Internal-audit plan
Define the audit objective, criteria, scope, methods, responsibilities, schedule, interviewees, independence position and sampling rationale before fieldwork begins.
Free Clause 9.2 working pack
Prepare an ISO 27001 internal audit with a practical working pack covering the audit programme, criteria, scope, objectivity, evidence requests, sampling, findings and corrective-action close-out. The resources are provided without an email gate and can be adapted to your own information security management system (ISMS).
4 resources · CSV and PDF · No email required
Editable working files
Define the audit objective, criteria, scope, methods, responsibilities, schedule, interviewees, independence position and sampling rationale before fieldwork begins.
Worked lines of enquiry to help plan clause-based checks and evidence requests.
Record the criterion, objective evidence, observed gap, correction, cause, corrective action, owner, due date and effectiveness verification.
An illustrative structure to adapt to the agreed audit scope, methods, evidence, findings and reporting requirements.
Audit workflow
Start with the audit programme, not the checklist. Confirm which processes, locations, requirements and applicable controls need coverage in this audit and what has already been covered elsewhere in the programme.
Define the criteria and scope before requesting evidence. A document or configuration is relevant only when it helps evaluate a defined requirement. An unstructured evidence dump makes the audit slower without making the conclusion stronger.
Document how objectivity and impartiality are protected. Record the auditor’s prior involvement, reporting relationship, competence and any areas that must be assigned elsewhere.
Identify the available population before selecting a sample. Retain the population source, period, selection rationale and limitations so another reviewer can understand how the evidence supports the conclusion.
Write findings against the criterion and evidence. Avoid recommendations disguised as nonconformities, and avoid closing findings based only on management assertion.
A fixed checklist cannot determine which Annex A controls should be sampled, how much evidence is sufficient or whether a gap constitutes a nonconformity in your engagement. Those decisions depend on the ISMS scope, Statement of Applicability, risk, audit programme, previous results and objective evidence available to the auditor.
Independent assurance
Aegentra provides separately scoped ISO 27001 Clause 9.2 internal audits for an operating ISMS. The service includes documented criteria and scope, risk-based evidence sampling, traceable findings, reporting and agreed corrective-action close-out. Where Aegentra implements the ISMS, a different competent Aegentra consultant, independent of the implementation work, performs the internal audit subject to documented conflict-of-interest and impartiality checks. If independence cannot be protected, a separate provider is required. An independent accredited certification body remains responsible for certification.