ISO 27001 · the internal audit programme
The internal audit programme, written from five answers
Clause 9.2 wants a programme, not a one-off: how often the company audits itself, against what, by whom, how and where the results go, written below from five answers with the 7 clause sections and the 4 Annex A themes of 93 controls spread over the year's audits, so that every part of the system is audited at least once a year by someone who did not build it.
The schedule for 2026
The clause sections and the Annex A themes spread over the audits in order, each at least once a year; a control excluded in the Statement of Applicability is audited for its justification, not its operation.
Audit 1: October 2026
- 4: Context of the organization (4 clauses)
- 5: Leadership (3 clauses)
- 6: Planning (5 clauses)
- 7: Support (5 clauses)
- 8: Operation (3 clauses)
- 9: Performance evaluation (4 clauses)
Audit 2: April 2027
- 10: Improvement (2 clauses)
- Annex A, Organizational (37 controls)
- Annex A, People (8 controls)
- Annex A, Physical (14 controls)
- Annex A, Technological (34 controls)
The programme
# Internal audit programme: [company] Programme owner: [the programme owner] · Approved by: [top management] · Year: 2026 Written on with the free page on getstandardos.com against Clause 9.2 of ISO/IEC 27001:2022. The wording is StandardOS's own; the clause and theme headings are its descriptions, not the standard's text. ## Purpose and criteria The internal audits check whether the information security management system of [company] meets the requirements of ISO/IEC 27001:2022 and the company's own requirements, and whether it is implemented and maintained as written. The criteria for every audit are the standard, the scope statement, the information security policy and the policies under it, the risk treatment plan and the Statement of Applicability in force on the audit date. ## Frequency and coverage Two internal audits a year share the system between them: the 7 clause sections and the 4 Annex A themes of 93 controls are spread over the two audits so that every section and every theme is audited at least once a year, with the controls sampled by theme. An audit is added when a significant change, an incident or a customer's finding calls for one. ## Auditors and independence The audits are performed by people of [company] trained for it, chosen for each audit so that nobody audits work they own or perform; where the team is too small for that on a topic, that topic is audited by an external auditor. An auditor never audits a control they operate, a policy they own or a record they produced. The audit is against evidence: a claim without a record is a finding, not a pass. ## Methods - Document review: the policy, the procedures and the Statement of Applicability read against the criteria before the audit. - Interviews: the owners of the clauses and controls in scope, asked to show rather than tell. - Sampling of records: access reviews, incidents, supplier evaluations, training records and change records, sampled across the period. - Observation of systems: configurations, logs and settings checked where the control lives in a system, not in a document. ## The schedule for 2026 Each audit covers the sections and themes below; the plan for each audit, with its dates, auditor and the records sampled, is written two weeks before it. ### Audit 1: October 2026 - 4: Context of the organization (4 clauses) - 5: Leadership (3 clauses) - 6: Planning (5 clauses) - 7: Support (5 clauses) - 8: Operation (3 clauses) - 9: Performance evaluation (4 clauses) ### Audit 2: April 2027 - 10: Improvement (2 clauses) - Annex A, Organizational (37 controls) - Annex A, People (8 controls) - Annex A, Physical (14 controls) - Annex A, Technological (34 controls) ## Reporting and follow-up Each audit ends in a written report to [the programme owner] and to top management within two weeks, listing the evidence seen, the findings as nonconformities or observations with the clause or control they touch, and the good practice noted. Every nonconformity enters the corrective action process with an owner and a date; the findings and their status are an input of the next management review. ## Records This programme, each audit plan, each report and the evidence of the corrective actions are kept as documented information of the management system, versioned and available to the certification body. Approved by [top management] on [date]. Reviewed at the management review and whenever the scope, the risks or the results of the audits call for a change. This programme is written from the answers given. It is not certification advice; the certification body reads the programme, the plans and the reports at the audit, and the record it accepts is the one the company keeps.
StandardOS runs the programme it writes
In StandardOS the programme is a calendar: each audit has its date, its scope, its auditor and its checklist drawn from the clause register and the Statement of Applicability, the findings become corrective actions with owners, and the results flow into the management review without being retyped.
The Statement of ApplicabilityThe Annex A controlsThe clauses, one by one