What an ISO Internal Audit Requires

August 3, 2026

Written by:

Wil Seiler
Two Professionals Analyzing Data on Multiple Computer Screens
  • ISO 19011 defines an audit as obtaining and evaluating evidence to reach a judgment. That’s why a monitoring dashboard, however sophisticated, isn’t an internal audit on its own. 
  • Clause 9.2 requires the same core elements across ISO/IEC 27001, 27701, and 42001: a maintained audit program, defined criteria and scope for each audit, objective auditor selection, and documented reporting to management. 
  • ISO/IEC 27701:2019 doesn’t add a new audit clause. It extends ISO/IEC 27001’s Clause 9.2 to cover privacy information management and the organization’s role as PII controller or processor. 
  • The internal audit tests the organization’s own Statement of Applicability at a defined point in time, tracing the line from risk assessment to risk treatment to the operating controls. 

Certifying management systems for a living means watching the internal audit reveal whether a program is alive or it’s just paperwork. Organizations often bring dashboards, control-monitoring tools, and language about “continuous” and “real-time” assurance to the table. The job of a certification body is narrower and more exacting than the marketing: we look for evidence that a competent, independent person planned an audit; gathered evidence; exercised judgment; and reported findings to management. 

This opens a two-part series on what ISO requires of an internal audit under ISO/IEC 27001:2022, ISO/IEC 27701:2019 & 2025, and ISO/IEC 42001:2023. Part 1 covers why the requirement reads the same across all three standards, and where the popular shortcuts fall apart. Part 2 covers the seven principles of an audit. 

WHAT THE STANDARDS MEAN WHEN THEY SAY “AUDIT” 

ISO 19011:2026, the international guideline for auditing management systems, defines an audit as a systematic, independent process for obtaining evidence and evaluating it objectively to determine how well audit criteria are fulfilled. ISO/IEC 42001:2023 carries the same definition into its own terms clause and adds a useful note: an internal audit is a first-party audit, conducted by the organization itself or by an external party on its behalf. 

Those definitions—obtaining, evaluating, determining, judging—are things a person does, not outputs a platform generates on its own. Weighing conflicting signals, interviewing a control owner, and forming a conclusion someone is willing to defend take a person exercising judgment and accepting accountability for it. The standard describes cognition and accountability. 

THE CLAUSE 9.2 REQUIREMENT, STANDARD BY STANDARD 

The same skeleton appears in all three ISO management system standards

The information security standard requires the organization to conduct internal audits at planned intervals, to determine whether the ISMS conforms to the organization’s own requirements and to the standard, and whether it’s effectively implemented and maintained (Clause 9.2.1). Clause 9.2.2 then requires an audit program that’s planned, established, implemented, and maintained, covering frequency, methods, responsibilities, planning requirements, and reporting. Building the program means weighing the importance of the processes concerned and the results of previous audits. 

For each audit, the organization defines the audit criteria and scope, selects auditors who keep the process objective and impartial, and reports results to relevant management. Documented information must be retained as evidence of both the program and the results. 

ISO/IEC 42001:2023, Clause 9.2 

The AI management system standard mirrors this structure almost word for word. Clause 9.2.1 requires internal audits at planned intervals to determine whether the Artificial Intelligence Management System conforms to the organization’s own requirements and to the standard and whether it’s effectively implemented and maintained. Clause 9.2.2 requires the same program attributes and adds one useful word: for each audit, the organization must define the audit objectives, criteria, and scope. The reporting requirement points to relevant managers, and documented information must be retained as evidence. 

ISO/IEC 27701:2025, Clause 5.7.2 

The privacy information management extension skips restating the requirement. Clause 5.7.2 says the requirements of ISO/IEC 27001, Clause 9.2, apply, together with the interpretation given in Clause 5.1. That interpretation instruction is the whole point of 27701: wherever 27001 says “information security,” the Privacy Information Management System (PIMS) reads it as extended to cover the protection of privacy as it can be affected by the processing of personally identifiable information. The internal audit obligation is identical in mechanics. What expands is the scope of what you’re auditing, which now includes the PIMS controls and the organization’s role as Personally Identifiable Information (PII) controller, PII processor, or both. 

WHAT A CONFORMING INTERNAL AUDIT MUST CONTAIN 

Below is the checklist Clause 9.2 and ISO 19011 produce together. Pull the clause text together with ISO 19011 guidance, and a defensible internal audit program demonstrates the following. Miss one and expect a finding. 

  1. A planned interval and a maintained audit program, with frequency, methods, responsibilities, planning requirements, and reporting all defined and documented. 
  2. A program risk basis: the importance of the processes concerned and the results of previous audits factor into what gets audited and how often. 
  3. Defined audit objectives, criteria, and scope for each individual audit, agreed before fieldwork begins. 
  4. Auditor selection that keeps the process objective and impartial. Auditors don’t audit their own work. 
  5. Evidence gathered and evaluated objectively against the stated criteria, built on appropriate sampling, since an audit runs over a finite period with finite resources. 
  6. Findings and conclusions reported to relevant management, with documented information retained as evidence of both the program and the results. 
  7. A feedback loop into management review and into nonconformity and corrective action, so the audit produces action rather than an archived report. 

INTERNAL AUDIT VERIFIES THE SOA THAT THE RISK ASSESSMENT PRODUCED 

The audit traces a chain from risk to control. 

A frequent misunderstanding: the internal audit checks an organization against a generic control catalogue. The real audit criteria are the organization’s own management system, and at the center of that system sits the Statement of Applicability (SoA). The SoA is the output of the risk assessment and risk-treatment process: the organization assesses risk, decides how to treat it, and records in the SoA which Annex A controls are applicable, why, and whether they’re implemented. 

That makes the internal audit’s job concrete. It validates the SoA that the risk assessment produced. The auditor traces the line from the risk assessment, through the risk-treatment decisions, into the SoA, and out to the controls operating in the organization. Where a control is marked applicable and implemented, the auditor looks for evidence that it operates as claimed. Where a control has been excluded, the auditor looks for the documented justification. The applicability decisions come from the client’s own SoA rather than a catalogue’s suggested control set. 

Knowing what the clause requires on paper is the easier half of the problem. The harder question, covered in Part 2, is why ISO insists a person must be the one doing this work and what that means for organizations preparing for a certification audit.