ISO 27001 guide · Clause 9
9.2.1 — General
Clause 9.2.1 sets the goal of internal audits: confirm at planned intervals that the ISMS meets your requirements and the standard, and is really implemented.
By Sentrix · Published 2026-07-16
Two things an internal audit has to confirm: that the ISMS follows its own rules, and that it actually works—not just one or the other.
Mandatory requirement · Documented information required: no
In plain language
9.2.1 sets the goal internal audits must achieve: at planned intervals, confirm that the ISMS meets both your own requirements and the requirements of the standard, and that it is genuinely implemented and kept up to date—not just documented on paper.
Why this requirement exists
There is a real difference between an ISMS that looks correct on paper and one that is actually followed. This requirement targets both: conformity (does the documentation match the standard and your own stated rules?) and effective implementation (do people actually do what the documentation says?). An audit that only checks one of the two misses half the picture.
Scenario: a policy states that access reviews happen quarterly. An audit that only reads the policy document would find it conforming. An audit that also checks whether the last four quarterly reviews were actually performed and evidenced might find that only one of the last four happened—a conformity pass hiding an implementation failure.
What the standard expects
The standard expects internal audits to be conducted at planned intervals, providing information on whether the ISMS conforms both to the organization’s own requirements for its information security management system and to the requirements of the standard, and whether the ISMS is effectively implemented and maintained. This dual test—conformity and effectiveness—is what the programme in 9.2.2 is built to deliver on a repeatable basis.
In practice
- Design audit checklists that ask both "does the document say this?" and "does the evidence show it actually happens?"
- Sample actual records (recent access reviews, recent backup logs) rather than trusting the policy statement alone.
Evidence the auditor will ask for
- A record showing internal audits actually happened at planned intervals, not just that a plan existed.
- Findings that address effective implementation, not only documentation conformity.
Related requirements
- 9.2.2 Internal audit programme—the concrete programme that delivers on this general expectation.
- 9.3 Management review—audit results feed directly into what leadership reviews.
- Parent clause: 9.2 Internal audit.
Sources
Frequently asked questions
- Does 9.2.1 require its own separate document?
- No. It is usually satisfied by showing that your internal audit programme (9.2.2) and its results actually test both conformity and effective implementation. The auditor will ask for a record showing audits actually happened at planned intervals, not just that a plan existed, and for findings that address effective implementation.
- What does an internal audit have to confirm?
- Two things, not just one or the other: that the ISMS conforms to your own requirements and to the standard’s, and that it is genuinely implemented and maintained. An audit that only reads a quarterly access review policy will find it conforming; an audit that checks whether the last four reviews actually happened tests implementation.
- How do you test effective implementation?
- Design checklists that ask both "does the document say this?" and "does the evidence show it actually happens?", then sample actual records—recent access reviews, recent backup logs—rather than trusting the policy statement alone. That dual test is what the programme in 9.2.2 has to deliver on a repeatable basis.
Related pages
ISO 27001 guide · Clause 9
9.2 — Internal audit
Clause 9.2 requires a periodic, independent internal audit checking that the ISMS conforms to your rules and to the standard, run through a defined programme.
ISO 27001 guide · Clause 9
9.2.2 — Internal audit programme
Clause 9.2.2 requires a recurring audit programme: frequency, criteria and scope, impartial auditors, reporting to management and retained evidence.
ISO 27001 guide · Clause 9
9.3 — Management review
Clause 9.3 requires top management to formally review the ISMS at planned intervals, against a defined set of inputs, and come away with documented decisions.
Let's talk about your compliance program.
Last updated: 2026-09-17
