A clause-by-clause ISO 27001 internal audit interview script for 2022. Includes evidence prompts, red flags, and practical auditor guidance for consistent, risk-based audits.
A practical, factual interview script you can use to run consistent, evidence-based internal audits mapped to ISO 27001 clauses 4–10, with example prompts, expected evidence, and common red flags.
Internal audits are not “asking people if they comply.” They’re verifying that the ISMS is working as designed.
ISO 27001:2022 references Annex A controls (aligned to ISO/IEC 27002:2022). Many internal audits include sampling key control areas.
Here’s a fast, high-value set to append: