5.2 ISMS Internal Audit Program & Principles (Clause 9.2 & ISO 19011)

Key Takeaways

  • ISO/IEC 27001 Clause 9.2 mandates conducting internal audits at planned intervals to determine whether the ISMS conforms to organization requirements and ISO 27001, and is effectively implemented.
  • ISO 19011 provides the international standard guidelines for auditing management systems, establishing seven core audit principles.
  • Auditors must maintain absolute objectivity and impartiality; Clause 9.2 explicitly requires that auditors shall not audit their own work.
  • An Internal Audit Program encompasses the governance, planning, resources, and schedule for conducting one or more audits within a specified timeframe.
  • Audit program managers must systematically manage audit risks, such as inadequate auditor competence, scope creep, and resource constraints.
Last updated: July 2026

5.2 ISMS Internal Audit Program & Principles (Clause 9.2 & ISO 19011)

Internal auditing is a core governance mechanism within an ISO/IEC 27001 Information Security Management System (ISMS). Clause 9.2 (Internal audit) requires the organization to conduct internal audits at planned intervals to provide objective assurance that the ISMS conforms to both the organization’s own requirements for its ISMS and the requirements of ISO/IEC 27001:2022, and is effectively implemented and maintained. To plan and execute an effective audit program, Lead Implementers must master the guidance standard ISO 19011:2018 (Guidelines for auditing management systems).


1. Clause 9.2 Requirements & Audit Objectives

ISO/IEC 27001 Clause 9.2 is split into two sub-clauses: 9.2.1 (General) and 9.2.2 (Internal audit programme).

Mandatory Audit Scope & Objectives (Clause 9.2.1)

An internal audit must objectively determine whether the ISMS:

  1. Conforms to:
    • The organization’s own requirements for its ISMS (internal security policies, baseline standards, contractual security obligations).
    • The requirements of the ISO/IEC 27001 standard (Clauses 4 through 10 and selected Annex A controls).
  2. Is effectively implemented and maintained (controls are actively executed, operationalized, and consistently enforced).

Mandatory Audit Program Management (Clause 9.2.2)

The organization must establish, implement, and maintain an internal audit program. Clause 9.2.2 explicitly mandates:

  • Planning, establishing, implementing, and maintaining audit programs including frequency, methods, responsibilities, planning requirements, and reporting.
  • Taking into consideration the importance of the processes concerned and the results of previous audits.
  • Defining audit criteria and scope for each audit.
  • Selecting auditors and conducting audits to ensure objectivity and impartiality of the audit process.
  • Ensuring audit results are reported to relevant management.
  • Retaining documented information as evidence of audit program implementation and audit results.

2. ISO 19011: The Seven Principles of Auditing

ISO 19011 defines auditing as a "systematic, independent and documented process for obtaining audit evidence and evaluating it objectively to determine the extent to which audit criteria are fulfilled." To guarantee that audit conclusions are reliable, relevant, and sufficient, ISO 19011 establishes seven fundamental principles:

#PrincipleDescription & Lead Implementer Application
1IntegrityThe foundation of professionalism. Auditors must perform work with honesty, diligence, responsibility, and observe all legal requirements.
2Fair PresentationThe obligation to report truthfully and accurately. Audit findings, conclusions, and reports must reflect truthfully and precisely the audit activities and evidence.
3Due Professional CareThe application of diligence and judgment in auditing. Auditors must exercise care corresponding to the importance of the task and confidence placed in them.
4ConfidentialitySecurity of information. Auditors must exercise discretion in the use and protection of information acquired in the course of their duties.
5IndependenceThe basis for impartiality and objectivity of audit conclusions. Auditors must be independent of the activity being audited wherever practicable, and free from bias and conflict of interest.
6Evidence-Based ApproachThe rational method for reaching reliable audit conclusions. Audit evidence must be verifiable and based on samples of available information.
7Risk-Based ApproachAn audit approach that considers risks and opportunities. Audit planning must focus on matters that are significant for the ISMS and organizational security goals.

Critical Exam Rule: Auditors shall not audit their own work. For example, an Information Security Officer who authored the organizational Access Control Policy or configured the corporate firewall cannot serve as the internal auditor for Access Control (Clause 9.2.2 requirement for impartiality).


3. Establishing and Managing the Audit Program

An Audit Program (governed by ISO 19011 Clause 5) is the overarching arrangements for a set of one or more audits planned for a specific timeframe and directed towards a specific purpose.

┌───────────────────────────────────────────────────────────┐
│                  ANNUAL AUDIT PROGRAM                     │
│  (Scope: Entire ISMS, Multi-site, High-Risk Processes)   │
└─────────────────────────────┬─────────────────────────────┘
                              │
        ┌─────────────────────┼─────────────────────┐
        ▼                     ▼                     ▼
┌───────────────┐     ┌───────────────┐     ┌───────────────┐
│ Audit Plan Q1 │     │ Audit Plan Q2 │     │ Audit Plan Q4 │
│ Access Control│     │ Incident Resp.│     │ Cloud Security│
└───────────────┘     └───────────────┘     └───────────────┘

Key Components of an Audit Program

  1. Program Objectives: Aligning audit priorities with organizational risks (e.g., verifying compliance of cloud infrastructure following migration).
  2. Program Scope: Establishing physical sites, logical boundaries, business units, and Clauses/Annex A controls included.
  3. Audit Schedule & Frequency: Determining how often specific areas are audited. High-risk areas (e.g., Privileged Identity Management) may be audited semi-annually, whereas low-risk administrative processes may be audited annually.
  4. Audit Methods: Remote audits, on-site physical audits, automated compliance testing, hybrid execution.
  5. Resource Allocation: Budgeting auditor days, assigning qualified internal staff or contracted third-party audit specialists.

4. Auditor Selection, Independence & Competency

To satisfy Clause 9.2.2, audit program managers must systematically select auditors based on defined competency criteria combining general auditing skills with domain-specific information security technical knowledge.

Auditor Competency Matrix (ISO 19011 Clause 7)

                       ┌───────────────────────────────┐
                       │   TOTAL AUDITOR COMPETENCE    │
                       └───────────────┬───────────────┘
                                       │
         ┌─────────────────────────────┴─────────────────────────────┐
         ▼                                                           ▼
┌─────────────────────────────────┐         ┌─────────────────────────────────┐
│   GENERIC AUDITING COMPETENCE   │         │ TECHNICAL SECURITY COMPETENCE   │
├─────────────────────────────────┤         ├─────────────────────────────────┤
│ • Audit principles & procedures │         │ • ISO/IEC 27001 standard knowledge│
│ • Evidence gathering methods    │         │ • Technical control awareness   │
│ • Interviewing technique        │         │ • Threat & risk assessment models│
│ • Report writing clarity        │         │ • Legal & regulatory landscape  │
└─────────────────────────────────┘         └─────────────────────────────────┘

Managing Independence Constraints in Small Organizations

Small organizations often struggle with auditor independence due to limited staff. Approved strategies include:

  • Cross-Auditing: Department A audits Department B, and Department B audits Department A.
  • Reciprocal Auditing: Peer organizations audit each other's ISMS under non-disclosure agreements.
  • Outsourced Co-Sourcing: Engaging an independent third-party consultant to conduct internal audits.

5. Managing Audit Program Risks & Opportunities

ISO 19011 requires the audit program manager to identify and manage risks that could impact the achievement of audit program objectives:

  • Planning Risks: Failing to allocate sufficient audit time or failure to account for peak operational cycles.
  • Resource Risks: Assigning auditors without technical competence in cloud environments or specialized database security.
  • Communication Risks: Ineffective escalation paths for critical vulnerabilities identified during audit fieldwork.
  • Auditor Bias Risks: Loss of objectivity due to familiarity with audited staff.

6. Implementation Scenario: Designing a Risk-Based Audit Schedule

Context

FinTech Pay Corp operates an ISO 27001 certified payment gateway. During the last 6 months, significant changes occurred: the core database was migrated to AWS Cloud, and a major security incident occurred in vendor access management.

Audit Program Manager Decision

Applying Clause 9.2.2 (which requires considering the importance of processes and results of previous audits), the Audit Program Manager revises the annual internal audit program:

  1. High Priority (Q1 Audit): AWS Cloud Infrastructure Access & Configuration (Annex A 8.22, 8.24) and Vendor Relationship Management (Annex A 5.19, 5.21) scheduled for immediate, deep-dive technical audit.
  2. Medium Priority (Q2 Audit): Cryptographic Controls (Annex A 8.24) and Incident Management (Annex A 5.24).
  3. Low Priority (Q4 Audit): Physical Security of Corporate Headquarters (Annex A 7.1) — low risk due to remote workforce model and clean historical audit results.
Test Your Knowledge

A senior security engineer who designed and implemented the organization's cloud access control architecture is assigned to serve as the internal auditor for Clause 9.2 audit of Access Control (Annex A 8.2). How should the ISMS Audit Program Manager respond to this assignment under ISO/IEC 27001?

A
B
C
D
Test Your Knowledge

Which of the seven ISO 19011 audit principles forms the rational foundation for reaching reliable and reproducible audit conclusions in an ISMS internal audit?

A
B
C
D
Test Your Knowledge

Under ISO/IEC 27001 Clause 9.2.2, which two mandatory factors must an organization explicitly take into consideration when establishing its internal audit program schedule and frequency?

A
B
C
D