ISO 27001 internal audit
Clause 9.2 makes an internal audit mandatory before certification and every year afterwards. The constraint that catches small Canadian companies is not the work, it is that whoever built the management system is not allowed to audit it.
An outsourced ISO 27001 internal audit costs $6,000 to $15,000 CAD a year in Canada, takes three to eight days of elapsed effort, and has to be complete before a certification body will run stage 2. Clause 9.2 requires it at planned intervals, requires the auditors to be objective and impartial, and requires the results to be reported to management. It is not a rehearsal for the real audit. It is a required part of the management system, it recurs every year for as long as you hold the certificate, and it is the line most first-time budgets leave out.
$6,000 to $15,000 Outsourced, per annual cycle, CAD
Every year Not once. It recurs for the life of the certificate
Who is allowed to run it
Clause 9.2.2 c) says the auditors must be selected to ensure objectivity and impartiality of the audit process, and adds that auditors shall not audit their own work. That single sentence is what makes this a purchase for most Canadian companies under about a hundred people, because the person who wrote the policies, built the risk register and configured the controls is usually the only person who understands them.
| Who | Cost (CAD) | Works when |
|---|---|---|
| Someone internal who did not build the ISMS | Internal time only | You have a second person with audit competence and no stake in the outcome. Rare under 50 staff. |
| A second consultant, not the one who implemented | $6,000 to $15,000 | The usual answer. Independent, competent, and it costs a fraction of the certification audit. |
| The firm that built your ISMS | $4,000 to $10,000 | Not prohibited by the standard, and weak. They are auditing their own work and a stage 2 auditor will notice the findings are thin. |
| Your certification body | Not available | Never. ISO/IEC 17021-1 bars an accredited body from providing management system consultancy, and internal auditing is consultancy. |
| A reciprocal arrangement with another certified company | Time swap | Legitimate and underused. Works where both sides have a trained internal auditor and no commercial relationship. |
The third row is the one to think hardest about. Using your implementation consultant is cheaper and it is the option most likely to produce an internal audit report with no nonconformities, which is itself a finding at stage 2. If budget forces it, at least have a different person from that firm run it, and expect to defend the arrangement.
What it has to cover
The whole management system, not a sample of the controls you feel good about. That means clauses 4 through 10 as well as the Annex A controls you declared applicable in your Statement of Applicability. The clause half is where first audits find the most, because the technical controls tend to exist and the management practices tend not to.
- Clause coverage
- Context and interested parties, leadership and policy, risk assessment and treatment, objectives, competence and awareness, documented information, operational planning, monitoring, previous audits and management review, nonconformity and corrective action.
- Annex A coverage
- Every control marked applicable, tested against evidence rather than against the policy that says it happens.
- Audit program
- Clause 9.2.2 asks for a planned program covering frequency, methods, responsibilities and reporting. One document, reviewed annually, and the thing auditors ask for before they ask for the report.
- Records
- The plan, the evidence sampled, the findings, and proof the results reached management. The report on its own is not enough.
You do not have to cover everything in one pass. A program that audits the whole system across three visits a year is acceptable and often better, provided the program is written down and the full system is covered within the cycle. What is not acceptable is a single two-hour meeting that produces a clean report.
Where it sits in the project
After the management system has been running long enough to have records, and before stage 2. Both halves of that matter. Audit too early and there is nothing to sample, so the report is about documents rather than practice. Audit too late and the nonconformities you find have to be closed while the certification body is waiting, which is the version that costs six weeks.
- Run the system for at least three months so access reviews, supplier reviews, incidents, backups and training have produced records.
- Book the internal auditor. Independent auditors are scheduled weeks out, and this is the step that slips.
- Run the internal audit and log the findings honestly, including the uncomfortable ones.
- Raise corrective actions with owners and dates, and close what you can before stage 1.
- Hold the management review, which takes the internal audit results as a required input.
- Go to stage 1 with the report, the corrective actions and the review minutes in hand.
A clean internal audit report is a red flag
An internal audit that found nothing tells a stage 2 auditor one of two things: the audit was not real, or the auditor was not independent. Neither helps you. A first internal audit on a young management system that raises five to fifteen findings, mostly minor, reads as a working system with a working assurance process. Write down what you found, assign it, and show the closure evidence. That is the outcome the standard is asking for.
What the report has to produce
A findings list, classified. Major nonconformity where a requirement is entirely absent or a failure is systemic, minor where a requirement is met inconsistently, and observation or opportunity for improvement where nothing is broken yet. Each finding needs the requirement it fails against, the evidence, an owner and a date. Corrective action under clause 10.2 asks for more than a fix: it asks what caused it and whether the same cause exists elsewhere.
That root cause step is the one companies skip, and surveillance auditors check it specifically, because a corrective action log full of one-line fixes tells them the improvement process is cosmetic. What happens to all of this in years two and three is on surveillance audits.
Budgeting for it properly
Price it as a recurring annual cost from year one, alongside the surveillance audit and the penetration test. On a three-year view an outsourced internal audit adds $18,000 to $45,000 CAD, which is a material share of the total on the cost page and is routinely missed. If nobody internally owns the management system between audits, a fractional CISO can hold that ownership, but the same person then cannot be your internal auditor, which is the trade to think through before you sign either contract.
Get an independent internal audit quoted
Tell us your scope and when stage 2 is booked, and we will match you with Canadian firms that run ISO 27001 internal audits.
Get matchedCommon questions
Can our ISO 27001 consultant do our internal audit?
It is not prohibited by the standard the way certification body consultancy is, but it is weak. A firm auditing the management system it built is auditing its own work, which clause 9.2.2 tells you to avoid. If cost forces it, use a different person from that firm and be ready to explain the arrangement at stage 2.
How often does an ISO 27001 internal audit have to happen?
At planned intervals, which in practice means at least annually and before each surveillance audit. The standard does not print a frequency, it asks for a program that considers the importance of the processes and the results of previous audits. A program covering the whole system once a year is the normal shape.
Does the internal auditor need a certification?
No. Clause 7.2 asks for competence, which can come from training, education or experience, and a lead auditor qualification is the easiest way to evidence it rather than the only way. What a certification body checks is that you can show why this person was competent to audit this system.
What is the difference between an internal audit and a gap assessment?
A gap assessment measures how far you are from being able to certify, and it is bought before the work. An internal audit is a required part of the running management system, it is performed against the standard and your own documented system, and it produces nonconformities that have to be corrected. Buying one and calling it the other is a common way to arrive at stage 1 missing a mandatory record.
Can we skip it if we are certifying for the first time?
No. A certification body will not proceed to stage 2 without evidence that an internal audit and a management review have been completed, because both are clause 9 requirements and stage 1 exists partly to check they happened. It is the most common reason a stage 2 date gets moved.