Key Takeaways:
- ISO 19011’s seven principles, including integrity, independence, and due professional care, describe judgment and ethics that belong to a person.
- ISO/IEC 17021-1 requires certification bodies to evaluate whether internal audits and management reviews are planned and performed before a client can proceed past the readiness review.
- ISO/IEC 27006-1:2024 states plainly that a certification body can’t certify an ISMS without evidence that internal audits and management reviews are implemented, effective, and maintained.
Part 1 of this series walked through what Clause 9.2 requires of an internal audit across ISO/IEC 27001, 27701, and 42001 and how that audit validates the Statement of Applicability that your risk assessment produced.
Part 2 asks the harder question: why does a competent, independent person need to be the one doing it? ISO 19011 answers with seven principles. Certification bodies like ours treat them as a gate on the road to certification.
THE SEVEN PRINCIPLES THAT MAKE IT AN AUDIT
ISO 19011:2026 grounds all auditing in seven principles. They’re the reason a human being, not a script, sits at the center of the activity.
- Integrity: the foundation of professionalism. Auditors work ethically, honestly, and only within their competence.
- Fair presentation: the obligation to report truthfully and accurately, including obstacles and unresolved disagreements.
- Due professional care: diligence and reasoned judgment matched to the importance of the task and the confidence placed in the auditor.
- Confidentiality: discretion in the use and protection of information acquired during the audit.
- Independence: the basis for impartiality. For internal audits, auditors should be independent of the function being audited where practicable; in small organizations, every effort goes toward removing bias and conflict of interest.
- Evidence-based approach: the rational method for reaching reliable, reproducible conclusions, using verifiable evidence and appropriate sampling.
- Risk-based approach: planning, conducting, and reporting audits so they focus on what’s significant to the audit client and the management system objectives.
Most of these principles rest on judgment, ethics, and independence. A monitoring tool can be evidence-based and tuned toward risk. Integrity, due professional care, and independence from the function being reported on belong to a person.
WHY THE CERTIFICATION BODY CARES SO MUCH
From the certification body’s chair, the internal audit is evidence we’re required to evaluate before we can certify. ISO/IEC 17021-1:2015 requires the audit team to evaluate, during the readiness review, whether internal audits and management reviews are being planned and performed, and whether the level of implementation shows the client is ready to proceed. The internal audit and management review process becomes a specific input the audit team examines when conducting the certification audit and forming its conclusions.
ISO/IEC 27006-1:2024, the standard governing bodies that certify information security management systems (ISMS), states the point without ambiguity: the certification body shall not certify an ISMS unless there’s sufficient evidence that arrangements for management reviews and internal ISMS audits have been implemented, are effective, and will be maintained across the scope of certification. A dashboard, however sophisticated, doesn’t satisfy this clause on its own. The internal ISMS audit the clause requires is the human process described in Part 1, with a monitoring feed serving only as an input to it.
WHAT WE EXPECT TO SEE WHEN WE ARRIVE
Preparing for a certification audit comes down to five habits.
- Treat continuous monitoring as an input to the internal audit. Let the tool identify anomalies, trends, and potential areas of concern, then have a competent auditor decide what they mean against your criteria.
- Assign auditors who are independent of the areas they audit. If your organization is small, document the measures used to minimize conflicts of interest and bias when full independence wasn’t practicable.
- Anchor every audit to the applicable ISMS criteria and current Statement of Applicability. ISO/IEC 27002, a predetermined control catalogue, and prior versions of your own SoA are not a substitute for the organization’s defined audit criteria.
- Retain the documented evidence: the audit program, the audit plans, the criteria and scope for each audit, the findings, and the reports to management. These records should provide sufficient evidence that the audit was planned, performed, and completed as required.
- Close the loop on control ownership, management review, cause evaluation, and corrective action so the audit demonstrably drives continual improvement and follow-up activities.
The internal audit is the most human part of a management system, which is exactly why it carries so much weight in the certification decision. Tools can make an auditor faster, better informed, and more consistent, but the evaluation of evidence and determination of conformity still require competent human judgment.
When ISO/IEC 27001, 27701, and 42001 say “conduct internal audits,” they’re asking a competent, independent person to do the auditing and to be able to demonstrate how objectivity and impartiality were maintained.