Skip to content

ISO 27001 internal audit checklist

Use this checklist to record a requirement, audit question, sample and finding for each process. Adapt the questions to your scope and agreed procedures.

Book an informal conversation

ISO Ready helps you align policy, risk, and evidence, without endless document churn.

Run the ISO 27001 readiness scan

A checklist is an investigation worksheet

A useful audit checklist contains more than yes/no questions. For each question, record the requirement examined, the evidence needed and what the auditor actually established. The questions below are practical examples, not a complete reproduction of ISO/IEC 27001. Use the standard and your organisation’s approved arrangements to complete your own checklist.

Example questions by topic

TopicAudit questionPossible evidence
ScopeDo the boundaries still match delivered services?Scope decision and record of changed services
Risk treatmentHas a selected measure actually been implemented?Risk register, assigned action and implementation record
AccessHas withdrawn permission also been removed technically?Departure notification and account record
RecoveryHas the agreed recovery method been tested?Test report, result and follow-up
ImprovementDid a previous action achieve its intended effect?Finding, cause analysis and effectiveness check
SuppliersDoes the assessment reflect the service risk?Risk classification, agreements and evaluation
GovernanceAre management review decisions followed through?Decision, assigned action and result check

Explain sample selection

Select records that help answer the investigation question. Include relevant differences, such as routine and emergency cases or different locations. Record the period and selection method. This example checklist has no universally correct number of files. Justify the sample using the objective, risk and available information. Extend the investigation where conflicting results make that necessary.

Fictional example: approval without implementation

A fictional organisation has a completed ticket for removing access. The checklist asks about both approval and implementation. The ticket says “done”, but the application account remains active. The auditor records both observations and investigates whether the status was changed manually without technical verification. This reveals more than a question asking only whether the ticket was closed.

Use explicit outcomes

Distinguish demonstrated, not demonstrated, not examined and not applicable with a reason. An empty field is ambiguous: was evidence missing, or was the topic skipped? Describe a nonconformity through the requirement and facts before proposing a solution. Keep findings traceable to the audit report and action register. Read the internal audit guide for planning and roles, and evidence and documentation for assessing records. ISO 19011:2026 provides guidance on audit methods.

Primary sources for this topic

Frequently asked questions

Does this checklist cover every ISO 27001 requirement?
No. These example questions help structure an investigation, but they are not a complete checklist of the standard. Add questions based on the applicable standard, scope, risks and internal arrangements. Record which topics will be examined elsewhere in the programme. A completed checklist without clear criteria and supporting evidence does not demonstrate that every requirement was assessed.
How many records should an audit sample contain?
Choose the sample size using the investigation objective, risk, differences in operation and previous findings. No single number is convincing for every process. Document the selection and period, and state the limits of the conclusion. If the sample reveals conflicting results, decide what further investigation is needed before drawing a broader conclusion about the process.

Need help with the next step?

Explore support for your next step at ISO Ready. ISO Ready and this knowledge base are operated by Oosterwal Consultancy.

Explore your next step at ISO Ready

isocertificering.org is operated by Oosterwal Consultancy (oosterwal.com). ISO Ready (iso-ready.nl) has the same owner. Links to ISO Ready refer to our own commercial offering. About us (Dutch)

AI reading guide (llms.txt)