Internal audit and management review: the two clauses your certifier may not do
Clause 9.2 requires an internal audit and clause 9.3 a management review. A certification body looks for both at Stage 1, again at Stage 2, and at every surveillance audit after that.
On this page (6)
Clause 9.2 of ISO/IEC 27001:2022 requires an internal audit. Clause 9.3 requires a management review. A certification body looks for evidence of both before it will conclude Stage 1, looks again at Stage 2, and looks again at every surveillance audit for as long as you hold the certificate.
Clause 9.3 puts the review in the hands of your own top management. And ISO/IEC 17021-1:2015 bars the certification body from carrying out your internal audits, while the ISMS-specific standard requires it to be independent of whoever does.
That is the scheme working as designed, and it puts a recurring, mandatory piece of work permanently outside the party most organisations would naturally ask.
What clause 9.2 asks for
Clause 9.2.1 sets the object of the audit. The organisation shall conduct internal audits at planned intervals to provide information on whether the information security management system
"a) conforms to
- the organization's own requirements for its information security management system;
- the requirements of this document; b) is effectively implemented and maintained."
Two things follow and both get missed. The audit is against your requirements as well as the standard's — your policies, your risk treatment decisions, your Statement of Applicability — so an audit that only walks the clauses of ISO 27001 has done half the job. And "effectively implemented and maintained" tests operation, not documentation: a procedure that exists and is not followed conforms on paper and fails 9.2.1 b).
Clause 9.2.2 governs the programme rather than the audit. The organisation shall plan, establish, implement and maintain an audit programme "including the frequency, methods, responsibilities, planning requirements and reporting", taking account of the importance of the processes concerned and the results of previous audits. It then requires defined criteria and scope for each audit, auditors selected and audits conducted "that ensure objectivity and the impartiality of the audit process", results reported to relevant management, and documented information as evidence.
"Planned intervals" and "frequency" are programme properties. There is no single internal audit; there is a programme, and a certification body reads the programme.
What clause 9.3 asks for
Clause 9.3.1: top management shall review the information security management system at planned intervals "to ensure its continuing suitability, adequacy and effectiveness". Top management, not the security team, and at an interval the organisation sets and records.
Clause 9.3.2 fixes the agenda. The review shall include the status of actions from previous management reviews; changes in external and internal issues relevant to the ISMS; changes in the needs and expectations of interested parties; feedback on information security performance, including trends in nonconformities and corrective actions, monitoring and measurement results, audit results, and fulfilment of information security objectives; feedback from interested parties; the results of risk assessment and the status of the risk treatment plan; and opportunities for continual improvement.
Seven inputs, and the record has to show all seven reached the people making the decisions. Two are what organisations most often cannot produce on demand: the status of actions from the previous review, which requires a previous review with actions recorded, and the results of risk assessment with the status of the risk treatment plan, which requires the risk register to have been touched since it was written.
Clause 9.3.3 requires the results to include decisions on continual improvement opportunities and on any needs for changes to the ISMS, with documented information available as evidence. The decisions are the output the standard asks you to evidence, so a review recorded as attendance and slides has recorded the wrong half of the meeting.
Where the certification body checks
ISO/IEC 17021-1:2015 is the standard certification bodies are accredited against, and it tells them where to look.
| Audit | Clause | What is examined |
|---|---|---|
| Stage 1 | 9.3.1.2.2 g) | Whether internal audits and management review are being planned and performed, and whether the level of implementation shows the client is ready for Stage 2 |
| Stage 2 | 9.3.1.3 e) | Internal auditing and management review, as one of the elements of evaluating implementation and effectiveness |
| Every surveillance audit | 9.6.2.2 a) | Internal audits and management review — first on the list each surveillance audit must review |
| Recertification | 9.6.3.1.2 | Performance of the management system across the whole certification period, including review of the previous surveillance audit reports |
Read the first row again. Stage 1 is the certifier's first visit, and one of its stated objectives is to evaluate whether internal audit and management review are being planned and performed. Both have to have happened before that visit concludes. Scheduling the internal audit for "after Stage 1, before Stage 2" misreads the sequence, and the correction lands where it is most expensive.
Then it recurs. Clause 9.1.3.2 requires the certifier's audit programme to cover a two-stage initial audit, surveillance in the first and second years after the certification decision, and recertification in the third year before expiry; clause 9.1.3.3 requires surveillance at least once a calendar year except in recertification years, the first not more than twelve months from the decision date. Each of those surveillance audits reviews internal audit and management review under 9.6.2.2 a) — four examinations of the same two clauses in the first cycle, and 9.1.3.2 restarts the cycle at each recertification decision.
Why it cannot be the certification body
ISO/IEC 17021-1:2015, clause 5.2.6, verbatim:
"The carrying out of internal audits by the certification body and any part of the same legal entity to its certified clients is a significant threat to impartiality. Therefore, the certification body … shall not offer or provide internal audits to its certified clients. A recognized mitigation of this threat is that the certification body shall not certify a management system on which it provided internal audits for a minimum of two years following the completion of the internal audits."
"Shall not offer or provide" is the prohibition. The two-year rule that follows is the recognised mitigation where a body has done the work anyway, and it runs from completion of the internal audits.
The ISMS-specific standard goes further, and its clause constrains your choice rather than your certifier's. ISO/IEC 27006-1:2024 is what an accreditation body assesses an ISMS certification body against. Its clause 5.2.1 applies the whole of ISO/IEC 17021-1:2015 clause 5.2, and 5.2.2 then adds:
"The certification body shall not provide internal information security reviews of the client's ISMS subject to certification. Furthermore, the certification body shall be independent from the body or bodies (including any individuals) which provide the internal ISMS audit."
Read the second sentence as a buyer. Clause 5.2.6 keeps your certification body out of your internal audit; this one requires it to be independent of whoever performs it. Who you appoint is therefore a condition of your certifier's own accreditation, not a matter of preference.
Accreditation is what enforces all of this, and its top layer changed this year. The International Accreditation Forum ceased operations on 1 January 2026; it and the International Laboratory Accreditation Cooperation became Global Accreditation Cooperation Incorporated, which commenced operations the same day under a single Multilateral Recognition Arrangement covering the scopes previously recognised under the IAF MLA and the ILAC MRA. The older marks "will remain valid for as long as required until full adoption of the Global Accreditation Cooperation Incorporated new mark", so a certificate carrying an IAF logo is not stale on that account. A page still describing the IAF MLA as a current arrangement is a different matter.
Which party produces which document across the programme is in who issues an ISO 27001 certificate; the full set of impartiality clauses, and how to read a proposal against them, is in why the firm that prepares you cannot be the firm that certifies you.
The failure that makes an internal audit worthless
An internal audit performed by the person who wrote the control is the commonest way a compliant-looking programme collapses at Stage 2.
Clause 9.2.2 b) requires the organisation to select auditors and conduct audits "that ensure objectivity and the impartiality of the audit process". ISO 19011:2026 — the fourth edition, published in May 2026, which cancels and replaces ISO 19011:2018 — states the principle behind it at clause 4.6:
"Auditors should be independent of the activity being audited wherever practicable and should in all cases act in a manner that is free from bias and conflict of interest. Auditors should maintain objectivity throughout the audit process to ensure that the audit findings and conclusions are based only on the audit evidence."
In a thirty-person company the person who runs the ISMS wrote every procedure in it. When that person audits access control against a procedure they drafted, the audit is not testing the control; it is restating the intent behind it. The visible symptom is an audit programme that has produced no nonconformities across a full cycle, which gives a certifier assessing 9.3.1.2.2 g) little to evaluate. An ISMS in its first year has findings. An audit report with none is more often evidence about the auditor than about the system.
Two routes satisfy 9.2.2 b): an auditor from a different function with no responsibility for what they audit, or an independent party from outside — in either case one that survives the 27006-1 test above. ISO/IEC 27007:2020 carries ISMS-specific auditing guidance on top of ISO 19011.
What the programme has to leave behind
Evidence, not activity. By the time Stage 1 opens the file should hold: an audit programme setting frequency, methods, responsibilities, planning requirements and reporting; defined criteria and scope for each audit in it; a record of auditor selection that speaks to objectivity and impartiality; audit reports showing what was sampled and concluded; evidence that results reached relevant management; management review records covering all seven inputs of 9.3.2 and the decisions required by 9.3.3; and corrective actions tracked to closure under clause 10.2.
One numbering trap while you are citing it. In ISO/IEC 27001:2022, clause 10.1 is Continual improvement and 10.2 is Nonconformity and corrective action; in the 2013 edition the two were the other way round. A corrective action register routing internal audit findings to "10.1 Nonconformity and corrective action" is written against a superseded edition, and that is the kind of reference an auditor pulls the thread on.
Security Brigade runs the clause 9.2 internal audit as an independent party: a programme scoped to your ISMS and to your own requirements, auditors who did not write the controls they are testing, and findings written so corrective action under clause 10.2 closes before your certification body arrives for Stage 1. Tell us your certification body and your Stage 1 date, and we will tell you what the programme has to cover.
Every clause number, quotation and date above was checked against published text on 27 August 2026.
Continue reading
All articles →Why the firm that prepares you cannot be the firm that certifies you
No certification body may prepare you for its own audit, nor may any entity under its organisational control. Where a related body prepares you, it shall not certify you for two years.
Who issues an ISO 27001 certificate, and what every other party produces
An ISO 27001 programme produces four kinds of document and no party produces more than two. Who holds the certificate, the accreditation, and the Statement of Applicability.
The Indian law that names ISO 27001 — and what changes on 13 May 2027
One Indian rule names IS/ISO/IEC 27001 in its own text and deems an audited implementation compliance with the IT Act. A later Act omits the provisions it was made under.