ISO 27001 Internal Audits

companies operating in regulated sectors such as medical devices, healthcare, and life sciences, protecting sensitive information—whether patient data, design documents, or clinical trial results—is not only critical for business continuity but also required under stringent regulatory obligations. This is where ISO/IEC 27001, the international standard for Information Security Management Systems (ISMS), comes into play.
ISO 27001 internal audits

Updated: 2nd July 2026

Reviewed by: David Small BSc (Hons), MSc, MTOPRA (Founder and CEO)

Understanding the Importance of ISO 27001 Internal Audits

A central component of ISO 27001 compliance is the internal audit process. More than just a tick-box activity, ISO 27001 internal audits are a powerful mechanism for identifying security risks, closing compliance gaps, and driving continuous improvement across the ISMS.

In this article, we will explore what ISO 27001 internal audits are, why they matter, and how to conduct them effectively within your organisation.

What Is ISO 27001?

ISO/IEC 27001 is the leading international standard that outlines the requirements for establishing, implementing, maintaining, and continually improving an ISMS. The standard follows a risk-based approach and promotes the protection of confidentiality, integrity, and availability of information.

An effective ISMS enables organisations to manage risks related to data breaches, cyberattacks, or misuse of information—threats that have become increasingly prevalent across all industries.

Untitled-design-2025-04-06T112113.839

The Role of Internal Audits in ISO 27001

Clause 9.2 of ISO 27001 outlines the requirement for organisations to conduct internal audits at planned intervals. The purpose of the audit is to:

  • Determine whether the ISMS conforms to the organisation’s own requirements and the requirements of ISO 27001.

  • Assess the effective implementation and maintenance of the ISMS.

  • Identify opportunities for improvement.

An internal audit serves as a mirror, allowing organisations to critically evaluate how well their security controls, processes, and procedures are performing in practice.

Why Internal Audits Are Crucial

Organisations that treat internal audits as more than just a compliance requirement are better positioned to build resilient, future-ready information security systems. Here’s why internal audits are critical:

1. Verify Compliance with ISO 27001 and Regulatory Requirements

Internal audits help ensure that the ISMS aligns with ISO 27001 requirements. For medical device companies and healthcare service providers, audits can also uncover gaps related to GDPR, MDR, HIPAA, or local data protection laws.

2. Identify and Mitigate Security Risks

Audits enable early identification of vulnerabilities or nonconformities before they escalate into incidents. This proactive risk management approach is at the heart of ISO 27001.

3. Support Continuous Improvement

ISO 27001 promotes a Plan-Do-Check-Act (PDCA) model. Internal audits are part of the “Check” phase, helping evaluate whether policies and controls are functioning as intended and guiding corrective actions.

4. Prepare for Certification and Surveillance Audits

A well-conducted internal audit program prepares organisations for external audits by certification bodies, making sure that everything from documentation to control effectiveness is in top form.

Planning and Conducting an ISO 27001 Internal Audit

1. Establish an Audit Program

The audit program should cover the entire scope of your ISMS and be risk-based. Some areas may need to be audited more frequently based on their importance or history of nonconformities.

Define:

  • Objectives and criteria: What are you auditing against? (e.g. ISO 27001 clauses, internal policies)

  • Frequency: How often will audits be conducted?

  • Responsibilities: Who will plan, perform, and report the audits?

  • Methods: On-site, remote, interviews, document reviews, technical tests, etc.

2. Ensure Auditor Competency and Impartiality

Auditors must be competent—meaning they understand ISO 27001, the ISMS, and your business environment. They must also be impartial and not audit their own work. For smaller organisations, this may require using external auditors or cross-functional audits.

3. Prepare the Audit Plan

An audit plan outlines:

  • Scope and objectives

  • Areas and processes to be audited

  • Timeframes

  • Audit methods

  • Resources needed

The plan should be shared with relevant stakeholders in advance to minimise disruption and ensure availability of key personnel.

4. Conduct the Audit

During the audit, the auditor gathers objective evidence by:

  • Reviewing documentation and records

  • Interviewing personnel

  • Observing processes in action

  • Inspecting physical or digital security controls

The auditor then assesses compliance, identifies nonconformities, and records observations and opportunities for improvement.

5. Report Findings

The audit report should be clear, concise, and actionable. It typically includes:

  • Audit scope, criteria, and objectives

  • Summary of the audit process

  • Details of any nonconformities or observations

  • Recommendations or corrective actions

  • Conclusions on ISMS effectiveness

Reports should be communicated to top management and relevant process owners.

6. Follow-Up and Corrective Actions

Nonconformities identified during the audit must be addressed through corrective actions. This involves:

  • Root cause analysis

  • Planning and implementing corrective actions

  • Verifying their effectiveness

  • Closing the findings formally

ISO 27001 expects this follow-up to be documented and tracked to closure.

Common Pitfalls in ISO 27001 Internal Audits

Even well-intentioned audit programs can fall short. Watch out for these common issues:

  • Lack of objectivity: Auditors reviewing their own departments or systems can introduce bias.

  • Superficial audits: Merely reviewing policies without testing implementation won’t provide a true picture.

  • Neglecting risk-based focus: Treating all areas equally instead of focusing on high-risk or critical areas undermines the value of audits.

  • Poor documentation: Audit trails must be clearly recorded to support findings and demonstrate due diligence.

  • Failure to act on findings: If audit results are ignored, the cycle of improvement is broken.

Integrating Audits into the ISMS Lifecycle

ISO 27001 is not a one-time achievement—it’s a living system. Internal audits play a key role in the ongoing lifecycle of the ISMS:

  • Post-incident reviews: Internal audits can validate the implementation of changes after a security breach or issue.

  • Control maturity checks: Are controls still suitable as the organisation grows or adopts new technologies?

  • Alignment with business strategy: Periodic audits help ensure that the ISMS evolves alongside business goals and risk appetites.

Internal Audit Tools and Techniques

Depending on your organisation’s size and complexity, you can use various tools to enhance your internal audit process:

    • Checklists aligned with ISO 27001 clauses and Annex A controls

    • Audit management software like ISMS.online, Conformio, or manual trackers (Excel, Google Sheets)

    • Risk and control matrices to tie audit findings back to the ISMS risk assessment

    • Templates for audit plans, reports, and corrective action tracking

When to Consider External Support

  • For some organisations—especially SMEs or those new to ISO 27001—developing and maintaining an effective audit function internally can be challenging. In such cases, external consultants can:

    • Act as impartial auditors

    • Provide training and mentoring to internal staff

    • Review or design your audit program

    • Perform mock audits before certification

    At Patient Guard, we support medical device manufacturers, healthcare providers, and digital health companies in building and maintaining effective ISMSs, including tailored internal audit support.

Frequently Asked Questions About ISO/IEC 27001 Internal Audits

There is no fixed frequency specified in the ISO 27001 standard. However, audits must be performed at planned intervals based on the needs of the business and the risk profile of the ISMS. Most organisations conduct internal audits annually, though high-risk areas or newly implemented controls may require more frequent auditing. The key is to ensure full ISMS coverage over a defined audit cycle (e.g., every 12 or 24 months).

Yes, but only if they are independent of the areas they are auditing and have the necessary competence. ISO 27001 requires internal auditors to be objective and impartial. If your IT team member is responsible for implementing controls, they shouldn’t audit those same controls. In smaller organisations, consider rotating responsibilities or engaging an external auditor to maintain independence.

Finding nonconformities is a normal and useful part of the internal audit process. Each nonconformity should be:

  1. Documented clearly with supporting evidence

  2. Assessed for risk or impact

  3. Addressed through a corrective action plan

  4. Reviewed to ensure the issue is fully resolved

Certification bodies will expect to see that internal findings are tracked and resolved in a structured way. It’s a sign of a healthy, functioning ISMS.

Not necessarily. You are only required to implement and audit the Annex A controls that are applicable to your ISMS, based on your risk assessment and Statement of Applicability (SoA). Your internal audit should check that:

  • The SoA correctly justifies which controls are included or excluded

  • The controls that are implemented are working effectively

  • There is evidence to support the control’s implementation and monitoring

This targeted approach ensures the audit remains relevant and risk-focused.

Conclusion: More Than a Checklist

ISO 27001 internal audits are not just a requirement—they’re a strategic tool that fosters risk awareness, drives compliance, and strengthens the integrity of your ISMS. When planned and executed thoughtfully, internal audits provide a window into the health of your security posture and a roadmap for continuous improvement.

If your organisation is pursuing ISO 27001 certification or simply wants to raise its information security maturity, embedding an effective internal audit process into your ISMS is a crucial step.

Need help setting up or performing your ISO 27001 internal audits?
Contact Patient Guard today for expert support tailored to the needs of your industry and your ISMS maturity level.

David Small BSc (Hons), MSc, MTOPRA

David Small BSc (Hons), MSc, MTOPRA

Reviewed by
David Small, BSc (Hons), MSc, MTOPRA
Founder & CEO |
20+ years in medical device regulatory affairs,  MDR/IVDR compliance and quality systems.

Patient Guards Recent Posts

Cosmetic Product Safety Report (CPSR): A Complete Guide to UK Cosmetic Compliance

Before a cosmetic product can legally be placed on the UK market, manufacturers and Responsible Persons must demonstrate that it is safe for human use under normal or reasonably foreseeable conditions. The Cosmetic Product Safety Report (CPSR) is one of the most important regulatory documents required under the UK Cosmetics Regulation. This guide explains what a CPSR is, who can prepare one, what information it must contain, how it relates to the Product Information File (PIF) and how it supports legal cosmetic compliance.

Read More »

IVDR PMPF Explained: A Complete Guide to Post-Market Performance Follow-up

Post-Market Performance Follow-up (PMPF) is a fundamental requirement under the EU In Vitro Diagnostic Regulation (IVDR), ensuring that manufacturers continually monitor the scientific validity, analytical performance and clinical performance of their in vitro diagnostic medical devices after CE marking. This guide explains IVDR PMPF requirements, PMPF Plans, PMPF Reports, Annex XIII expectations and how ongoing performance monitoring supports continued regulatory compliance throughout the device lifecycle.

Read More »

IVDR Scientific Validity Explained: A Complete Guide for Manufacturers

Scientific Validity is the first pillar of IVDR Performance Evaluation and provides the scientific foundation demonstrating that an analyte or biomarker is associated with a specific clinical condition or physiological state. This guide explains Scientific Validity under Regulation (EU) 2017/746, including literature reviews, Scientific Validity Reports, Annex XIII requirements, evidence appraisal and how Scientific Validity supports successful CE marking.

Read More »

Patient Guards Related Services

Patient Guards Regulatory Tools

Need Training?

Do you need training on Quality Management Systems or EU MDR/ EU IVDR? then check out our training courses.

Share this guide:
Posted on Google Google
Munna P profile picture
Munna P
52 days ago
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
Working with the Patient Guard team has been a great experience throughout our MHRA and ISO 13485 documentation journey. Their expertise, structured approach, and practical guidance helped our team build a robust quality management system while keeping us aligned with regulatory expectations. The collaboration was professional, responsive, and focused on finding solutions rather than simply identifying issues. A special thank you to Alex and Steve for their outstanding coordination, responsiveness, and continuous support throughout the project. They were always approachable, provided valuable feedback, and worked closely with our team to resolve challenges efficiently. Their commitment made a significant difference in keeping our documentation effort on track. I highly recommend Patient Guard to any healthcare or MedTech organization looking for experienced regulatory and quality system partners for MHRA, ISO 13485, and broader medical device compliance initiatives. Thank you again to the entire Patient Guard team for being such reliable partners.
Posted on Google Google
Peter Reeve profile picture
Peter Reeve
79 days ago
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
STEPPER design, manufacture & distribute eyewear across the globe. With the increasingly complex landscape concerning the placing of Mecial Devices onto the market, we realised we needed professional guidance. We found Patient Guard via a simple internet search and are delighted we did! They provide a pragmatic solution to our needs, are totally reliable & always available to answer our (often simplistic) questions. They are highly efficient & responsive to what is a changing picture in our world and nothing is too much trouble. We have a much better understanding of regulatory affairs and our responsibilities as manufacturers & distributors and they support us in navigating the requirements in different territories. Updating our Declaration of Conformity, ensuring our labelling is compliant and acting as our PRRC are the key areas of their service for us.
Posted on Google Google
Derek Timm profile picture
Derek Timm
79 days ago
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
For those companıes lookıng to comply to ISO standards and ın partıcular ISO13485 whıch to be honest ıs a nıghtmare I would strongly suggest goıng to the professıonals as ındeed we dıd by joınıng forces wıth Patıent Guard Ltd The staff are fantastıc nothıng ıs too much trouble and as a medıcal supply company we sımply cannot lıve wıthout them Thanks ın partıcular to Alex and Steve for all the hard work and our best regards from Dan Medıca South Lımıted
Posted on Google Google
BMSCriticalCare profile picture
BMSCriticalCare
116 days ago
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
Great service, very helpful and always willing to answer any questions we have,
Posted on Google Google
Thomson Software profile picture
Thomson Software
787 days ago
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
Alex Lewis of PatientGuard guided us through the ISO13485 process in a thorough, systematic and efficient manner. He was friendly, patient and willing to go the extra mile. Excellent service.
Verified by Trustindex
Trustindex verified badge is the Universal Symbol of Trust. Only the greatest companies can get the verified badge who has a review score above 4.5, based on customer reviews over the past 12 months. Read more

Most Popular

Cosmetic Product Safety Report (CPSR): A Complete Guide to UK Cosmetic Compliance

Before a cosmetic product can legally be placed on the UK market, manufacturers and Responsible Persons must demonstrate that it is safe for human use under normal or reasonably foreseeable conditions. The Cosmetic Product Safety Report (CPSR) is one of the most important regulatory documents required under the UK Cosmetics Regulation. This guide explains what a CPSR is, who can prepare one, what information it must contain, how it relates to the Product Information File (PIF) and how it supports legal cosmetic compliance.

Read More »

IVDR PMPF Explained: A Complete Guide to Post-Market Performance Follow-up

Post-Market Performance Follow-up (PMPF) is a fundamental requirement under the EU In Vitro Diagnostic Regulation (IVDR), ensuring that manufacturers continually monitor the scientific validity, analytical performance and clinical performance of their in vitro diagnostic medical devices after CE marking. This guide explains IVDR PMPF requirements, PMPF Plans, PMPF Reports, Annex XIII expectations and how ongoing performance monitoring supports continued regulatory compliance throughout the device lifecycle.

Read More »

IVDR Scientific Validity Explained: A Complete Guide for Manufacturers

Scientific Validity is the first pillar of IVDR Performance Evaluation and provides the scientific foundation demonstrating that an analyte or biomarker is associated with a specific clinical condition or physiological state. This guide explains Scientific Validity under Regulation (EU) 2017/746, including literature reviews, Scientific Validity Reports, Annex XIII requirements, evidence appraisal and how Scientific Validity supports successful CE marking.

Read More »

IVDR Performance Evaluation Explained: A Complete Guide for Manufacturers

Performance Evaluation is one of the most important requirements under the EU In Vitro Diagnostic Regulation (IVDR). Every manufacturer must demonstrate that their in vitro diagnostic medical device achieves its intended purpose through robust scientific validity, analytical performance and clinical performance evidence. This guide explains every stage of IVDR Performance Evaluation, including Performance Evaluation Plans (PEPs), Performance Evaluation Reports (PERs), Post-Market Performance Follow-up (PMPF) and how Performance Evaluation supports successful CE marking under Regulation (EU) 2017/746.

Read More »
patient guard
Patient Guard

Sign up to our newsletter

Be the first to hear industry news and how Patient Guard can help you.

Get the latest updates on medical device regulation

Sign up to our newsletter and we’ll deliver news and insights straight to your inbox.

Get the Medical Device Technical Checklist

Thank you! The checklist is now ready to download.