Skip to main content

ISO 27001 internal audit case study: Clause 9.2 for a small Australian technology company

By Harry Sidhu — ISO 27001 Lead Implementer · Director and Principal Consultant, Aegentra · Published 31 July 2026

Transitioning to ISO/IEC 27001 and overcoming internal audit bottlenecks — how a small Australian technology company obtained an independent Clause 9.2 audit in time to use it as evidence at its first surveillance audit.

A small Australian technology company certified to ISO/IEC 27001:2022 needed a Clause 9.2 internal audit before its first surveillance audit, and could not run one in-house without breaching the impartiality requirement. Aegentra audited all of Clauses 4 to 10 and a risk-based sample of 47 Annex A controls across 73 lines of enquiry. No nonconformities were raised. Five opportunities for improvement were recorded, the previous certification audit’s findings were verified as closed, an interim summary was issued before the surveillance audit began, and the final report followed within four business days of the closing meeting.

At a glance

MeasureResult
Nonconformities raised0
Lines of enquiry tested73
Annex A controls sampled47
Business days from closing meeting to final report4
Opportunities for improvement recorded5
Fixed fee an Aegentra internal audit starts from$2,300 + GST

The client

A small Australian technology company, certified to ISO/IEC 27001:2022, operating with a lean team and a compliance-automation platform, and approaching its first surveillance audit. The organisation is not named, and will not be — Aegentra publishes no client name without written approval on file. Everything below is therefore stated in terms of what was audited, what was found and how it was reported, which is the part a reader can actually evaluate.

Who audits a management system its own authors built?

Clause 9.2 of ISO/IEC 27001 requires internal audits conducted at planned intervals, and it requires them to be conducted by auditors who are objective and impartial with respect to what they are auditing. A small organisation cannot easily satisfy that in-house. The people who designed and operate the management system are the same people who would audit it, and they are usually the only people who understand it well enough to try.

A compliance-automation platform does not solve this. It collects evidence continuously and it will tell you a control is configured — it will not form an audit opinion, sample against an audit criterion, or satisfy an impartiality requirement that is about people rather than tooling.

There was a second constraint: timing. The audit had to be reported within a narrow window so the results were available as evidence for the certification body and as an input to management review. An internal audit report that arrives after the surveillance audit has already begun has missed the point of running one.

Our approach

  1. Fixed fee, agreed before fieldwork. The audit plan, the audit criteria and the sampling rationale were agreed and signed off before any fieldwork began. Scope was therefore not something that moved once testing was under way, and the fee did not move with it
  2. A documented two-year audit programme. Clause 9.2.2 requires a programme, not a single audit. The controls sampled in this cycle and those scheduled for the next were planned together so that the two cycles achieve full coverage across the three-year certification cycle — a point certification bodies routinely test, and one of the most common gaps in a small organisation’s internal audit file
  3. Independent audit team. Fieldwork was led by a certified ISO 27001 Lead Auditor who also holds CISA and CISM. Engagement oversight and report issue sat with a certified ISO 27001 Lead Implementer. Neither had any part in designing or operating the management system under audit, which is what Clause 9.2 means by objective and impartial
  4. Evidence obtained four ways, and indexed. Interview, inspection of documented information, examination of records and configuration, and sampling of operational records. Every item was indexed and retained in the working papers, so each conclusion in the report can be traced back to the evidence that supports it
  5. Matters tested before they were reported. Anything raised during fieldwork was put back to the organisation and tested against its evidence before it reached the report, rather than carried into the report unexamined. That is why two potential nonconformities were closed on evidence instead of being written up

The outcome

The audit covered all requirements of Clauses 4 to 10 and a risk-based sample of 47 Annex A controls, across 73 lines of enquiry. No nonconformities were identified. Five opportunities for improvement were recorded, and the previous certification audit’s findings were verified as closed.

Two matters initially raised as potential nonconformities were examined further and closed on evidence. Both were reported transparently as such, with the reasoning recorded in the working papers — rather than dropped silently, and rather than left in the report because withdrawing a finding is awkward.

An interim summary was issued before the surveillance audit began, giving the organisation a written position for its certification body on day one. The final report followed within four business days of the closing meeting.

A nil-nonconformity result reflects the state of that organisation’s management system on the day it was audited. It is an outcome, not something any auditor can promise in advance — what the engagement demonstrates is the method.

Nonconformity, opportunity for improvement, observation

The three terms are not interchangeable, and organisations routinely lose points at surveillance for recording one as another. The distinction is what a finding is measured against.

  • Nonconformity — a requirement of the standard, or of the organisation’s own management system, is not fulfilled. It must be stated against the specific requirement, evidenced, and closed through correction and corrective action with the root cause addressed.
  • Opportunity for improvement — the requirement is met, but the way it is met could be strengthened. An OFI is not a finding of failure and does not require corrective action — which is exactly why recording a real nonconformity as an OFI is the error auditors look for.
  • Observation — a matter noted during the audit that is neither a failure nor a recommendation — typically a risk emerging, or a change since the last cycle that will need attention in the next one.

In this engagement the split was five opportunities for improvement and no nonconformities, with two potential nonconformities examined and closed on evidence before the report was issued.

Why it matters

An internal audit is not a formality. Done properly it gives management real assurance, produces evidence a certification body can rely on, and surfaces improvements while there is still time to act on them. Done as a formality it produces a document that satisfies nobody: the certification body treats a self-audited report as weak evidence, management learns nothing it did not already believe, and the opportunities that a genuine sample would have surfaced stay where they are until an external auditor finds them instead.

Frequently asked questions

Can we do our own ISO 27001 internal audit?

You can, if you have someone who is genuinely independent of the part of the management system being audited. Clause 9.2.2 requires the organisation to select auditors and conduct audits in a way that ensures objectivity and impartiality of the audit process. In a small organisation the people who wrote the policies, run the risk assessment and operate the controls are usually the only people who understand them well enough to audit them — and auditing your own work is exactly what the clause rules out. Certification bodies test this. An internal audit report signed by the ISMS manager is a predictable finding.

What does an ISO 27001 internal audit cost in Australia?

An Aegentra ISO 27001 internal audit starts from $2,300 + GST as a single fixed fee, with the audit plan, criteria and sampling rationale agreed before fieldwork begins. The fee covers the fieldwork, the working papers, the report and the closing meeting.

Does an internal audit have to cover all 93 Annex A controls every year?

No. ISO/IEC 27001 requires a planned audit programme, and the programme — not any single audit — is what has to achieve coverage. A risk-based sample each cycle is normal and expected, provided the programme documents which controls are covered when, and the cycles together cover the whole scope across the certification cycle. In this engagement 47 controls were sampled in cycle one, with the remainder scheduled into cycle two.

Is a nil-nonconformity internal audit a good result?

It is a result about that organisation on that day, not a service guarantee. A nil-nonconformity outcome reflects the state of a management system at the time it was audited, and no auditor can commit to one in advance — an auditor who could would not be auditing. What an engagement can demonstrate is method: the scope tested, the evidence obtained, the reasoning recorded, and whether matters raised were examined before being reported.

How quickly is the internal audit report issued?

In this engagement an interim summary was issued before the surveillance audit began, so the organisation had a written position for its certification body on day one, and the final report followed within four business days of the closing meeting. Timing is agreed with the engagement, because the internal audit result is an input to management review and evidence for the certification body — a report that lands after the surveillance audit has limited value.

Will you name us in a case study?

Not without written approval. No client is named in this document, and none is named anywhere on this site without approval on file.

Surveillance audit coming and no independent auditor? An Aegentra ISO 27001 internal audit starts from $2,300 + GST as a single fixed fee. We also run ISO 27001 implementation, and the free ISO 27001 checklist and Annex A controls reference cover the ground an internal audit tests.