Skip to content

Audit

Planning an internal ISO 27001 audit that finds more than missing documents

A good audit follows requirements into decisions, samples and actual operational evidence.

Back to ISO 27001

8 minute read · Content as of 21.07.2026

Audit programme and individual audit are two levels

Over its period, the audit programme ensures that the entire scope and all relevant requirements are covered. The individual audit has a concrete objective, criteria, extent, method and sampling concept.

Check chains of effect instead of file names

An approved policy does not yet prove that the process works. Therefore follow a requirement through role, execution and evidence down to a current sample.

  • Independence and competence of the auditors
  • Risk-based focus
  • Verifiable findings instead of opinions
  • Cause-oriented corrective actions

The free audit plan sets the frame

The template contains audit objectives, criteria, scope, interview partners, samples and result logic. Then add your organisation-specific risks and past findings.

Sources used

  • ISO/IEC 27001:2022 · ISO · 2022 + Amd 1:2024
  • ISO/IEC 27007 · ISO · 2020
  • ISMS practice patterns · KaitoSec

Back to ISO 27001