Skip to main content
Free tool · Excel

ISO 27001 internal audit checklist

122 audit questions: every clause of the ISO/IEC 27001:2022 management system, then one question for each of the 93 Annex A controls, grouped into organisational, people, physical and technological themes. Every question is shown below. The Excel version adds a rating drop-down, the same questions grouped by department, a findings log and an audit plan.

The checklist

Audit questions by clause

This is a generalised checklist. It does not set out your organisation's specific requirements. It is a sound starting point, and we recommend tailoring it to your organisation's context, processes, risks and legal obligations. For support on your ISO journey, contact us at [email protected].

Written against ISO/IEC 27001:2022 with Amendment 1:2024 (climate action). Clauses 4 to 10 come first, then Annex A by theme. Audit the Annex A controls listed as applicable in your Statement of Applicability.

Clause 4 Context of the organisation

  1. 4.1 Internal and external issues

    Has the organisation identified the internal and external issues relevant to its purpose that affect its ability to achieve the intended outcomes of the ISMS?

    Evidence: Context analysis with review date, covering threat landscape, regulation, technology and business model

  2. 4.1 Climate change

    Has the organisation decided whether climate change is a relevant issue for its ISMS (for example physical risks to data centres or service continuity), and recorded the reasoning?

    Evidence: Context analysis naming climate change and the conclusion; link to risk assessment where relevant

  3. 4.2 Interested parties

    Are interested parties relevant to the ISMS identified with their requirements, including climate-related ones, and is it decided which of these requirements the ISMS will address?

    Evidence: Interested parties register: customers, regulators, data subjects, suppliers, owners; requirements mapped to the ISMS

  4. 4.3 Scope

    Is the ISMS scope documented, considering the issues, requirements, and the interfaces and dependencies between the organisation's activities and those performed by others?

    Evidence: Scope statement with locations, assets, processes, and interfaces such as cloud providers; certificate scope

  5. 4.4 ISMS and processes

    Is the ISMS established with the processes needed and their interactions, and does it run in practice as described?

    Evidence: ISMS manual or process map; sample of records from each process

Clause 5 Leadership

  1. 5.1 Leadership and commitment

    Can top management show that the information security policy and objectives fit the strategic direction, that ISMS requirements are integrated into business processes, that resources are available, and that they direct and support people to contribute?

    Evidence: Interview with top management; security steering committee minutes; security budget

  2. 5.2 Information security policy

    Is there a policy appropriate to the organisation's purpose that gives a framework for objectives and commits to meeting applicable requirements and to continual improvement, documented, communicated and available to interested parties as appropriate?

    Evidence: Approved, dated policy; communication records; publication to staff

  3. 5.3 Roles and authorities

    Are responsibilities and authorities for roles relevant to information security assigned and communicated, including who makes sure the ISMS conforms and who reports on its performance to top management?

    Evidence: Organisation chart; CISO or ISMS manager appointment; RACI

Clause 6 Planning

  1. 6.1.1 Risks and opportunities

    When planning the ISMS, has the organisation considered its context and interested parties and determined the risks and opportunities to address, with actions planned and evaluated?

    Evidence: ISMS risk and opportunity register; action plans

  2. 6.1.2 Risk assessment process

    Is there a defined risk assessment process with risk acceptance criteria and criteria for performing assessments, producing consistent, valid and comparable results, identifying risks to confidentiality, integrity and availability with named risk owners?

    Evidence: Risk assessment methodology; acceptance criteria; risk register with owners, likelihood and impact

  3. 6.1.2 Risk analysis and evaluation

    Are the potential consequences and realistic likelihood of each risk assessed, risk levels determined, and risks compared with the criteria and prioritised for treatment?

    Evidence: Completed risk assessment with ratings and prioritisation; date of last full assessment

  4. 6.1.3 Risk treatment

    Have treatment options been chosen, the necessary controls determined and compared with Annex A to make sure none has been overlooked, and is there a risk treatment plan approved by risk owners, who also accept the residual risks?

    Evidence: Risk treatment plan; risk owner approval and acceptance of residual risk

  5. 6.1.3 Statement of Applicability

    Is there a Statement of Applicability listing the necessary controls, the justification for including them, whether they are implemented, and the justification for excluding any Annex A control?

    Evidence: Current, approved Statement of Applicability matching the risk treatment plan

  6. 6.2 Information security objectives

    Are information security objectives set at relevant functions and levels, consistent with the policy, measurable where practicable, monitored, communicated and updated, with plans stating what, who, when, resources and how results are evaluated?

    Evidence: Objectives register with targets and current results; action plans

  7. 6.3 Planning of changes

    When changes to the ISMS are needed, are they carried out in a planned manner?

    Evidence: ISMS change records; plans for scope or structure changes

Clause 7 Support

  1. 7.1 Resources

    Are the resources needed for the ISMS determined and provided?

    Evidence: Security budget; staffing; tooling

  2. 7.2 Competence

    Are competence needs defined for people whose work affects information security performance, are they competent, and is the effectiveness of training or other actions evaluated?

    Evidence: Competence matrix; certifications; training records

  3. 7.3 Awareness

    Are people aware of the policy, their contribution to the ISMS and the implications of not conforming?

    Evidence: Staff interviews; awareness campaign records; phishing simulation results

  4. 7.4 Communication

    Has the organisation decided what to communicate about information security, when, with whom and how?

    Evidence: Communication plan; security bulletins; customer and regulator communications

  5. 7.5 Documented information

    Does the ISMS include the documented information the standard requires and what the organisation needs, properly identified, reviewed and approved, available where needed, protected, and controlled for distribution, changes and retention?

    Evidence: Document register; version control; access permissions on the document repository

Clause 8 Operation

  1. 8.1 Operational planning and control

    Are processes needed to meet requirements and carry out the planned actions defined with criteria and controlled, are planned changes controlled and unintended changes reviewed, and are externally provided processes, products and services relevant to the ISMS controlled?

    Evidence: Operating procedures; change records; supplier controls

  2. 8.2 Risk assessment at intervals

    Are information security risk assessments carried out at planned intervals and when significant changes are proposed or occur, with results retained?

    Evidence: Dated risk assessments; assessments triggered by changes such as a cloud migration

  3. 8.3 Risk treatment implemented

    Is the risk treatment plan being implemented, with results of risk treatment retained?

    Evidence: Treatment plan progress; evidence that planned controls are in place

Clause 9 Performance evaluation

  1. 9.1 Monitoring and measurement

    Has the organisation decided what to monitor and measure, including security processes and controls, with methods that give comparable and reproducible results, who does it, when, and who analyses the results?

    Evidence: Security metrics; dashboards; monitoring schedule

  2. 9.2 Internal audit

    Are internal audits carried out at planned intervals under a programme that considers process importance and previous results, with defined criteria and scope, objective and impartial auditors, and results reported to management?

    Evidence: Audit programme covering clauses and Annex A controls over the cycle; audit reports; auditor independence

  3. 9.3 Management review

    Does top management review the ISMS at planned intervals, considering previous actions, changes in issues and interested-party needs, nonconformities, monitoring and audit results, achievement of objectives, interested-party feedback, risk assessment results, the treatment plan status and improvement opportunities?

    Evidence: Management review minutes checked against each required input

  4. 9.3 Management review outputs

    Do the outputs include decisions on continual improvement opportunities and any need for changes to the ISMS, with the results retained?

    Evidence: Minutes with decisions, owners and dates

Clause 10 Improvement

  1. 10.1 Continual improvement

    Does the organisation continually improve the suitability, adequacy and effectiveness of the ISMS?

    Evidence: Improvement trends; management review decisions implemented

  2. 10.2 Nonconformity and corrective action

    When a nonconformity occurs, does the organisation react, find the root cause, check for similar cases, take action, review its effectiveness and change the ISMS where needed, with records retained?

    Evidence: Corrective action log with root cause and effectiveness review

Annex A.5 Organisational controls

  1. A.5.1 Policies for information security

    Is there an approved information security policy supported by topic-specific policies, communicated to staff and relevant parties, and reviewed at planned intervals and after significant changes?

    Evidence: Policy set with approval and review dates; acknowledgement records

  2. A.5.2 Security roles and responsibilities

    Are information security roles and responsibilities defined and allocated according to the organisation's needs?

    Evidence: Role descriptions; asset and risk owner assignments

  3. A.5.3 Segregation of duties

    Are conflicting duties and areas of responsibility separated, for example requesting, approving and implementing access or payments?

    Evidence: Segregation matrix; sample of access requests showing different requester and approver

  4. A.5.4 Management responsibilities

    Does management require all personnel to apply information security in line with the policies and procedures?

    Evidence: Manager briefings; performance objectives including security; enforcement records

  5. A.5.5 Contact with authorities

    Is contact with relevant authorities (regulators, law enforcement, data protection authority, cyber security agency) established and maintained?

    Evidence: Contact list with named authorities; records of notifications

  6. A.5.6 Contact with special interest groups

    Does the organisation maintain contact with security forums, professional associations or information sharing groups?

    Evidence: Memberships; advisories received and acted on

  7. A.5.7 Threat intelligence

    Is information about threats collected and analysed to produce threat intelligence that feeds risk assessment and controls?

    Evidence: Threat feeds; threat intelligence reports; resulting actions

  8. A.5.8 Security in project management

    Is information security built into project management, with security requirements and risks addressed from the start of each project?

    Evidence: Project methodology with security gates; sample project risk assessments

  9. A.5.9 Inventory of assets

    Is there an accurate, up-to-date inventory of information and other associated assets, with an owner for each?

    Evidence: Asset register with owners; reconciliation with discovery tools

  10. A.5.10 Acceptable use

    Are rules for the acceptable use and handling of information and assets identified, documented and implemented?

    Evidence: Acceptable use policy; signed acknowledgements

  11. A.5.11 Return of assets

    Do personnel and other parties return the organisation's assets when their employment, contract or agreement changes or ends?

    Evidence: Leaver checklists; asset return records for a sample of leavers

  12. A.5.12 Classification of information

    Is information classified according to confidentiality, integrity, availability and interested-party requirements?

    Evidence: Classification scheme; classified sample documents and systems

  13. A.5.13 Labelling of information

    Are procedures in place for labelling information in line with the classification scheme, and are they followed?

    Evidence: Labelling procedure; document headers and email labels in practice

  14. A.5.14 Information transfer

    Are rules, procedures or agreements in place for all types of information transfer, internal and external, by electronic, physical and verbal means?

    Evidence: Transfer policy; secure file transfer tools; data sharing agreements

  15. A.5.15 Access control

    Are rules for physical and logical access to information and assets set and implemented based on business and security requirements?

    Evidence: Access control policy; role-based access model

  16. A.5.16 Identity management

    Is the full life cycle of identities managed, with unique identities and shared accounts only where justified and approved?

    Evidence: Joiner, mover, leaver process; identity records; justification for shared accounts

  17. A.5.17 Authentication information

    Is the allocation and management of authentication information (passwords, tokens, keys) controlled, including advice to users on handling it?

    Evidence: Password policy; secure issuance process; secrets vault

  18. A.5.18 Access rights

    Are access rights provided, reviewed at regular intervals, modified and removed in line with the access control policy?

    Evidence: Access reviews with sign-off; removal of leaver access within a defined time

  19. A.5.19 Supplier relationships

    Are processes in place to manage the security risks of using suppliers' products and services?

    Evidence: Supplier security policy; supplier risk assessments

  20. A.5.20 Security in supplier agreements

    Are relevant security requirements agreed with each supplier according to the type of relationship?

    Evidence: Contracts with security, confidentiality, audit and breach notification clauses

  21. A.5.21 ICT supply chain

    Are security risks in the ICT products and services supply chain managed?

    Evidence: Requirements flowed down to sub-suppliers; software provenance checks

  22. A.5.22 Supplier monitoring and change

    Does the organisation monitor, review, evaluate and manage changes in suppliers' security practices and service delivery?

    Evidence: Supplier reviews; SOC 2 or ISO 27001 reports from suppliers; service reports

  23. A.5.23 Cloud services

    Are the processes for acquiring, using, managing and exiting cloud services set according to the organisation's security requirements?

    Evidence: Cloud policy; shared responsibility mapping; exit plans

  24. A.5.24 Incident management planning

    Is incident management planned, with processes, roles and responsibilities defined and communicated?

    Evidence: Incident response plan; on-call roster; contact lists

  25. A.5.25 Assessment of security events

    Are security events assessed and a decision made on whether to categorise them as incidents?

    Evidence: Triage criteria; event log with classification decisions

  26. A.5.26 Response to incidents

    Are incidents responded to in line with the documented procedures?

    Evidence: Incident records showing containment, eradication and recovery steps followed

  27. A.5.27 Learning from incidents

    Is knowledge gained from incidents used to strengthen and improve controls?

    Evidence: Post-incident reviews; resulting control changes

  28. A.5.28 Collection of evidence

    Are procedures in place for identifying, collecting, acquiring and preserving evidence related to security events?

    Evidence: Forensic procedure; chain of custody forms

  29. A.5.29 Security during disruption

    Has the organisation planned how to maintain information security at an appropriate level during disruption?

    Evidence: Continuity plans that address security controls in degraded or alternate operation

  30. A.5.30 ICT readiness for business continuity

    Is ICT readiness planned, implemented, maintained and tested against business continuity objectives and requirements?

    Evidence: Business impact analysis; recovery time and point objectives; disaster recovery test results

  31. A.5.31 Legal, regulatory and contractual requirements

    Are legal, statutory, regulatory and contractual requirements relevant to information security identified, documented, kept up to date, and is the approach to meeting them defined?

    Evidence: Legal and regulatory register (data protection, sector rules, cryptography export rules)

  32. A.5.32 Intellectual property rights

    Are procedures in place to protect intellectual property rights, including software licensing?

    Evidence: Licence register; software asset management reports

  33. A.5.33 Protection of records

    Are records protected from loss, destruction, falsification, unauthorised access and unauthorised release?

    Evidence: Records retention schedule; access controls and backups for records

  34. A.5.34 Privacy and protection of PII

    Does the organisation identify and meet requirements for preserving privacy and protecting personally identifiable information under applicable laws, regulations and contracts?

    Evidence: Privacy policy; records of processing; data protection impact assessments

  35. A.5.35 Independent review of security

    Is the organisation's approach to managing information security reviewed independently at planned intervals or when significant changes occur?

    Evidence: Independent review or external audit reports; follow-up actions

  36. A.5.36 Compliance with policies and standards

    Is compliance with the security policy, topic-specific policies, rules and standards regularly reviewed?

    Evidence: Compliance checks; configuration compliance scans; management reviews of compliance

  37. A.5.37 Documented operating procedures

    Are operating procedures for information processing facilities documented and available to the personnel who need them?

    Evidence: Runbooks; standard operating procedures with version control

Annex A.6 People controls

  1. A.6.1 Screening

    Are background verification checks carried out on candidates before joining and on an ongoing basis, proportionate to legal requirements, business needs, the classification of information accessed and the risks?

    Evidence: Screening policy; screening records for a sample of recent joiners

  2. A.6.2 Terms and conditions of employment

    Do employment contracts state the personnel's and the organisation's responsibilities for information security?

    Evidence: Contract templates with security clauses; signed contracts

  3. A.6.3 Awareness, education and training

    Do personnel and relevant interested parties receive appropriate security awareness, education and training, with regular updates relevant to their job?

    Evidence: Training plan; completion rates; role-based training for administrators and developers

  4. A.6.4 Disciplinary process

    Is there a formal, communicated disciplinary process for personnel who breach the information security policy?

    Evidence: Disciplinary procedure referencing security breaches; records of use

  5. A.6.5 Responsibilities after termination or change

    Are security responsibilities that remain valid after termination or change of employment defined, enforced and communicated?

    Evidence: Exit interview forms; continuing confidentiality reminders

  6. A.6.6 Confidentiality agreements

    Are confidentiality or non-disclosure agreements that reflect the organisation's needs identified, documented, regularly reviewed and signed by personnel and other relevant parties?

    Evidence: NDA templates with review date; signed NDAs for staff and contractors

  7. A.6.7 Remote working

    Are security measures in place for personnel working remotely to protect information accessed, processed or stored outside the organisation's premises?

    Evidence: Remote working policy; VPN or zero trust access; device controls

  8. A.6.8 Event reporting

    Is there a mechanism for personnel to report observed or suspected security events promptly through appropriate channels?

    Evidence: Reporting channel; staff interviews; volume of reports received

Annex A.7 Physical controls

  1. A.7.1 Physical security perimeters

    Are security perimeters defined and used to protect areas containing information and other associated assets?

    Evidence: Site plans showing zones; perimeter walls, doors and barriers on inspection

  2. A.7.2 Physical entry

    Are secure areas protected by entry controls and access points?

    Evidence: Badge access logs; visitor records; access reviews for secure areas

  3. A.7.3 Securing offices, rooms and facilities

    Is physical security for offices, rooms and facilities designed and implemented?

    Evidence: Site inspection; locked server and communications rooms

  4. A.7.4 Physical security monitoring

    Are premises continuously monitored for unauthorised physical access?

    Evidence: CCTV coverage and retention; intrusion alarms; guard patrol logs

  5. A.7.5 Physical and environmental threats

    Is protection against physical and environmental threats, such as natural disasters, fire, flooding and other intentional or unintentional threats, designed and implemented?

    Evidence: Fire suppression; water detection; site risk assessment

  6. A.7.6 Working in secure areas

    Are security measures for working in secure areas designed and implemented?

    Evidence: Secure area rules; escort procedures; no photography signage

  7. A.7.7 Clear desk and clear screen

    Are clear desk rules for papers and removable media and clear screen rules for processing facilities defined and enforced?

    Evidence: Policy; walk-round checks after hours; screen lock settings

  8. A.7.8 Equipment siting and protection

    Is equipment sited securely and protected?

    Evidence: Inspection of equipment placement; screens not visible to the public

  9. A.7.9 Assets off-premises

    Are off-site assets protected?

    Evidence: Off-site asset register; laptop encryption; rules for equipment taken home

  10. A.7.10 Storage media

    Is storage media managed through its life cycle of acquisition, use, transport and disposal in line with the classification scheme and handling rules?

    Evidence: Media handling procedure; USB controls; media disposal records

  11. A.7.11 Supporting utilities

    Are processing facilities protected from power failures and other disruptions caused by failures in supporting utilities?

    Evidence: UPS and generator test records; cooling redundancy

  12. A.7.12 Cabling security

    Are cables carrying power, data or supporting services protected from interception, interference or damage?

    Evidence: Cable routing inspection; locked patch panels

  13. A.7.13 Equipment maintenance

    Is equipment maintained correctly to ensure the availability, integrity and confidentiality of information?

    Evidence: Maintenance schedules and records; supervised third-party maintenance

  14. A.7.14 Secure disposal or re-use of equipment

    Are items of equipment containing storage media checked so that sensitive data and licensed software are removed or securely overwritten before disposal or re-use?

    Evidence: Disposal records; data wiping or destruction certificates

Annex A.8 Technological controls

  1. A.8.1 User endpoint devices

    Is information stored on, processed by or accessible through user endpoint devices protected?

    Evidence: Endpoint policy; device management console; encryption and patch status

  2. A.8.2 Privileged access rights

    Is the allocation and use of privileged access rights restricted and managed?

    Evidence: Privileged account list; approvals; privileged access management tool logs

  3. A.8.3 Information access restriction

    Is access to information and other associated assets restricted in line with the access control policy?

    Evidence: Access permissions on sample systems and shares

  4. A.8.4 Access to source code

    Is read and write access to source code, development tools and software libraries appropriately managed?

    Evidence: Repository permissions; branch protection; access reviews

  5. A.8.5 Secure authentication

    Are secure authentication technologies and procedures in place according to access restrictions and the access control policy, for example multi-factor authentication?

    Evidence: MFA coverage reports; authentication configuration

  6. A.8.6 Capacity management

    Is the use of resources monitored and adjusted in line with current and expected capacity requirements?

    Evidence: Capacity reports; alert thresholds; capacity plans

  7. A.8.7 Protection against malware

    Is protection against malware implemented and supported by appropriate user awareness?

    Evidence: Anti-malware or EDR coverage; detection logs; awareness content

  8. A.8.8 Technical vulnerabilities

    Is information about technical vulnerabilities obtained, the organisation's exposure evaluated and appropriate measures taken?

    Evidence: Vulnerability scans; patch timelines against policy; penetration test results

  9. A.8.9 Configuration management

    Are configurations, including security configurations, of hardware, software, services and networks established, documented, implemented, monitored and reviewed?

    Evidence: Hardening baselines; configuration management database; drift reports

  10. A.8.10 Information deletion

    Is information stored in systems and devices deleted when no longer required?

    Evidence: Retention and deletion rules; deletion logs

  11. A.8.11 Data masking

    Is data masking used in line with the access control policy, business requirements and legal requirements?

    Evidence: Masking rules; masked data in test and reporting environments

  12. A.8.12 Data leakage prevention

    Are data leakage prevention measures applied to systems, networks and devices that process, store or transmit sensitive information?

    Evidence: DLP policies and alerts; email and endpoint controls

  13. A.8.13 Information backup

    Are backup copies of information, software and systems maintained and regularly tested in line with an agreed backup policy?

    Evidence: Backup policy; job reports; restore test records

  14. A.8.14 Redundancy

    Are information processing facilities implemented with enough redundancy to meet availability requirements?

    Evidence: Architecture diagrams; failover tests

  15. A.8.15 Logging

    Are logs that record activities, exceptions, faults and other relevant events produced, stored, protected and analysed?

    Evidence: Logging standard; SIEM sources; log retention and integrity protection

  16. A.8.16 Monitoring activities

    Are networks, systems and applications monitored for anomalous behaviour, with action taken to evaluate potential incidents?

    Evidence: Monitoring use cases; alert handling records; security operations reports

  17. A.8.17 Clock synchronisation

    Are the clocks of information processing systems synchronised to approved time sources?

    Evidence: NTP configuration; time source settings on sample systems

  18. A.8.18 Privileged utility programs

    Is the use of utility programs that can override system and application controls restricted and tightly controlled?

    Evidence: List of permitted utilities; restrictions and usage logs

  19. A.8.19 Software installation

    Are procedures and measures in place to securely manage software installation on operational systems?

    Evidence: Application allow-listing; installation rights; change records

  20. A.8.20 Network security

    Are networks and network devices secured, managed and controlled to protect information in systems and applications?

    Evidence: Network diagrams; firewall rule reviews; device hardening

  21. A.8.21 Security of network services

    Are security mechanisms, service levels and service requirements of network services identified, implemented and monitored?

    Evidence: Network service agreements; monitoring of provider performance

  22. A.8.22 Segregation of networks

    Are groups of information services, users and systems segregated in the organisation's networks?

    Evidence: VLAN or segmentation design; guest network separation; test of segmentation

  23. A.8.23 Web filtering

    Is access to external websites managed to reduce exposure to malicious content?

    Evidence: Web filtering policy and categories blocked; logs

  24. A.8.24 Use of cryptography

    Are rules for the effective use of cryptography, including cryptographic key management, defined and implemented?

    Evidence: Cryptography policy; encryption at rest and in transit; key management records

  25. A.8.25 Secure development life cycle

    Are rules for the secure development of software and systems established and applied?

    Evidence: Secure development policy; SDLC with security activities at each stage

  26. A.8.26 Application security requirements

    Are information security requirements identified, specified and approved when developing or acquiring applications?

    Evidence: Requirements documents with security requirements; approval records

  27. A.8.27 Secure architecture and engineering

    Are principles for engineering secure systems established, documented, maintained and applied to development activities?

    Evidence: Architecture principles; design reviews; threat models

  28. A.8.28 Secure coding

    Are secure coding principles applied to software development?

    Evidence: Coding standards; static analysis results; peer review records

  29. A.8.29 Security testing

    Are security testing processes defined and carried out in the development life cycle and at acceptance?

    Evidence: Security test plans; DAST or penetration test results before release

  30. A.8.30 Outsourced development

    Does the organisation direct, monitor and review activities related to outsourced system development?

    Evidence: Development contracts with security requirements; code review of supplier deliveries

  31. A.8.31 Separation of environments

    Are development, testing and production environments separated and secured?

    Evidence: Environment architecture; access rights per environment

  32. A.8.32 Change management

    Are changes to information processing facilities and systems subject to change management procedures?

    Evidence: Change records with risk assessment, approval, testing and rollback plans

  33. A.8.33 Test information

    Is test information appropriately selected, protected and managed?

    Evidence: Rules on use of production data in testing; approvals; masked test data

  34. A.8.34 Protection during audit testing

    Are audit tests and other assurance activities involving operational systems planned and agreed between the tester and appropriate management?

    Evidence: Agreed scope and timing for audits and penetration tests; read-only access for auditors

Written against ISO/IEC 27001:2022 with Amendment 1:2024 (climate action changes to clauses 4.1 and 4.2), the current edition as of October 2026. The transition from the 2013 edition ended on 31 October 2025, so every accredited certificate is now to the 2022 edition. Annex A follows the 2022 structure: 93 controls in four themes (organisational, people, physical, technological). Guidance on each control is in ISO/IEC 27002:2022.

The questions paraphrase the requirements of each clause. They are a working aid, not a substitute for the standard, which is published by ISO and national standards bodies. Add questions for your own legal requirements, procedures and sites.

Free download

Get the Excel version

Enter your work email. We'll send the workbook to your inbox and unlock the direct download here.

Work or organisation email required. No spam.

  • Five sheets: legend, checklist, by department, findings log, audit plan
  • Filter by clause or by Annex A theme
  • Editable, in Calibri, works in Excel and Google Sheets
Questions

Using an internal audit checklist

What does an ISO 27001 internal audit cover?

Two things. The management system clauses 4 to 10 (context, leadership, risk assessment and treatment, the Statement of Applicability, support, operation, performance evaluation and improvement) and the Annex A controls you have chosen to apply. This checklist has 29 clause questions and one question for each of the 93 Annex A controls in ISO/IEC 27001:2022.

Do we have to audit all 93 Annex A controls every year?

No. The audit programme sets frequency by importance and previous results, so higher-risk controls are audited more often and the rest are covered across the certification cycle. Every control in your Statement of Applicability should be audited at least once within the three-year cycle, and controls you excluded should have a justification that still holds.

How are the 2022 Annex A controls organised?

In four themes: 37 organisational controls (A.5), 8 people controls (A.6), 14 physical controls (A.7) and 34 technological controls (A.8). The 2022 edition replaced the 114 controls of the 2013 edition in 14 domains, merging many and adding new ones such as threat intelligence, cloud services, data leakage prevention and secure coding. The transition from 2013 ended on 31 October 2025.

What is the most common ISO 27001 internal audit finding?

A gap between the Statement of Applicability and reality: a control marked as implemented with no evidence it operates, or a risk treatment plan that names controls nobody owns. Start the audit from the risk assessment and the Statement of Applicability, then sample controls for evidence that they run as described.

Related: ISO internal audit services, ISO certification support and ISO internal auditor training.

Other free checklists: ISO 9001 (quality), ISO 14001 (environment), ISO 45001 (health and safety), ISO 50001 (energy), ISO 14001 and ISO 45001 combined.