Skip to content

Internal audit and management review without the theatre

5 min read Last checked on

ISO 27001 requires internal audits in clause 9.2 and a management review in clause 9.3, both at planned intervals. For a company of 10 to 100 people, an audit programme that covers the whole scope over a few years and one management review a year is usually enough. Findings are followed up under clause 10.2.

ISO 27001 requires internal audits in clause 9.2 and a management review in clause 9.3, both at planned intervals. Together they are how the ISMS checks itself. They turn into theatre when they exist only for the auditor: an audit that finds nothing, a review that decides nothing. For a company of 10 to 100 people they can be smaller and more useful.

What the standard asks

In our own words, without reproducing the standard:

Clause Subject What it means in practice
9.2 Internal audit Checking at planned intervals whether the ISMS meets your own requirements and the standard, and whether it works, following an audit programme.
9.3 Management review Top management checks at planned intervals whether the ISMS is still suitable, adequate and effective, and decides on improvements.
10.2 Nonconformity and corrective action Fixing problems, removing their cause and checking that this worked.

For all three you keep a record of what happened. To a certification body, an audit without a record did not take place.

The audit programme

An audit programme is the multi-year plan for your internal audits. The standard asks you to set out how often you audit, which methods you use, who is responsible and how you report. For each audit you define the criteria and the scope in advance.

For a software company, organising the programme around your own processes works better than around the 93 Annex A controls. An example for a SaaS provider:

  1. Development and change management, every year.
  2. Hosting, backups and recovery, every year.
  3. Access management, joiners and leavers, every year.
  4. Suppliers and cloud services, every other year.
  5. Incident management and continuity, every other year, possibly combined with a tabletop exercise.
  6. The management system clauses 4 to 10, every year.

That way the whole scope is covered within a few years, and the areas with the highest risks get attention more often. Spread the audits over the year rather than squeezing everything into the month before the external audit. For a company this size, half a day per subject is usually enough.

Independence

The standard asks for auditors who are objective and impartial. The practical consequence is that nobody audits their own work. With 10 to 100 people there are three common solutions:

  • Cross-auditing. The development lead audits hosting, the platform engineer audits access management. This works if both have had some basic auditor training.
  • External. A freelance auditor or consultant runs the programme. It costs money, but brings a fresh pair of eyes.
  • Mixed. External for the management system clauses and for the areas the security officer owns, internal for the rest.

The security officer who runs the ISMS therefore cannot audit the ISMS independently. ISO 19011, the guideline for auditing management systems, is a good resource for anyone learning the craft. The current edition dates from 2026.

An audit without the theatre

A useful audit tests reality, not documents. Take a sample: three recent pull requests, two people who left the company, the latest restore test. Ask for the evidence, talk to the people doing the work and compare that with what the procedure says. An audit that finds nothing more often points to a shallow audit than to a perfect ISMS.

Keep the report short: what was tested, which sample, which findings, and what went well. The report goes to the responsible manager and feeds the management review.

What a management review covers as a minimum

Clause 9.3 lists the topics that must be covered. In our own words:

  1. The status of actions from the previous management review.
  2. Changes outside and inside the organisation that affect the ISMS, such as a new service or new legislation.
  3. Changes in what interested parties expect of you, such as customers asking for NEN 7510, the Dutch healthcare information security standard.
  4. How security is performing: nonconformities and corrective actions, measurement results, audit results and progress on objectives.
  5. Feedback from interested parties, such as customer questions and complaints.
  6. The results of the risk assessment and the status of the risk treatment plan.
  7. Opportunities for improvement.

The outcome must contain decisions: on improvements and on changes to the ISMS. Minutes that only say "discussed" are not a review. Once a year is usually enough, with an agenda running through the seven topics and a decision log with an owner and a date for each item. That fits into ninety minutes if the security officer prepares it well.

Following up findings

Clause 10.2 describes what you do with a nonconformity, whether it comes from an internal audit, an incident or a customer:

  1. Correct. Fix the immediate problem, for example by revoking a former employee's account.
  2. Find the cause. Why did it happen? For example: HR does not notify IT when people leave.
  3. Look wider. Does the same thing happen elsewhere?
  4. Corrective action. Remove the cause, for example with a fixed step in the leavers process.
  5. Check effectiveness. After a few months, verify that the problem has not come back.

Record for each finding what was done and when. An auditor looks mostly at steps 2 and 5: was the cause found, and was it checked that the action works.

What a certification body does with it

In the second stage of the certification audit, the certification body checks that internal audits and management reviews have been carried out. That follows from ISO/IEC 17021-1, the standard for certification bodies. So plan at least one complete round of both before that audit, and keep them going afterwards. Trustbird records every action in an audit trail, so findings, decisions and follow-up can be traced later. The work itself, the audit and the decision, remains done by people.

Frequently asked questions

What is a management review?

A standing meeting in which top management assesses whether the ISMS still fits, works well and does what it should. ISO 27001 requires it in clause 9.3 and lists the topics it must cover as a minimum.

How often should an internal audit take place?

ISO 27001 sets no fixed frequency, only planned intervals. A common approach is to audit every part of the scope at least once within the certification cycle, and higher-risk parts more often.

Can an employee carry out the internal audit?

Yes, as long as that person is objective and impartial. In practice that means nobody audits their own work. A colleague from another team or an external internal auditor are the usual solutions.

Does the internal audit have to be done before the certification audit?

In practice, yes. In the second stage of the certification audit, the certification body checks that internal audits and management reviews have been carried out.

What happens to findings from an internal audit?

You fix the immediate problem, look for the cause, take action that prevents recurrence and check later whether it worked. Clause 10.2 requires you to keep a record of this.

Read next

Sources

  1. ISO, ISO/IEC 27001:2022 Information security management systems
  2. ISO, ISO 19011:2026 Guidelines for auditing management systems
  3. ISO, ISO/IEC 17021-1 Requirements for bodies providing audit and certification of management systems

Trustbird is being built with two certified design partners, and we are looking for more companies to join them at co-founder pricing.

Become a design partner