Audit
Planning an internal ISO 27001 audit that finds more than missing documents
A good audit follows requirements into decisions, samples and actual operational evidence.
8 minute read · Content as of 21.07.2026
Audit programme and individual audit are two levels
Over its period, the audit programme ensures that the entire scope and all relevant requirements are covered. The individual audit has a concrete objective, criteria, extent, method and sampling concept.
Check chains of effect instead of file names
An approved policy does not yet prove that the process works. Therefore follow a requirement through role, execution and evidence down to a current sample.
- Independence and competence of the auditors
- Risk-based focus
- Verifiable findings instead of opinions
- Cause-oriented corrective actions
The free audit plan sets the frame
The template contains audit objectives, criteria, scope, interview partners, samples and result logic. Then add your organisation-specific risks and past findings.
Sources used
- ISO/IEC 27001:2022 · ISO · 2022 + Amd 1:2024
- ISO/IEC 27007 · ISO · 2020
- ISMS practice patterns · KaitoSec