Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What do organisations often get wrong about ISO…
Governance, Ownership & Risk

What do organisations often get wrong about ISO 27001 internal audits?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 24, 2026 Domain: Governance, Ownership & Risk

A common mistake is treating the internal audit as a lighter version of the certification audit. In practice, the internal audit must cover all mandatory and Annex A controls, be planned, documented, and performed by someone independent and competent. If the auditor helped implement or run the ISMS, impartiality is lost and the audit evidence weakens.

What internal audits are actually meant to test in ISO 27001

An internal audit is not a mini certification audit or a box-ticking exercise. Its job is to check whether the ISMS matches the organisation’s own requirements, the iso 27001 requirements, and the implemented controls in practice. That means the audit has to be broad enough to examine the system, not just a few easy samples.

The common error is narrowing the audit to a light review of policies, or to areas that are convenient for the auditor. A proper internal audit should test whether control design is complete, whether controls operate as intended, and whether evidence exists to prove it.

For organisations using an ISMS alongside broader assurance activity, the audit should be treated as an independent line of challenge. That makes it different from day-to-day control monitoring, management review, or certification preparation.

Why independence and competence matter more than familiarity

Internal audits fail when the auditor is too close to the process. If the same person designed the control, runs the process, or informally approves exceptions, the audit no longer provides meaningful challenge. Independence is not about organisational distance alone, it is about whether the auditor can assess the ISMS without defending it.

Competence matters just as much. An auditor needs enough understanding of the scope, risks, controls, and evidence to tell the difference between a process that exists on paper and a control that is actually effective. A good internal audit is evidence-led, not opinion-led.

That is why organisations often underestimate the need for audit planning, audit criteria, and consistent sampling. Without those basics, findings become subjective and the resulting corrective actions are weaker than they should be.

Relevant background on the relationship between governance, auditability, and access controls is also covered in NHIMG’s Ultimate Guide to NHIs, Regulatory and Audit Perspectives and its Cloud Compliance Pulse 2025.

How to think about scope, evidence, and Annex A coverage

The other frequent mistake is treating internal audit scope as if only a few visible controls matter. ISO 27001 internal audits should cover the full ISMS scope, the mandatory clauses, and the Annex A controls that the organisation has selected as applicable. If the audit ignores parts of the Statement of Applicability, the organisation is not really testing the ISMS it claims to operate.

Evidence quality is also central. Auditors should be able to see not just that a process exists, but that it is repeatable, current, and supported by records such as logs, tickets, approvals, reviews, and remediation tracking. If evidence is assembled late or reconstructed from memory, the audit result becomes fragile.

For practical guidance on control breadth and audit traceability, see ISO/IEC 27001:2022 Information Security Management and the companion implementation guidance in ISO/IEC 27002:2022 Information Security Controls. Together they help auditors avoid turning an ISMS audit into a narrow document review.

Risk and Threat Considerations

Weak internal audits create a false sense of control. The organisation may believe it has validated its ISMS, while unresolved control gaps, poor evidence, or unmanaged exceptions continue to accumulate under the surface. That risk matters because audit failure is often discovered later through incident response, external audit scrutiny, or a customer due diligence review.

Failure mechanism: Audits become ineffective when independence is compromised, scope is reduced, or evidence is accepted without sufficient validation. That allows control weaknesses to persist undetected and makes remediation priorities less reliable.

Impact: The organisation can overstate compliance, miss systemic control failure, and face avoidable findings during certification, customer assurance, or regulatory review.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

ISO/IEC 27001:2022 and SOC 2 (AICPA) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
ISO/IEC 27001:2022A.5.35 — Independent Review of Information SecurityInternal audits need independent challenge over the ISMS and controls.
A.5.36 — Compliance with Policies, Rules and Standards for Information SecurityThe question is about testing whether the ISMS complies with its own requirements.
A.5.37 — Documented Operating ProceduresAudits depend on evidence that procedures are documented and actually followed.
Recommendation — Ensure audit reviewers are independent from the controls and processes they assess. Audit compliance against the organisation's security policies, rules, and standards. Check that operating procedures are documented, current, and used in practice.
SOC 2 (AICPA)CC4.1 — Monitoring ActivitiesInternal audits support ongoing monitoring of control effectiveness and exceptions.
CC4.2 — Evaluation and Communication of Internal Control DeficienciesAudit findings should identify deficiencies and drive remediation action.
Recommendation — Use monitoring results to validate that controls operate effectively over time. Document control deficiencies and track remediation until closure.

Practitioner Guidance

What to prioritise: Treat internal audit as a test of the ISMS operating model, not a pre-certification rehearsal. The first question should be whether the audit plan truly covers the scope, mandatory clauses, selected Annex A controls, and the evidence needed to support each conclusion.

What to verify: Confirm that the auditor is independent from the implementation and operation of the controls being tested, and that competence is documented rather than assumed. If the same person wrote the process and audits it, the result should be treated as a higher-risk exception.

Practitioner takeaway: The best internal audit is the one that can surface uncomfortable findings early; if it only confirms what the implementers already believe, it is not giving the ISMS meaningful assurance.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 24, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org