ISO 27001:2022 Internal Audit Guide

In the quest to help organizations approach ISO 27001, I’ve added an ISO 27001 Internal Audit Guide to the toolbox. Because it closely aligns with the standard’s details, I cannot share the link to the tool itself. What I can and will do is share the driving idea and structure, with illustrations.

The guide does not replace the need to have and read the ISO 27001:2022 (Information security, cybersecurity and privacy protection — Information security management systems — Requirements) and ISO 27002:2022 (Information security, cybersecurity and privacy protection — Information security controls) documents. Nor does it replace the need for formal training for internal auditors. 

Hopefully, this article will help dispel some of the perceived complexity and magic surrounding ISO 27001. In fact, there is no magic at all. ISO 27001 is the international standard for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS), just as ISO 9001 is for a QMS (Quality Management System).

ISO standards can seem overwhelming at first glance, but the good news is that many of them share the same logical structure. Should you have followed this blog since 2021, you may recall the article “ISO 9001:2015 in a nutshell“. As stated in that article, a number of ISO’s international standards, including ISO 9001:2015, share the same structure, called HLS (High Level Structure) or Annex SL, which contains 10 clauses. This includes ISO 27001:2022.

The High Level Structure and PDCA

HLS_full

The ISO 27001 Internal Audit Guide provides an overview of clauses 4-10:

Planning

Operation

Performance and Evaluation

9 - Performance 27001_full

Improvement

Clause 10_full

Annex A Controls

Annex A - Controls_full

What is mandatory and what is not

Mandatory: ISO 27001 requires you to

    • Perform a risk assessment.
    • Select appropriate controls to treat identified risks.
    • Produce a Statement of Applicability (SoA) that:
      • Lists all Annex A controls,
      • States whether each control is included or excluded, and
      • Provides a justification for each decision.

This is explicitly required by Clause 6.1.3 d). Annex A is a reference catalog, not a checklist, and the SoA must justify each control’s inclusion or exclusion.

produce a Statement of Applicability that contains:

    • the necessary controls
    • justification for their inclusion
    • whether the necessary controls are implemented or not
    • the justification for excluding any of the Annex A controls.

ISO 27001 Clause 6.1.3 d)

ISO 27001 does not prescribe any mandatory template or format for the Statement of Applicability (SoA).

Not mandatory: You do not have to implement all Annex A controls. Controls are selected based on your risk assessment, not because Annex A says so. Annex A is a set of safeguards to consider, not mandatory requirements.

To conclude: ISO 27001 is risk‑based, not control‑based. Annex A is a reference list, not a mandatory implementation list.

Internal Audit Lifecycle (ISO 19011)

The Connection to ISO 27001: While Clause 9.2 (Internal audit) is the mandatory requirement dictating that you must conduct impartial audits at planned intervals, the ISO 19011 standard provides definitive best-practice guidelines on how to manage the audit program, structure the audit lifecycle, and execute those audits effectively.

The 7 Principles of ISO 19011

ISO 19011 principles_full

Mandatory documented information

To pass an ISO 27001:2022 audit, an auditor will explicitly look for “documented information” across these specific clauses.

Core ISMS Documentation (The Foundation)

Risk Management Documentation (The Engine)

Risk management documentation_full

Mandatory Records and Evidence (The Proof)

Annex A Specific Documents

Annex A specific documents_full

Recommended ISMS structure

A well-organized Information Security Management System (ISMS) relies on a clear hierarchy of documentation.

While ISO 27001 does not strictly mandate this specific 4-tier structure, it is the globally recognized best practice for aligning high-level management intent with day-to-day operations.

ISMS details_full

The audit checklist

While the ISO/IEC 27001 standard is written chronologically from Clause 4 to Clause 10, an auditor rarely conducts an audit in that exact sequential order.

The suggested “Phases” in the Audit Checklist represent a practical, logical workflow for how an auditor actually investigates an Information Security Management System (ISMS) in the real world. Instead of blindly following the clause numbers, the phases group highly interconnected requirements together based on the Plan-Do-Check-Act (PDCA) cycle:

Phases:Context, Leadership & Planning (The Foundation)Risk Management (The Engine)Support & Operations (Execution)Evaluation & Improvement (The Safety Net)Technical Sampling (The Ground Truth)
What it refers toClauses 4, 5, and parts of 6.The intersection of Clauses 6.1.2, 6.1.3, and 8.2, 8.3.Clauses 7 and 8.1.Clauses 9 and 10.Annex A (Themes 5-8).
RationaleAn auditor must first understand what the organization does, what the boundaries of the ISMS are, and whether Top Management actually supports it before looking at anything technical.Risk management is the beating heart of ISO 27001. An auditor evaluates this as one continuous, end-to-end story: identifying the risk, assessing it, choosing a treatment, and producing the Statement of Applicability (SoA).Once the plan and risks are understood, the auditor checks if the organization actually has the budget, the trained personnel, the communication plans, and the day-to-day procedures to execute the security plan.An ISMS doesn't have to be perfect; it has to be self-correcting. The auditor checks if the organization measures its own performance, conducts its own internal audits/management reviews, and effectively fixes nonconformities (CAPAs) when things break.After the core management system (Clauses 4-10) is verified, the auditor hits the floor. They sample the specific technical, physical, and organizational controls declared in the SoA (like firewalls, backups, and physical locks) to ensure the technical reality matches the management policies.

Below you’ll find examples of how the audit checklist is used across the five phases in the Internal Audit Guide. The design of the audit cards is intended to mimic the workflow in actual audits, including full traceability.

4.1 27001_full
7.4 27001_full
9.2 27001_full
10.2 27001_full

The suggested phase 5 includes a significant number of checks, not all of which are shown here.

Phase 5 - 27001_full
5.9 27001_full_v2

Knowledge test

In the quest to accelerate insights, the audit guide includes a knowledge test section. A good knowledge test shouldn’t feel like a multiple-choice formality; it should force the internal auditor to carefully distinguish between what ISO 27001 actually requires and common best-practice assumptions or ISO 27002 implementation guidance.

The guide currently includes 20 questions. Here is an example:

Q1 27001_full

Wrap-up

Yes, Annex A is relatively big, and ISO 27002 is bigger. But still no magic. If you have an analytical and structural approach, it is straightforward and a lot of work to get your ISMS in great shape.

Just hard work, no magic, no rocket science.