ChecklistInternal Audit

Internal Audit Checklist: What to Cover

A practical checklist for planning and executing your ISO 27001 internal audit programme.

Updated 13 Mar 2026

Before the Audit

Define audit scope and objectives
Create audit schedule covering all ISMS processes over audit cycle
Select auditors who are independent of the area being audited
Review previous audit findings and corrective actions
Prepare audit checklists based on ISO 27001 clauses and Annex A controls
Notify auditees and schedule interviews

During the Audit

Hold opening meeting to confirm scope and approach
Review documentation: policies, procedures, records
Interview process owners and staff
Observe actual practices (don't just read documents)
Verify evidence of control implementation
Check that previous nonconformities have been addressed
Document findings as you go — with evidence references

Classifying Findings

Major nonconformity A requirement is not met at all, or a systematic failure
Minor nonconformity A partial failure or isolated incident
Observation An area for improvement (not a formal nonconformity)
Positive finding Something working particularly well

After the Audit

Hold closing meeting to present findings
Write audit report with clear findings and evidence
Raise corrective actions for all nonconformities
Track corrective actions to completion
Verify effectiveness of corrective actions
Present results to management review

What Auditors Expect

Certification auditors will review your internal audit programme for:

Coverage of all ISMS requirements over the audit cycle
Independence of auditors
Quality of findings (not just "everything is fine")
Evidence that corrective actions were effective

Related Modules

Corrective Actions
Documents
Calendar

Related Controls / Clauses

9.2
10.1
10.2

26 practitioner guides — included free with your workspace

27 Launchpad generates your full compliance toolkit from a 10-minute setup: policies, risk register, legal register, controls, and AI-assisted document review.