ISO/IEC 27003:2017
Performance evaluation – ISO/IEC 27003:2017

ISO/IEC 27003:2017 ISO27003-9.2: Internal audit

Audit the ISMS internally on a set schedule to learn whether it meets the organization's own ISMS requirements and those of ISO/IEC 27001 and whether it is effectively in place and kept up; plan and maintain one or more audit programmes that fix how often, how, by whom, with what planning and with what reporting audits happen, weighted by how important the processes are and what earlier audits found; set criteria and scope for each audit; choose auditors and run audits so the process is objective and impartial; report results to the relevant managers; and keep documented evidence of the programme and results. Implementation points (general practice; the 27003 guidance text is not held): cover the whole ISMS over a cycle, test effectiveness as well as conformity, and use ISO 19011 for auditing guidance.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 18 controls across 14 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 14001:2015 · 2 controls

  • 9.2 Internal audit
  • 9.2.2 Internal audit programme

ISO 37301:2021 · 2 controls

  • 9.2 Internal audit
  • 9.2.2 Internal audit programme

ISO 45001:2018 · 2 controls

  • 9.2 Internal audit
  • 9.2.2 Internal audit programme

ISO 13485:2016 · 1 control

ISO 14004:2016 · 1 control

  • 9.2 Internal audit

ISO 22000:2018 · 1 control

  • 9.2 Internal audit

ISO 22301:2019 · 1 control

  • 9.2 Internal audit

ISO 27001:2022 · 1 control

  • 9.2.2 Internal audit programme

ISO 27701:2019 · 1 control

ISO 37001:2016 · 1 control

  • 9.2 9.2 Internal audit

ISO 55001:2014 · 1 control

  • 9.2 Internal audit

ISO 9001:2015 · 1 control

  • 9.2 Internal audit

ISO/IEC 42001:2023 · 1 control

  • 9.2 Internal audit

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Performance evaluation – ISO/IEC 27003:2017

Query this from an agent

The graph holds this control, the 18 it maps to, and the evidence behind each claim, over MCP and REST.