Skip to main content

ISO/IEC 27001:2022 · Clause 9.2 · Australia-wide

ISO 27001 Internal Audit Services Australia

Independent. Evidence-led. Designed for certification-body scrutiny.

Aegentra provides ISO 27001 internal audits for Australian organisations preparing for certification, surveillance or recertification. We assess your ISMS against agreed criteria, sample operating evidence and report findings your team can act on. Audit scope, personnel, independence checks and the fixed fee are agreed before fieldwork.

From A$2,300 + GST

For smaller organisations with one clear ISMS scope and straightforward evidence access. Final fee confirmed after scope review.

Remote across Australia; onsite by arrangement. Internal audit is separate from certification.

Get the brochure by email

/ At a glance

ISO 27001 internal audit at a glance

Standard
ISO/IEC 27001:2022, including Amendment 1:2024
Coverage
Clauses 4–10 and risk-based sampling of applicable controls
Outputs
Audit plan, working papers, findings register, report and agreed close-out review
Assurance boundary
Aegentra provides internal audit; an independent accredited certification body certifies

/ Australia-wide delivery

Independent ISO 27001 internal audits across Australia

Aegentra is based in Melbourne and delivers independent ISO 27001 internal audits across all Australian states and territories. Planning, document review, interviews, technical evidence testing and closing meetings are normally completed remotely. Onsite attendance is arranged where physical controls, restricted evidence, site-specific operations or the agreed audit scope require it. Travel is quoted separately. New Zealand and wider Asia-Pacific engagements may be available by arrangement.

Delivered across Australia—all states and territories—with remote planning, evidence review, interviews and technical testing. Onsite attendance is available by arrangement where the agreed scope requires it. New Zealand and wider Asia-Pacific engagements may be available by arrangement.

Independent ISO 27001 internal-audit delivery across Australia
Delivery elementAustralia-wide approach
Discovery and planningRemote
Document and evidence reviewRemote through agreed secure channels
InterviewsMicrosoft Teams or another agreed platform
Technical evidence testingRemote where evidence access and security arrangements permit
Physical security reviewOnsite where included in scope
Opening and closing meetingsRemote or onsite
LocationsAll Australian states and territories
TravelQuoted separately where onsite attendance is required

ISO 27001 support for Sydney businesses includes remote delivery and onsite work by arrangement.

Page owner: Harry Sidhu, Director and Principal Consultant, Aegentra. Harry Sidhu holds the PECB ISO/IEC 27001 Lead Implementer credential. The assigned auditor retains responsibility for audit judgements and conclusions.

Last reviewed:

/ Delivery team and independence

Who will deliver your ISO 27001 internal audit?

The written engagement record identifies the accountable lead, assigned auditor, any specialist support and the quality-review responsibility for the engagement. The audit is accepted only after the required competence, prior involvement, conflicts and independence boundary have been checked against the proposed scope.

Credentials and experience are attributed only to the people who hold them. The proposal identifies the people assigned to the engagement and the evidence relevant to their role; it does not imply that every team member holds every qualification published by Aegentra.

Harry Sidhu, Director and Principal Consultant, holds practice accountability for the engagement. The assigned auditor retains responsibility for audit judgements and conclusions. Where Aegentra implements the ISMS, a different competent Aegentra consultant, independent of the implementation work, performs the internal audit subject to documented conflict-of-interest and impartiality checks. If independence cannot be protected, a separate provider is required.

ResponsibilityAudit accountability
Assigned roleEngagement lead and assigned auditor
How it is confirmedThe people performing those functions and their responsibilities are named in the scope and audit plan.
ResponsibilityCompetence and support
Assigned roleCompetence relevant to the agreed ISMS scope
How it is confirmedCompetence, prior involvement and any technical specialist contribution are checked before fieldwork.
ResponsibilityObjectivity and review
Assigned roleConflict check and traceability review
How it is confirmedThe auditor does not audit their own work, and review responsibility is recorded before the report is issued.

Qualified delivery matched to your scope

Our team combines implementation, audit, security-governance and technical expertise. Across their professional careers, team members have delivered 2,000+ hours of ISO, ISM and GRC audit work across 70+ organisations.

Team qualifications and credentials

Qualifications, professional credentials and formal training held across Aegentra’s delivery team.

Management systems and audit

  • ISO/IEC 27001 Lead Implementer
  • PECB ISO/IEC 27001 Lead Auditor
  • ISO/IEC 42001 Lead Auditor
  • CISA — Certified Information Systems Auditor
  • ISM Auditor

Cybersecurity and cloud

  • CISSP — Certified Information Systems Security Professional
  • CISM — Certified Information Security Manager
  • Certificate of Cloud Security Knowledge (CCSK)
  • OSCP+ — OffSec Certified Professional Plus

Service delivery and specialist training

  • ITIL Expert
  • PRINCE2
  • Mastering Generative AI for Cybersecurity Certificate
  • Essential Eight Assessment Course certificate — TAFEcyber

Further training and audit qualifications across the team include ISO/IEC 42001 Lead Implementer training, ASD ISM General and Technical audit codes, ISO/IEC 27017 and ISO/IEC 27018 audit codes, and ISO 9001 and ISO 19011 audit qualifications.

Personnel security clearance

NV1 Security Clearance

NV1 security clearance is held within the team. It is a personnel clearance, not a company accreditation or government endorsement. Any clearance requirement and the assigned consultant’s current status are confirmed for the engagement.

Credentials are held across the team and matched to assigned roles. Your proposal identifies the consultants, their responsibilities and the relevant qualification evidence before work begins.

The people assigned to your engagement—and the experience and qualification evidence relevant to their roles—are confirmed in your proposal before work begins.

Harry Sidhu, Director and Principal Consultant, holds practice accountability. The assigned auditor retains responsibility for audit judgements and conclusions.

/ How conclusions are built

What we test—and how each conclusion is supported

The audit starts with the agreed ISMS scope, ISO/IEC 27001 requirements, your own policies and commitments, and the audit programme. We select evidence using risk, process importance, change and previous results. Each conclusion is linked to the criterion tested, evidence examined and reasoning recorded in the working papers.

Sampling does not mean every record or all 93 Annex A controls are tested in every audit. Coverage is determined by applicability, risk and the documented audit programme; the report states what was actually examined.

  1. Criterion
  2. Population
  3. Sample
  4. Test
  5. Conclusion
  6. Action
Coverage: clauses, applicable controls and operating evidence

The audit criteria are agreed before fieldwork. They normally include ISO/IEC 27001, the organisation’s own ISMS requirements and any additional criteria explicitly recorded in the audit plan. The audit tests both documented arrangements and whether the selected processes and controls operate in practice.

Clauses 4–10

Mandatory ISMS requirements

Context, leadership, planning, support, operation, performance evaluation and improvement are assessed against the agreed criteria.

Statement of Applicability (SoA)

Applicable Annex A controls

ISO/IEC 27001:2022 contains 93 Annex A reference controls. The Statement of Applicability records the organisation’s necessary controls and applicability decisions. The audit samples the applicable controls selected for the agreed scope using risk and the audit programme; it does not automatically inspect all 93 controls every year.

Your ISMS

Policies, procedures and commitments

The audit also tests requirements established through the organisation’s policies, procedures, contracts, objectives, risk-treatment decisions and other commitments.

Operation

Whether controls actually work

Documents alone are not sufficient. Samples connect the stated process to retained records, configuration, interviews, observation and other objective evidence.

Audit programme

Risk-based coverage over time

Frequency, scope and sampling consider process importance, information-security risk, material change and previous audit results. The programme may distribute coverage over time where that approach is planned and justified.

Improvement

Previous findings and corrective action

The audit reviews whether previous issues were corrected, causes were addressed and effectiveness was evaluated before findings were closed.

How the evidence trail is recorded

Criterion
The ISO/IEC 27001 clause, applicable control, policy, procedure, contractual requirement or other agreed criterion being tested.
Population
The complete set of relevant records, systems, transactions, people or events from which audit evidence may be selected.
Sample
The items selected using information-security risk, process importance, change, previous results, known exceptions and the documented audit programme.
Test
The interview, inspection, observation, configuration review or record tracing performed against the criterion.
Conclusion
The auditor’s reasoned determination of conformity, nonconformity or an opportunity for improvement, supported by the evidence retained.
Action
The correction, cause, corrective action, owner, due date, verification evidence and final close-out status where action is required.

The audit file should allow a competent reviewer who was not present during fieldwork to follow how the evidence led to the conclusion.

How audit samples are selected

Sampling is agreed from the ISMS scope, Statement of Applicability, information-security risk, process importance, significant change, previous audit results, known exceptions and available populations. A control is not selected merely because it is easy to demonstrate. The audit plan records why each sample was chosen, what population it came from, the evidence reviewed and the conclusion reached. The sample supports a defensible conclusion for the agreed scope; it is not a claim that every record or all 93 Annex A controls were examined.

Information-security risk

Higher-risk processes and control failures normally receive greater attention.

Process importance

Processes critical to the ISMS objectives or in-scope services affect the sample.

Significant change

New systems, major configuration changes, acquisitions, restructures and changed suppliers can increase sampling.

Previous results

Prior findings, unresolved actions and weak evidence influence the next audit.

Incidents and exceptions

Security events, approved exceptions, complaints and repeated failures may require targeted testing.

Statement of Applicability

The sample must remain connected to the organisation’s current applicability and implementation decisions.

Population quality

The size, completeness and reliability of the available population affect what can be selected and concluded.

Audit programme

The sample is considered alongside the planned coverage achieved in earlier and future audits.

What sampling does not mean

Sampling does not mean that the auditor chooses a convenient screenshot and assumes the control works. The population, selection rationale, evidence source, period and limitations should be clear enough for the conclusion to be understood and, where appropriate, reproduced.

Examples of the evidence we examine

The evidence request follows the criteria and agreed sample. It should not be an unstructured request for every document the organisation possesses.

Practical evidence sampled and the purpose of each test
AreaEvidence that may be sampledWhat the sample tests
ISMS scope and contextCurrent ISMS scope, context analysis, interested-party requirements, organisational interfaces and outsourced dependenciesWhether the documented boundary reflects the services, locations, people, systems and obligations actually managed by the ISMS
Risk assessment and treatmentRisk criteria, current risk register, assessment records, treatment plan, owner approvals and residual-risk decisionsWhether risks are assessed consistently, treatment decisions are authorised and agreed actions operate
Statement of ApplicabilityApplicability decisions, inclusion and exclusion rationale, implementation status and links to risk treatmentWhether necessary controls are accounted for and the SoA reflects the current scope and risk decisions
Identity and access managementJoiner-mover-leaver records, access requests, privileged-role assignments, periodic reviews and removal evidenceWhether access is authorised, reviewed and removed in accordance with the organisation’s own requirements
Change and vulnerability managementChange records, approvals, testing evidence, vulnerability results, remediation tickets, exceptions and closure recordsWhether changes and vulnerabilities are identified, authorised, treated and verified within the defined process
Logging and monitoringLog settings, alerts, review records, retention settings, investigations and escalation recordsWhether monitoring is configured, retained and acted on rather than only described in a policy
Incident response and resilienceIncident register, response records, exercises, backup jobs, restoration tests, lessons learned and corrective actionsWhether the organisation can respond, recover and improve using evidence from real events or exercises
Supplier securityDue diligence, contracts, security clauses, risk ratings, review records, incidents and offboarding evidenceWhether supplier risks and responsibilities are evaluated and managed throughout the relationship
Awareness and competenceRole requirements, training records, acknowledgements, awareness activities and interview responsesWhether people understand relevant security responsibilities and competence is supported by evidence
Performance and improvementObjectives, metrics, monitoring results, management-review minutes, prior findings, root-cause records and effectiveness checksWhether management evaluates the ISMS and improvement actions address causes rather than only symptoms
Worked example: a traceable access-review finding

Every finding should allow a reader who was not in the interview to follow the reasoning. It records the audit criterion, objective evidence, observed gap, conclusion, responsible owner, target date and close-out status. Advice is separated from the conformity conclusion.

Illustrative example—not client data
Criterion
The organisation’s access-control procedure requires privileged-access assignments to be reviewed at planned intervals.
Population
Eleven active privileged-role assignments in the in-scope identity platform.
Sample and evidence
The current role export, the latest scheduled review records, approval history and interviews with the access-review owner and platform administrator.
Observed evidence
Review and approval evidence was retained for eight assignments. No completed review or documented exception was available for three active assignments.
Observed gap
The organisation could not demonstrate that the full privileged-access population had been reviewed in accordance with its documented procedure.
Conclusion
Nonconformity against the organisation’s own access-review requirement.
Immediate correction
Review the three outstanding assignments and remove or approve access as appropriate.
Root cause
The review population was prepared manually and was not reconciled to the current authoritative privileged-role export.
Corrective action
Generate each review population from the authoritative export, assign a named owner, reconcile exceptions and retain approval evidence for every planned cycle.
Verification evidence
The next complete population, approval records, removed access and documented exceptions are reviewed before closure.
Close-out status
Open until follow-up evidence demonstrates that the revised review process operated effectively.

The example demonstrates structure only. The existence, classification and wording of a real finding depend on the agreed criteria, objective evidence and engagement context.

/ Completed engagement evidence

A surveillance-cycle audit supported by traceable working papers.

An Australian technology company approaching a surveillance audit needed an independent Clause 9.2 review because the people operating its ISMS could not impartially audit their own work. The engagement assessed the mandatory management-system clauses, used risk-based sampling of applicable controls and retained a traceable record for every conclusion.

73
Lines of enquiry tested
47
Applicable Annex A controls sampled
4–10
Management-system clauses assessed
0
Nonconformities reported
5
Opportunities for improvement
4 business days
Closing meeting to final report

The audit assessed Clauses 4–10, tested 73 lines of enquiry and sampled 47 applicable Annex A controls. No nonconformities were reported, five opportunities for improvement were recorded, and the final report was issued four business days after the closing meeting. Two potential nonconformities were examined further and closed on evidence before report issue.

These figures describe one completed engagement for one organisation at one point in time. They demonstrate the audit method and reporting discipline; they are not a standard audit quota, a promised result or evidence that every organisation should use the same sample.

The client name and identifying details remain withheld. The published record describes the agreed scope, method and reported outcome without presenting the result as a guarantee for another organisation.

Read the completed ISO 27001 internal audit case study

/ Scope and price

A$2,300 + GST

Starting price · fixed fee after scope review

What does an ISO 27001 internal audit cost in Australia?

An Aegentra ISO 27001 internal audit starts from A$2,300 + GST for a smaller organisation with a clear, single ISMS scope and straightforward evidence access. The final fixed fee is confirmed after reviewing the ISMS boundary, locations, business processes, technical complexity, applicable controls, previous findings, available evidence, interview requirements, sampling needs and any onsite work.

The written scope states the audit criteria, locations, interviews, evidence assumptions, fieldwork dates, reporting date, responsibilities, inclusions and any corrective-action close-out review before work begins.

Certification-body fees are separate. Travel and other onsite costs are quoted separately where attendance is required.

For implementation, certification-body fees and ongoing ownership, read the ISO 27001 certification cost guide. The worked budget keeps each responsibility and fee separate.

Seeking certification as well? Your customer’s accreditation requirements can affect which certification bodies you can choose, while scope and audit effort affect their quotes. ANAB and IAS accredit certification bodies; they are not different grades of ISO 27001. See ANAB, IAS and JASANZ: customer acceptance and certification costs.

Request a fixed audit scope

/ When to use this service

Independent assurance for an operating ISMS.

This service is designed for organisations that already operate an ISMS and need an objective, evidence-based internal audit—not for organisations that still need the management system implemented.

You implemented ISO 27001 in-house

Your team built and operates the ISMS, but the people closest to the controls cannot impartially evaluate their own work across the required scope.

Another provider implemented the ISMS

You need an audit team whose prior involvement, competence and responsibilities are checked before fieldwork begins.

Aegentra implemented the ISMS

A different competent Aegentra consultant, independent of the implementation work, performs the audit subject to documented conflict-of-interest and impartiality checks. If independence cannot be protected, a separate provider is required.

Your team cannot avoid self-review

The internal auditor has left, the organisation is small, or control ownership makes a defensible internal separation impractical.

Certification, surveillance or recertification is approaching

You need the internal-audit programme, findings and corrective actions completed early enough for management review and the certification cycle.

This is not the right engagement when:

  • You still need the ISMS designed or implemented. See ISO 27001 implementation.
  • A different competent Aegentra consultant cannot be assigned independently of the implementation work, or conflicts cannot be adequately controlled. A separate provider is then required.
  • You need Stage 1, Stage 2 or an ISO certificate. Engage an independent accredited certification body.
  • You want an individual auditor qualification. See ISO 27001 Lead Auditor training.

/ Engagement boundaries

Clear separation makes the audit easier to defend.

Aegentra does not certify

Aegentra performs the organisation’s Clause 9.2 internal audit. Stage 1, Stage 2, surveillance, recertification and the certificate remain the responsibility of an independent accredited certification body.

A different consultant performs the internal audit

Where Aegentra implements the ISMS, a different competent Aegentra consultant, independent of the implementation work, performs the internal audit subject to documented conflict-of-interest and impartiality checks. If independence cannot be protected, a separate provider is required. The auditor should not evaluate work they designed, implemented or operate.

Sampling is scoped, not generic

The audit plan follows the ISMS scope, risks, applicable controls, process importance, change and previous results. The same fixed checklist or sample is not appropriate for every organisation.

Findings are not closed by assertion

A finding is not closed because an owner says the issue has been fixed. Follow-up evidence is reviewed and the close-out record identifies what was verified, when it was verified and what remains open.

Gap assessment, internal audit and certification audit compared

A readiness or gap assessment helps identify work that may be needed. The Clause 9.2 internal audit evaluates conformity and effective implementation under the organisation’s audit programme. Stage 1 and Stage 2 are separate external assessments performed by an accredited certification body.

ISO 27001 readiness, Clause 9.2 internal audit and certification audit compared
ComparisonReadiness or gap assessmentClause 9.2 internal auditCertification audit
Primary purposeIdentify likely gaps and preparation prioritiesEvaluate conformity and whether the ISMS is effectively implemented and maintainedEvaluate the ISMS under the certification body’s accredited process and make a certification decision
StatusOptional diagnosticRequired management-system activity at planned intervalsRequired only where the organisation seeks or maintains third-party certification
Who performs itAn internal team or external adviserCompetent auditors selected so objectivity and impartiality are protectedAn independent accredited certification body
Evidence testingFlexible diagnostic reviewObjective evidence sampled against defined criteria and a documented audit programmeEvidence sampled under the certification body’s audit process
Typical outputGap list and preparation prioritiesAudit report, traceable findings and corrective-action recordAudit findings and the certification body’s decision
IndependenceMay be combined with advisory supportThe auditor should not audit their own workCertification-body independence and accreditation requirements apply
Can Aegentra provide it?Yes, as a separately scoped engagementYes, including after Aegentra implementation by a different consultant independent of that work, subject to conflict, competence and impartiality checksNo. Aegentra is not a certification body
Can it issue an ISO certificate?NoNoYes, where the certification body makes a positive decision

Aegentra provides separately scoped readiness and Clause 9.2 internal-audit services. An independent accredited certification body certifies.

/ What you receive

What you receive, from scope to close-out

Your audit file should make clear what was agreed, what was tested, what was found and which actions remain open. The written scope confirms the schedule, responsibilities and any follow-up review before work begins.

  1. 1. Agree the scope and audit plan

    Review the ISMS boundary, sites, audit programme, Statement of Applicability, previous findings and evidence-access constraints. Confirm the audit criteria, methods, responsibilities, interviews, dates and fixed fee, then issue the audit plan and evidence request.

  2. 2. Test evidence and retain working papers

    Interview control owners and test selected documents, records, configurations and operating evidence. Working papers connect each criterion to the population, sample, test and conclusion so the reasoning can be followed.

  3. 3. Report findings and conclusions

    Complete the working papers, quality review and closing meeting. The audit report and findings register identify the scope and sample examined, evidence supporting each finding and the actions requiring management attention.

  4. 4. Review agreed corrective actions

    Where close-out review is included, examine the correction, cause, corrective action and effectiveness evidence. Record owners, dates and whether each action has been verified as closed or remains open. Follow-up review does not mean unlimited remediation or a guaranteed audit outcome.

The report states the scope and sample actually completed. It is not a generic declaration that every record or control was examined.

/ Delivery method

Remote-first does not mean evidence-light.

Most document review, interviews and cloud-control testing can be completed remotely. Onsite work is considered where physical security, restricted evidence, operational processes or site-specific controls cannot be evaluated adequately through remote methods. The delivery mode and travel assumptions are recorded in scope rather than added after fieldwork starts.

Remote methods are normally suitable for:

  • ISMS documents and records
  • Risk, SoA and corrective-action review
  • Control-owner interviews
  • Microsoft 365 and other cloud evidence
  • Tickets, logs, exports and approvals
  • Opening, progress and closing meetings

Onsite methods may be appropriate for:

  • Physical access and environmental controls
  • Restricted evidence that cannot be shared remotely
  • Observation of site-specific operations
  • Secure facilities and controlled areas
  • Processes whose operation cannot be established adequately through remote evidence

A hybrid engagement may combine remote planning and evidence review with targeted onsite testing. Onsite requirements and travel costs are agreed before fieldwork.

/ Methodology references

Audit criteria first. Method second.

ISO 19011:2026 is the current international guidance for auditing management systems. It addresses auditing principles, audit-programme management, conducting management-system audits and auditor competence. The engagement plan records the criteria, scope, methods, responsibilities, sampling approach and reporting arrangements for the audit.

ISO/IEC TS 17012:2024 provides additional guidance on the conditions, possibilities and limitations associated with remote management-system auditing. Where remote methods are used, the audit plan considers whether the available technology, evidence access, confidentiality arrangements and site conditions allow the audit objective to be achieved.

These documents guide audit practice. They do not replace ISO/IEC 27001, the organisation’s own requirements or any other criteria explicitly recorded in the audit plan, and they do not create a separate certification.

/ Supported technical evidence

Technical evidence supported by Aeges. Audit judgement retained by people.

Where the agreed scope includes supported Microsoft 365 evidence, Aeges can help organise current configuration evidence and maintain traceability between requirements, working papers and findings. It does not determine conformity, grade the ISMS, issue findings or approve the audit report.

The assigned auditor defines the criteria, selects samples, conducts interviews, evaluates context, reaches conclusions and approves the report. Policies, people, physical controls, supplier records and non-Microsoft systems require other evidence.

Microsoft 365 evidence may include

  • Microsoft Entra ID role assignments, sign-in records, access reviews and Conditional Access or MFA configuration
  • Microsoft Intune device-compliance records and relevant Defender, Sentinel or other security alerts where used
  • Microsoft 365 audit, Exchange and SharePoint settings or exports supporting the control being tested
  • Related tickets, approvals, exceptions and retained operating records showing the process around the configuration

Evidence can be obtained through agreed read-only methods, exports or guided screen sharing. Direct tenant access is not assumed. The audit tests evidence relevant to the agreed ISMS scope and criteria rather than applying a generic Microsoft configuration checklist.

/ Free working resource

Prepare with an ISO 27001 internal audit checklist.

Use the free working resource to prepare the audit programme, criteria, scope, independence check, evidence request, sampling record, findings and corrective-action close-out. The material is provided as readable HTML with editable working files and no email gate. It is a planning aid, not a substitute for competent audit judgement or access to the licensed standard.

For the wider sequence, budgets and certification-body boundary, read the ISO 27001 certification guide for Australia. The broader ISO 27001 templates library and implementation-readiness checklist serve different planning needs.

Learning the audit language first? The ISO 27001 Foundation course introduces the management-system concepts; the free Clauses 4–10 study map shows how the requirements connect.

/ Service brochure

Get the ISO 27001 internal audit brochure.

Review the audit scope, evidence requirements, delivery approach and reporting in one document. Receive a copy by email to read or share with your team.

PDF · 13 pages · 1.8 MB

Where should we email your brochure?

Use your company email. Gmail, Yahoo and other personal or temporary email addresses are not accepted.

We use your name and work email to send the brochure and keep a copy of your request in our enquiry inbox. Privacy policy.

/ Integrated audit programme

Operating ISO 27001 and ISO 42001 together?

ISO 27001 and ISO 42001 share a management-system structure. Where the scopes, responsibilities and audit calendars align, shared processes such as context, leadership, competence, document control, internal audit, management review and corrective action can be tested once. The standard-specific controls and evidence remain separately traceable so each conclusion is mapped to the correct criterion.

A combined programme may reduce duplicated interviews and evidence requests, but it must not blur which standard, clause or control supports each finding.

  • Shared management-system processes tested once where appropriate
  • ISO 27001 and ISO 42001 controls sampled separately
  • Findings mapped to the correct standard and criterion
  • One coordinated schedule where certification cycles align
See ISO 42001 internal audit

/ FAQ

ISO 27001 internal audit questions

What is an ISO 27001 internal audit?

An ISO 27001 internal audit is an objective, evidence-based evaluation of whether an information security management system conforms to the organisation’s requirements and ISO/IEC 27001, and whether it is effectively implemented and maintained. The audit uses defined criteria, scope and methods, samples objective evidence, reports results to relevant management and retains records of the programme and findings. It is not the external certification audit.

Is an ISO 27001 internal audit mandatory?

Yes. Clause 9.2 requires an organisation operating an ISO/IEC 27001 ISMS to conduct internal audits at planned intervals. The organisation needs an audit programme, defined criteria and scope, appropriate methods, auditors selected so objectivity and impartiality are protected, results reported to relevant management and retained evidence of the programme and results. A gap assessment may help preparation, but it does not automatically satisfy the internal-audit requirement.

Does the internal audit need to be completed before Stage 2?

Plan to complete the internal audit and management review before Stage 2, with enough time to address material findings. The certification body will normally examine the audit programme, results, management-review records and corrective actions as evidence that the organisation has evaluated and improved its own ISMS before the certification decision.

How often is an ISO 27001 internal audit required?

ISO/IEC 27001 requires internal audits at planned intervals; it does not prescribe one universal full audit every calendar year. The audit programme should determine frequency, methods and coverage using process importance, information-security risk, significant changes and previous audit results. Many organisations use an annual cycle because it aligns with management and certification calendars, while others distribute coverage across a documented multi-year programme.

Does ISO 27001 require all 93 Annex A controls to be audited every year?

No. ISO/IEC 27001:2022 contains 93 Annex A reference controls, but it does not require every control to be audited every year. The audit criteria normally include Clauses 4–10, the organisation’s own ISMS requirements and applicable controls identified through risk treatment and the Statement of Applicability. Sampling follows risk, process importance, material change, previous findings and the documented audit programme.

Who can perform an ISO 27001 internal audit?

A competent internal employee or an external auditor can perform the audit where the organisation protects objectivity and impartiality. The auditor should have competence relevant to the scope and should not audit work they designed, implemented or operate. When a small team cannot avoid self-review, a separately appointed external auditor usually provides the clearest separation.

Can the consultant who implemented our ISMS perform the internal audit?

The person conducting the audit should not audit their own work. Where Aegentra implements the ISMS, a different competent Aegentra consultant, independent of the implementation work, performs the internal audit subject to documented conflict-of-interest and impartiality checks. If independence cannot be protected, a separate provider is required. The service is also available for systems implemented in-house or by another provider, subject to the same conflict and prior-involvement checks.

What does an ISO 27001 internal audit cost in Australia?

Aegentra’s ISO 27001 internal-audit service starts from A$2,300 + GST for a smaller organisation with a clear, single ISMS scope and straightforward evidence access. The final fixed fee is confirmed after reviewing locations, processes, applicable controls, previous findings, evidence volume, interview requirements, sampling needs and any onsite work. The written scope records the inclusions, assumptions and dates before work begins.

How long does an ISO 27001 internal audit take?

Duration depends on the agreed scope rather than headcount alone. Locations, business processes, applicable controls, prior findings, evidence quality, interview availability and onsite requirements all affect fieldwork and reporting. Aegentra confirms dates only after reviewing the audit programme, ISMS scope and evidence access. The audit plan then identifies the fieldwork, closing meeting, report issue and any close-out review dates.

What evidence does an ISO 27001 auditor review?

The auditor reviews evidence relevant to the agreed criteria and sample. This normally begins with the ISMS scope, audit programme, risk assessment, treatment plan, Statement of Applicability, policies, objectives, previous findings and management-review records. Operating samples may include access reviews, approvals, tickets, logs, incident records, supplier reviews, backup tests, training records and corrective actions.

Can an ISO 27001 internal audit be performed remotely?

Yes. Document review, interviews and cloud-control testing can normally be completed remotely. Onsite attendance may be appropriate where physical security, restricted evidence, site-specific operations or the agreed audit objective cannot be evaluated adequately through remote methods. The delivery mode, access arrangements and travel assumptions are agreed before fieldwork.

What happens if the internal audit identifies nonconformities?

The organisation records each nonconformity, addresses the immediate issue, evaluates the cause and plans corrective action proportionate to the gap. Owners and due dates are assigned, and follow-up evidence is reviewed to establish whether the action was completed and effective. A nonconformity is an input to improvement; it is not automatically a certification failure.

Can Aegentra guarantee that the audit will find no nonconformities?

No. A competent auditor cannot promise an audit outcome before reviewing the evidence. The purpose is to reach an objective conclusion against the agreed criteria, not to produce a predetermined result. A published nil-nonconformity case study describes one completed engagement and is not a guarantee for another organisation.

What is the difference between an internal audit and Stage 1 or Stage 2?

The internal audit is the organisation’s Clause 9.2 assurance activity. Stage 1 and Stage 2 are separate external assessments conducted by an accredited certification body. The internal audit evaluates conformity and effective implementation, reports findings to relevant management and supports corrective action. Only the certification body makes the decision to issue, maintain, suspend or withdraw certification.

Does Aegentra issue ISO 27001 certificates?

No. Aegentra is not a certification body and does not issue ISO 27001 certificates. Aegentra can provide readiness support and, where its independence policy permits, the Clause 9.2 internal audit. Stage 1, Stage 2, surveillance and recertification assessments are performed by an independent accredited certification body.

What should we prepare for an audit scoping call?

Have the current ISMS scope, Statement of Applicability, risk register, internal-audit programme, previous findings, target certification or surveillance date, site list and expected evidence-access constraints available. These inputs allow the audit criteria, sampling, interview requirements, delivery method, fixed fee and reporting dates to be scoped accurately.

/ Scope the audit

Ready for an independent Clause 9.2 review?

Bring the current ISMS scope, Statement of Applicability, risk register, audit programme, previous findings, certification or surveillance date, site list and any evidence-access constraints. Aegentra will use those inputs to confirm the criteria, sample approach, interview requirements, delivery method, fixed fee and reporting dates before fieldwork begins.

Aegentra performs the Clause 9.2 internal audit. An independent accredited certification body remains responsible for certification.