ISO 37001:2016
Performance evaluation – ISO 37001:2016

ISO 37001:2016 9.2: 9.2 Internal audit

Run internal audits at planned intervals that show whether the system meets the organization's own requirements and this standard and is effectively implemented and maintained (9.2.1). Plan, set up, run and maintain audit programmes that set how often audits happen, how they are done, who is responsible, what planning requires and how results are reported, weighted by how important the processes are and by earlier results; set criteria and scope for each audit; choose competent auditors and conduct audits objectively and impartially; send the results to the managers concerned, to the compliance function, to top management and, where appropriate, to the governing body; and keep evidence of the programme and results (9.2.2). Audits are reasonable, proportionate and risk-based, and look at procedures, controls and systems for bribery, actual or suspected, breaches of the policy or system, business associates' failures to meet the organization's anti-bribery requirements, and weaknesses or improvement opportunities in the system (9.2.3). For objectivity they are done by an independent function or person set up or appointed for the purpose, by the compliance function (except where the audit evaluates the system itself or the function's own work), by a suitable person from another department, by a suitable third party, or by a mix of these, and nobody audits their own work area (9.2.4).

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 41 controls across 26 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 19011:2018 · 5 controls

  • 5.5.2 Defining the objectives, scope and criteria for an individual audit
  • 6.2 Initiating audit
  • 6.2.2 Establishing contact with auditee
  • 6.2.3 Determining feasibility of audit
  • 6.6 Completing audit
  • 4.5.5 Internal Audit
  • SPC1-4.5.6 Internal Audit

ISO 14001:2015 · 2 controls

  • 9.2 Internal audit
  • 9.2.2 Internal audit programme
  • ISO-37002-9.2 Internal audit
  • ISO37002-9.2 Internal Audit

ISO 37301:2021 · 2 controls

  • 9.2 Internal audit
  • 9.2.2 Internal audit programme
  • ISO-39001-9.2 Internal audit
  • ISO39001-9.2 Internal Audit
  • ISO-41001-9.2 Internal audit
  • ISO41001-9.2 Internal Audit

ISO 45001:2018 · 2 controls

  • 9.2 Internal audit
  • 9.2.2 Internal audit programme
  • ISO-50001-9.3 Internal audit
  • 9.2 Internal audit

ISO 56002 · 2 controls

  • ISO-56002-9.2 Internal audit
  • ISO56002-9.2 Internal audit

ISO/IEC 27003:2017 · 2 controls

  • CPS220-11 Annual Audit Review of the Framework
  • AS9100D-9.2 Internal Audit

ISO 13485:2016 · 1 control

ISO 14004:2016 · 1 control

  • 9.2 Internal audit

ISO 22000:2018 · 1 control

  • 9.2 Internal audit

ISO 22301:2019 · 1 control

  • 9.2 Internal audit

ISO 27001:2022 · 1 control

  • 9.2.2 Internal audit programme

ISO 27701:2019 · 1 control

  • ISO28001-4.17 Internal audit

ISO 30401 · 1 control

  • ISO30401-9.2 Internal audit

ISO 55001:2014 · 1 control

  • 9.2 Internal audit

ISO 9001:2015 · 1 control

  • 9.2 Internal audit

ISO/IEC 27031:2011 · 1 control

  • 27031-9.2 Internal Audit

ISO/IEC 42001:2023 · 1 control

  • 9.2 Internal audit

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Performance evaluation – ISO 37001:2016

Query this from an agent

The graph holds this control, the 41 it maps to, and the evidence behind each claim, over MCP and REST.