Skip to main content

Free Clause 9.2 working pack

ISO 27001 internal audit checklist

Prepare an ISO 27001 internal audit with a practical working pack covering the audit programme, criteria, scope, objectivity, evidence requests, sampling, findings and corrective-action close-out. The resources are provided without an email gate and can be adapted to your own information security management system (ISMS).

4 resources · CSV and PDF · No email required

Editable working files

What is included

Working file 01

Internal-audit plan

Define the audit objective, criteria, scope, methods, responsibilities, schedule, interviewees, independence position and sampling rationale before fieldwork begins.

Working file 02

Clauses 4–10 audit checklist

Worked lines of enquiry to help plan clause-based checks and evidence requests.

Working file 03

Nonconformity and corrective-action record

Record the criterion, objective evidence, observed gap, correction, cause, corrective action, owner, due date and effectiveness verification.

Working file 04

Audit-report structure

An illustrative structure to adapt to the agreed audit scope, methods, evidence, findings and reporting requirements.

Audit workflow

How to use the working pack

  1. Step 1

    Start with the audit programme, not the checklist. Confirm which processes, locations, requirements and applicable controls need coverage in this audit and what has already been covered elsewhere in the programme.

  2. Step 2

    Define the criteria and scope before requesting evidence. A document or configuration is relevant only when it helps evaluate a defined requirement. An unstructured evidence dump makes the audit slower without making the conclusion stronger.

  3. Step 3

    Document how objectivity and impartiality are protected. Record the auditor’s prior involvement, reporting relationship, competence and any areas that must be assigned elsewhere.

  4. Step 4

    Identify the available population before selecting a sample. Retain the population source, period, selection rationale and limitations so another reviewer can understand how the evidence supports the conclusion.

  5. Step 5

    Write findings against the criterion and evidence. Avoid recommendations disguised as nonconformities, and avoid closing findings based only on management assertion.

What the checklist cannot decide for you

A fixed checklist cannot determine which Annex A controls should be sampled, how much evidence is sufficient or whether a gap constitutes a nonconformity in your engagement. Those decisions depend on the ISMS scope, Statement of Applicability, risk, audit programme, previous results and objective evidence available to the auditor.

Independent assurance

Need the audit performed independently?

Aegentra provides separately scoped ISO 27001 Clause 9.2 internal audits for an operating ISMS. The service includes documented criteria and scope, risk-based evidence sampling, traceable findings, reporting and agreed corrective-action close-out. Where Aegentra implements the ISMS, a different competent Aegentra consultant, independent of the implementation work, performs the internal audit subject to documented conflict-of-interest and impartiality checks. If independence cannot be protected, a separate provider is required. An independent accredited certification body remains responsible for certification.