Clause 9.2
Internal Audit Programme
Clause 9.2 asks for a programme, not an audit — frequency, methods, responsibilities, planning requirements and reporting, weighted by the importance of the processes concerned and by what the last audits found. A certification body reads the programme, and it reads it four times in the first cycle.
ISO 27001 Clause 9.2 Internal Audit Programme
Enter your work email for the printable programme — the audit schedule across clauses 4 to 10 and the four Annex A themes, a depth vocabulary, the auditor impartiality register, the nonconformity record, and the Stage 1 evidence gate.
Check your inbox
We've emailed you a link to download ISO 27001 Clause 9.2 Internal Audit Programme.
The link expires in 48 hours. If it hasn't arrived in a few minutes, check your spam folder.
We couldn't send the download link. Please try again, or contact us and we'll email you ISO 27001 Clause 9.2 Internal Audit Programme.
What it answers to
Five clauses, and the obligation inside each that gets missed
Clause 9.2 is short. What makes it expensive is that four other clauses have to be able to read its output, and the programme is planned before anybody knows that.
9.2.1
Two objects, and programmes reach one of them
Internal audits at planned intervals, establishing whether the ISMS conforms to the organisation’s own requirements for it and to the requirements of the standard, and whether it is effectively implemented and maintained. An audit that walks only the clauses of ISO 27001 has not reached your policies, your risk treatment decisions or your Statement of Applicability.
9.2.2
The programme, not the audit
Frequency, methods, responsibilities, planning requirements and reporting — planned taking into consideration the importance of the processes concerned and the results of previous audits. There is no single internal audit. There is a programme, and a certification body reads the programme.
9.2.2 b)
Objectivity and impartiality of the process
Auditors selected and audits conducted so as to ensure objectivity and the impartiality of the audit process. ISO 19011:2026 — the fourth edition, which cancels and replaces ISO 19011:2018 — states the principle at clause 4.6: independent of the activity being audited wherever practicable, free from bias and conflict of interest, conclusions based on the audit evidence alone.
9.3.2 / 9.3.3
The management review has to consume the output
Audit results are among the inputs the review considers, and the results of the review have to include decisions on continual improvement opportunities and on any needs for changes to the ISMS. A finding that never reached the review is a finding the review could not have acted on, and the gap between the two records is visible to anyone holding both.
10.2
Correction is not corrective action
The correction deals with the instance found; the corrective action deals with what allowed it, so that the nonconformity does not recur. A finding record carrying only the first has evidenced that a symptom was cleared — and in the 2022 edition it is 10.2 that covers nonconformity, with 10.1 covering continual improvement. The two were the other way round in 2013.
Contents
Eleven sections you write in
It is a programme, not a guide. The schedule is the page people photocopy; the finding record is the page that decides whether a nonconformity closes or comes back at Stage 2.
Programme cover sheet
Scope, cycle, the intervals you set and the reasoning behind them, and where the documented information clause 9.2.2 requires is actually retained.
Clause 9.2 as obligations
Ten lines drawn from 9.2.1 and 9.2.2, each with a write-in for the document and section that satisfies it.
The programme schedule
Clauses 4 to 10, the four Annex A themes and three cross-cutting passes, with auditor, planned window, depth and report-reference columns. The page people reuse.
A depth vocabulary
Document review, record sample, interview, observation, re-performance — what each one examines, and what the report has to record to have used it.
Auditor register
Who audits what, what they own in the ISMS, their competence evidence for those areas, and the impartiality conclusion.
The finding record
One sheet per nonconformity: requirement, audit evidence, statement of nonconformity, correction, root cause, corrective action, verification of effectiveness.
Finding register
The page that goes to the management review — and the input clause 9.2.2 requires the next programme to take into consideration.
What the certifier examines
Stage 1, Stage 2, every surveillance audit and recertification, against the ISO/IEC 17021-1:2015 clause that sends them there.
Where we sit
Your certification body is barred from doing this for you
ISO/IEC 17021-1:2015 is the standard an accreditation body assesses a certification body against. Clause 5.2.5 states that the certification body, any part of the same legal entity and any entity under its organisational control shall not offer or provide management system consultancy. Clause 5.2.6 states that it shall not offer or provide internal audits to its certified clients, the recognised mitigation being that it shall not certify a management system on which it provided internal audits for a minimum of two years after those audits complete. Clause 5.2.9 states that its activities shall not be marketed or offered as linked with the activities of an organisation providing management system consultancy.
ISO/IEC 27006-1:2024 applies the whole of that clause 5.2 to an ISMS certification body and adds one more at 5.2.2: it shall not provide internal information security reviews of the ISMS it is certifying, and shall be independent of the body or bodies — including any individuals — that provide the internal ISMS audit. Who runs your clause 9.2 programme is therefore a condition of your certifier’s own accreditation rather than a matter of preference.
Security Brigade performs the clause 9.2 internal audit as an independent party. We are not a certification body and issue no certificate — we hold one, ISO/IEC 27001 certificate AMER24908, as a certified organisation. The certificate comes from an accredited certification body, and the clauses above are why that has to be a different supplier.
Stage 1 in the diary?
Tell us your ISMS scope and your Stage 1 date. One line on the worksheet cannot be recovered by starting late — a full cycle of the programme has to have run, and its output has to have reached a management review, before that first visit concludes.
Describe your ISMS