Risk Management

Internal Audit Policy

A internal audit policy template defining how internal audits of the management system are planned, conducted independently and reported, aligned to ISO 27001, SOC 2, NIST SP 800-53.

14-20 pages|Updated 2026-09-12|3 frameworks

What's Included

1. Purpose & Scope

Objective and the management system audited.

Policy ObjectiveScope of the ProgrammeRoles and Responsibilities

2. Audit Programme

Plans coverage over a cycle rather than ad hoc.

Risk-Based PlanningCoverage CycleSchedule ApprovalResource Allocation

3. Auditor Independence

An auditor may not audit their own work.

Independence RequirementCompetence CriteriaConflict Declaration

4. Conduct

How an audit is actually run.

Opening MeetingEvidence SamplingInterview RecordsClosing Meeting

5. Findings & Reporting

Turning observations into decisions.

Finding ClassificationReport ContentDistributionEscalation Criteria

6. Follow-Up

Confirms findings are closed.

Corrective Action InterfaceVerificationOverdue Escalation

7. Records & Review

Evidence and cadence.

Audit RecordsRetentionAnnual Programme Review

Frequently Asked Questions

What should a internal audit policy include?

A comprehensive internal audit policy should include purpose & scope, audit programme, auditor independence, conduct, and more. This template covers 7 key sections aligned to ISO 27001, SOC 2, NIST SP 800-53 requirements.

Which frameworks require a risk management policy?

Major frameworks requiring risk management policies include ISO 27001, SOC 2, NIST SP 800-53. This template maps directly to their control requirements, making it easier to demonstrate compliance across multiple standards.

How often should a internal audit policy be reviewed?

Best practice is to review your internal audit policy at least annually, or whenever significant changes occur in your organisation, technology environment, or regulatory landscape. Most frameworks including ISO 27001 and NIST CSF require documented policy review cycles.

Build Your Compliance Programme

Pair this policy template with our compliance platform to map controls across 686+ frameworks, run self-assessments, and get AI-powered compliance advisory.

Get Started Free →

Free forever — no credit card required