Can our own team run the ISO 27001 internal audit?

Yes, an organisation's own team can conduct the ISO 27001 internal audit, provided the auditors are independent of the function being audited and possess the necessary competence. This approach can leverage internal knowledge and be cost-effective, but requires careful management to ensure objectivity and avoid conflicts of interest. Maintaining the integrity and impartiality of the audit process is crucial for the effective functioning of the Information Security Management System (ISMS).

ISO/IEC 27001:2022, Clause 9.2, mandates that organisations conduct internal audits at planned intervals to determine if the Information Security Management System (ISMS) conforms to the organisation's own requirements and the standard's requirements, and is effectively implemented and maintained. A critical aspect of this requirement is auditor independence. While internal personnel can perform these audits, they must not audit their own work or department. For instance, an IT operations manager should not audit the IT operations department's controls, but could audit the human resources department's information security processes. This ensures a degree of objectivity, which is fundamental to identifying genuine nonconformities and opportunities for improvement.

A common challenge with internal teams conducting these audits is ensuring sufficient competence and maintaining true impartiality. Internal auditors require training not only in ISO 27001 requirements but also in auditing principles and techniques, often guided by ISO 19011. Organisations sometimes err by assigning audit responsibilities to staff without adequate training or by failing to enforce strict independence, leading to superficial audits that may overlook significant weaknesses. While internal audits are a mandatory component of ISO 27001, many organisations choose to supplement their internal efforts with external auditors, particularly for initial certification or periodic reviews, to gain an unbiased perspective and validate the robustness of their internal audit programme.

Sources

  • ISO/IEC 27001:2022, Clause 9.2

Related