ISO 27001 clause 9.2 / Independent by rule

ISO 27001 Internal Audit Service

The clause 9.2 internal audit your certification body expects, performed by an auditor who did not build or operate your ISMS. Also covers ISO 42001 AI management systems.

$4,500 per audit. $7,900 for the annual programme. Fixed.

Independence stated in the reportControls sampled in live systemsYou review before you pay
Independent ISO 27001 clause 9.2 internal audit service by Atlant Security

Why the Internal Audit Keeps Failing

Your certification body visit is booked and clause 9.2 is not evidenced

ISO 27001 requires internal audits at planned intervals, by auditors who are objective and impartial about what they audit. A missing or self-performed internal audit is the first nonconformity an external auditor looks for, because it is the easiest to find.

The only person who could audit the ISMS is the person who runs it

In a team of five to fifty, the ISMS manager cannot audit their own work and nobody else has the standard in their head. The result is either no audit or an audit that does not survive a certification body question.

The consultant who built your ISMS offered to audit it too

That is the same independence problem with a vendor logo on it. Auditing your own implementation is a segregation-of-duties failure. We only audit management systems we did not design or operate, and we say so in the report.

ISO 27001 clause 9.2 requires internal audits at planned intervals by impartial auditors
96,709 valid ISO 27001 certificates worldwide each needing internal audits every cycle

What the Audit Covers

A full internal audit covers the management system clauses and the controls you declared applicable. We sample controls in the systems where they live, because a certification body will, and a document-only internal audit gives you false comfort.

Clauses 4 to 10
Context, leadership, planning, support, operation, performance evaluation, improvement
Statement of Applicability
Every included and excluded Annex A control, with justification checked
Control sampling
Evidence that selected controls are implemented and effective, not just documented
Risk treatment
Risk assessment methodology applied consistently and treatment plans tracked
Management review
Inputs, outputs and decisions recorded as clause 9.3 requires
Corrective action
Previous nonconformities closed with root cause and verification
What the annual ISO 27001 internal audit programme covers
Also covered: ISO 42001 and ISO 22301 internal audits and mock audits
Why auditor independence is not optional under ISO 27001

Independence Is the Product

Clause 9.2 requires auditors to ensure objectivity and impartiality. Many consultancies implement an ISMS and then run its internal audit, mock audit and risk assessment with the same people. Certification bodies notice, and so do customers doing due diligence.

We hold a simple rule: we do not audit management systems we designed or operate, and we do not take the ISMS manager seat for a client we audit. Each report carries a signed independence statement saying so.

If you want us to build your ISMS as well, we will point you to a separate auditor. Turning that work down is what makes the audit worth paying for.

Who Uses an External Internal Auditor?

SaaS companies holding ISO 27001 with no independent auditor in-house
Fintech and payment firms whose auditors and customers both ask for the audit programme
Manufacturers combining ISO 27001 with TISAX or NIS 2 obligations
AI vendors extending an ISMS into ISO 42001 who need both systems audited

Compared With the Alternatives

Atlant SecurityTypical arrangement
IndependenceWe never audit an ISMS we built or operate, and the report states itThe implementation consultant audits their own work
Who auditsA CISSP with 200+ assessments across 14 countries, personallyA junior with a checklist template
Technical depthControls sampled in the live systems: Entra, AWS, endpoints, codeDocument review only
ShapeAn annual programme with a tracker, not a one-off PDFA single audit, then silence until next year
PricingPublished per audit and per programmeQuoted after the scoping call

How an Audit Cycle Runs

1

Plan

Audit programme, scope, criteria and schedule agreed with management and aligned to your surveillance or recertification date. Auditor independence confirmed in writing.

2

Fieldwork

Remote evidence review, interviews with control owners, and sampling of technical controls in the systems themselves rather than in screenshots.

3

Report

Findings graded as major, minor or opportunity, each with the clause or control reference, root cause and a proposed corrective action.

4

Follow-up

Nonconformity closure verified before the certification body arrives, and a management review input pack with trends across cycles.

How an ISO 27001 internal audit cycle runs in four steps
Deliverables per ISO 27001 internal audit

Pricing

Published and fixed. An internal audit is two to five auditor days of judgement, and the price reflects that rather than a template with your logo.

Single Internal Audit

One full-scope audit of a single-site ISMS ahead of a surveillance or recertification visit.

$4,500fixed
  • Audit plan and independence statement
  • Clauses 4 to 10 and Statement of Applicability
  • Control sampling in live systems
  • Graded findings report with references
  • Nonconformity and corrective action tracker
Book Free Planning Call
Recommended

Annual Audit Programme

Two audits a year, the tracker maintained between them, and management review inputs.

$7,900per year
  • Everything in the single audit, twice a year
  • Audit programme aligned to your CB calendar
  • Corrective action follow-up and closure verification
  • Management review input pack with trends
  • Certification body liaison on audit day
  • ISO 42001 integration available
Book Free Planning Call

Multi-site and integrated ISO 27001 and ISO 42001 programmes are priced per site in writing before we start. You review the report before you pay.

Walk Into the Certification Audit Already Audited

One planning call, an audit programme aligned to your certification body dates, and findings you can close before anyone else sees them.

Book Your Planning Call

Schedule Your Free Audit Planning Call

ISO 27001 Internal Audit FAQ

What does ISO 27001 actually require for internal audits?
Clause 9.2 requires the organisation to conduct internal audits at planned intervals to determine whether the ISMS conforms to its own requirements and to the standard, and is effectively implemented and maintained. The organisation must plan an audit programme, define criteria and scope, select auditors who ensure objectivity and impartiality, report results to management and retain documented evidence. Certification bodies check all of these.
Can we do the internal audit ourselves?
You can, if you have someone competent in the standard who is independent of the area being audited. In practice, small and mid-size certified companies rarely do: the ISMS manager cannot audit their own work and nobody else holds the standard. An external internal auditor is the normal solution and is explicitly acceptable to certification bodies.
Why will you not audit an ISMS you helped build?
Because that would be auditing our own work. ISO 27001 clause 9.2 requires objectivity and impartiality, and an auditor who designed the controls cannot credibly find them deficient. If we implemented your ISMS, we will recommend a separate auditor for the internal audit, and vice versa. The rule is inconvenient and it is the point.
How often do we need one?
The standard says at planned intervals and leaves the frequency to you, but certification bodies expect the full ISMS to be covered within each certification cycle and most organisations audit annually, with surveillance visits in between. The annual programme option spreads coverage across two audits so no visit lands on a cold ISMS.
Do you also audit ISO 42001?
Yes. ISO 42001 has the same clause 9.2 structure for the AI management system, and organisations that hold both standards usually want an integrated audit programme so the shared clauses are covered once. We audit AIMS implementations we did not build, under the same independence rule.
What do we receive?
A formal internal audit report with graded findings and references, a nonconformity and corrective action tracker, an audit evidence file structured for the certification body, a management review input pack with trends, and a signed auditor competence and independence statement.
How much does it cost?
A single internal audit of a single-site ISMS is $4,500 fixed, typically two to five auditor days. The annual programme, which covers two audits, the tracker maintained between them, and the management review pack, is $7,900 per year. Multi-site and integrated ISO 27001 and 42001 programmes are quoted per site before we start.
Is it done remotely?
Almost entirely. Evidence review, interviews and control sampling in your systems are remote. Physical security controls at a site are checked on site where they are in scope, priced separately.

Related Services