Internal Audit: A Practical Checklist
Prepare an ISO 27001 internal audit with clear scope, evidence-based checks and follow-up actions that can be verified.
In 30 seconds
- Purpose: assess the ISMS against defined audit criteria.
- Inputs: policies, risk assessment, SoA, procedures and operational records.
- Outputs: findings, an audit report and tracked follow-up actions.
- When to use it: within your planned audit programme and when significant changes or risks justify additional attention.
An internal audit helps you understand whether your information security management system works in practice. The aim is to examine evidence, identify gaps and support improvement before problems become more difficult to resolve.
Prepare the audit
Define the scope, criteria, dates and people involved. Select samples that reflect the risks and critical activities in scope. Arrange access to records and choose auditors who can assess the work objectively and impartially.
A checklist is a prompt for investigation, not a substitute for professional judgement. Adapt each question to your environment and record what you actually examined.
Practical checks
| Area | Question | Example evidence |
|---|---|---|
| Access management | Are access rights approved, reviewed and removed when no longer needed? | A sample of onboarding, access review and leaver records. |
| Incident management | Are incidents assessed, escalated and followed through to closure? | Incident records, timelines and lessons learned. |
| Information protection | Are the controls selected for critical information operating as intended? | Configuration records and relevant control checks. |
| Document control | Can staff identify and use the current approved procedure? | Version history, approvals and a walkthrough with a user. |
| Corrective actions | Are actions completed and their effectiveness checked? | Action owners, completion evidence and effectiveness reviews. |
Record findings clearly
For each finding, state the relevant criterion, the evidence examined and the gap observed. Distinguish facts from assumptions. Discuss the finding with the relevant owner so that misunderstandings can be resolved without weakening the evidence.
Close the improvement loop
Assign an owner and due date to each action. Address causes where corrective action is required, retain completion evidence, and check whether the action achieved its intended result. Closing a task in a tracker is not the same as demonstrating effectiveness.
Common mistakes
- Reviewing documents without testing how work is performed.
- Using the same generic checklist for every system.
- Recording opinions without evidence or an audit criterion.
- Collecting findings without arranging follow-up.
Deliverables
- A practical set of audit questions and evidence examples.
- A finding-record structure and action follow-up approach.
Editable Excel workbook with FR and EN tabs. Record evidence, owners, deadlines, actions and decisions.
Operational summary
Define criteria, examine evidence, record clear findings and verify follow-up effectiveness.
Download
Build an audit you can act on
NetQualIT can help define the audit scope, organise evidence and turn findings into a manageable improvement plan.