Skip to main content
Category: Audit Process

ISMS Audit Programme

Also known as: ISMS Audit Program, ISO 27001 Internal Audit Programme, ISMS Internal Audit Program
Simply put

An ISMS audit programme is a planned, ongoing set of internal audits an organization uses to check that its Information Security Management System (ISMS) meets the requirements of ISO/IEC 27001 and the organization's own requirements. Its purpose is to find and resolve gaps or deficiencies in the ISMS before they cause problems. It is an internal activity and is distinct from the external audit performed by an accredited certification body.

Formal definition

Within an ISO/IEC 27001 ISMS, an audit programme is the managed arrangement of internal audits scheduled over time to provide assurance that the ISMS conforms to the requirements of ISO/IEC 27001 and to the organization's defined information security requirements. In practice, internal audits within the programme evaluate the organization's information security practices to identify gaps, deficiencies, and risks and to support conformity ahead of, and between, certification body assessments; the specific scope, frequency, and methods typically depend on the organization's risk profile and scoping decisions. The programme supports internal audit obligations under the ISMS requirements (ISO/IEC 27001 clauses 4 through 10) and is separate from external certification audits and from the selection of Annex A reference controls via the Statement of Applicability. Because it is an internal control activity, it provides assurance over the defined ISMS scope only and does not itself result in certification.

Why it matters

An ISMS audit programme is the mechanism through which an organization gains ongoing internal assurance that its Information Security Management System actually conforms to ISO/IEC 27001 and to its own defined information security requirements. Rather than treating conformity as a once-a-year event, a well-run programme identifies gaps, deficiencies, and risks continuously, so that problems can be resolved before they escalate or before they surface during an external certification body assessment. This makes it a practical early-warning system for the ISMS.

The programme also matters because internal auditing is one of the ISMS requirements found in ISO/IEC 27001 clauses 4 through 10. An organization pursuing or maintaining certification typically needs to demonstrate that it plans, conducts, and acts on internal audits over time, not merely that it holds a set of controls on paper. A credible programme gives management, and ultimately the certification body, evidence that the ISMS is being tested and improved between assessments.

It is important to keep expectations proportionate, however. An ISMS audit programme is an internal control activity that provides assurance over the defined ISMS scope only. It does not itself result in certification, which is issued by an accredited certification body following its own external audit, and it does not guarantee freedom from security incidents. Its value lies in surfacing issues early, not in providing an absolute assurance of security.

Who it's relevant to

ISMS Managers and Information Security Leads
Those responsible for maintaining the ISMS use the audit programme to plan internal audits over time and to confirm that the system conforms to ISO/IEC 27001 and to the organization's own requirements. It gives them a structured way to find and resolve gaps and deficiencies before they cause problems or surface in an external assessment.
Internal Auditors
Internal auditors execute the individual audits within the programme, evaluating information security practices to identify gaps, deficiencies, and risks. They rely on the programme's defined scope, frequency, and methods, which typically depend on the organization's risk profile and scoping decisions, to structure their work.
GRC and Compliance Professionals
Compliance and governance teams use the programme to demonstrate that internal audit obligations under the ISMS requirements (clauses 4 through 10) are being met on an ongoing basis. It helps them keep the ISMS audit-ready ahead of, and between, certification body assessments, while recognizing that it provides assurance over the defined scope only and does not itself result in certification.
Senior Management and ISMS Owners
Leadership accountable for the ISMS relies on the programme's findings for assurance that the management system is being tested and improved over time. This supports informed decisions about resolving deficiencies before they escalate, with the understanding that internal audit outcomes are distinct from external certification results.

Inside ISMS Audit Programme

Audit Programme Definition
A planned, documented arrangement of one or more internal audits covering the ISMS over a defined timeframe, established to fulfil the internal audit requirements set out in ISO/IEC 27001 clauses 4 through 10, and specifically clause 9.2 on internal audit.
Scope and Coverage
A definition of which parts of the ISMS, processes, and clauses will be audited and over what cycle. The programme typically ensures all applicable requirements and controls selected via the Statement of Applicability are examined across the cycle, though the exact frequency and depth depend on scoping decisions.
Frequency and Scheduling
A schedule indicating when audits occur. The programme generally considers the importance of processes and results of previous audits when setting frequency; specific intervals vary by organisation rather than being fixed by the standard.
Audit Criteria and Methods
The reference points against which the ISMS is assessed (such as clause requirements, the organisation's own policies, and applicable Annex A reference controls) and the methods used to gather objective evidence, which depend on the auditor and engagement scope.
Auditor Assignment and Independence
Provisions for selecting auditors and conducting audits in a manner that supports objectivity and impartiality, typically meaning auditors do not audit their own work.
Reporting and Records
Documented information recording the programme, audit results, findings, and any nonconformities identified, retained as evidence that the audit activity was carried out.
Linkage to Corrective Action
A connection between audit findings and the organisation's corrective action and management review processes, so that identified nonconformities are addressed and feed continual improvement of the ISMS.

Common questions

Answers to the questions practitioners most commonly ask about ISMS Audit Programme.

Is an ISMS audit programme the same as the external certification audit performed by a certification body?
No. The ISMS audit programme typically refers to the organization's own planned schedule of internal audits, which is an ISMS requirement under the clauses 4 through 10 framework of ISO/IEC 27001. Internal audits are conducted by or on behalf of the organization to check that the ISMS conforms to its own requirements and to the standard. The external certification audit, by contrast, is carried out by an accredited certification body and leads to the ISO 27001 certificate. The two are distinct activities, and a robust internal audit programme is generally expected to be in place ahead of a certification audit rather than replacing it.
Does an ISMS audit programme have to cover every Annex A control in every audit cycle?
Not in a single audit and not in a fixed way. The audit programme is typically planned to cover the ISMS requirements and the applicable controls over time, with scope, frequency, and priorities informed by the results of risk assessment and the importance of the areas concerned. Which Annex A controls are in scope at all depends on the Statement of Applicability, since Annex A lists reference controls selected via that document rather than a mandatory checklist. In most programmes, coverage is distributed across a cycle rather than attempting everything at once, and the specific approach depends on the organization's scope and decisions.
How often should internal audits be scheduled within the programme?
The standard does not prescribe a fixed interval, so frequency is generally set at the organization's discretion based on the status and importance of the processes and areas, along with the results of previous audits. In most engagements the programme is designed so that the ISMS requirements and applicable controls are covered over a defined cycle, with higher-risk or higher-importance areas typically audited more often. The appropriate cadence depends on scope, resources, and risk, so it is best documented within the programme itself rather than assumed.
Who is qualified to conduct the internal audits under the programme?
Internal audits are typically conducted by auditors selected to ensure objectivity and impartiality of the audit process. In practice this often means auditors do not audit their own work, so an area's owner would not usually audit that same area. Depending on scope and available resources, organizations may use trained internal staff from other functions, a separate internal audit team, or outsource the activity to a competent third party. The programme should define the criteria for auditor competence and independence rather than leaving them implicit.
How should audit findings from the programme be handled?
Findings from internal audits typically feed into the organization's corrective action and continual improvement processes. Nonconformities identified are generally recorded, evaluated for cause, and addressed through corrective actions, with results tracked to closure. Audit results are also commonly reported to relevant management and used as an input to management review. The exact workflow depends on how the organization has structured its ISMS, but the programme should make clear how findings are documented, escalated, and resolved.
What documentation supports an effective ISMS audit programme?
In most implementations the programme is supported by documented audit plans, defined audit scope and criteria, records of the audits conducted, and records of results including any nonconformities and follow-up actions. Retaining this documented information helps demonstrate that audits were planned, performed, and acted upon. Because it provides evidence of the internal audit activity, this documentation is often reviewed during the certification body's assessment, though the precise records expected can vary with scope and the certification body's approach.

Common misconceptions

The ISMS internal audit programme is the same as the external certification audit performed by a certification body.
The internal audit programme is an organisation's own activity supporting the ISMS requirements in clauses 4 through 10. It is distinct from the assessment conducted by an accredited certification body that leads to an ISO/IEC 27001 certificate; both are typically expected but serve different purposes.
ISO 27001 prescribes a fixed audit frequency, such as auditing everything annually.
The standard requires that audits be planned considering factors like the importance of processes and prior results, but it does not mandate a single universal interval. Frequency and coverage depend on scoping decisions and the organisation's context.
An ISMS audit programme covers the SOC 2 Trust Services Criteria as well.
The ISMS audit programme addresses ISO/IEC 27001 requirements and the Annex A reference controls selected via the Statement of Applicability. The Trust Services Criteria are a separate framework used in SOC 2 examinations; mapping between the two is possible but partial, and auditing one does not automatically satisfy the other.

Best practices

Plan the programme so that all applicable clause requirements and selected Annex A controls are covered across the audit cycle, using previous audit results and the importance of each process to prioritise.
Assign auditors in a way that preserves objectivity and impartiality, typically ensuring individuals do not audit their own work.
Define audit criteria and methods clearly for each audit, referencing the relevant clauses, internal policies, and the Statement of Applicability.
Retain documented information on the programme, schedules, and audit results as evidence that internal audit activity was performed.
Link audit findings to the corrective action and management review processes so that nonconformities are addressed and support continual improvement.
Review and adjust the programme over time based on changes in scope, prior findings, and the evolving context of the ISMS rather than treating it as static.