Auditing Internal Audit and Management Review
In an ISO/IEC 27001 certification audit, the Lead Auditor must verify that the organization's Information Security Management System (ISMS) can evaluate and improve itself. Two key mechanisms are Internal Audit (Clause 9.2) and Management Review (Clause 9.3). Auditing them shows whether top managem… In an ISO/IEC 27001 certification audit, the Lead Auditor must verify that the organization's Information Security Management System (ISMS) can evaluate and improve itself. Two key mechanisms are Internal Audit (Clause 9.2) and Management Review (Clause 9.3). Auditing them shows whether top management and the organization actively monitor ISMS performance. Auditing Internal Audit (Clause 9.2): The auditor checks that the organization has planned, established, implemented and maintained an audit programme. This includes frequency, methods, responsibilities, planning requirements and reporting. The programme should reflect the importance of the processes concerned and the results of previous audits. Key evidence includes the audit programme, audit plans, checklists, reports, nonconformity records and corrective action follow-up. The auditor verifies that audit criteria and scope are defined for each audit and that the whole ISMS, including Annex A controls, is covered over the cycle. Auditors must be competent, objective and impartial, and should not audit their own work. The auditor also confirms that results are reported to relevant management and that documented information is retained. Weak findings, superficial checklists or overdue corrective actions may indicate a nonconformity. Auditing Management Review (Clause 9.3): The auditor verifies that top management reviews the ISMS at planned intervals to ensure its continuing suitability, adequacy and effectiveness. Required inputs include the status of previous actions, changes in external and internal issues, changes in interested party needs, feedback on security performance (nonconformities, monitoring results, audit results, achievement of objectives), interested party feedback, risk assessment results and the status of the risk treatment plan, and opportunities for improvement. Outputs must include decisions on improvement opportunities and any needed changes to the ISMS. Evidence includes minutes, attendance records, presentations and action trackers. The Lead Auditor uses interviews, document review and sampling to confirm genuine leadership engagement rather than a paper exercise. Effective internal audits and management reviews are strong indicators of ISMS maturity and readiness for certification.
Auditing Internal Audit and Management Review (ISO/IEC 27001 Lead Auditor Guide)
Introduction
In an ISO/IEC 27001 certification audit, two clauses act as the self-checking engine of the Information Security Management System (ISMS). They are Clause 9.2 Internal Audit and Clause 9.3 Management Review. A Lead Auditor must be able to evaluate whether these processes exist and are effective, not just whether they are documented. This guide explains what they are, why they matter, how auditors examine them, and how to answer exam questions on them with confidence.
1. Why Auditing Internal Audit and Management Review Is Important
They are the feedback loop of the PDCA cycle. Clause 9 (Performance Evaluation) is the Check phase of Plan-Do-Check-Act. Without effective internal audits and management reviews, the organization cannot know whether its ISMS works. It also cannot drive improvement under Clause 10.
They demonstrate top management commitment. Management review is direct evidence of leadership involvement, which Clause 5 requires. An ISMS where top management never reviews performance is a warning sign of a 'paper system'.
They indicate system maturity. A certification auditor relies partly on the organization's own internal audit findings. If internal audits are superficial, the certification auditor should increase sampling and scepticism elsewhere.
They are mandatory for certification. The organization must complete at least one full internal audit cycle and one management review before a Stage 2 audit. If either is missing, that is normally a major nonconformity and blocks certification.
They feed corrective action and continual improvement. Nonconformities from internal audits and decisions from management review flow into Clause 10.1 (Continual improvement) and 10.2 (Nonconformity and corrective action).
2. What They Are: Requirements of the Standard
Clause 9.2 Internal Audit (ISO/IEC 27001:2022)
The 2022 version splits this clause into two parts.
9.2.1 General. The organization shall conduct internal audits at planned intervals. Their purpose is to find out whether the ISMS:
a) conforms to the organization's own requirements for its ISMS;
b) conforms to the requirements of ISO/IEC 27001;
c) is effectively implemented and maintained.
9.2.2 Internal audit programme. The organization shall plan, establish, implement and maintain audit programme(s). These cover:
- frequency, methods, responsibilities, planning requirements and reporting;
- the importance of the processes concerned and the results of previous audits.
For each audit, it shall also:
- define the audit criteria and scope;
- select auditors who ensure objectivity and impartiality;
- ensure results are reported to relevant management.
Documented information must be available as evidence of the implementation of the audit programme(s) and the audit results.
Clause 9.3 Management Review
9.3.1 General. Top management shall review the ISMS at planned intervals to ensure its continuing suitability, adequacy and effectiveness.
9.3.2 Management review inputs. The review shall include consideration of:
a) the status of actions from previous management reviews;
b) changes in external and internal issues relevant to the ISMS;
c) changes in needs and expectations of interested parties relevant to the ISMS (new in 2022);
d) feedback on information security performance, including trends in:
1) nonconformities and corrective actions;
2) monitoring and measurement results;
3) audit results;
4) fulfilment of information security objectives;
e) feedback from interested parties;
f) results of risk assessment and status of the risk treatment plan;
g) opportunities for continual improvement.
9.3.3 Management review results. The results shall include decisions related to continual improvement opportunities and any needs for changes to the ISMS. Documented information shall be available as evidence of the results of management reviews.
Supporting guidance
- ISO 19011 gives guidelines for auditing management systems, including managing an audit programme and auditor competence.
- ISO/IEC 27007 gives ISMS-specific auditing guidance.
- ISO/IEC 27006-1 sets requirements for certification bodies.
3. How It Works: How a Lead Auditor Audits These Clauses
A. Auditing the Internal Audit Process
Step 1: Review the audit programme.
- Is there a documented programme covering the full ISMS scope, including all clauses 4-10 and applicable Annex A controls, over a defined cycle (often 12 months, sometimes up to 3 years)?
- Is it risk-based? Do high-risk processes and areas with previous findings get audited more often?
- Have changes (new sites, new technologies, incidents) prompted programme updates?
Step 2: Verify planning of individual audits.
- Are scope, criteria, objectives and dates defined for each audit?
- Are audit plans and checklists available?
Step 3: Check auditor objectivity and impartiality.
- Auditors should not audit their own work. For example, the IT manager should not audit IT access controls they designed and operate.
- Small organizations may use external consultants or cross-department auditors.
Step 4: Check auditor competence (link to Clause 7.2).
- Look for evidence of training in auditing (for example, ISO 19011 or internal auditor courses) and knowledge of information security.
- Competence records must be kept as documented information.
Step 5: Sample audit reports and evidence.
- Do reports contain objective evidence, findings, and conclusions?
- Are findings clearly graded (nonconformity, observation, opportunity for improvement)?
- Be suspicious of 'zero findings' audits in a complex organization. They may indicate a superficial audit.
Step 6: Verify reporting to management.
- Were results communicated to relevant management and used as input to management review?
Step 7: Trace follow-up (link to Clause 10.2).
- Select internal audit nonconformities and trace them through root cause analysis, corrective action, and verification of effectiveness.
B. Auditing the Management Review Process
Step 1: Obtain evidence of management reviews.
- Look at minutes, presentations, attendance lists and action logs.
- Confirm reviews happened at planned intervals (commonly annually or more frequently).
Step 2: Confirm top management participation.
- 'Top management' means the person or group that directs and controls the organization within the ISMS scope.
- A review attended only by the ISMS manager is insufficient.
Step 3: Check all required inputs (a-g) were considered.
- Use the inputs list as a checklist.
- Missing inputs, such as risk treatment status or changes to interested parties, are a common finding.
Step 4: Check outputs and decisions.
- Look for decisions on improvement opportunities, changes to the ISMS, and resource needs.
- Are actions assigned owners and deadlines?
Step 5: Trace actions forward.
- Verify that actions from the previous review were tracked and their status reviewed. This is input (a).
Step 6: Interview top management.
- Ask executives about ISMS performance, objectives and key risks.
- Their answers reveal whether the review was genuine or a formality.
C. Audit Techniques Used
- Document review: audit programme, plans, reports, minutes.
- Interviews: internal auditors, ISMS manager, top management.
- Sampling: select internal audit reports and nonconformities to trace.
- Audit trails: follow the chain from internal audit finding to management review input, then to decision, then to corrective action and verification.
D. Typical Nonconformities
- No internal audit conducted before certification: major.
- No management review conducted: major.
- Audit programme does not cover the whole ISMS scope or all clauses: usually minor; major if systemic.
- Internal auditor audited own work: minor, a lack of objectivity.
- No evidence of auditor competence: minor.
- Management review missing one or more required inputs: minor.
- Top management absent from management review: can be major, because it shows a breakdown of leadership.
- Internal audit findings not followed up with corrective action: minor or major depending on extent.
4. Key Concepts to Remember
- Objectivity vs independence: ISO/IEC 27001 requires objectivity and impartiality, not full organizational independence. An employee from another department can audit as long as they are not auditing their own work.
- Planned intervals: the standard does not fix the frequency. The organization decides, based on risk and previous results.
- Documented information: evidence is required for both the audit programme and results (9.2) and for management review results (9.3).
- Internal audit vs certification audit: internal audits are first-party audits. Certification audits are third-party audits.
- Management review is not a meeting checklist. It must evaluate suitability, adequacy and effectiveness, and produce decisions.
- Combined reviews are acceptable. Management review can be part of a broader business meeting, provided all inputs and outputs are covered and recorded.
5. Exam Tips: Answering Questions on Auditing Internal Audit and Management Review
Tip 1: Know the clause numbers and the 2022 structure.
Remember that 9.2 is Internal Audit (9.2.1 General, 9.2.2 Programme) and 9.3 is Management Review (9.3.1 General, 9.3.2 Inputs, 9.3.3 Results). Exam questions often ask you to identify the clause breached. Quote it precisely.
Tip 2: Memorize the management review inputs.
A useful memory aid is 'Previous actions, Issues, Parties, Performance, Feedback, Risk, Improvement'. In scenario questions, check each input against what the minutes show. The missing one is often the answer.
Tip 3: Identify the precise nonconformity in scenarios.
A good nonconformity statement has three parts:
1) the requirement, for example 'ISO/IEC 27001 Clause 9.2.2 requires auditors to be selected to ensure objectivity and impartiality';
2) the evidence, for example 'The access control audit of March 2024 was conducted by the IT Security Manager, who is responsible for that process';
3) the nonconformity statement, for example 'The organization did not ensure objectivity of the internal audit process'.
Tip 4: Classify major vs minor correctly.
Major means the process is absent or totally broken, or there is a systemic failure that undermines the ISMS's ability to achieve intended results. Examples are no internal audit, no management review, or top management never involved.
Minor means an isolated lapse that does not cause systemic failure. An example is one missing input, or one audit report without evidence.
Always justify your classification with reasoning.
Tip 5: Distinguish objectivity from independence.
A common trap: 'The internal auditor is an employee, so the audit is invalid.' This is false. Employees can be internal auditors if they do not audit their own work.
Tip 6: Watch for frequency traps.
The standard does not mandate 'annual' audits or reviews. Answer that intervals must be planned and justified by risk and results. However, before initial certification, at least one complete cycle must have occurred.
Tip 7: Use audit trails in essay answers.
When asked 'How would you audit...?', describe the evidence you would request, who you would interview, and how you would sample and trace. For example: 'I would request the audit programme, sample three internal audit reports, verify auditor competence records, interview an internal auditor, and trace two nonconformities to closure.'
Tip 8: Link to other clauses.
Strong answers show integration:
- 5.1 for leadership commitment;
- 7.2 for auditor competence;
- 7.5 for documented information;
- 9.1 for monitoring data feeding management review;
- 10.2 for corrective actions from audit findings.
Examiners reward this systems-thinking.
Tip 9: Question 'zero findings' and 'rubber-stamp' reviews.
If a scenario shows internal audits with no findings, or a 15-minute management review with no decisions, recognize possible ineffectiveness. Effectiveness is a requirement (9.2.1c, 9.3.1), not just existence.
Tip 10: Reference ISO 19011 for audit programme management.
For questions on how internal audits should be managed, mention ISO 19011 principles: integrity, fair presentation, due professional care, confidentiality, independence, evidence-based approach, and risk-based approach. Also mention ISO/IEC 27007 for ISMS-specific guidance.
Tip 11: Read scenarios carefully for who attended and who audited.
Names and job titles in scenarios are deliberate clues. Check whether the auditor owns the process, and whether the CEO or the board attended the review.
Tip 12: Avoid giving consultancy advice.
As a Lead Auditor, you report nonconformities. You do not design solutions. In exam answers, state the finding and the evidence. If asked about corrective action, say the auditee is responsible for proposing corrections and corrective actions, which the auditor then evaluates.
6. Sample Exam Scenario and Model Answer
Scenario: During a Stage 2 audit, you find that the organization's management review minutes from last month list attendance by the ISMS Manager and the IT Director. The CEO did not attend. The minutes discuss incident trends and internal audit results, but not the status of the risk treatment plan or changes in interested party requirements. No actions were recorded.
Model answer:
Nonconformity against Clause 9.3. There are three issues.
1) Top management participation is unclear. Verify whether the IT Director qualifies as top management for the ISMS scope. If not, Clause 9.3.1 is not met.
2) Required inputs are missing. The review did not cover 9.3.2 (c) changes in interested parties' needs or (f) risk assessment results and the risk treatment plan status.
3) No outputs were recorded. There were no decisions on improvement or changes, so 9.3.3 is not met.
Classification: if this was the only review conducted and top management was absent, this could be graded major, as it indicates systemic failure of the performance evaluation and leadership requirements. Otherwise it is minor. Evidence would be recorded with references to the minutes, including date and document ID.
7. Quick Revision Checklist
- Audit programme exists, is risk-based, and covers the full scope.
- Individual audits have defined criteria and scope.
- Auditors are objective, impartial and competent.
- Results are reported to management.
- Documented evidence of the programme and results is kept.
- Nonconformities lead to corrective action.
- Management review is held at planned intervals with top management.
- All inputs (a) to (g) are considered.
- Outputs include improvement decisions and ISMS changes.
- Management review results are documented.
Conclusion
Internal audit and management review are the mechanisms through which an organization proves its ISMS is alive, monitored, and improving. As a Lead Auditor, your task is to look beyond the existence of documents and assess their effectiveness, objectivity, and leadership engagement. In the exam, anchor every answer to the specific clause, cite concrete evidence, classify findings logically, and show how these clauses connect to the rest of the ISMS.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!