on the owner's word alone. | Internal auditor | With step 19 | Closed finding |
Stage 8 — Report to management
Step | What happens | Who | When | Output |
|---|---|---|---|---|
21 | Write the programme summary: audits done against plan, findings by grade and area, repeat findings, corrective actions open and overdue, effectiveness checks passed, any independence issue, and the auditors' view of where the ISMS is weakest. It is an input to the management review. | ISMS manager | Within [[10]] working days of the cycle's last audit, and before every management review | Programme summary |
22 | Update the programme: move areas to or from yearly, add audits for new risks or changes, and record why. | ISMS manager | After each management review | Updated programme |
Grading findings
Three grades, the same for every audit:
Grade | What it means | For example |
|---|---|---|
Major nonconformity | A requirement is not met at all, or a failure is widespread or repeated enough to put in doubt whether the ISMS achieves what it is for. A certification body finding the same would normally stop or delay the certificate. | No risk treatment plan exists; no internal audit has been carried out; access reviews that the Statement of Applicability says run quarterly have not run for a year. |
Minor nonconformity | A requirement is met in part: an isolated lapse, a missing record, one sample in several that fails. The system as a whole still works. | One leaver in a sample of [[10]] kept an account for three weeks; two documents past their review date. |
Observation | No requirement is broken, but there is a weakness that could become a nonconformity, or a change that would make a control work better. Recorded, considered, not tracked as a nonconformity. | A measure just short of its own target; a manual step that depends on one person remembering. |
Guidance — delete before approval
Grade by effect, not by embarrassment. The question is whether the requirement is met and the ISMS works, not whether the gap looks bad. When in doubt between major and minor, take more samples.
Certification bodies grade their own findings with similar words. A major nonconformity at Stage 2 normally means no certificate until it is corrected and verified, so treat every internal major as a blocker.
Decision points
Decision | Who decides | Rule | Recorded in |
|---|---|---|---|
Which areas are yearly? | ISMS manager | The three frequency rules; re-rated after each management review | Audit programme |
Who may audit this area? | ISMS manager | Not their own work (IS-07); competent | Audit plan, independence statement |
Is it a finding, and which grade? | Internal auditor | Grading findings | Audit report |
Disputed grade | ISMS manager; Executive sponsor if the ISMS manager is the auditee | Evidence, within [[5]] working days | Audit report |
Is the root cause real? | Internal auditor, with the ISMS manager | Something the organisation can change; not 'human error' alone | Finding record |
Did the corrective action work? | Internal auditor | New samples after the action (IS-09) | Finding record |
Is the ISMS ready for Stage 2? | Top management | Full cycle complete; no open major; corrective actions under way (IS-06, IS-09) | Management review minutes |
Outputs and records produced
Output | Produced at step | Held in | Maintained by |
|---|---|---|---|
Audit programme, with frequencies and reasons | 1 to 3, 22 | [[ISMS document store]] | ISMS manager |
Auditor assignments, independence statements, competence evidence | 2, 4 | [[ISMS document store]]; training records | ISMS manager |
Audit plan and notice | 4, 5 | [[Audit file for the audit]] | Internal auditor |
Checklist, sample list and working papers | 7, 9 to 11 | [[Audit file for the audit]] | Internal auditor |
Audit report | 14 | [[Audit file]]; copy to the auditees | Internal auditor |
Finding records: correction, root cause, action, effectiveness | 15 to 20 | Finding record; ISMS Gap & Remediation Tracker | Control owners; Internal auditor |
Programme summary | 21 | [[ISMS document store]]; management review pack | ISMS manager |
The documented information the standard requires, which these records satisfy:
Clause | Required | Kind | Records from this procedure |
|---|---|---|---|
7.2 Competence | Evidence of competence | Record | Auditor competence evidence (step 2) |
9.2.2 Internal audit programme | Internal audit programme and audit results | Record | Audit programme, plans, reports, programme summary (steps 1 to 14, 21) |
10.2 Nonconformity and corrective action | Nonconformities, actions taken and results of corrective action | Record | Finding records with correction, root cause, action and effectiveness check (steps 15 to 20) |
Clauses 9.2.2 Internal audit programme and 10.2 Nonconformity and corrective action are both blocking items in the Certification Readiness Self-Assessment: each must reach readiness 3 (Operating) before the Stage 2 date. The first cycle's reports and finding records are what move them there.
Timing targets
Placeholders are this template's defaults; change them to fit your organisation, and keep the order: notice, documents, audit, report, response, action, check.
Activity | Target | Basis |
|---|---|---|
Audit notice and plan to the auditee | At least [[10]] working days before the audit | Step 5 |
Documents to the auditor | At least [[5]] working days before the audit | Step 6 |
Audit report | Within [[5]] working days of the closing meeting | Step 14 |
Executive sponsor told of a major nonconformity | At once, and within [[2]] working days of the closing meeting at the latest | Step 14 |
Correction, root cause and corrective action plan | Within [[10]] working days of the report | IS-09; steps 15 to 17 |
Major nonconformity: corrective action complete | Within [[30]] calendar days of the report, and before the Stage 1 date where there is one | IS-09 |
Minor nonconformity: corrective action complete | Within [[90]] calendar days of the report, and before the Stage 2 date where there is one | IS-09 |
Effectiveness check | Within [[60]] calendar days of the action being complete | IS-09; step 19 |
Programme summary | Within [[10]] working days of the cycle's last audit | Step 21 |
First full cycle complete | Before Stage 1; at the latest before Stage 2 | IS-06 |
ISM-03 Gaps overdue | Zero on the critical path | ISMS Gap & Remediation Tracker; corrective actions count as gaps |
Escalation
When | Escalated to | By | Basis |
|---|---|---|---|
Auditee cannot give dates, documents or people for an audit | ISMS manager; then Executive sponsor | Internal auditor | Steps 5, 6 |
No independent auditor is available for an area | Executive sponsor | ISMS manager | IS-07 |
A major nonconformity | Executive sponsor | Internal auditor | Step 14 |
No correction or action plan by the deadline | ISMS manager; then Executive sponsor | Internal auditor | IS-09 |
A corrective action past its date | Executive sponsor; named in the monthly readiness review and the management review | ISMS manager | IS-09; IS-10; ISM-03 |
An effectiveness check fails twice | Top management | ISMS manager | IS-09 |
The first cycle will not be complete before Stage 1 | Executive sponsor; Top management, with a proposal to move the Stage 1 date or re-plan | ISMS manager | IS-06 |
Evidence retained
Evidence | Shows | Minimum retention |
|---|---|---|
Audit programmes, with reasons for frequencies | The programme is planned and risk-based (clause 9.2.2) | [[Current cycle plus one]] |
Audit plans, independence statements, competence records | Auditors are independent and competent (IS-07, clause 7.2) | [[Current cycle plus one]] |
Working papers and sample lists | Findings rest on evidence | [[3 years]] |
Audit reports | Audits carried out and results reported (clause 9.2.2) | [[Current cycle plus one]] |
Finding records with effectiveness checks | Nonconformities corrected and causes removed (clause 10.2, IS-09) | [[3 years after closure]] |
Programme summaries | Results reported to management | [[Current cycle plus one]] |
Guidance — delete before approval
At Stage 1 the certification body typically asks for the programme, and at Stage 2 samples an audit end to end: the plan, the report, one finding, its root cause, the corrective action and the effectiveness check. Test this yourself on one finding before Stage 1.
Worked example — the first-year programme
EXAMPLE, not part of the procedure. The organisation is the one used throughout the pack: a software services company with 240 staff in two offices, an NIS2 important entity. Its ISMS scope: the design, development, hosting and support of the company's software services, from its two offices, including the cloud platform they run on. The project started on 6 Apr 2026; Stage 1 is booked for 18 Jan 2027 and Stage 2 for 1 Mar 2027. Replace every date, role and area with your own.
Auditors
Auditor | Role | Basis | May not audit |
|---|---|---|---|
AUD-A | Engineering quality lead (EXAMPLE) | In-house, trained as an ISO/IEC 27001 internal auditor [[in Oct 2026]] | A.8 Technological controls |
AUD-B | Finance systems manager (EXAMPLE) | In-house, trained as an ISO/IEC 27001 internal auditor [[in Oct 2026]] | finance systems |
AUD-C | Contracted ISO/IEC 27001 lead auditor (EXAMPLE) | External, engaged for the clauses the ISMS manager wrote or runs | Anything they advised on or designed |
Audits, November 2026 to January 2027
6 audits cover every clause from 4 to 10 except 9.3, and all 4 Annex A themes, in November and December. The seventh, in January, audits the first management review, which cannot be audited before it has happened. The main cycle finishes 6 weeks before Stage 1.
Audit | Scope | Dates | Auditor | Auditees | Why this way |
|---|---|---|---|---|---|
IA-01 | Context, leadership and planning: Clause 4 Context of the organization; Clause 5 Leadership; Clause 6 Planning | Wed, 4 Nov 2026 to Thu, 5 Nov 2026 | AUD-C | Executive sponsor (Chief Operating Officer); ISMS manager | The ISMS manager wrote the scope, the risk method and the Statement of Applicability, so an external auditor audits them. (EXAMPLE) |
IA-02 | Support and operation: Clause 7 Support; Clause 8 Operation | Wed, 11 Nov 2026 | AUD-A | HR Director; ISMS manager; risk owners | Competence and awareness records, document control, and the records that risk assessment and treatment ran as planned. (EXAMPLE) |
IA-03 | Organisational controls: A.5 Organizational controls | Tue, 17 Nov 2026 to Thu, 19 Nov 2026 | AUD-A | Control owners for A.5 (Head of IT, Head of Procurement, Head of Information Security, HR Director) | The largest theme; supplier controls are yearly because the Supplier Security Policy (P04 register SUP-001) was still awaiting approval at 30 Sept 2026. (EXAMPLE) |
IA-04 | People and physical controls, both offices: A.6 People controls; A.7 Physical controls | Wed, 25 Nov 2026 to Thu, 26 Nov 2026 | AUD-B | HR Director; office and facilities managers at each office | One day at each office: physical controls are sampled where they are. (EXAMPLE) |
IA-05 | Technological controls: A.8 Technological controls | Tue, 1 Dec 2026 to Thu, 3 Dec 2026 | AUD-B | Head of IT; IT Operations Manager; engineering leads | The auditor from engineering (AUD-A) may not audit the development controls, so the finance systems manager does, and does not sample finance systems. (EXAMPLE) |
IA-06 | Performance evaluation and improvement: Clause 9.1 Monitoring, measurement, analysis and evaluation; Clause 9.2 Internal audit; Clause 10 Improvement | Wed, 9 Dec 2026 | AUD-C | ISMS manager | The ISMS manager runs measurement, the audit programme and corrective action, so an external auditor audits them; AUD-A reviews the records of IA-01, which AUD-C carried out. (EXAMPLE) |
IA-07 | Management review and corrective action follow-up: Clause 9.3 Management review | Tue, 12 Jan 2027 | AUD-C | Executive sponsor; ISMS manager | Clause 9.3 can only be audited once the first management review has taken place (6 Jan 2027). Also checks the corrective actions from IA-01 to IA-06, and their effectiveness where they have had time to work. (EXAMPLE) |
Milestones
Date | Milestone | From |
|---|---|---|
[[by 14 Oct 2026]] | Programme, owned by the ISMS manager (Head of Information Security), and its auditors approved by the executive sponsor (Chief Operating Officer) (step 3) (EXAMPLE) | Step 3 |
21 Oct 2026 | First audit notice (IA-01), 10 working days before it (EXAMPLE) | Step 5 |
4 Nov 2026 to 9 Dec 2026 | Audits IA-01 to IA-06 (EXAMPLE) | Steps 4 to 14 |
18 Nov 2026 | F-01 corrected: the overdue reviews done and the approval route fixed (EXAMPLE) | IS-09 |
23 Dec 2026 | Programme summary, 10 working days after the last audit (EXAMPLE) | Step 21 |
6 Jan 2027 | First management review, using the programme summary (Management Review Meeting Pack) (EXAMPLE) | Clause 9.3 |
12 Jan 2027 | IA-07: the management review and corrective action progress (EXAMPLE) | Steps 4 to 14 |
18 Jan 2027 | Stage 1 audit by the certification body | Project plan |
1 Mar 2027 | Stage 2 audit by the certification body | Project plan |
What the first cycle found
The findings follow the example's readiness forecast (the one the Certification Readiness Self-Assessment and the ISMS Gap & Remediation Tracker use): at each audit, every requirement in scope that was not yet In place was raised — a minor nonconformity, or a major one for a blocking item still not In place by Stage 1. 15 minor and 0 major nonconformities, plus one observation (O-01). Each is corrected on the date the forecast puts it In place; the effectiveness check is at IA-07 where the action has had [[4]] weeks to work, otherwise within [[60]] calendar days.
Ref | Audit | Requirement | Grade | What was found | Owner | Corrected by | Effective-ness check |
|---|---|---|---|---|---|---|---|
F-01 | IA-02 | Clause 7.5.3 Control of documented information | Minor | Overdue and unapproved documents in the policy register (record below). (EXAMPLE) | Head of Information Security | 18 Nov 2026 | 12 Jan 2027 |
F-02 | IA-02 | Clause 8.3 Information security risk treatment | Minor | Treatment actions are under way but their completion and the residual risk are not recorded. (EXAMPLE) | Head of Information Security | 2 Dec 2026 | 12 Jan 2027 |
F-03 | IA-03 | Annex A 5.5 Contact with authorities | Minor | No list of which authorities to contact, when, and who may do it. (EXAMPLE) | Head of Information Security | 20 Jan 2027 | 21 Mar 2027 |
F-04 | IA-03 | Annex A 5.7 Threat intelligence | Minor | Threat information is read informally; nothing is recorded or acted on. (EXAMPLE) | Head of Information Security | 3 Feb 2027 | 4 Apr 2027 |
F-05 | IA-03 | Annex A 5.21 Managing information security in the ICT supply chain | Minor | No check of the security of the software and cloud supply chain. (EXAMPLE) | Head of Procurement | 18 Nov 2026 | 12 Jan 2027 |
F-06 | IA-03 | Annex A 5.22 Monitoring, review and change management of supplier services | Minor | Supplier performance and changes are not reviewed for security. (EXAMPLE) | Head of Procurement | 2 Dec 2026 | 12 Jan 2027 |
F-07 | IA-05 | Annex A 8.10 Information deletion | Minor | Customer data is not deleted on a set schedule after contracts end. (EXAMPLE) | IT Operations Manager | 2 Dec 2026 | 12 Jan 2027 |
F-08 | IA-05 | Annex A 8.12 Data leakage prevention | Minor | No controls to detect data leaving through email, storage or endpoints. (EXAMPLE) | Head of IT | 2 Dec 2026 | 12 Jan 2027 |
F-09 | IA-05 | Annex A 8.16 Monitoring activities | Minor | Logs are collected but not monitored for anomalies. (EXAMPLE) | Head of IT | 23 Dec 2026 | 21 Feb 2027 |
F-10 | IA-05 | Annex A 8.18 Use of privileged utility programs | Minor | Use of privileged utility programs is not restricted. (EXAMPLE) | Head of IT | 30 Dec 2026 | 28 Feb 2027 |
F-11 | IA-05 | Annex A 8.23 Web filtering | Minor | Web filtering is on in the offices only, not on remote devices. (EXAMPLE) | Head of IT | 6 Jan 2027 | 7 Mar 2027 |
F-12 | IA-05 | Annex A 8.33 Test information | Minor | No rules for selecting and protecting test data. (EXAMPLE) | Head of Engineering | 9 Dec 2026 | 12 Jan 2027 |
F-13 | IA-06 | Clause 9.1 Monitoring, measurement, analysis and evaluation | Minor | Measures are listed but not yet collected or reported; no one analyses the results. (EXAMPLE) | Head of Information Security | 23 Dec 2026 | 21 Feb 2027 |
F-14 | IA-06 | Clause 9.2.1 General | Minor | No check yet that each audit has set criteria and scope, an independent auditor and results reported to management. (EXAMPLE) | Head of Information Security | 30 Dec 2026 | 28 Feb 2027 |
F-15 | IA-06 | Clause 10.1 Continual improvement | Minor | Improvements are made but not recorded as such. (EXAMPLE) | Head of Information Security | 13 Jan 2027 | 14 Mar 2027 |
Years 2 and 3 of the 3-year cycle
After certification the example spreads the cycle over [[3]] years. The yearly areas are chosen by the frequency rules, from the example's own records as at 30 Sept 2026.
Area | Year 1 | Year 2 | Year 3 | Why |
|---|---|---|---|---|
Blocking clauses: 4.3, 5.2, 6.1.2, 6.1.3, 6.2, 9.2.2, 9.3.3, 10.2 | Yes | Yes | Yes | Blocking items; surveillance audits look at them yearly |
Other clauses 4 to 10 | Yes | Clauses 4, 5, 7 | Clauses 6.3, 8, 9.1, 10.1 | Once per cycle |
A.5.19 to A.5.23, supplier controls (from A.5.19 Information security in supplier relationships) | Yes | Yes | Yes | The Supplier Security Policy (P04 register SUP-001) was still awaiting approval at 30 Sept 2026 (EXAMPLE) |
A.8.25 to A.8.34, development controls (from A.8.25 Secure development life cycle) | Yes | Yes | Yes | The services in scope are software the company builds (EXAMPLE) |
A.8.13 Information backup | Yes | Yes | Yes | The Backup Standard (BKP-001) was past its review date at 30 Sept 2026 (EXAMPLE) |
Other A.5 organisational controls | Yes | [[A.5.1 to A.5.18]] | [[A.5.24 to A.5.37]] | Once per cycle |
A.6 people and A.7 physical controls | Yes | A.6 | A.7 | Once per cycle |
Other A.8 technological controls | Yes | [[A.8.1 to A.8.12]] | [[A.8.14 to A.8.24]] | Once per cycle |
Sample audit plan
Copy this plan for each audit. It is shown completed for audit IA-03 of the example; every entry is EXAMPLE and marked so where it is not a placeholder.
Audit plan | |||
Audit reference | [[IA-nn]] | Programme year | [[Year 1 / 2 / 3]] |
Scope clauses and controls audited | [[Clause numbers and Annex A controls, with titles]] | ||
Criteria what the area is audited against | [[ISO/IEC 27001:2022 clauses and controls above; the organisation's own documents, with references]] | ||
Auditor(s) | [[Name, role]] | Auditees | [[Names, roles]] |
Independence statement signed by each auditor | [[I have not run, managed, designed or advised on the processes and controls in this scope in the last [[12]] months. — Name, date]] | ||
Dates | [[YYYY-MM-DD to YYYY-MM-DD]] | Notice sent | [[YYYY-MM-DD]] |
Documents requested and by when | [[List; date]] | ||
Sampling plan populations and sample sizes | [[Population — sample size — period]] | ||
Timetable | [[Opening meeting; sessions by topic and person; time to prepare findings; closing meeting]] | ||
Report due | [[YYYY-MM-DD]] | Distribution | [[Auditees, their manager, ISMS manager]] |
Audit plan — IA-03 — EXAMPLE | |||
Audit reference | IA-03 | Programme year | Year 1, before certification |
Scope | A.5 Organizational controls: the controls the Statement of Applicability marks as applicable. (EXAMPLE) | ||
Criteria | ISO/IEC 27001:2022 Annex A theme A.5; the example's own documents: ISP-001 Information Security Policy; AUP-001 Acceptable Use Policy; ACP-001 Access Control Policy; INC-001 Incident Management Policy; EXC-STD Security Exception & Waiver Standard; JML-PRC Joiner, Mover, Leaver Procedure; the Supplier Security Policy (P04 register SUP-001), audited as the draft awaiting approval; and the policy register. (EXAMPLE) | ||
Auditor(s) | AUD-A, Engineering quality lead (EXAMPLE) | Auditees | Control owners for A.5 (Head of IT, Head of Procurement, Head of Information Security, HR Director) (EXAMPLE) |
Independence statement | AUD-A works in engineering and has no role in any A.5 process. Signed [[date]]. (EXAMPLE) | ||
Dates | 17 Nov 2026 to 19 Nov 2026 | Notice sent | 3 Nov 2026 |
Documents requested | The documents above; the policy register; the leaver list, access review records, supplier register, incident log and continuity plans for 18 Aug 2026 to 16 Nov 2026. By 10 Nov 2026. (EXAMPLE) | ||
Sampling plan | Policy register: all 10 documents. Leavers: [[10]] from the period. Access reviews: every quarterly review in the period. Suppliers: [[3]] of the most critical. Incidents: [[5]] from the log. Continuity: the latest test. (EXAMPLE) | ||
Timetable | Day 1: 09:00 opening; governance, roles and policies (A.5.1 to A.5.8); information and assets (A.5.9 to A.5.14). Day 2: access (A.5.15 to A.5.18); suppliers (A.5.19 to A.5.23). Day 3: incidents and continuity (A.5.24 to A.5.30); legal and compliance (A.5.31 to A.5.37); 15:00 prepare findings; 16:00 closing meeting. (EXAMPLE) | ||
Report due | 26 Nov 2026 | Distribution | Auditees; the ISMS manager; the executive sponsor (EXAMPLE) |
Finding record
One record per finding, opened by the auditor and completed by the auditee. Keep it with the audit report; it is the record clause 10.2 asks for.
Finding record | |||
Finding reference | [[F-nn or O-nn]] | Audit | [[IA-nn]] |
Grade | [[Major nonconformity / Minor nonconformity / Observation]] | Date raised | [[YYYY-MM-DD]] |
Requirement clause or control number and title, or own document | [[e.g. Annex A 5.1 Policies for information security]] | ||
What was found | [[The facts, stated so the auditee can agree them]] | ||
Evidence | [[Records, samples and interviews that support it]] | ||
Facts agreed by auditee | [[Name, date]] | Report date | [[YYYY-MM-DD]] |
Correction the immediate fix | [[What, by whom, date done]] | ||
Root cause why it happened | [[Something the organisation can change]] | ||
Same cause elsewhere? | [[Where else checked; result]] | ||
Corrective action removes the cause | [[What]] | ||
Action owner | [[Name, role]] | Due | [[YYYY-MM-DD]] |
Effectiveness check how and when | [[New samples after the action; date; result]] | ||
Closed by | [[Auditor, date]] | Outcome | [[Closed / Reopened]] |
Finding record — F-01 — EXAMPLE | |||
Finding reference | F-01 | Audit | IA-02 |
Grade | Minor nonconformity | Date raised | 11 Nov 2026 |
Requirement | Clause 7.5.3 Control of documented information | ||
What was found | 2 of the 10 documents in the policy register were past their review date — AUP-001 Acceptable Use Policy (due 1 Jul 2026) and BKP-001 Backup Standard (due 15 Aug 2026) — and the Supplier Security Policy (P04 register SUP-001) was still awaiting approval. The quarterly policy health report as at 30 Sept 2026 showed all three; none had changed on the audit date. (EXAMPLE) | ||
Evidence | Policy register extract on the audit date; quarterly policy health report; interviews with the document owners. (EXAMPLE) | ||
Facts agreed by auditee | Head of Information Security (register owner), 11 Nov 2026 (EXAMPLE) | Report date | 18 Nov 2026 |
Correction | Owners review AUP-001 and BKP-001 and record the review, even where nothing changes; the Supplier Security Policy (P04 register SUP-001) goes to its approver. By 18 Nov 2026. (EXAMPLE) | ||
Root cause | Review dates are held in the register, but nobody is told before one falls due: the quarterly report goes to management, not to the owners, and arrives after the date has passed. (EXAMPLE) | ||
Same cause elsewhere? | Every other document in the register checked: none past its date on the audit day. (EXAMPLE) | ||
Corrective action | The register owner sends each document owner a reminder [[30]] calendar days before the review date, and checks review dates monthly in the ISMS meeting. (EXAMPLE) | ||
Action owner | Head of Information Security (register owner) (EXAMPLE) | Due | 18 Nov 2026; latest 16 Feb 2027 (plan by 2 Dec 2026) |
Effectiveness check | At IA-07, 12 Jan 2027, before Stage 1: no document past its review date in the register, and the reminders sent for every review due since the action. (EXAMPLE) | ||
Closed by | [[AUD-C at IA-07, date]] | Outcome | [[Closed / Reopened]] |
The example's other finding is an observation: O-01, raised at IA-02 — policy acknowledgement coverage was 907 of 960 person-and-policy pairs (94.5%) across the 4 policies people must acknowledge, against the organisation's own target of 95%. No requirement is broken; the gap is mostly the Acceptable Use Policy, which is also past its review date (F-01). It goes to the management review, not into corrective action.
Related documents
Document | Relationship |
|---|---|
ISO 27001 Implementation Methodology & Project Plan | The project plan: Phase 5 (Check) is the first internal audit cycle and management review |
Statement of Applicability Template | The applicable controls: the scope of the Annex A audits |
Mandatory ISMS Documentation Checklist | The records this procedure produces for clauses 7.2, 9.2.2 and 10.2 |
Certification Readiness Self-Assessment | Readiness of clauses 9.2.2 and 10.2, both blocking items |
ISMS Gap & Remediation Tracker | Where corrective actions are tracked to completion (step 18) |
Management Review Meeting Pack | Receives the programme summary and the audit results (step 21) |
Stage 1 and Stage 2 Audit Preparation Guide | What the certification body will ask about the audit programme at Stage 1 and Stage 2 |
Policy Register & Review Schedule; Policy Health & Attestation Reporting Workbook | Audit criteria and document review dates; Security Policy Management pack |
Information Security Risk Register; Risk Treatment Plan | Which areas are high risk (step 1), and the thread from risk to control (step 10); Information Security Risk Management pack |
Adapting this template
Guidance — delete before approval
Small organisation: the programme can be a single page and the first cycle [[four or five]] audits of a day each. Independence is the hard part: use a contracted auditor for the clauses the ISMS manager runs, and swap auditing with a manager from another team for the controls — or with a peer from another small organisation, under a confidentiality agreement. Keep the finding records complete: they are what an auditor samples.
Regulated entity: ISO/IEC 27001:2022 is the requirement this procedure meets. If you are also subject to NIS2 or DORA, the same programme can test the measures those laws expect, and the certification body's report is useful evidence to a supervisor — but a certificate is evidence, not compliance, and a law's own audit or review duties may need a function independent of management. Agree with [[legal or compliance]] whether an internal audit function already covers ICT risk, and share one programme rather than running two.
IT run by a service provider: controls the provider runs are still in your ISMS. Audit what you can see — the contract, the provider's reports and certificates, your own monitoring of the service — and use your right to audit or the provider's assurance reports for the rest. Do not let the provider audit its own work for you (IS-07).
Delete this section before approval.
Framework references
These references show where this document supports an external framework. They indicate relevance only and do not reproduce the text of any standard. Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0.
Framework | Reference | Supported by |
|---|---|---|
ISO/IEC 27001:2022 | Clause 9.2 — Internal audit | Whole procedure |
ISO/IEC 27001:2022 | Clause 9.2.1 — General | The audit programme: what is audited; auditor independence; Stages 2 to 6 |
ISO/IEC 27001:2022 | Clause 9.2.2 — Internal audit programme | The audit programme: how often; Stage 1; Stage 8; outputs and records; worked example |
ISO/IEC 27001:2022 | Clause 10.2 — Nonconformity and corrective action | Stage 7: correction, root cause, corrective action, effectiveness check; finding record |
ISO/IEC 27001:2022 | Annex A 5.35 — Independent review of information security | Auditor independence; the audit programme as an independent review of the ISMS |
NIST CSF 2.0 | ID.IM-01 — “Improvements are identified from evaluations” | Stages 4 to 6: improvements identified from audits |
NIST CSF 2.0 | ID.IM-03 — “Improvements are identified from execution of operational processes, procedures, and activities” | Stage 7 and Stage 8: improvements from how processes actually run |
Definitions
Term | Meaning in this procedure |
|---|---|
Audit criteria | What an area is audited against: the clauses and controls in scope, and the organisation's own policies and procedures. |
Audit plan | The plan for one audit: scope, criteria, auditors, auditees, dates, documents and samples. |
Audit programme | The set of audits for a year and across the [[3]]-year cycle, with their frequency and the reasons for it. |
Auditee | The person or team whose processes and controls are audited. |
Blocking item | A requirement without which a Stage 2 audit cannot pass; the Certification Readiness Self-Assessment lists them. |
Calendar day | Every day, including weekends and public holidays. |
Correction | The immediate fix of a nonconformity, without addressing its cause. |
Corrective action | The change that removes the cause of a nonconformity so that it does not happen again. |
Effectiveness check | A later test, on new samples, that the corrective action removed the cause. |
Finding | What an audit concludes about a requirement, graded as a major or minor nonconformity or an observation. |
Independence | The auditor has not run, managed, designed or advised on what they audit (IS-07). |
ISMS | Information security management system: the policies, processes, people and records an organisation uses to manage information security risk. |
Nonconformity | A requirement not met — of the standard, or of the organisation's own ISMS documents. |
Observation | A weakness or improvement noted without a requirement being broken. |
Root cause | Why a nonconformity happened, stated as something the organisation can change. |
Stage 1 and Stage 2 | The certification body's two audits: first of readiness and documentation, then of the ISMS in operation. |
Working day | Monday to Friday, excluding [[public holidays where you are]]. |