ISO 27001 Internal Audit

Frequently Asked Questions

What is an ISO 27001 internal audit?

An internal audit is quite simply an opportunity for an organisation to take an ‘inwards look’ to assess...

Read more

How can your organisation meet the internal auditing requirement of ISO 27001?

The ISO 27001 Standard requires that internal audits are conducted at planned intervals.  On the face of it...

Read more

How can an organisation conduct internal audits on an ISMS to comply with ISO 27001?

Your organisation should aim to conduct internal audits on the mandatory clauses of the Standard...

Read more

What are the ISO 27001 requirements for an internal audit?

Requirements for conducting internal audits are contained within Clause 9.2 of the Standard.  This Clause states...

Read more

What is the ISO 27001 internal audit process?

The process of conducting an audit typically involves the ‘check’ element of the Plan-Do-Check-Act...

Read more

Does ISO 27001 require internal audits to be conducted?

Yes - Clause 9.2 of the Standard makes this requirement explicit.  Remember, you must...

Read more

With ISO 27001, what do you audit against?

Organisations are required to conduct audits to provide evidence of conformance to:...

Read more

Who can perform an internal audit for ISO 27001?

The value that an internal audit brings to your organisation will be influenced significantly by...

Read more

Does an internal audit need to be conducted by someone internal to your organisation?

No, internal audits can be conducted by third parties, such as URM...

Read more

What are the pros and cons of using a third-party organisation?

Pros include impartiality, knowledge of the Standard and expectations of certification body...

Read more

How do you conduct an internal ISO 27001 audit?

The responsibility to conduct an audit will typically be delegated by a member of the organisational...

Read more

How do you develop an internal audit checklist for ISO 27001?

Internal audit checklists are sourced directly from the audit criteria.  The Standard, or the ISMS will...

Read more

Are standards on internal audit mandatory?

The International Organization for Standardization (ISO) has produced a specific...

Read more

What standards do internal auditors use?

Whilst ISO 19011 is not mandatory, it is recommended that auditors align to this guidance...

Read more

What are some of the traits or characteristics of an effective auditor?

Here are some valuable traits and characteristics of an effective auditor...

Read more

Who are the typical auditees in an ISO 27001 internal audit?

During an internal audit, an auditor will need to speak to people at different levels and authorities...

Read more

What are the different types of ISO 27001 audits?

There are 3 types of ISO 27001 audits:...

Read more

How do you prepare for an ISO internal audit?

In order to prepare for an audit, the following steps should be taken...

Read more

What are the pitfalls to avoid in conducting ISO 27001 audits?

Some pitfalls to avoid when organising and conducting an ISO 27001 audit include...

Read more

What are the different levels of findings/nonconformities?

There are 3 levels of findings which may result from an audit...

Read more

What is the difference between a minor and major nonconformity?

A minor nonconformity is a single or non-critical failure of the ISMS, whereas a major nonconformity is...

Read more

How do you ensure consistency in internal auditing?

To maintain consistency in internal auditing, organisations should implement an internal audit process...

Read more

Stay in the loop

Please provide your contact details and we will email you with any future changes to ISO 27001 (and the implications!).

5 Must-Dos of Effective ISO 27001 Risk Management

Published on
7 Aug
2026

URM’s blog explores five key actions organisations can take to strengthen their ISO 27001 information risk management processes.

Read more
Thumbnail of the Blog Illustration
Information Security
published on
7/8/2026
The Fundamentals of Risk Management in ISO 27001

URM’s blog explains the risk management requirements in ISO 27001, including identifying ISMS risk, risk assessment and treatment, documentation and more

Read more
Thumbnail of the Blog Illustration
Information Security
published on
4/8/2026
ISO 27001 Clause 10.2: Nonconformity and corrective action

URM’s blog explains how to meet ISO 27001 Clause 10.2, including finding nonconformities, performing root cause analysis, implementing corrective actions & more

Read more
Thumbnail of the Blog Illustration
Information Security
published on
30/7/2026
ISO 27001 Clause 7.4: Communication

URM’s blog explains ISO 27001 communications requirements, their links to interested parties, & how both can be addressed through a single framework.

Read more
"
Our URM consultant was most helpful. Very constructive with her thoughts. She completely understood the technology we are using to monitor the ISMS, which allowed her to fully appreciate the documentation.
contact US

Let us help you

Let us help you in your compliance journey by completing the form and letting us know how we can best support you.