Internal Audit Explained
Dr. Abeer Alshammari · Published 7/29/2026
IntermediateProfessionalsCISOs
Internal audit is the organization checking its own ISMS conformance before the external certification body does. It is not optional -- Clause 9.2 requires it at planned intervals, with results feeding Clause 9.3 management review.
Core requirements
- An audit programme covering frequency, methods, responsibilities, and reporting
- Audit criteria and scope defined for each audit
- Auditor objectivity and impartiality -- auditors cannot audit their own work
- Results reported to relevant management
- Findings tracked to closure, feeding corrective action under Clause 10
Why "auditors cannot audit their own work" matters in practice
In smaller organizations, this often means using a trained internal auditor from a different department, rotating audit assignments, or bringing in an external party to perform internal audits. A security manager auditing the ISMS they personally designed and run is a common independence gap that certification auditors will flag.
Try it yourself
An interactive CyberAbeer experience for this topic is in development.
Coming soon