Skip to content
Log inRegister

Internal Audit Explained

Dr. Abeer Alshammari · Published 7/29/2026

IntermediateProfessionalsCISOs

Internal audit is the organization checking its own ISMS conformance before the external certification body does. It is not optional -- Clause 9.2 requires it at planned intervals, with results feeding Clause 9.3 management review.

Core requirements

  • An audit programme covering frequency, methods, responsibilities, and reporting
  • Audit criteria and scope defined for each audit
  • Auditor objectivity and impartiality -- auditors cannot audit their own work
  • Results reported to relevant management
  • Findings tracked to closure, feeding corrective action under Clause 10

Why "auditors cannot audit their own work" matters in practice

In smaller organizations, this often means using a trained internal auditor from a different department, rotating audit assignments, or bringing in an external party to perform internal audits. A security manager auditing the ISMS they personally designed and run is a common independence gap that certification auditors will flag.

Try it yourself

An interactive CyberAbeer experience for this topic is in development.

Coming soon
Back to insights