Clause 9.2
Internal Audit
Certification Readiness
Clause 9.2 Explained: What ISO 27001 Internal Audit Really Requires
Clause 9.2 is not just about completing one internal audit report. It is about proving that your organization has a planned, objective, evidence-based audit process that checks whether the ISMS is working.
Quick Answer
What does ISO 27001 Clause 9.2 require?
Clause 9.2 requires organizations to conduct internal audits at planned intervals.
The audit must check whether the ISMS conforms to ISO 27001, the organization’s own requirements, and planned ISMS arrangements.
Bottom line: Clause 9.2 is not only about doing an audit. It is about maintaining a controlled internal audit program that supports continual improvement.
Canadian Cyber Clause 9.2 Support
Build a Strong ISO 27001 Internal Audit Program
Canadian Cyber helps organizations meet Clause 9.2 with practical, evidence-based internal audit support.
We support audit program design, audit schedules, evidence reviews, control owner interviews, NCR and OFI reporting, corrective action verification, management review preparation, and SharePoint audit tracking.
Quick Snapshot
| Clause 9.2 Area | What It Means |
|---|---|
| Planned Intervals | Internal audits should happen on a planned schedule. |
| Audit Program | The organization should define how audits are planned and managed. |
| Audit Criteria | Audits should be based on ISO 27001, policies, procedures, risks, and controls. |
| Audit Scope | Each audit should define what areas, systems, processes, and controls are reviewed. |
| Auditor Objectivity | Auditors should not audit their own work. |
| Corrective Action | Findings should be tracked, fixed, evidenced, and verified. |
Why Clause 9.2 Matters
ISO 27001 is not only about writing policies.
It is about operating a management system.
A management system needs self-checking.
Internal audit is that self-checking process.
Clause 9.2 helps your organization find problems before the certification auditor finds them.
Who This Guide Is For
- ISO 27001 implementation teams.
- ISMS managers and compliance leads.
- Internal auditors and security managers.
- IT managers, risk owners, and control owners.
- vCISO teams and cybersecurity leaders.
- Canadian businesses preparing for certification.
- Organizations preparing for Stage 1, Stage 2, or surveillance audits.
- Teams using Microsoft 365 or SharePoint for ISMS evidence.
Clause 9.2 in Plain English
Clause 9.2 asks two simple questions.
The answers should be supported by evidence.
Question 1: Is the ISMS conforming?
The ISMS should align with ISO 27001 and the organization’s own requirements.
This includes policies, procedures, risks, controls, legal needs, customer expectations, and the Statement of Applicability.
Question 2: Is the ISMS operating?
The ISMS should not only exist on paper.
The audit should confirm that reviews, controls, incidents, training, evidence, and corrective actions are actually happening.
Practical rule: Clause 9.2 tests both design and operation.
What Clause 9.2 Does Not Mean
Clause 9.2 is often misunderstood.
It is more than one quick audit before certification.
- It does not mean only reviewing policies.
- It does not mean only checking whether documents exist.
- It does not mean only using a generic checklist.
- It does not mean auditing once and forgetting the findings.
- It does not mean asking control owners if everything is fine.
- It does not mean collecting screenshots with no follow-up.
- It does not mean preparing a report with no corrective action tracking.
A weak internal audit checks boxes. A strong internal audit improves the ISMS.
Clause 9.2.1 Explained: Internal Audit General
Clause 9.2.1 focuses on whether internal audits happen at planned intervals.
It also checks whether those audits evaluate conformity and effectiveness.
Questions to Ask
- Was an internal audit performed?
- Was it planned?
- Did it cover the ISMS scope?
- Did it review ISO clauses and Annex A controls?
- Did it review evidence?
- Were findings reported?
Evidence to Prepare
- Internal audit plan.
- Audit schedule.
- Audit scope and criteria.
- Audit checklist and interview notes.
- Internal audit report.
- Findings register and corrective action tracker.
Practical rule: Clause 9.2.1 proves that internal audit happened and tested the right things.
Clause 9.2.2 Explained: Internal Audit Program
Clause 9.2.2 focuses on the audit program.
This is where many organizations get weak.
The audit program should define:
- Audit frequency and methods.
- Audit responsibilities and planning requirements.
- Audit criteria and audit scope.
- Reporting expectations and records to retain.
- Auditor objectivity and competence.
- Previous audit results and risk levels.
- Follow-up and corrective action tracking.
The internal audit program should be risk-based, not random.
What “Planned Intervals” Really Means
ISO 27001 does not require every organization to use the same audit frequency.
The frequency should fit the organization’s size, risk, scope, and maturity.
| Approach | When It Works Well |
|---|---|
| Annual Full Internal Audit | Useful for smaller organizations with a focused ISMS scope. |
| Quarterly Thematic Audits | Useful for growing teams with recurring control activity. |
| Monthly Evidence Checks | Useful for fast-moving teams that need regular evidence confidence. |
| Event-Based Audits | Useful after major incidents, system changes, vendor changes, or scope changes. |
| Pre-Certification Review | Useful before Stage 1, Stage 2, or surveillance audits. |
Audit Criteria and Audit Scope
Audit criteria define what the auditor is auditing against.
Audit scope defines what the audit will cover.
Both should be clear before the audit starts.
Common Audit Criteria
- ISO 27001 clauses.
- Annex A controls selected in the SoA.
- Internal policies and procedures.
- Risk treatment plan.
- Customer and contractual requirements.
- Prior findings and management review actions.
Common Audit Scope Items
- Departments and systems.
- Locations and cloud environments.
- Business processes and vendors.
- Products or services.
- ISMS clauses and Annex A controls.
- Audit period and evidence types.
Practical rule: Criteria answer “against what?” Scope answers “what is included?”
Need Help Meeting Clause 9.2?
Canadian Cyber helps organizations plan, perform, report, and follow up ISO 27001 internal audits.
Auditor Objectivity: Why Independence Matters
Clause 9.2 expects audits to be objective and impartial.
This means auditors should not audit their own work.
For smaller organizations, this can be difficult. But it still needs to be considered.
Weak Objectivity Examples
- The IT Manager audits the access review they own.
- The HR Lead audits training records they manage.
- The ISMS Manager audits every process they built.
Better Options
- Use a trained auditor from another department.
- Use a vCISO or external internal auditor.
- Split audit responsibilities.
- Document how objectivity is maintained.
The auditor should be competent enough to audit and independent enough to challenge.
Clause 9.2 Evidence Pack
A Clause 9.2 audit file should not contain only the final report.
It should show the full audit trail.
Recommended Evidence
What Certification Auditors Usually Look For
Certification auditors often review Clause 9.2 carefully.
It proves whether the organization checks itself.
- When was the internal audit performed?
- Who performed it?
- Was the auditor objective?
- What was the audit scope?
- What criteria were used?
- Which evidence was reviewed?
- Were interviews conducted?
- Were findings documented?
- Were corrective actions assigned?
- Did management review the audit results?
Practical rule: Be ready to explain not only what was found, but how the audit was performed.
Common Clause 9.2 Findings
Internal audit was planned but not completed.
Audit scope was too narrow.
Auditor independence was weak.
No audit criteria were defined.
Evidence was not reviewed.
NCRs and OFIs were not tracked.
Corrective actions had no root cause.
Closure evidence was missing.
Audit results were not reported to management.
No internal audit program exists.
Clause 9.2 Internal Audit Checklist
| Internal Audit Requirement | Ready? |
|---|---|
| Internal audit procedure exists. | |
| Annual audit program is documented. | |
| Audit frequency is defined. | |
| Audit scope is documented. | |
| Audit criteria are documented. | |
| Auditor competence is confirmed. | |
| Auditor objectivity is considered. | |
| Audit methods are defined. | |
| Evidence sampling method is documented. | |
| Interviews are planned. | |
| Evidence is reviewed and retained. | |
| Findings are classified. | |
| Results are reported to relevant management. | |
| Corrective actions are assigned. | |
| Closure evidence is collected. | |
| Corrective actions are verified. | |
| Audit results feed management review. | |
| Audit records are retained as documented information. |
How Clause 9.2 Connects to Clause 9.3 and Clause 10
Clause 9.2 does not stand alone.
Internal audit results should feed leadership review and improvement.
| Clause | Role in the ISMS |
|---|---|
| Clause 9.2 Internal Audit | Finds issues and tests conformity. |
| Clause 9.3 Management Review | Gives leadership visibility into audit results, risks, incidents, and actions. |
| Clause 10 Improvement | Requires corrective action and ISMS improvement. |
Practical rule: Clause 9.2 finds the issue. Clause 9.3 gives leadership visibility. Clause 10 drives improvement.
How to Build a Strong Clause 9.2 Internal Audit Program
- Define the audit program. Document frequency, scope, methods, responsibilities, reporting, and follow-up.
- Use risk-based planning. Prioritize access control, vendors, incidents, backups, change management, and corrective actions.
- Prepare audit criteria. Use ISO 27001, policies, procedures, SoA, risks, and customer obligations.
- Confirm auditor independence. Use objective and competent auditors.
- Collect evidence before interviews. Review evidence early where possible.
- Test control operation. Do not only ask whether the control exists.
- Document findings clearly. Classify nonconformities, OFIs, observations, or evidence gaps.
- Assign corrective actions. Add owners, root cause, deadlines, evidence requirements, and verification steps.
- Report to management. Audit results should reach relevant leadership.
- Verify closure. Do not close findings without evidence.
Clause 9.2 Evidence Example
| Audit Element | Example Evidence |
|---|---|
| Audit Program | Annual internal audit schedule. |
| Audit Scope | Access control, vendors, incident response, and risk treatment. |
| Audit Criteria | ISO 27001, policies, SoA, and procedures. |
| Auditor Objectivity | Independence statement. |
| Audit Method | Interviews, sampling, and document review. |
| Evidence Reviewed | Access reviews, vendor reviews, and risk register. |
| Findings | NCR and OFI register. |
| Follow-Up | Corrective action tracker and verification records. |
How SharePoint Can Help With Clause 9.2
A structured SharePoint ISMS can make Clause 9.2 much easier to manage.
It gives the organization one controlled workspace for audit planning, evidence, findings, and follow-up.
Canadian Cyber’s ISMS SharePoint Solution can organize:
- Internal audit procedure and annual audit program.
- Audit schedule, audit plans, criteria, and scopes.
- Control register and evidence library.
- Audit request tracker and interview schedule.
- Audit workpapers and internal audit report library.
- NCR register and OFI tracker.
- Corrective action tracker and closure evidence.
- Verification records, management review dashboard, Power Automate reminders, Teams notifications, and auditor-ready views.
Clause 9.2 becomes easier when audit planning, evidence, findings, owners, deadlines, and verification live in one controlled workspace.
How Canadian Cyber Helps
Canadian Cyber helps organizations meet ISO 27001 Clause 9.2 with practical internal audit support.
We help teams move beyond checklist audits and build audit programs that support certification, surveillance, leadership review, and continual improvement.
Canadian Cyber can support:
- Clause 9.2 readiness reviews.
- ISO 27001 internal audits.
- Annual internal audit program design.
- Risk-based audit schedule development.
- Audit scope and criteria definition.
- Control owner interview planning.
- Evidence readiness reviews.
- Audit sampling strategy.
- NCR and OFI reporting.
- Corrective action planning and verification.
- Management review preparation, vCISO services, SOC 2 alignment, ISO 42001 readiness, ISO 27017, ISO 27018, and SharePoint ISMS implementation.
Senior Advisory Support
Canadian Cyber also provides senior advisory support for Clause 9.2 readiness, ISO 27001 internal audits, certification readiness, corrective action verification, vCISO oversight, and SharePoint ISMS implementation.
Frequently Asked Questions
What is ISO 27001 Clause 9.2?
Clause 9.2 is the ISO 27001 internal audit requirement. It requires organizations to conduct internal audits at planned intervals and maintain an audit program to evaluate whether the ISMS conforms to requirements and is effectively implemented.
Is an internal audit required for ISO 27001 certification?
Yes. Internal audit is a key requirement for ISO 27001 certification readiness. Certification auditors expect evidence that internal audit was planned, performed, reported, and followed up.
How often should ISO 27001 internal audits be performed?
Internal audits should be performed at planned intervals. Many organizations conduct a full internal audit annually and review higher-risk areas more often.
Who can perform an ISO 27001 internal audit?
The audit should be performed by a competent and objective auditor. This can be trained internal staff, a vCISO, a consultant, or an external internal audit provider.
What evidence is needed for Clause 9.2?
Evidence may include the audit procedure, schedule, plan, scope, criteria, auditor competence record, independence statement, checklist, evidence reviewed, interview notes, audit report, findings register, corrective action tracker, and closure evidence.
Can Canadian Cyber help with Clause 9.2?
Yes. Canadian Cyber helps organizations design internal audit programs, perform ISO 27001 internal audits, prepare Clause 9.2 evidence, verify corrective actions, and build SharePoint audit tracking systems.
Takeaway
Clause 9.2 is not a formality.
It asks whether your organization checks if the ISMS actually works.
A strong internal audit process includes planned intervals, clear scope, defined criteria, objective auditors, evidence-based testing, useful findings, management reporting, corrective action tracking, closure verification, and retained audit records.
The goal is not only to pass ISO 27001. The goal is to build an ISMS that leadership can trust.
Need Help Meeting Clause 9.2 Internal Audit Requirements?
Canadian Cyber can help you plan, perform, and improve your ISO 27001 internal audit program.
We provide ISO 27001 internal audits, Clause 9.2 readiness reviews, annual audit program design, evidence readiness reviews, corrective action verification, management review preparation, vCISO services, cybersecurity assessments, SOC 2 readiness, ISO 42001 AI governance readiness, ISO 27017, ISO 27018, and SharePoint ISMS implementation.
Stay Connected With Canadian Cyber
Follow Canadian Cyber for practical guidance on ISO 27001 Clause 9.2, internal audits, ISMS evidence, corrective actions, management review, SOC 2, ISO 42001, ISO 27017, ISO 27018, SharePoint ISMS, cybersecurity assessments, and vCISO support.
