ISO/IEC 27001:2022 Internal Audit

Independent internal audit of your ISMS – verifying it works in practice, not just on paper, ahead of certification or surveillance audits.

Why an Internal Audit Matters

ISO/IEC 27001 requires organizations to conduct internal audits of their ISMS at planned intervals – it’s a mandatory clause, not an optional extra. Beyond compliance, a well-executed internal audit is your best opportunity to catch gaps before your certification body does, protecting both your certification status and your organization’s actual security posture.

What You Get


Independent audit against all applicable ISO/IEC 27001:2022 clauses and Annex A controls, tailored to your Statement of Applicability.


Audit conducted by qualified auditors independent of your implementation team, satisfying the standard’s independence requirement and giving management an unbiased view.


Findings, non-conformities, and observations documented in the format certification bodies expect to see during Stage 2 and surveillance audits.

Methodology

  1. Audit Planning – Define audit scope, criteria, and schedule based on your ISMS and SoA.
  2. Documentation Review – Review policies, procedures, risk register, and ISMS records.
  3. Process & Control Testing – Interview process owners and test control implementation and effectiveness.
  4. Non-Conformity Identification – Document non-conformities and observations against clause and control requirements.
  5. Reporting – Deliver a formal internal audit report suitable for management review and certification body submission.
  6. Corrective Action Follow-Up – Support tracking and verification of corrective actions before the next audit cycle.

Who This Is For

Organizations that need to:

  • Fulfill the mandatory ISO/IEC 27001 internal audit requirement (Clause 9.2)
  • Prepare for Stage 2 certification or a surveillance audit
  • Get an independent view when internal resources lack audit independence
  • Verify their ISMS operates effectively, not just exists on paper
  • Address findings from a previous certification body audit

Why IO Consulting

Our team brings together certified audit expertise – CISA, CISM, ISO/IEC 27001 Senior Lead Auditor and Lead Implementer – with practical, hands-on experience in IT governance, network administration, systems administration, database administration and software development. This breadth of technical background allows us to understand client environments from the inside out, delivering audits that are both rigorous and precisely tailored to what each organization actually needs.