Hael
Book a meeting
ISO 27001 · Internal audit

ISO 27001 - Internal Audit Consultants

Hael · Published 7 August 2026 · Last reviewed 7 August 2026 · 7 min read
Key takeaways
  • Clause 9.2 requires internal audits at planned intervals, in practice before certification and annually afterwards.
  • Your certification body cannot perform it. That is a rule under ISO/IEC 17021, not a preference.
  • The auditor must be objective and impartial, which normally rules out whoever built the ISMS.
  • Most organisations under a few hundred people have nobody who qualifies, so it is usually outsourced.
  • Outsourced internal audits typically cost £4,000 to £12,000 per cycle and take one to two weeks.

What Clause 9.2 requires

ISO/IEC 27001 Clause 9.2 requires internal audits of the information security management system at planned intervals, to check that it conforms to your own requirements and to the standard, and that it is effectively implemented and maintained. In practice that means one before certification and one every year for as long as you hold the certificate.

The requirement is unusual because the answer to “who can do this” is a rule rather than an opinion, and for most organisations that rule ends in a decision to bring someone in.

Who cannot do it

Your certification body. Under ISO/IEC 17021, the body that certifies you cannot provide internal audit services for the same management system.

Whoever built the ISMS. The standard requires the audit programme to ensure objectivity and impartiality. Someone auditing documentation they wrote does not satisfy that in substance, and a Stage 2 or surveillance auditor will test it.

Anyone responsible for the area being audited. A head of IT auditing IT controls has an obvious conflict, whatever the intent.

Who can

Anyone competent and independent. That can be an internal person from another function, an internal audit team, or an external firm.

Competence matters as much as independence. The auditor needs management system auditing skill, which is a specific discipline, and enough technical understanding to test whether the controls in your Statement of Applicability are real rather than nominal.

The combination is why most organisations outsource it. There is often exactly one person who understands the ISMS, and they built it.

What a good internal audit produces

OutputWhat it should contain
Audit planScope, criteria, method, and which clauses and controls this cycle covers
Evidence recordWhat was sampled, from which period, and what it showed
FindingsNonconformities classified as major or minor, each written so it can be closed
ObservationsThings that conform now but will not survive the next change
Report to managementClear enough for the management review to make decisions from
Follow-upVerification that corrective actions were actually completed

A finding has to name the requirement, describe the evidence, and state why the evidence does not meet the requirement. Anything vaguer cannot be closed and reappears next cycle.

Covering 93 controls without auditing everything every year

Clause 9.2 requires an audit programme, not a full audit of everything annually. A sensible programme covers all clauses and all applicable controls across the three-year certification cycle, weighted by risk, with higher-risk areas audited more often.

That is both cheaper and better. A programme that superficially touches all 93 controls every year tests nothing properly. One that examines a risk-weighted subset in depth finds real problems.

Your certification body will want to see the programme as well as this cycle's report.

The audit that finds nothing

An internal audit reporting no findings at all, in a first-year ISMS, is usually a signal rather than a result.

First-year management systems almost always have something: an access review with no retained record, a supplier assessed informally, a policy version nobody updated, an incident handled well but documented poorly. Finding those is the point, and closing them before the certification body arrives is the value.

An audit designed to reassure produces a comfortable report and a surprise at Stage 2.

Cost and timing

ItemTypical range
Outsourced internal audit, small to mid-sized organisation£4,000 to £12,000 per cycle
Duration1 to 2 weeks including reporting
FrequencyBefore certification, then annually
Combined with ISO 42001 or SOC 2 readiness workUsually cheaper than separate engagements

Where you hold both ISO 27001 and ISO/IEC 42001, one integrated internal audit across both management systems normally costs less than two, and Annex D of ISO/IEC 42001 supports treating them together.

Why this is the part that recurs

Implementation happens once. Certification happens once, then recertification at year three. The internal audit happens every single year, for as long as the certificate is held.

That makes it the most durable relationship in ISO 27001 work. An auditor who knows your system from last year is faster and finds more, provided they remain independent of building it.

Our internal audit service covers this, and where we implemented the ISMS we use a separate practitioner so independence is real rather than asserted.

How it fits with management review

Clause 9.3 requires management review, and internal audit results are a required input. The sequence is audit, then review, then certification audit.

Leadership has to actually consider the findings and record decisions on resources, risks accepted and improvements. A management review that rubber-stamps a report is itself a common finding.

What to do next

Answer one question: is there anyone in your organisation who understands the ISMS, has audit competence, and did not build it? If not, plan for an external audit rather than discovering the problem weeks before Stage 1.

Our free readiness diagnostic gives a first view, and the ISO 27001 service page sets out how the annual cycle runs.

References

FAQ

Does ISO 27001 require an internal audit?

Yes. Clause 9.2 requires internal audits at planned intervals, which in practice means before certification and annually afterwards.

Can our certification body do it?

No. ISO/IEC 17021 prevents it.

Can the person who built the ISMS audit it?

Not while satisfying the objectivity and impartiality requirement in substance. Auditors test this.

Do we have to audit all 93 controls every year?

No. The requirement is an audit programme covering all clauses and applicable controls across the certification cycle, weighted by risk.

How much does an outsourced internal audit cost?

Typically £4,000 to £12,000 per cycle, taking one to two weeks.

About Hael

Hael is an advisory firm specialising in AI governance and security compliance. We run ISO 27001 internal audits, including for organisations whose management system we did not build, and where we did build it we use a separate practitioner so independence is real. We are not a certification body and we take no commission from certification bodies. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on authorisation and compliance since 2013.

This guide is general information and is not professional advice on your particular circumstances.

Free check

See where you stand on ISO 27001, free.

Answer a short set of questions and see what ISO 27001 expects of your AI systems and where you stand today. No sign-up to see your result.

Applicability

Whether ISO 27001 applies to how you use AI, and to which systems.

What is expected

Risk classification, governance, documentation and human oversight.

Where you stand

A banded result, pointed at the gaps that matter most.

What you get

On screen in about five minutes, pre-scoped to ISO 27001.

Or speak to us about your deadline. Book a meeting.