Last reviewed 8 August 2026 by Daniyah Imran. This page is reviewed quarterly; the next review is due November 2026. Market facts are date-stamped “as of 07-08-2026”.
Clause-text notice: ISO/IEC 27001 is a paywalled standard. Clause language below is drawn from the ISO/IEC Harmonized Structure (HS) template and corroborating certification-body guidance, paraphrased and reconstructed, so check the wording against your own copy of the standard.
The short answer
Yes. An internal audit is mandatory for ISO 27001. Clause 9.2 of ISO/IEC 27001:2022 says your organisation shall conduct internal audits “at planned intervals”. There is no exemption for small teams and no opt-out in year two.
You can do it with your own people, but clause 9.2 requires the audit process to be objective and impartial, and an auditor must not audit their own work, which rules out whoever built or runs your ISMS. Small teams therefore choose one of three routes: train someone genuinely uninvolved, swap auditors with a peer company, or outsource the internal audit (which the standard explicitly permits). One route is closed: your certification body cannot perform your internal audit. Skipping it entirely is a major nonconformity at certification or surveillance.
What clause 9.2 actually requires
Clause 9.2 has two halves. Clause 9.2.1 (General) requires internal audits at planned intervals to provide information on whether the ISMS conforms to the organisation’s own requirements and to ISO/IEC 27001, and is effectively implemented and maintained.
Clause 9.2.2 (Internal audit programme) requires you to plan, establish, implement and maintain an audit programme covering frequency, methods, responsibilities, planning and reporting, weighted by the importance of the processes concerned and the results of previous audits. For each audit you must define the audit criteria and scope; select auditors so as to ensure objectivity and the impartiality of the audit process; report results to relevant managers; and keep documented information as evidence the programme ran and what it found.
(Clause language here follows the ISO Harmonized Structure template. Note the template reads “audit objectives, criteria and scope” while the published ISO/IEC 27001:2022 text uses “audit criteria and scope”; the published standard governs.)
Two things follow. The obligation is unconditional, “at planned intervals” describes when, not whether. And clause 9.2 requires not just an audit but an audit system: programme, scope, impartial auditors, management reporting, retained records.
The independence test, in plain language
The most-asked follow-up, “can we do our own internal audit?”, has a simple test:
Can the person auditing the work look at it as if it were someone else’s? If they designed it, built it or run it day to day, the answer is no.
Certification auditors apply clause 9.2.2(b) as: you must not audit your own work. The CTO who implemented the controls cannot audit them; the consultant who built your ISMS cannot sign off its internal audit. A practitioner on r/ISO27001 put it memorably: “You can review your work, not audit” (a practitioner’s phrasing, not a formal definition). Another reports, anecdotally, seeing a certification body reject an entire internal audit report because the person who built the system had signed the audit (an account we could not verify, though the underlying rule is not in doubt). Buyer forums are genuinely split on this point (practitioner sentiment, collected 07-08-2026); plan around the certification-body reading, independence is questioned first.
One route is closed: your certification body cannot do it
ISO/IEC 27006-1 clause 5.2.2, the standard governing ISO 27001 certification bodies, states that the certification body shall not provide internal information security reviews of the client’s ISMS, and shall be independent from the body or individuals which provide the internal ISMS audit. European Accreditation’s official FAQ (Q49.4, March 2025) goes further: under the general certification-body rules (ISO/IEC 17021-1), consultancy conflicts can sometimes be managed by a two-year separation, but for ISMS internal audits there is no two-year cooling-off mitigation. If your certification body, or one of its auditors, performed your internal audit, it can never certify you.
So when a firm offers to “handle everything, certification included”, split the question in two: who certifies, and who audits internally. They can never legitimately be the same party.
Does the internal auditor need a certificate? No, and not a CPA either
No certification is legally required for an ISO 27001 internal auditor. Nothing in ISO/IEC 27001:2022 demands a Lead Auditor or Internal Auditor certificate. The operative requirement is competence: clause 7.2 requires the organisation to determine the necessary competence and ensure people are competent “on the basis of appropriate education, training, or experience”, retaining documented evidence (clause 7.2, paraphrased). ISO/IEC 27007:2020 frames auditor requirements the same way, competence guidance, not certification.
One live misconception worth correcting: buyers regularly ask whether the internal auditor must be a CPA. That is a SOC 2 rule bleeding across frameworks, under AICPA rules, SOC is “a suite of service offerings CPAs may provide”, and SOC 2 examinations are performed by licensed CPA firms (AICPA & CIMA, “System and Organization Controls: SOC Suite of Services”, as of 07-08-2026), but accredited ISO 27001 auditors do not need to be CPAs (forum phrasing that shows the misconception; the ISO position follows from the sources above).
Competence must still be demonstrable, training records, an internal-auditor course, prior audit experience, and your certification body will look at it. Practitioners describe the finance-lead-trained-as-internal-auditor route being accepted in ~20-person companies (a practitioner account).
How often? Frequency and the audit programme
The standard requires audits “at planned intervals”, it does not mandate annual audits. In practice, certification has converged on at least one full internal-audit cycle per year, because surveillance audits are annual and clause 9.3 management review must take audit results as an input. Very few organisations could justify going more than 12 months without one and still claim the ISMS is actively maintained (published guidance, and practitioners report the same).
Buyers report certification bodies giving contradictory instructions, one saying every clause annually but only a third of Annex A controls, another saying everything every year (a practitioner account). Your documented programme sets the bar you are measured against: promise annual full-scope audits and skip one, and the nonconformity is worse, not better. Design a programme you can sustain: at least one full cycle per 12 months aligned to your surveillance date; all clauses and Statement of Applicability controls covered across the cycle, weighted by process importance and previous findings; and enough gap before the external audit to close findings, in buyers’ words, the internal audit is your “trial run” or “dry run” (buyers’ own phrasing).
Internal audit vs certification audit vs surveillance audit
Three different audits, three different actors, conflating them is where most confusion starts:
| Internal audit | Certification audit (Stage 1 & 2) | Surveillance audit | |
|---|---|---|---|
| Who performs it | Your organisation, or an external party acting on its behalf | An accredited certification body | The same certification body |
| Required by | ISO 27001 clause 9.2 | The certification process (ISO/IEC 17021-1 / 27006-1) | ISO/IEC 17021-1 surveillance rules |
| Purpose | Check the ISMS conforms and works; feed management review and corrective action | Decide whether to issue the certificate | Confirm the ISMS is maintained between (re)certifications |
| Frequency | At planned intervals (de facto annual) | Once per certification cycle (Stage 1 + Stage 2) | At least annually |
| Who it reports to | Your management | The certification body’s decision-maker | The certification body |
| If it goes badly | Findings and corrective actions, no certificate at stake | Certificate withheld until major NCs are closed | Certificate at risk of suspension or withdrawal |
Internal-audit evidence, the programme, reports, auditor competence and independence, is itself sampled during certification and surveillance audits. The internal audit is audited.
What an internal audit actually produces
From clause 9.2.2 and the management-review linkage, a compliant internal audit leaves this paper trail:
- An audit programme, frequency, methods, responsibilities and reporting.
- Defined criteria and scope for each individual audit.
- Evidence of auditor selection demonstrating objectivity and impartiality.
- Audit records, plans, working papers, sampled evidence, findings.
- A report to relevant management, including nonconformities and observations.
- Corrective actions raised under clause 10.2, tracked to closure.
- Audit results as an input to the clause 9.3 management review.
This evidence pack is typically the first thing a certification auditor requests (published practitioner guidance); a thin or missing pack is what turns a paperwork gap into a major nonconformity.
What happens if you skip it
Skipping the internal audit is not a calculated risk; it is a predictable failure. Under certification-body grading rules (e.g. NQA’s published criteria; NQA lists UKAS accreditation, qualifier not re-verified as of 07-08-2026), a major nonconformity is raised when there is a failure to fulfil a requirement of the standard, and clause 9.2 is a requirement. Certification will not be issued or reissued until correction evidence is accepted (NQA’s published timelines: response within 30 days, correction evidence for majors within 90 days; as of 07-08-2026), and at surveillance a major NC puts the certificate at risk of suspension. Practitioner guidance describes a wholly absent internal-audit trail as a near-automatic major (a characterisation from published guidance; the grading rule itself is the anchor), and “no arranged internal audits or management reviews” appears on published lists of the most common ISO 27001 nonconformities .
The cautionary tale circulating among practitioners as of 07-08-2026: a certified company asked an AI assistant whether it needed a second-year internal audit, was told no, skipped it, and took a major nonconformity at surveillance (a forum account, unverified and disputed in the thread itself, but consistent with the grading rules). The lesson is durable even if the anecdote is not: clause 9.2 does not lapse after year one.
Your three realistic options as a small team
1. Train someone genuinely uninvolved. A finance or operations lead, anyone who neither built nor runs the ISMS, takes an internal-auditor course and conducts the audit. Cheapest in cash, costliest in senior time, and only viable if you truly have an independent person.
2. Swap with a peer. Real arrangements buyers describe include consultancies whose staff audit each other’s clients rather than their own, and founders bartering internal-audit work with peers at other startups (practitioner sentiment). Workable, but document the independence and competence case carefully, the “returning consultant” variant (the implementer coming back as internal auditor a year later) is contested precisely because of the independence rule.
3. Outsource it. Not a workaround, it is written into the standards framework. ISO’s own definition of “audit” (ISO/IEC 27000:2018, the vocabulary standard ISO/IEC 27001:2022 normatively references, Note 2 to the term “audit”; identical wording appears in ISO/IEC 42001:2023, term 3.18) states that an internal audit “is conducted by the organisation itself, or by an external party on its behalf“: the definitive answer to “can we outsource the internal audit”, and one almost no competitor guide cites (as of 07-08-2026). One caveat buyers phrase well: you can outsource 100% of the audit work, but you cannot outsource ownership of the audit programme or the ISMS (practitioners’ phrasing; consistent with clause 9.2.2’s “the organisation shall”). Our ISO 27001 certification cost guide shows how internal-audit costs fit the overall budget.
Whichever route you choose, the outputs above are what you must be able to show. If you are still building the ISMS, our ISO 27001 implementation service covers the audit programme from the start; if you need the audit itself performed independently, see our ISO 27001 internal audit service.
Frequently asked questions
1. Is an internal audit mandatory for ISO 27001 certification?
Yes. Clause 9.2 of ISO/IEC 27001:2022 requires internal audits at planned intervals, before initial certification and throughout the certificate’s life. A missing internal audit is treated as a major nonconformity at Stage 2 or surveillance.
2. Can we do our own ISO 27001 internal audit?
Yes, the organisation may conduct the audit itself. But clause 9.2.2 requires objectivity and impartiality, and an auditor must not audit their own work. Whoever built or runs your ISMS cannot audit it.
3. Who can perform an ISO 27001 internal audit?
Anyone competent and independent of the work audited: a trained employee uninvolved in the ISMS, a peer company’s auditor under a swap arrangement, or an external provider, ISO’s definition of “audit” (ISO/IEC 27000:2018, Note 2 to the term “audit”) explicitly allows an external party acting on the organisation’s behalf. The one excluded party is your certification body.
4. Does an ISO 27001 internal auditor need a certificate or to be a CPA?
No. The standard requires demonstrable competence (clause 7.2), not a Lead Auditor certificate. The CPA requirement belongs to SOC 2, not ISO 27001.
5. How often is an ISO 27001 internal audit required?
The standard says “at planned intervals” and sets no fixed frequency. Certification practice has converged on at least one full cycle per year, because surveillance is annual and management review requires audit results as an input.
6. Can our certification body perform our internal audit?
No. ISO/IEC 27006-1 clause 5.2.2 forbids it, and European Accreditation (FAQ Q49.4, March 2025) confirms there is no two-year cooling-off mitigation for ISMS, a certification body that performed your internal audit can never certify you.
7. What happens if we skip the internal audit?
Expect a major nonconformity: at Stage 2 the certificate is withheld until corrections are evidenced; at surveillance the certificate is at risk of suspension or withdrawal. Certification auditors routinely request the internal-audit evidence pack first.
8. Can we outsource the internal audit entirely?
Yes, the standards framework explicitly contemplates an external party conducting the internal audit on your behalf. What you cannot outsource is ownership: the audit programme, management reporting and corrective action remain your organisation’s responsibility under clause 9.2.2.