Internal audit program builder for ISO 27001 clause 9.2
Clause 9.2 wants audits at planned intervals, an audit program that accounts for importance and prior results, and auditors who do not audit their own work. This builds the schedule and then spells out the independence problem small companies actually have.
Internal audit is the clause that catches first-time certifications. Not because it is hard, but because it is the one requirement you cannot buy, borrow or generate. Clause 9.2 asks for audits at planned intervals, a program that takes account of the importance of the processes and the results of previous audits, defined criteria and scope for each audit, auditors selected to ensure objectivity and impartiality, results reported to relevant management, and documented information as evidence of the program and the results.
Six questions produce a schedule and an honest answer about who can run it. The result appears on this page. Nothing is emailed anywhere unless you ask for it at the end.
On its way
Check your inbox shortly. If you would rather talk it through, book a time.
What clause 9.2 asks for, item by item
The clause splits into 9.2.1, what the audits have to establish, and 9.2.2, what the program has to do. Both get sampled, and the second one is where the evidence is usually missing, because a company that ran one audit before the certification visit has audit results and no program.
| Requirement | Evidence that satisfies it |
|---|---|
| Audits at planned intervals | A dated schedule covering the cycle, written before the audits happened rather than after. |
| Program accounts for importance and prior results | A note beside each entry saying why that area is audited at that frequency. Two lines is enough; nothing is not. |
| Criteria and scope defined for each audit | An audit plan per audit naming the clauses and controls in scope and the criteria being tested against. |
| Auditors ensure objectivity and impartiality | A named auditor per audit plus a statement of their independence from the work being examined. |
| Results reported to relevant management | A report with findings, and minutes or an email showing it reached the people who can act on it. |
| Documented information as evidence | The program, the plans, the reports and the corrective actions raised from them, retained and retrievable. |
A clean internal audit is not the goal
An internal audit that finds nothing, run a month before a certification visit, tells the external auditor one of two things: either the audit was not deep enough, or findings were quietly fixed and never recorded. Findings with corrective actions attached are the evidence that the management system works. A first internal audit that raises five or six minor nonconformities and shows them being closed is a stronger position than a clean sheet.
Common questions
Do I have to give an email address to see the result?
No. The schedule, the day estimate and the independence assessment render on this page as soon as you finish the questions. The field underneath sends a written version formatted as a program document. Skipping it costs you nothing.
Can the person who built the management system audit it?
Not the parts they built. Clause 9.2 asks for objectivity and impartiality, and the working rule auditors apply is that nobody audits their own work. In a company of fifteen this is often unsolvable internally, and the accepted answers are a reciprocal arrangement with a colleague in another function, or an external internal auditor. Both are normal and neither is a finding.
Does every control have to be audited every year?
No. The program samples across the cycle, weighted by importance and by prior results. What does have to be covered in every cycle is the full set of clause requirements and the applicable controls, so that by the time recertification comes round nothing has gone three years unexamined.
How long does an internal audit take?
For a company under fifty people with a single product, one to two days of auditor time per audit event, plus half a day of reporting. The variable is not company size, it is how many separate processes are in scope and how much evidence has to be pulled by hand rather than exported.
What happens if we skip it before stage 2?
The audit does not proceed, or it proceeds and raises a major nonconformity. Internal audit and management review are the two clause requirements that cannot be produced on the day, which is why they appear in the internal audit page and in the stage 1 readiness check as blocking items rather than as gaps.
Get an independent internal auditor
Tell us your scope and we will put it in front of Canadian firms that do internal audits against ISO 27001.
Get matched