Skip to content

Running an ISO 27001 internal audit

By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 1 min read · ISO 27001

The internal audit is not a dry run you fake — it is a required control, and a real one catches the gaps before the external auditor does.

Why it is mandatory

ISO 27001 Clause 9.2 requires internal audits at planned intervals to check that the ISMS conforms to the standard and to your own requirements, and that it is effectively implemented. It is the self-check that makes the management system self-correcting — and the certification body will look for evidence it happened.

Objectivity is the rule

The one hard requirement on who audits: they must be objective and impartial — auditors cannot audit their own work. A small company can use a trained internal person auditing areas they do not own, or bring in an external auditor. What matters is independence from the thing being audited.

Make it real

A box-ticking internal audit that finds nothing tells the certification body either your ISMS is flawless (unlikely) or your audit is shallow (more likely). A useful internal audit samples real evidence, interviews people, and surfaces genuine gaps — which is far better found by you now than by the external auditor at Stage 2.

Close the loop

Internal audit findings feed corrective action (Clause 10) and the management review (Clause 9.3). Record the audit plan, the findings, and how each was resolved — that record is the evidence. SentinelPanda schedules the internal audit, tracks findings to closure, and keeps the records audit-ready.

The ISO 27001 management review Nonconformities and corrective action The ISO 27001 certification process

Run your compliance program in one workspace.