Skip to main content
Category: Audit Process

Internal Auditor

Also known as: IA, Internal Audit Function, Certified Internal Auditor (CIA)
Simply put

An internal auditor is typically a person within an organization who independently and objectively reviews how well the organization's operations, controls, and processes are working. Unlike an external auditor who issues a report or certification to outside parties, an internal auditor generally provides assurance and advice to the organization's own management and governance bodies. In a security compliance context, this role often helps prepare for and support external assessments such as a SOC 2 examination or an ISO 27001 certification audit.

Formal definition

An internal auditor performs an independent, objective assurance and consulting activity intended to add value and improve an organization's operations, commonly assessing the effectiveness of internal controls, risk management, and reporting processes. The role is often filled by a company employee or in-house function, and professional recognition may include the Certified Internal Auditor (CIA) credential offered by The Institute of Internal Auditors. In SOC 2 and ISO 27001 programs, internal audit is distinct from the external assessor: it does not issue the SOC 2 report (produced by a licensed CPA firm under SSAE 18) or the ISO 27001 certificate (issued by an accredited certification body). Notably, ISO/IEC 27001 clauses 4 through 10 require the organization to conduct internal audits of its information security management system (ISMS) at planned intervals, making the internal auditor a defined component of ISMS conformance, whereas its role in SOC 2 engagements is typically supportive rather than attestation-issuing. The scope, independence arrangements, and reporting lines of an internal auditor vary depending on the organization and the applicable framework.

Why it matters

The internal auditor provides organizations with an independent, objective line of sight into how well their controls, risk management, and reporting processes are actually functioning, before an external party ever looks. In security compliance programs, this function is often the difference between walking into an external assessment prepared and walking in blind. Because the internal auditor reports to the organization's own management and governance bodies rather than to outside parties, it can surface control gaps, remediation needs, and process weaknesses early enough to address them, adding value and improving operations rather than simply documenting failures after the fact.

The role carries different weight depending on the framework. For ISO/IEC 27001, the internal audit is not optional: the ISMS requirements in clauses 4 through 10 require the organization to conduct internal audits of its information security management system at planned intervals, which makes the internal auditor a defined component of demonstrating conformance to the standard. In SOC 2 engagements the role is typically supportive rather than attestation-issuing, helping the organization prepare for and sustain the controls that a licensed CPA firm will later examine.

It is important not to overstate what the internal auditor delivers. The internal audit function does not issue the SOC 2 report, which is produced by a licensed CPA firm under SSAE 18, nor does it issue the ISO 27001 certificate, which is issued by an accredited certification body. Its independence, scope, and reporting lines vary by organization and framework, and internal assurance does not substitute for the external examination or certification audit. Treating an internal audit result as equivalent to an external outcome is a common misunderstanding that can leave organizations with a false sense of assurance.

Who it's relevant to

Compliance and GRC Managers
Compliance and GRC managers rely on the internal audit function to identify control gaps and remediation needs ahead of external assessments. Internal audit findings help them prioritize work and demonstrate that controls are being monitored on an ongoing basis, particularly to satisfy the ISO 27001 requirement to conduct internal audits of the ISMS at planned intervals.
Security Engineers and Control Owners
Security engineers and the owners of specific controls interact with internal auditors during reviews of how effectively their controls operate. This internal review typically occurs before the external SOC 2 examination or ISO 27001 certification audit, giving control owners an opportunity to correct issues while they are still internal findings.
Management and Governance Bodies
Because the internal auditor generally provides assurance and advice to the organization's own management and governance bodies rather than to outside parties, leadership uses internal audit results to oversee the effectiveness of internal controls, risk management, and reporting processes and to make decisions about remediation.
Internal Audit Professionals
Individuals performing or aspiring to this role, including those pursuing the Certified Internal Auditor (CIA) credential offered by The Institute of Internal Auditors, need to understand how their independent, objective assurance work fits into SOC 2 and ISO 27001 programs, and the boundary that separates their role from the external CPA firm or accredited certification body that issues the actual report or certificate.

Inside IA

Independence from the audited activity
An internal auditor should not review processes for which they hold operational responsibility, so that the assessment remains objective. In smaller organizations full independence can be difficult, and compensating measures such as separation of duties or oversight are typically used.
Internal audit programme (ISO 27001 context)
ISO/IEC 27001 clause 9.2 requires the organization to conduct internal audits of the ISMS at planned intervals to determine whether the ISMS conforms to the organization's own requirements and to the standard, and whether it is effectively implemented and maintained. The audit programme, criteria, and scope are defined by the organization.
Distinction from external assessment
Internal audit is a self-assessment activity performed by or on behalf of the organization. It is separate from an external SOC 2 examination performed by a licensed CPA firm and from certification audits performed by an accredited certification body for ISO 27001.
Evidence gathering and findings
The internal auditor collects evidence against defined criteria and records findings, including nonconformities or control gaps, which feed corrective action and management review. The specific evidence and sampling approach depend on scope and the criteria being assessed.
Readiness support role
In many engagements, internal audit work helps an organization prepare for an external SOC 2 examination or an ISO 27001 certification audit by identifying gaps in advance, though it does not itself produce a SOC 2 report or an ISO 27001 certificate.

Common questions

Answers to the questions practitioners most commonly ask about IA.

Is the internal auditor the same as the external auditor who issues a SOC 2 report or ISO 27001 certificate?
No. The internal auditor is part of the organization's own assurance function and cannot issue a SOC 2 report or an ISO 27001 certificate. A SOC 2 report is issued only by a licensed CPA firm performing an attestation examination under the AICPA SSAE 18 standard, and an ISO 27001 certificate is issued only by an accredited certification body. Internal audit work supports readiness and ongoing conformity but does not substitute for the independent external engagement.
Does having an internal auditor mean the organization automatically satisfies both SOC 2 and ISO 27001 requirements?
No. Internal audit activity contributes to a control environment and, in ISO 27001, internal audits are a requirement of the ISMS clauses (clauses 4 through 10). However, the two frameworks are distinct: SOC 2 is an attestation examination and ISO 27001 is a management system certification, and satisfying one does not automatically satisfy the other. Mapping between them is possible but partial, so internal audit coverage for one framework does not guarantee coverage for the other.
How does the internal auditor's role differ between a SOC 2 engagement and an ISO 27001 certification?
In an ISO 27001 context, internal audits are an explicit ISMS requirement within clauses 4 through 10 and are typically conducted on a planned basis to check conformity and effectiveness. In a SOC 2 context, internal audit is not a defined role within the AICPA attestation itself; instead, internal auditors typically support readiness by testing controls mapped to the applicable Trust Services Criteria before the external CPA firm performs its examination. In both cases the scope of internal audit work depends on the organization's decisions.
How should an internal auditor decide what to include in the audit scope?
Scope typically follows the framework being addressed. For ISO 27001, internal audit scope is informed by the defined scope of the ISMS, the risk assessment, and the Statement of Applicability, which determines which Annex A reference controls apply. For SOC 2, scope is driven by the selected Trust Services Criteria, Security (the Common Criteria) is required, while Availability, Processing Integrity, Confidentiality, and Privacy are optional and chosen based on scope. Because scoping is set by the organization, coverage varies between engagements.
Can internal audit evidence be reused by the external auditor or certification body?
It depends on the engagement. External auditors and certification bodies exercise their own professional judgment about how much reliance they place on internal audit work, and this varies by auditor, certification body, and scope. Internal audit documentation can help demonstrate readiness and support the external process, but it does not replace the independent testing the external party performs to reach its own conclusion.
How often should internal audits be performed to support ongoing compliance?
Frequency depends on the framework, scope, and the organization's risk decisions rather than a single fixed rule. For ISO 27001, internal audits are typically conducted on a planned basis to support the ISMS. For SOC 2, internal testing frequency often aligns with readiness needs and the review period being pursued, recognizing that a Type II examination assesses operating effectiveness over a defined period whose length is set by scoping decisions, while a Type I assesses design at a point in time.

Common misconceptions

An internal audit produces a SOC 2 report or an ISO 27001 certificate.
Internal audit is a self-assessment activity. A SOC 2 report can only result from an examination performed by a licensed CPA firm under SSAE 18, and an ISO 27001 certificate can only be issued by an accredited certification body. Internal audits inform readiness but do not produce either outcome.
A clean internal audit guarantees a successful external SOC 2 examination or ISO 27001 certification.
An internal audit reflects the organization's own assessment against its chosen criteria and scope. External conclusions depend on the auditor or certification body, the scope, the applicable criteria, and the evidence reviewed, so a favorable internal result does not guarantee the external outcome.
The internal auditor can audit any process regardless of their own responsibilities.
Objectivity is typically expected, so an internal auditor should generally not assess activities for which they are operationally responsible. Where full independence is impractical, compensating measures are commonly applied.

Best practices

Define the internal audit scope, criteria, and schedule in advance, and align them with the framework being addressed (for ISO 27001, the clause 9.2 internal audit requirement; for SOC 2 readiness, the selected Trust Services Criteria).
Preserve objectivity by assigning auditors who are not responsible for the activities under review, and apply compensating oversight where full independence is not feasible.
Document findings, nonconformities, and control gaps with supporting evidence, and route them into corrective action and management review.
Use internal audit results as readiness input before an external SOC 2 examination or ISO 27001 certification audit, while recognizing that the external outcome is determined by the CPA firm or certification body.
Confirm which framework and version apply before assessing controls, since criteria differ between SOC 2 Trust Services Criteria and ISO 27001 requirements and Annex A reference controls, and Annex A control counts depend on the edition.
Communicate the limits of internal audit clearly to stakeholders, noting that it covers only the defined scope and criteria and does not by itself constitute an attestation or certification.