ISO 27001 • Internal Audit Checklist • Canadian Businesses • Certification Readiness

ISO 27001 Internal Audit Checklist for Canadian Businesses Preparing for Certification

Many Canadian businesses create ISO 27001 documents. The real question is whether they can prove the ISMS is working.

Canadian Cyber ISO 27001 Certification Support

Prepare Your Internal Audit Before Certification

Canadian Cyber helps Canadian businesses prepare for ISO 27001 certification with readiness reviews, internal audits, evidence checks, corrective action planning, and SharePoint ISMS implementation.

We help you test whether your ISMS is actually ready before the certification auditor arrives.

Quick Answer

Canadian businesses preparing for ISO 27001 certification should complete an internal audit checklist before the external audit.

The checklist should review ISMS scope, context, interested parties, risk assessment, risk treatment, Statement of Applicability, policies, access controls, vendors, incidents, training, backups, management review, corrective actions, and audit evidence.

Practical takeaway: The goal is to confirm that the ISMS is not only documented. It must also be implemented, operating, and supported by proof.

Quick Snapshot

Checklist Area What to Confirm
ISMS Scope Scope is clear, approved, and realistic.
Risk Assessment Risks are current, assessed, owned, and reviewed.
Statement of Applicability Annex A controls are justified and current.
Access Control Access is approved, reviewed, and removed on time.
Management Review Leadership reviews ISMS performance and decisions.
Corrective Actions Findings are tracked to verified closure.

Why Internal Audit Matters Before Certification

An ISO 27001 internal audit is not just a document review.

It checks whether the Information Security Management System is implemented, operating, evidenced, reviewed, and improving.

For Canadian businesses preparing for certification, the internal audit is a key step before the external certification audit.

It helps identify gaps while there is still time to fix them.

The internal audit should find gaps before the certification auditor does.

Who This Guide Is For

  • Canadian businesses preparing for ISO 27001 certification.
  • SaaS, MSP, FinTech, HealthTech, and AI companies.
  • Professional services and manufacturing businesses.
  • Cloud-based organizations and remote teams.
  • Startups selling to enterprise customers.
  • Organizations preparing for Stage 1 or Stage 2 audit.
  • Teams using Microsoft 365 or SharePoint for ISMS evidence.

The Canadian Business Context

Canadian organizations often pursue ISO 27001 because customers, partners, insurers, investors, or procurement teams want stronger evidence of cybersecurity governance.

For many teams, certification is also linked to enterprise sales, cloud trust, SOC 2 alignment, cyber insurance, and board-level oversight.

ISO 27001 helps turn cybersecurity from informal activity into a structured, evidence-backed management system.

Practical rule: Certification is easier when ISO 27001 is treated as business governance, not only an IT project.

Checklist 1: ISMS Scope

Your ISO 27001 scope defines what certification covers.

A weak or unclear scope can create audit problems.

Internal audit questions:

  • Is the ISMS scope documented and approved?
  • Does it identify products, services, locations, teams, systems, and processes?
  • Are remote workers and cloud services included where relevant?
  • Are exclusions clearly justified?
  • Can control owners explain what is in scope?

Evidence to prepare:

  • ISMS scope statement and scope approval record.
  • Organization chart and process map.
  • System inventory and data flow diagram.
  • Service description and cloud architecture summary.

If the scope is unclear, the audit will become unclear.

Checklist 2: Organizational Context

ISO 27001 requires the organization to understand internal and external issues that affect the ISMS.

Internal audit questions:

  • Has the organization identified internal and external issues?
  • Are business, legal, technology, market, and customer factors considered?
  • Are Canadian business requirements considered where relevant?
  • Is context updated when the business changes?

Evidence to prepare:

  • Context analysis and business overview.
  • Technology environment summary.
  • Regulatory or contractual requirement list.
  • Customer requirement summary and management review input.

Checklist 3: Interested Parties and Requirements

Interested parties are people or organizations with information security requirements.

They may include customers, employees, vendors, regulators, partners, insurers, investors, auditors, and enterprise procurement teams.

Internal audit questions:

  • Are interested parties identified?
  • Are security requirements documented?
  • Are customer and contractual obligations included?
  • Are privacy expectations included?
  • Are requirements reviewed periodically?

Evidence to prepare:

  • Interested parties register.
  • Legal and contractual requirements list.
  • Customer and vendor requirements.
  • Privacy requirements summary and management review records.

Checklist 4: Risk Assessment

Risk assessment is the heart of ISO 27001.

The internal audit should confirm that risks are not only listed. They must be actively managed.

Internal audit questions:

  • Is there a documented risk assessment methodology?
  • Is the risk register current?
  • Are risk owners assigned?
  • Are likelihood and impact assessed?
  • Are accepted risks approved?
  • Are new risks added when systems, vendors, or services change?

Evidence to prepare:

  • Risk assessment methodology and scoring criteria.
  • Risk register and owner assignments.
  • Risk review history and accepted risk approvals.
  • Management review risk summary.

Practical rule: A risk register should guide decisions, not sit untouched until audit week.

Checklist 5: Risk Treatment Plan

Risk treatment shows what the organization is doing about identified risks.

Internal audit questions:

  • Are risk treatment actions documented?
  • Are owners and deadlines defined?
  • Are treatments linked to risks?
  • Are controls selected based on risk?
  • Are overdue actions escalated?

Evidence to prepare:

  • Risk treatment plan and action tracker.
  • Control mapping and owner assignments.
  • Deadline tracker and status updates.
  • Residual risk approval and management review records.

Checklist 6: Statement of Applicability

The Statement of Applicability is one of the most important ISO 27001 certification documents.

It explains which Annex A controls apply and why.

Internal audit questions:

  • Does the SoA include all Annex A controls?
  • Is each control marked applicable or not applicable?
  • Is each decision justified?
  • Is implementation status accurate?
  • Can control owners support the status with evidence?

Evidence to prepare:

  • Statement of Applicability.
  • Control applicability justification.
  • Risk treatment links and control evidence.
  • SoA approval record and review history.

The SoA should tell a clear story: what controls apply, why they apply, and how they are implemented.

Preparing for ISO 27001 Certification in Canada?

Canadian Cyber helps Canadian businesses test whether the ISMS is actually ready before the certification audit.

Checklist 7: Policies and Procedures

Policies define expectations. Procedures explain how work is performed.

Internal audit questions:

  • Are required policies approved?
  • Do policies have owners and review dates?
  • Are employees aware of relevant policies?
  • Are procedures aligned with actual practice?
  • Are exceptions documented?

Common policies to review:

  • Information Security Policy and Access Control Policy.
  • Acceptable Use Policy and Risk Management Policy.
  • Incident Response Plan and Vendor Management Policy.
  • Change Management Policy and Business Continuity Policy.
  • Remote Work Policy and AI Acceptable Use Policy where relevant.

Checklist 8: Asset Management

Organizations should know what information assets, systems, and services need protection.

Internal audit questions:

  • Is there an asset inventory?
  • Are critical systems identified?
  • Are owners assigned?
  • Are cloud platforms and endpoints included?
  • Are decommissioned assets removed?

Evidence to prepare:

  • Asset inventory and system inventory.
  • Data classification register.
  • Asset owner list and cloud system list.
  • Endpoint inventory and asset review records.

Checklist 9: Access Control

Access control is one of the most common audit finding areas.

Internal audit questions:

  • Is MFA enforced?
  • Are new access requests approved?
  • Are privileged accounts reviewed?
  • Are terminated users removed quickly?
  • Are shared accounts and exceptions managed?

Evidence to prepare:

  • MFA report and access request records.
  • User and privileged access reviews.
  • Support and contractor access reviews.
  • Offboarding records, admin list, and exception register.

Practical rule: Access control evidence should prove approval, review, removal, and exception handling.

Checklist 10: Vendor and Supplier Management

Canadian businesses often rely on cloud platforms, consultants, software providers, MSPs, and outsourced services.

Vendor risk must be managed.

Internal audit questions:

  • Is there a vendor register?
  • Are critical vendors identified and risk-rated?
  • Are contracts and DPAs stored?
  • Are supplier security reports reviewed?
  • Are AI vendors included where relevant?

Evidence to prepare:

  • Vendor register and critical supplier list.
  • Vendor risk assessments, contracts, and DPAs.
  • SOC 2 reports and ISO certificates.
  • Subprocessor list and AI vendor review records.

Checklist 11: Security Awareness and Training

Employees must understand their security responsibilities.

Internal audit questions:

  • Is security training assigned?
  • Do new hires complete training?
  • Are employees trained on policies?
  • Are training records complete?
  • Is AI tool use covered where relevant?

Evidence to prepare:

  • Training completion report.
  • New hire training records.
  • Policy acknowledgment records.
  • Overdue follow-up and AI acceptable use acknowledgment.

Checklist 12: Incident Response

The organization should know how to respond to security incidents.

Internal audit questions:

  • Is there an incident response plan?
  • Are roles and severity levels documented?
  • Do employees know how to report incidents?
  • Has a tabletop exercise been completed?
  • Are lessons learned and corrective actions tracked?

Evidence to prepare:

  • Incident response plan and incident register.
  • Severity matrix and escalation contacts.
  • Tabletop report and lessons learned.
  • Corrective action tracker and awareness records.

Checklist 13: Backup and Business Continuity

Certification readiness should include proof that the organization can recover from disruption.

Internal audit questions:

  • Are critical systems identified?
  • Are backups configured and monitored?
  • Are backup failures reviewed?
  • Has restore testing been performed?
  • Is there a business continuity plan?

Evidence to prepare:

  • Backup policy and backup reports.
  • Backup failure logs and restore test report.
  • Business continuity and disaster recovery plans.
  • Critical system list and continuity test record.

Backups are not enough. Restore testing proves recovery readiness.

Checklist 14: Logging and Monitoring

Organizations should monitor relevant security events.

Internal audit questions:

  • Are logs enabled for critical systems?
  • Are alerts reviewed?
  • Are security events escalated?
  • Are monitoring responsibilities assigned?
  • Are exceptions tracked?

Evidence to prepare:

  • Logging configuration and monitoring dashboard.
  • Alert review records and security event tickets.
  • Escalation records, monitoring reports, and exception records.

Checklist 15: Change Management

Changes to systems, applications, infrastructure, and processes should be controlled.

Internal audit questions:

  • Are changes requested and approved?
  • Are production changes reviewed?
  • Are emergency changes documented?
  • Is testing performed before release?
  • Are deployment records retained?

Evidence to prepare:

  • Change management procedure and change tickets.
  • Pull request approvals and test results.
  • Deployment records and release approvals.
  • Emergency change records and rollback evidence.

Checklist 16: Management Review

Management review proves that leadership is involved in the ISMS.

Internal audit questions:

  • Has management review been completed?
  • Were required inputs reviewed?
  • Were risks and internal audit results reviewed?
  • Were incidents and corrective actions reviewed?
  • Were decisions and actions documented?

Evidence to prepare:

  • Management review agenda and attendee list.
  • Input pack and meeting minutes.
  • Risk summary and internal audit summary.
  • Decision log and action tracker.

Checklist 17: Corrective Actions and Improvement

ISO 27001 requires continual improvement.

Findings should be tracked and closed properly.

Internal audit questions:

  • Are nonconformities recorded?
  • Are OFIs tracked?
  • Is root cause documented?
  • Are owners and deadlines assigned?
  • Is closure evidence collected?
  • Is closure verified?

Evidence to prepare:

  • NCR register and OFI tracker.
  • Corrective action tracker.
  • Root cause records and owner assignments.
  • Closure evidence, verification records, and management review status.

Practical rule: Corrective action is not closed until evidence proves the fix worked.

ISO 27001 Internal Audit Readiness Checklist

Readiness Question Ready?
ISMS scope is documented and approved.
Interested parties and requirements are identified.
Risk assessment methodology is documented.
Risk register is current and reviewed.
Statement of Applicability is justified and current.
Policies are approved and communicated.
Asset inventory is maintained.
MFA and access controls are evidenced.
Access reviews are completed.
Vendor register is complete.
Security training records are complete.
Incident response plan is tested.
Backup restore testing is documented.
Management review is completed.
Corrective actions are tracked and verified.
Evidence is organized in a central workspace.

Common Mistakes Canadian Businesses Should Avoid

  • Waiting until certification audit week. Evidence should be prepared earlier.
  • Treating ISO 27001 as documentation only. Auditors test whether controls operate.
  • Weak Statement of Applicability. Control applicability must be justified clearly.
  • Scattered evidence. Evidence should not be spread across emails, chats, and personal folders.
  • No evidence owner. Every key evidence item should have an accountable owner.
  • No management review decisions. Management review should include decisions and follow-up.
  • Ignoring OFIs. Opportunities for improvement can prevent future findings.
  • No corrective action verification. Closure should be checked with evidence.

How SharePoint Can Help Canadian Businesses Prepare

Many Canadian businesses already use Microsoft 365.

SharePoint can help manage ISO 27001 evidence in a structured way.

Canadian Cyber’s ISMS SharePoint Solution can organize:

  • policy and procedure libraries.
  • risk register and SoA tracker.
  • control register and evidence library.
  • asset inventory and access review tracker.
  • vendor register and incident register.
  • training, backup, and change evidence.
  • internal audit workspace.
  • management review dashboard.
  • corrective action tracker and client-ready evidence room.

SharePoint becomes powerful for ISO 27001 when it is designed as an ISMS evidence system, not just a document folder.

How Canadian Cyber Helps

Canadian Cyber helps Canadian businesses prepare for ISO 27001 certification with practical, evidence-based support.

We help organizations assess readiness, organize evidence, perform internal audits, fix findings, prepare management review, and build audit-ready ISMS workspaces.

Canadian Cyber can support:

  • ISO 27001 readiness assessments.
  • ISO 27001 implementation and internal audits.
  • Stage 1 and Stage 2 preparation.
  • Risk register and SoA reviews.
  • Policy and procedure review.
  • Access review and vendor evidence checks.
  • Incident response tabletop exercises.
  • Management review preparation.
  • Corrective action verification.
  • SharePoint ISMS implementation.

Senior Advisory Support

Canadian Cyber also provides senior advisory support for ISO 27001 certification readiness, internal audits, SharePoint ISMS implementation, corrective action verification, and vCISO oversight.

View Waqar Mehboob’s Profile

Frequently Asked Questions

What is an ISO 27001 internal audit checklist?

It is a structured list of areas to review before or during internal audit. It covers scope, risks, SoA, policies, access controls, vendors, incidents, training, management review, corrective actions, and evidence.

Is internal audit required before ISO 27001 certification?

Yes. Internal audit is part of ISO 27001 certification readiness. It helps confirm whether the ISMS is implemented and operating effectively before the external certification audit.

What should Canadian businesses prepare before internal audit?

They should prepare the scope, risk register, risk treatment plan, SoA, approved policies, access reviews, vendor reviews, training records, incident response evidence, backup evidence, management review records, and corrective action tracker.

What is the most common internal audit problem?

A common problem is weak evidence. Controls may exist, but proof may be scattered, incomplete, outdated, or not linked to ISO 27001 requirements.

Can SharePoint be used for ISO 27001 evidence?

Yes. SharePoint can manage policies, risk registers, SoA, evidence libraries, access reviews, vendor reviews, internal audit records, management review dashboards, and corrective actions.

Can Canadian Cyber help with ISO 27001 internal audits?

Yes. Canadian Cyber supports ISO 27001 internal audits, readiness reviews, evidence organization, corrective action verification, certification preparation, and SharePoint ISMS implementation for Canadian businesses.

Takeaway

ISO 27001 certification readiness is not about hoping the audit goes well.

It is about preparing proof.

A Canadian business is more ready when it can show clear scope, current risks, a justified SoA, approved policies, working access controls, reviewed vendors, trained employees, tested incident response, restore testing evidence, completed management review, and verified corrective actions.

The stronger the internal audit preparation, the smoother the certification journey.

Preparing Your Canadian Business for ISO 27001 Certification?

Canadian Cyber can help you assess readiness and organize evidence before the audit.

We provide ISO 27001 readiness assessments, ISO 27001 internal audits, evidence reviews, risk register and SoA reviews, corrective action verification, management review preparation, vCISO services, cybersecurity assessments, SOC 2 readiness, ISO 27017, ISO 27018, ISO 42001 AI governance, and SharePoint ISMS implementation. You can also learn more through Waqar Mehboob’s profile.

Stay Connected With Canadian Cyber

Follow Canadian Cyber for practical guidance on ISO 27001 certification, internal audits, ISMS evidence, corrective actions, SOC 2, ISO 42001, ISO 27017, ISO 27018, SharePoint ISMS, cybersecurity assessments, and vCISO support.