9.2 Internal audit: the independent health check
Clause 9.2 is split into two subclauses covering the audit programme (9.2.1) and the execution requirements (9.2.2). Together they require the organization to conduct internal audits at planned intervals to provide information on whether the ISMS conforms to the organization's own requirements and to the requirements of ISO 27001, and whether it is effectively implemented and maintained.
The mandatory elements of an ISO 27001 internal audit programme are:
1. Planning the programme (9.2.1)
The audit programme must consider the importance of the processes concerned and the results of previous audits. In practice this means high-risk areas — access control, third-party supplier security, incident response — get audited more frequently than lower-risk administrative processes. A typical approach is a rolling 12-month audit plan that covers the full scope of the ISMS at least once per certification cycle, with critical Annex A control areas revisited annually.
2. Defining criteria and scope (9.2.2)
For each audit, the organization must define the audit criteria and scope. The criteria are typically the relevant ISO 27001 clauses, the applicable Annex A controls per the Statement of Applicability, and the organization's own internal policies and procedures. The scope defines which department, process, system or location is being examined in that particular audit cycle.
3. Selecting objective and impartial auditors (9.2.2)
This is the requirement most frequently flagged in audits. Clause 9.2.2 requires that auditors be selected and that audits be conducted in a manner that ensures objectivity and impartiality of the audit process — in practice, nobody audits their own work. A small IT team without independent staff can satisfy this by using a peer from another department trained as an internal auditor, rotating auditors between areas, or engaging an external internal-audit contractor. Without evidence of this independence check, certification bodies will raise a nonconformity even if the audit itself was thorough.
4. Reporting to relevant management and retaining evidence (9.2.2)
The results of each audit must be reported to relevant management, and documented information must be retained as evidence of the audit programme and the audit results. This means an audit report with findings, evidence sampled, nonconformities raised (if any), and observations, distributed to the process owners and top management — not just filed away.
9.3 Management review: closing the loop at the top
Clause 9.3 requires top management to review the organization's ISMS at planned intervals to ensure its continuing suitability, adequacy and effectiveness. This is split into three parts: general requirements (9.3.1), the mandatory inputs (9.3.2), and the mandatory outputs (9.3.3).
The inputs that management review must consider include:
- The status of actions from previous management reviews.
- Changes in external and internal issues relevant to the ISMS (linking back to clause 4.1).
- Changes in needs and expectations of interested parties relevant to the ISMS (clause 4.2).
- Feedback on the information security performance, including trends in nonconformities and corrective actions, monitoring and measurement results, audit results, and fulfillment of information security objectives.
- Feedback from interested parties.
- Results of risk assessment and status of the risk treatment plan.
- Opportunities for continual improvement.
The mandatory outputs of management review must include decisions related to continual improvement opportunities and any need for changes to the ISMS. As with 9.1 and 9.2, documented information must be retained as evidence of the results.
A common weakness auditors identify is a management review meeting that produces minutes listing what was discussed, but no explicit decisions. To satisfy 9.3.3, the output has to be actionable: "approved additional budget for MFA rollout to legacy systems by Q4" is a valid output; "discussed MFA coverage gaps" is not.
Common audit errors in clause 9
Across ISO 27001 certification and surveillance audits, these are the recurring nonconformities and observations linked to clause 9:
- 9.1 — Metrics not linked to information security objectives: organizations track generic IT metrics (tickets closed, uptime) without connecting any of them back to the objectives set under clause 6.2.
- 9.1 — No defined analysis or evaluation step: data is collected but nobody is assigned to interpret it, and there is no record of when or how it was evaluated.
- 9.2 — Auditor independence not evidenced: the same person who manages IT operations conducts the internal audit of IT operations, with no documented justification of impartiality.
- 9.2 — Audit programme not risk-based: every area gets audited on the same fixed schedule regardless of criticality, with no rationale linking audit frequency to risk.
- 9.3 — Management review inputs incomplete: the meeting happens, but agenda items skip mandatory inputs like interested party feedback or risk treatment plan status.
- 9.3 — No traceable outputs: minutes describe discussion but contain no explicit decisions, owners, or deadlines that can be traced in the next review cycle.
| Subclause |
Mandatory evidence |
Typical frequency |
Owner |
| 9.1 Monitoring & measurement |
Documented metrics with method, timing, analysis and evaluation results |
Monthly / quarterly dashboards |
CISO / Security lead |
| 9.2.1 Audit programme |
Risk-based multi-year audit plan covering full ISMS scope |
Reviewed annually |
ISMS manager |
| 9.2.2 Audit execution |
Audit report with criteria, scope, findings, independence statement |
Per planned audit (e.g. quarterly) |
Internal auditor |
| 9.3 Management review |
Minutes covering all mandatory inputs and explicit, actionable outputs |
At least annually |
Top management |
// Demo IgeraIndustria — ISMS performance evaluation query
ISMS Manager: Which internal audit actions from last quarter are still open?
IgeraIndustria: Internal audit IA-2026-Q2 (scope: Annex A.8 asset management, A.5.15 access control). 2 findings open. Finding IA-2026-Q2-01: privileged access review not evidenced for 3 of 12 sampled admin accounts, owner IT Operations, due 15/08/2026. Finding IA-2026-Q2-02: asset inventory missing 4 cloud storage instances identified during audit, owner Cloud Team, due 01/08/2026. Both findings scheduled for verification in follow-up review IA-2026-Q3.
Auditor: Show me the last management review outputs related to the risk treatment plan.
IgeraIndustria: Management review MR-2026-01, held 14/03/2026. Input reviewed: risk treatment plan status — 27 of 31 planned controls implemented, 4 overdue relating to third-party supplier security assessments. Decision recorded: approved extension of Q2 budget to complete supplier security assessments for 4 critical vendors, action owner Procurement & Security, deadline 30/06/2026. Status: closed, verified during IA-2026-Q3.
Frequently asked questions about ISO 27001 clause 9
How often does ISO 27001 require internal audits and management review?
ISO 27001 does not fix an exact frequency — it requires both to happen at "planned intervals" appropriate to the organization. In practice, most certified organizations run management review at least once a year (often aligned with the certification or surveillance audit cycle), and structure internal audits so that the full ISMS scope is covered at least once within each three-year certification cycle, with higher-risk areas audited more frequently, for example quarterly or semi-annually.
Not for the areas they are directly responsible for. Clause 9.2.2 requires objectivity and impartiality, which generally means auditors cannot audit their own work. A security manager can conduct internal audits of areas outside their direct operational responsibility, or organizations can rotate auditors across departments, train a peer from a different function, or bring in an external internal-audit resource for smaller teams without enough internal separation.
What documented evidence do auditors expect for clause 9.1 monitoring?
Auditors typically expect to see a defined list of what is monitored and measured, the method used for each metric, who is responsible for collection, the frequency, and — critically — evidence that results were actually analyzed and evaluated against defined criteria, not just collected. Dashboards or reports alone are insufficient if there is no record of who reviewed them and what conclusion was drawn.
A nonconformity found during an internal audit is handled the same way as one found in an external audit: it feeds into clause 10.1 (nonconformity and corrective action). The organization must react to the nonconformity, evaluate the need for action to eliminate the root cause, implement any action needed, and review the effectiveness of the corrective action taken. This should be tracked to closure and verified, typically in the following internal audit cycle or at management review.
Does management review have to be a single meeting?
No. ISO 27001 does not require management review to be one formal meeting on one date. Some organizations spread it across several shorter sessions, or combine it with existing governance meetings, as long as all the mandatory inputs from 9.3.2 are addressed and the mandatory outputs from 9.3.3 are documented within the review period. What matters is that top management is genuinely involved and that the decisions are recorded, not the meeting format.
Clause 6.2 requires the organization to set measurable information security objectives. Clause 9.1 is where you demonstrate whether those objectives are actually being met, by defining metrics that map directly to them. Clause 9.3 then requires management review to explicitly consider "the extent to which information security objectives have been met" as one of its mandatory inputs. Without a clear link from objectives (6.2) to metrics (9.1) to review (9.3), auditors will flag the ISMS as having a disconnected performance evaluation loop.
Struggling to keep internal audit findings and management review actions from falling through the cracks?
IgeraIndustria centralizes ISMS metrics, internal audit programmes and management review records for clause 9 — with real-time status on every open finding, no spreadsheets required.
See the ISO 27001 solution
Expert ISO 27001 · Updated 2026-07-31 · ISO 27001 step-by-step series: Article 5 — Clause 8 · Article 7 — Clause 10