ISO 27001 internal audit checklist
122 audit questions: every clause of the ISO/IEC 27001:2022 management system, then one question for each of the 93 Annex A controls, grouped into organisational, people, physical and technological themes. Every question is shown below. The Excel version adds a rating drop-down, the same questions grouped by department, a findings log and an audit plan.
Audit questions by clause
This is a generalised checklist. It does not set out your organisation's specific requirements. It is a sound starting point, and we recommend tailoring it to your organisation's context, processes, risks and legal obligations. For support on your ISO journey, contact us at [email protected].
Written against ISO/IEC 27001:2022 with Amendment 1:2024 (climate action). Clauses 4 to 10 come first, then Annex A by theme. Audit the Annex A controls listed as applicable in your Statement of Applicability.
Clause 4 Context of the organisation
- 4.1 Internal and external issues
Has the organisation identified the internal and external issues relevant to its purpose that affect its ability to achieve the intended outcomes of the ISMS?
Evidence: Context analysis with review date, covering threat landscape, regulation, technology and business model
- 4.1 Climate change
Has the organisation decided whether climate change is a relevant issue for its ISMS (for example physical risks to data centres or service continuity), and recorded the reasoning?
Evidence: Context analysis naming climate change and the conclusion; link to risk assessment where relevant
- 4.2 Interested parties
Are interested parties relevant to the ISMS identified with their requirements, including climate-related ones, and is it decided which of these requirements the ISMS will address?
Evidence: Interested parties register: customers, regulators, data subjects, suppliers, owners; requirements mapped to the ISMS
- 4.3 Scope
Is the ISMS scope documented, considering the issues, requirements, and the interfaces and dependencies between the organisation's activities and those performed by others?
Evidence: Scope statement with locations, assets, processes, and interfaces such as cloud providers; certificate scope
- 4.4 ISMS and processes
Is the ISMS established with the processes needed and their interactions, and does it run in practice as described?
Evidence: ISMS manual or process map; sample of records from each process
Clause 5 Leadership
- 5.1 Leadership and commitment
Can top management show that the information security policy and objectives fit the strategic direction, that ISMS requirements are integrated into business processes, that resources are available, and that they direct and support people to contribute?
Evidence: Interview with top management; security steering committee minutes; security budget
- 5.2 Information security policy
Is there a policy appropriate to the organisation's purpose that gives a framework for objectives and commits to meeting applicable requirements and to continual improvement, documented, communicated and available to interested parties as appropriate?
Evidence: Approved, dated policy; communication records; publication to staff
- 5.3 Roles and authorities
Are responsibilities and authorities for roles relevant to information security assigned and communicated, including who makes sure the ISMS conforms and who reports on its performance to top management?
Evidence: Organisation chart; CISO or ISMS manager appointment; RACI
Clause 6 Planning
- 6.1.1 Risks and opportunities
When planning the ISMS, has the organisation considered its context and interested parties and determined the risks and opportunities to address, with actions planned and evaluated?
Evidence: ISMS risk and opportunity register; action plans
- 6.1.2 Risk assessment process
Is there a defined risk assessment process with risk acceptance criteria and criteria for performing assessments, producing consistent, valid and comparable results, identifying risks to confidentiality, integrity and availability with named risk owners?
Evidence: Risk assessment methodology; acceptance criteria; risk register with owners, likelihood and impact
- 6.1.2 Risk analysis and evaluation
Are the potential consequences and realistic likelihood of each risk assessed, risk levels determined, and risks compared with the criteria and prioritised for treatment?
Evidence: Completed risk assessment with ratings and prioritisation; date of last full assessment
- 6.1.3 Risk treatment
Have treatment options been chosen, the necessary controls determined and compared with Annex A to make sure none has been overlooked, and is there a risk treatment plan approved by risk owners, who also accept the residual risks?
Evidence: Risk treatment plan; risk owner approval and acceptance of residual risk
- 6.1.3 Statement of Applicability
Is there a Statement of Applicability listing the necessary controls, the justification for including them, whether they are implemented, and the justification for excluding any Annex A control?
Evidence: Current, approved Statement of Applicability matching the risk treatment plan
- 6.2 Information security objectives
Are information security objectives set at relevant functions and levels, consistent with the policy, measurable where practicable, monitored, communicated and updated, with plans stating what, who, when, resources and how results are evaluated?
Evidence: Objectives register with targets and current results; action plans
- 6.3 Planning of changes
When changes to the ISMS are needed, are they carried out in a planned manner?
Evidence: ISMS change records; plans for scope or structure changes
Clause 7 Support
- 7.1 Resources
Are the resources needed for the ISMS determined and provided?
Evidence: Security budget; staffing; tooling
- 7.2 Competence
Are competence needs defined for people whose work affects information security performance, are they competent, and is the effectiveness of training or other actions evaluated?
Evidence: Competence matrix; certifications; training records
- 7.3 Awareness
Are people aware of the policy, their contribution to the ISMS and the implications of not conforming?
Evidence: Staff interviews; awareness campaign records; phishing simulation results
- 7.4 Communication
Has the organisation decided what to communicate about information security, when, with whom and how?
Evidence: Communication plan; security bulletins; customer and regulator communications
- 7.5 Documented information
Does the ISMS include the documented information the standard requires and what the organisation needs, properly identified, reviewed and approved, available where needed, protected, and controlled for distribution, changes and retention?
Evidence: Document register; version control; access permissions on the document repository
Clause 8 Operation
- 8.1 Operational planning and control
Are processes needed to meet requirements and carry out the planned actions defined with criteria and controlled, are planned changes controlled and unintended changes reviewed, and are externally provided processes, products and services relevant to the ISMS controlled?
Evidence: Operating procedures; change records; supplier controls
- 8.2 Risk assessment at intervals
Are information security risk assessments carried out at planned intervals and when significant changes are proposed or occur, with results retained?
Evidence: Dated risk assessments; assessments triggered by changes such as a cloud migration
- 8.3 Risk treatment implemented
Is the risk treatment plan being implemented, with results of risk treatment retained?
Evidence: Treatment plan progress; evidence that planned controls are in place
Clause 9 Performance evaluation
- 9.1 Monitoring and measurement
Has the organisation decided what to monitor and measure, including security processes and controls, with methods that give comparable and reproducible results, who does it, when, and who analyses the results?
Evidence: Security metrics; dashboards; monitoring schedule
- 9.2 Internal audit
Are internal audits carried out at planned intervals under a programme that considers process importance and previous results, with defined criteria and scope, objective and impartial auditors, and results reported to management?
Evidence: Audit programme covering clauses and Annex A controls over the cycle; audit reports; auditor independence
- 9.3 Management review
Does top management review the ISMS at planned intervals, considering previous actions, changes in issues and interested-party needs, nonconformities, monitoring and audit results, achievement of objectives, interested-party feedback, risk assessment results, the treatment plan status and improvement opportunities?
Evidence: Management review minutes checked against each required input
- 9.3 Management review outputs
Do the outputs include decisions on continual improvement opportunities and any need for changes to the ISMS, with the results retained?
Evidence: Minutes with decisions, owners and dates
Clause 10 Improvement
- 10.1 Continual improvement
Does the organisation continually improve the suitability, adequacy and effectiveness of the ISMS?
Evidence: Improvement trends; management review decisions implemented
- 10.2 Nonconformity and corrective action
When a nonconformity occurs, does the organisation react, find the root cause, check for similar cases, take action, review its effectiveness and change the ISMS where needed, with records retained?
Evidence: Corrective action log with root cause and effectiveness review
Annex A.5 Organisational controls
- A.5.1 Policies for information security
Is there an approved information security policy supported by topic-specific policies, communicated to staff and relevant parties, and reviewed at planned intervals and after significant changes?
Evidence: Policy set with approval and review dates; acknowledgement records
- A.5.2 Security roles and responsibilities
Are information security roles and responsibilities defined and allocated according to the organisation's needs?
Evidence: Role descriptions; asset and risk owner assignments
- A.5.3 Segregation of duties
Are conflicting duties and areas of responsibility separated, for example requesting, approving and implementing access or payments?
Evidence: Segregation matrix; sample of access requests showing different requester and approver
- A.5.4 Management responsibilities
Does management require all personnel to apply information security in line with the policies and procedures?
Evidence: Manager briefings; performance objectives including security; enforcement records
- A.5.5 Contact with authorities
Is contact with relevant authorities (regulators, law enforcement, data protection authority, cyber security agency) established and maintained?
Evidence: Contact list with named authorities; records of notifications
- A.5.6 Contact with special interest groups
Does the organisation maintain contact with security forums, professional associations or information sharing groups?
Evidence: Memberships; advisories received and acted on
- A.5.7 Threat intelligence
Is information about threats collected and analysed to produce threat intelligence that feeds risk assessment and controls?
Evidence: Threat feeds; threat intelligence reports; resulting actions
- A.5.8 Security in project management
Is information security built into project management, with security requirements and risks addressed from the start of each project?
Evidence: Project methodology with security gates; sample project risk assessments
- A.5.9 Inventory of assets
Is there an accurate, up-to-date inventory of information and other associated assets, with an owner for each?
Evidence: Asset register with owners; reconciliation with discovery tools
- A.5.10 Acceptable use
Are rules for the acceptable use and handling of information and assets identified, documented and implemented?
Evidence: Acceptable use policy; signed acknowledgements
- A.5.11 Return of assets
Do personnel and other parties return the organisation's assets when their employment, contract or agreement changes or ends?
Evidence: Leaver checklists; asset return records for a sample of leavers
- A.5.12 Classification of information
Is information classified according to confidentiality, integrity, availability and interested-party requirements?
Evidence: Classification scheme; classified sample documents and systems
- A.5.13 Labelling of information
Are procedures in place for labelling information in line with the classification scheme, and are they followed?
Evidence: Labelling procedure; document headers and email labels in practice
- A.5.14 Information transfer
Are rules, procedures or agreements in place for all types of information transfer, internal and external, by electronic, physical and verbal means?
Evidence: Transfer policy; secure file transfer tools; data sharing agreements
- A.5.15 Access control
Are rules for physical and logical access to information and assets set and implemented based on business and security requirements?
Evidence: Access control policy; role-based access model
- A.5.16 Identity management
Is the full life cycle of identities managed, with unique identities and shared accounts only where justified and approved?
Evidence: Joiner, mover, leaver process; identity records; justification for shared accounts
- A.5.17 Authentication information
Is the allocation and management of authentication information (passwords, tokens, keys) controlled, including advice to users on handling it?
Evidence: Password policy; secure issuance process; secrets vault
- A.5.18 Access rights
Are access rights provided, reviewed at regular intervals, modified and removed in line with the access control policy?
Evidence: Access reviews with sign-off; removal of leaver access within a defined time
- A.5.19 Supplier relationships
Are processes in place to manage the security risks of using suppliers' products and services?
Evidence: Supplier security policy; supplier risk assessments
- A.5.20 Security in supplier agreements
Are relevant security requirements agreed with each supplier according to the type of relationship?
Evidence: Contracts with security, confidentiality, audit and breach notification clauses
- A.5.21 ICT supply chain
Are security risks in the ICT products and services supply chain managed?
Evidence: Requirements flowed down to sub-suppliers; software provenance checks
- A.5.22 Supplier monitoring and change
Does the organisation monitor, review, evaluate and manage changes in suppliers' security practices and service delivery?
Evidence: Supplier reviews; SOC 2 or ISO 27001 reports from suppliers; service reports
- A.5.23 Cloud services
Are the processes for acquiring, using, managing and exiting cloud services set according to the organisation's security requirements?
Evidence: Cloud policy; shared responsibility mapping; exit plans
- A.5.24 Incident management planning
Is incident management planned, with processes, roles and responsibilities defined and communicated?
Evidence: Incident response plan; on-call roster; contact lists
- A.5.25 Assessment of security events
Are security events assessed and a decision made on whether to categorise them as incidents?
Evidence: Triage criteria; event log with classification decisions
- A.5.26 Response to incidents
Are incidents responded to in line with the documented procedures?
Evidence: Incident records showing containment, eradication and recovery steps followed
- A.5.27 Learning from incidents
Is knowledge gained from incidents used to strengthen and improve controls?
Evidence: Post-incident reviews; resulting control changes
- A.5.28 Collection of evidence
Are procedures in place for identifying, collecting, acquiring and preserving evidence related to security events?
Evidence: Forensic procedure; chain of custody forms
- A.5.29 Security during disruption
Has the organisation planned how to maintain information security at an appropriate level during disruption?
Evidence: Continuity plans that address security controls in degraded or alternate operation
- A.5.30 ICT readiness for business continuity
Is ICT readiness planned, implemented, maintained and tested against business continuity objectives and requirements?
Evidence: Business impact analysis; recovery time and point objectives; disaster recovery test results
- A.5.31 Legal, regulatory and contractual requirements
Are legal, statutory, regulatory and contractual requirements relevant to information security identified, documented, kept up to date, and is the approach to meeting them defined?
Evidence: Legal and regulatory register (data protection, sector rules, cryptography export rules)
- A.5.32 Intellectual property rights
Are procedures in place to protect intellectual property rights, including software licensing?
Evidence: Licence register; software asset management reports
- A.5.33 Protection of records
Are records protected from loss, destruction, falsification, unauthorised access and unauthorised release?
Evidence: Records retention schedule; access controls and backups for records
- A.5.34 Privacy and protection of PII
Does the organisation identify and meet requirements for preserving privacy and protecting personally identifiable information under applicable laws, regulations and contracts?
Evidence: Privacy policy; records of processing; data protection impact assessments
- A.5.35 Independent review of security
Is the organisation's approach to managing information security reviewed independently at planned intervals or when significant changes occur?
Evidence: Independent review or external audit reports; follow-up actions
- A.5.36 Compliance with policies and standards
Is compliance with the security policy, topic-specific policies, rules and standards regularly reviewed?
Evidence: Compliance checks; configuration compliance scans; management reviews of compliance
- A.5.37 Documented operating procedures
Are operating procedures for information processing facilities documented and available to the personnel who need them?
Evidence: Runbooks; standard operating procedures with version control
Annex A.6 People controls
- A.6.1 Screening
Are background verification checks carried out on candidates before joining and on an ongoing basis, proportionate to legal requirements, business needs, the classification of information accessed and the risks?
Evidence: Screening policy; screening records for a sample of recent joiners
- A.6.2 Terms and conditions of employment
Do employment contracts state the personnel's and the organisation's responsibilities for information security?
Evidence: Contract templates with security clauses; signed contracts
- A.6.3 Awareness, education and training
Do personnel and relevant interested parties receive appropriate security awareness, education and training, with regular updates relevant to their job?
Evidence: Training plan; completion rates; role-based training for administrators and developers
- A.6.4 Disciplinary process
Is there a formal, communicated disciplinary process for personnel who breach the information security policy?
Evidence: Disciplinary procedure referencing security breaches; records of use
- A.6.5 Responsibilities after termination or change
Are security responsibilities that remain valid after termination or change of employment defined, enforced and communicated?
Evidence: Exit interview forms; continuing confidentiality reminders
- A.6.6 Confidentiality agreements
Are confidentiality or non-disclosure agreements that reflect the organisation's needs identified, documented, regularly reviewed and signed by personnel and other relevant parties?
Evidence: NDA templates with review date; signed NDAs for staff and contractors
- A.6.7 Remote working
Are security measures in place for personnel working remotely to protect information accessed, processed or stored outside the organisation's premises?
Evidence: Remote working policy; VPN or zero trust access; device controls
- A.6.8 Event reporting
Is there a mechanism for personnel to report observed or suspected security events promptly through appropriate channels?
Evidence: Reporting channel; staff interviews; volume of reports received
Annex A.7 Physical controls
- A.7.1 Physical security perimeters
Are security perimeters defined and used to protect areas containing information and other associated assets?
Evidence: Site plans showing zones; perimeter walls, doors and barriers on inspection
- A.7.2 Physical entry
Are secure areas protected by entry controls and access points?
Evidence: Badge access logs; visitor records; access reviews for secure areas
- A.7.3 Securing offices, rooms and facilities
Is physical security for offices, rooms and facilities designed and implemented?
Evidence: Site inspection; locked server and communications rooms
- A.7.4 Physical security monitoring
Are premises continuously monitored for unauthorised physical access?
Evidence: CCTV coverage and retention; intrusion alarms; guard patrol logs
- A.7.5 Physical and environmental threats
Is protection against physical and environmental threats, such as natural disasters, fire, flooding and other intentional or unintentional threats, designed and implemented?
Evidence: Fire suppression; water detection; site risk assessment
- A.7.6 Working in secure areas
Are security measures for working in secure areas designed and implemented?
Evidence: Secure area rules; escort procedures; no photography signage
- A.7.7 Clear desk and clear screen
Are clear desk rules for papers and removable media and clear screen rules for processing facilities defined and enforced?
Evidence: Policy; walk-round checks after hours; screen lock settings
- A.7.8 Equipment siting and protection
Is equipment sited securely and protected?
Evidence: Inspection of equipment placement; screens not visible to the public
- A.7.9 Assets off-premises
Are off-site assets protected?
Evidence: Off-site asset register; laptop encryption; rules for equipment taken home
- A.7.10 Storage media
Is storage media managed through its life cycle of acquisition, use, transport and disposal in line with the classification scheme and handling rules?
Evidence: Media handling procedure; USB controls; media disposal records
- A.7.11 Supporting utilities
Are processing facilities protected from power failures and other disruptions caused by failures in supporting utilities?
Evidence: UPS and generator test records; cooling redundancy
- A.7.12 Cabling security
Are cables carrying power, data or supporting services protected from interception, interference or damage?
Evidence: Cable routing inspection; locked patch panels
- A.7.13 Equipment maintenance
Is equipment maintained correctly to ensure the availability, integrity and confidentiality of information?
Evidence: Maintenance schedules and records; supervised third-party maintenance
- A.7.14 Secure disposal or re-use of equipment
Are items of equipment containing storage media checked so that sensitive data and licensed software are removed or securely overwritten before disposal or re-use?
Evidence: Disposal records; data wiping or destruction certificates
Annex A.8 Technological controls
- A.8.1 User endpoint devices
Is information stored on, processed by or accessible through user endpoint devices protected?
Evidence: Endpoint policy; device management console; encryption and patch status
- A.8.2 Privileged access rights
Is the allocation and use of privileged access rights restricted and managed?
Evidence: Privileged account list; approvals; privileged access management tool logs
- A.8.3 Information access restriction
Is access to information and other associated assets restricted in line with the access control policy?
Evidence: Access permissions on sample systems and shares
- A.8.4 Access to source code
Is read and write access to source code, development tools and software libraries appropriately managed?
Evidence: Repository permissions; branch protection; access reviews
- A.8.5 Secure authentication
Are secure authentication technologies and procedures in place according to access restrictions and the access control policy, for example multi-factor authentication?
Evidence: MFA coverage reports; authentication configuration
- A.8.6 Capacity management
Is the use of resources monitored and adjusted in line with current and expected capacity requirements?
Evidence: Capacity reports; alert thresholds; capacity plans
- A.8.7 Protection against malware
Is protection against malware implemented and supported by appropriate user awareness?
Evidence: Anti-malware or EDR coverage; detection logs; awareness content
- A.8.8 Technical vulnerabilities
Is information about technical vulnerabilities obtained, the organisation's exposure evaluated and appropriate measures taken?
Evidence: Vulnerability scans; patch timelines against policy; penetration test results
- A.8.9 Configuration management
Are configurations, including security configurations, of hardware, software, services and networks established, documented, implemented, monitored and reviewed?
Evidence: Hardening baselines; configuration management database; drift reports
- A.8.10 Information deletion
Is information stored in systems and devices deleted when no longer required?
Evidence: Retention and deletion rules; deletion logs
- A.8.11 Data masking
Is data masking used in line with the access control policy, business requirements and legal requirements?
Evidence: Masking rules; masked data in test and reporting environments
- A.8.12 Data leakage prevention
Are data leakage prevention measures applied to systems, networks and devices that process, store or transmit sensitive information?
Evidence: DLP policies and alerts; email and endpoint controls
- A.8.13 Information backup
Are backup copies of information, software and systems maintained and regularly tested in line with an agreed backup policy?
Evidence: Backup policy; job reports; restore test records
- A.8.14 Redundancy
Are information processing facilities implemented with enough redundancy to meet availability requirements?
Evidence: Architecture diagrams; failover tests
- A.8.15 Logging
Are logs that record activities, exceptions, faults and other relevant events produced, stored, protected and analysed?
Evidence: Logging standard; SIEM sources; log retention and integrity protection
- A.8.16 Monitoring activities
Are networks, systems and applications monitored for anomalous behaviour, with action taken to evaluate potential incidents?
Evidence: Monitoring use cases; alert handling records; security operations reports
- A.8.17 Clock synchronisation
Are the clocks of information processing systems synchronised to approved time sources?
Evidence: NTP configuration; time source settings on sample systems
- A.8.18 Privileged utility programs
Is the use of utility programs that can override system and application controls restricted and tightly controlled?
Evidence: List of permitted utilities; restrictions and usage logs
- A.8.19 Software installation
Are procedures and measures in place to securely manage software installation on operational systems?
Evidence: Application allow-listing; installation rights; change records
- A.8.20 Network security
Are networks and network devices secured, managed and controlled to protect information in systems and applications?
Evidence: Network diagrams; firewall rule reviews; device hardening
- A.8.21 Security of network services
Are security mechanisms, service levels and service requirements of network services identified, implemented and monitored?
Evidence: Network service agreements; monitoring of provider performance
- A.8.22 Segregation of networks
Are groups of information services, users and systems segregated in the organisation's networks?
Evidence: VLAN or segmentation design; guest network separation; test of segmentation
- A.8.23 Web filtering
Is access to external websites managed to reduce exposure to malicious content?
Evidence: Web filtering policy and categories blocked; logs
- A.8.24 Use of cryptography
Are rules for the effective use of cryptography, including cryptographic key management, defined and implemented?
Evidence: Cryptography policy; encryption at rest and in transit; key management records
- A.8.25 Secure development life cycle
Are rules for the secure development of software and systems established and applied?
Evidence: Secure development policy; SDLC with security activities at each stage
- A.8.26 Application security requirements
Are information security requirements identified, specified and approved when developing or acquiring applications?
Evidence: Requirements documents with security requirements; approval records
- A.8.27 Secure architecture and engineering
Are principles for engineering secure systems established, documented, maintained and applied to development activities?
Evidence: Architecture principles; design reviews; threat models
- A.8.28 Secure coding
Are secure coding principles applied to software development?
Evidence: Coding standards; static analysis results; peer review records
- A.8.29 Security testing
Are security testing processes defined and carried out in the development life cycle and at acceptance?
Evidence: Security test plans; DAST or penetration test results before release
- A.8.30 Outsourced development
Does the organisation direct, monitor and review activities related to outsourced system development?
Evidence: Development contracts with security requirements; code review of supplier deliveries
- A.8.31 Separation of environments
Are development, testing and production environments separated and secured?
Evidence: Environment architecture; access rights per environment
- A.8.32 Change management
Are changes to information processing facilities and systems subject to change management procedures?
Evidence: Change records with risk assessment, approval, testing and rollback plans
- A.8.33 Test information
Is test information appropriately selected, protected and managed?
Evidence: Rules on use of production data in testing; approvals; masked test data
- A.8.34 Protection during audit testing
Are audit tests and other assurance activities involving operational systems planned and agreed between the tester and appropriate management?
Evidence: Agreed scope and timing for audits and penetration tests; read-only access for auditors
Written against ISO/IEC 27001:2022 with Amendment 1:2024 (climate action changes to clauses 4.1 and 4.2), the current edition as of October 2026. The transition from the 2013 edition ended on 31 October 2025, so every accredited certificate is now to the 2022 edition. Annex A follows the 2022 structure: 93 controls in four themes (organisational, people, physical, technological). Guidance on each control is in ISO/IEC 27002:2022.
The questions paraphrase the requirements of each clause. They are a working aid, not a substitute for the standard, which is published by ISO and national standards bodies. Add questions for your own legal requirements, procedures and sites.
© 2026 ESGweise Global LLC. All rights reserved.
Get the Excel version
Enter your work email. We'll send the workbook to your inbox and unlock the direct download here.
Your checklist is on its way.
We've emailed the workbook. You can also download it now.
Download the Excel fileWant an independent auditor instead? ISO internal audit
- Five sheets: legend, checklist, by department, findings log, audit plan
- Filter by clause or by Annex A theme
- Editable, in Calibri, works in Excel and Google Sheets
Using an internal audit checklist
What does an ISO 27001 internal audit cover?
Two things. The management system clauses 4 to 10 (context, leadership, risk assessment and treatment, the Statement of Applicability, support, operation, performance evaluation and improvement) and the Annex A controls you have chosen to apply. This checklist has 29 clause questions and one question for each of the 93 Annex A controls in ISO/IEC 27001:2022.
Do we have to audit all 93 Annex A controls every year?
No. The audit programme sets frequency by importance and previous results, so higher-risk controls are audited more often and the rest are covered across the certification cycle. Every control in your Statement of Applicability should be audited at least once within the three-year cycle, and controls you excluded should have a justification that still holds.
How are the 2022 Annex A controls organised?
In four themes: 37 organisational controls (A.5), 8 people controls (A.6), 14 physical controls (A.7) and 34 technological controls (A.8). The 2022 edition replaced the 114 controls of the 2013 edition in 14 domains, merging many and adding new ones such as threat intelligence, cloud services, data leakage prevention and secure coding. The transition from 2013 ended on 31 October 2025.
What is the most common ISO 27001 internal audit finding?
A gap between the Statement of Applicability and reality: a control marked as implemented with no evidence it operates, or a risk treatment plan that names controls nobody owns. Start the audit from the risk assessment and the Statement of Applicability, then sample controls for evidence that they run as described.
Related: ISO internal audit services, ISO certification support and ISO internal auditor training.
Other free checklists: ISO 9001 (quality), ISO 14001 (environment), ISO 45001 (health and safety), ISO 50001 (energy), ISO 14001 and ISO 45001 combined.