Who should read this: whoever owns the ISO 27001 project plan and has “internal audit” and “management review” written as two single-day tasks somewhere near the end.
They are not two tasks near the end. They are two systems that have to have been running, and they are the most common reason a Stage 2 audit slips. Both are cheap to do properly and expensive to do late.
Clause 9.2 asks for a programme, not an audit
The wording most people remember is that the organisation shall conduct internal audits at planned intervals. The wording that catches projects out is what surrounds it.
Clause 9.2 requires five things, and four of them are not the audit itself:
- An audit programme. A standing document setting out frequency, methods, responsibilities, planning requirements and reporting. Auditors ask for this first. Producing three completed audit reports without a programme behind them is a nonconformity, and it is one of the most frequently raised.
- Defined criteria and scope for each audit. What is being examined, against what, covering which systems, sites and period.
- Auditor competence and objectivity. Knowledge of the standard, of auditing, and of the technology in scope. And the rule that does most of the damage: auditors shall not audit their own work.
- Reporting to relevant management. Results have to reach the people who can act, and they feed directly into the management review.
- Retained documented information. Programme, plans, working papers, reports, corrective actions.
Note what is not required. There is no obligation to audit the entire management system every twelve months. A rolling programme that covers everything across the cycle, weighted toward higher-risk areas, satisfies the standard and is usually more useful. What is not acceptable is a programme that leaves parts of the ISMS unaudited for the whole certification cycle without a documented reason.
The independence rule is the real cost
“Auditors shall not audit their own work” is one line in the standard and a structural problem in a company of forty people.
The person who built the management system understands it best. That is precisely why they cannot audit it. In a company with no security team, that person is usually the only person who could competently audit it, which leaves three options:
- Train a second person. Cheapest over time, slowest to arrange, and it only works if that person has enough independence from the ISMS to be credible.
- Use another function or another entity in the group. Works well where there is a quality function already running internal audits for another standard.
- Buy it in. External internal audit for an SME scope runs €4,000 to €12,000 a year. Note the “a year”. This is a recurring cost for the life of the certificate, and it is one of the lines missing from most budgets, as covered in what ISO 27001 actually costs an SME.
Whichever route you take, document why the auditor is independent. “They did not build this part” written down before the audit is worth more than an explanation offered to the certification auditor afterwards.
Clause 9.3 has a fixed agenda, and it is not a status update
Management review is where projects lose the most time for the least reason, because the requirement is unusually specific and easy to satisfy if you read it first.
Clause 9.3.2 lists what the review must consider. Treat it as a mandatory agenda:
- The status of actions from previous management reviews.
- Changes in external and internal issues relevant to the management system.
- Changes in the needs and expectations of interested parties.
- Feedback on information security performance: trends in nonconformities and corrective actions, monitoring and measurement results, audit results, and fulfilment of information security objectives.
- Feedback from interested parties.
- Results of risk assessment and the status of the risk treatment plan.
- Opportunities for continual improvement.
Clause 9.3.3 sets the output: decisions on continual improvement and on any need to change the management system, with documented information retained as evidence.
Two consequences worth planning around.
Item 1 means the first review is structurally different from every later one. There are no previous actions to review. Every subsequent review is judged partly on whether the last one’s decisions were tracked to closure. A series of reviews that each raise fresh actions and never close old ones is a visible pattern, and auditors look for it.
Item 4 requires that you have been measuring something. Feedback on performance and fulfilment of objectives assumes objectives exist and have measures attached. If clause 6.2 objectives were written as aspirations rather than as things with numbers, this is the meeting where that becomes obvious.
The standard says “planned intervals” and does not name a frequency. Annually is common and is the minimum most auditors accept. Quarterly is better in a company where the estate changes, and it also means the first certification audit sees a pattern rather than a single event.
What auditors actually raise
The findings against these two clauses are consistent enough to list in order.
Against 9.2:
- Audits performed but no audit programme document exists.
- Control coverage incomplete across the cycle, with no risk-based rationale for what was skipped.
- Auditor independence not documented.
- Corrective actions recorded without root cause analysis, or closed without verifying they worked.
- Audit results never formally reported to management, so the link into 9.3 is broken.
- Audits run so close to the certification visit that findings cannot be remediated in time.
Against 9.3:
- Minutes that do not cover all seven mandatory inputs. This is the single most common one, and it is entirely avoidable by using the list above as the agenda template.
- Attendance by delegates rather than top management. The standard means the people with authority over resources.
- No documented decisions. A record of discussion is not a record of decisions.
- Previous actions not tracked to closure.
- Inputs not prepared, so the meeting discusses impressions rather than the audit results and risk data it is supposed to consider.
Sequencing: the mistake that costs a quarter
The last finding on the 9.2 list is the expensive one. Internal audits scheduled a fortnight before Stage 2 leave no time to fix what they find, and finding nothing is worse, because a clean internal audit immediately before certification tells an auditor the internal audit was not searching.
A working sequence for a first certification:
| When | What |
|---|---|
| Month 1 | Write the audit programme. Book the reviews for the year |
| Month 2 onward | First management review, even with thin data. It starts the action trail |
| 3 to 4 months before Stage 2 | First internal audit, full scope, expecting findings |
| Following 6 weeks | Corrective actions, with root cause and effectiveness checks |
| 6 to 8 weeks before Stage 2 | Management review covering those audit results |
| Stage 2 | Auditor sees findings raised, actions closed, effectiveness verified |
That last row is the point of the whole exercise. A management system that has found and fixed its own problems is exactly what Stage 2 is looking for. Nonconformities raised by your own internal audit and closed properly are an asset in the audit, not a liability. Teams hide them, and that instinct is the wrong way round.
The timing above also has to fit inside the evidence period, which is the other constraint that cannot be compressed. Both are laid out in how long ISO 27001 really takes.
Who runs it in a company with no security function
Practically, three roles have to exist and only one of them can be contracted out cleanly.
The ISMS owner prepares the inputs and runs the corrective actions. This must be internal. Top management attends the review and makes decisions with resource implications. This cannot be delegated, and an auditor will check who was in the room. The internal auditor must be independent of the work being audited, and this is the role that is routinely bought in.
Where a company has nobody who can own the first role, that is usually the trigger for a named security lead on a fractional basis rather than a hire, because the work is a few days a month once the system is running rather than a full-time job. The wider version of that decision is in ISO 27001 for a company without a security team.
The technical reality: what a document-based internal audit misses
Here is the honest limitation of clause 9.2 as most SMEs run it.
An internal audit checks conformity: does a control exist, is it documented, is there a record. It does not check whether the control works. An auditor can confirm that A.8.8 is covered by a vulnerability management procedure, that scans run monthly, and that a report is produced. Every one of those statements can be true while critical findings sit unremediated for months, because the control asked for a process and got one.
The same holds across the operational controls. Logging exists and nobody queries it. Backups run and nobody has restored one. Access reviews are signed and the leaver still has a token. These pass an internal audit conducted against the documentation, and they are also, in order, three of the most common ways a company of this size gets breached. The grouping in the Annex A controls grouped for real work separates the controls that are recording work from the ones that are engineering work, and the second group is where this gap sits.
The fix is not more auditing. It is to write the audit programme so that the operational controls are tested rather than reviewed: restore a backup and time it, pick a leaver and hunt for live credentials, take a finding from the scanner and follow it to closure. That turns internal audit from a paperwork exercise into the thing that finds problems before an attacker or an auditor does, which is what clause 9.2 was for.