ISO 27001 guide · Clause 9
9.2.2 — Internal audit programme
Clause 9.2.2 requires a recurring audit programme: frequency, criteria and scope, impartial auditors, reporting to management and retained evidence.
By Sentrix · Published 2026-07-16
The requirement that turns "we should audit ourselves sometime" into a defined, repeatable programme an external auditor can actually inspect.
Mandatory requirement · Documented information required: yes
In plain language
9.2.2 requires you to plan, set up, run, and maintain an actual audit programme—not a single audit, but a recurring system that decides how often audits happen, what gets checked each time, who is qualified and independent enough to check it, and how the results get reported and kept.
Why this requirement exists
A single thorough audit tells you about one moment in time. A programme is what makes internal audit a management tool rather than a one-time compliance exercise—it forces you to decide in advance how coverage will rotate across the ISMS, so high-risk areas actually get checked on a predictable cadence instead of whichever area someone happened to have time for.
Scenario: a company’s only internal audit in two years was performed by the same person who manages the ISMS day to day, focused entirely on documentation review, with no defined criteria and no report retained. At the certification audit, the external auditor asks for the internal audit programme and finds there effectively was not one—a major nonconformity, even though individual controls were in decent shape.
What the standard expects
The standard expects the organization to plan, establish, implement, and maintain an audit programme, including the frequency, methods, responsibilities, planning requirements, and reporting—taking into account the importance of the processes concerned and the results of previous audits. For each audit, you must define the audit criteria and scope; select auditors and conduct audits that ensure objectivity and impartiality of the process; ensure results are reported to relevant management; and retain documented information as evidence of the programme and the results.
In practice
- Write a one-page audit programme document: annual frequency (or more often for higher-risk areas), scope rotation across ISMS domains, and named responsibilities.
- Ensure whoever conducts the audit is independent of the area being audited—someone from a different team, or an external contractor for smaller organizations without enough internal separation.
- Define audit criteria before each audit (which clauses, which controls, which documents) instead of improvising scope on the day.
- Produce a written report for every audit and route it to the people who can act on it, not just to a file.
Evidence the auditor will ask for
- The documented internal audit programme: frequency, scope rotation, responsibilities.
- Audit reports showing criteria, scope, findings, and who conducted each audit.
- Evidence of auditor independence—an organization chart or statement showing the auditor was not reviewing their own work.
- Records showing findings were reported to relevant management and tracked to closure.
Common pitfalls
- An auditor who reviews their own area of responsibility—the single most common finding against this sub-clause.
- A "programme" that is really just one audit, done once, with no plan for repetition or full ISMS coverage over time.
- No defined criteria before the audit—the auditor decides what to check as they go, which makes results hard to compare year over year.
Related requirements
- 9.2.1 General—the general goal this programme is built to achieve.
- 9.3 Management review—internal audit results are a required input to management review.
- Parent clause: 9.2 Internal audit.
2013 → 2022 mapping
| 2022 version | 2013 version | Nature of change |
|---|---|---|
| 9.2.1 / 9.2.2 | 9.2 Internal audit (single clause) | Split into two numbered sub-clauses; requirements largely carried over |
Sources
Frequently asked questions
- Can a small company use an external contractor for internal audits?
- Yes, and it is common practice when the organization is too small to have staff independent of the ISMS. What matters is objectivity and impartiality, not whether the auditor is an employee. The external auditor will ask for evidence of that independence—an organization chart or statement showing the auditor was not reviewing their own work.
- How often should the internal audit programme run?
- The standard does not set a fixed frequency; it asks you to take into account the importance of the processes concerned and the results of previous audits. Most organizations audit the full ISMS at least once a year, often spreading coverage across quarterly audits of different domains, with a more frequent cadence for higher-risk areas.
- Do audit criteria have to be the same every time?
- No. Criteria and scope can and should vary by audit, targeting different processes or controls, as long as the overall programme provides full ISMS coverage over time. What matters is defining them before each audit—which clauses, which controls, which documents—instead of improvising scope on the day.
Related pages
ISO 27001 guide · Clause 9
9.2 — Internal audit
Clause 9.2 requires a periodic, independent internal audit checking that the ISMS conforms to your rules and to the standard, run through a defined programme.
ISO 27001 guide · Clause 9
9.2.1 — General
Clause 9.2.1 sets the goal of internal audits: confirm at planned intervals that the ISMS meets your requirements and the standard, and is really implemented.
ISO 27001 guide · Clause 9
9.3 — Management review
Clause 9.3 requires top management to formally review the ISMS at planned intervals, against a defined set of inputs, and come away with documented decisions.
Let's talk about your compliance program.
Last updated: 2026-09-17
