ISO 27001 Internal Audit: What to Test Before Certification
Use the internal audit to test whether the ISMS works, not simply whether its documents exist.
Start with the ISMS scope
Confirm that the documented scope matches the products, locations, teams, systems and interfaces actually included. Scope drift is difficult to correct late in the certification process.
Test the risk process
Trace selected risks from identification through assessment, treatment and ownership. Check whether the organization applies its stated methodology consistently and whether material decisions are supported by evidence.
Test controls where they operate
Interview owners, inspect records and sample evidence from normal operations. For example, don't stop at an access-control policy: test whether access reviews happen, whether exceptions are handled and whether the resulting records can be produced.
Look at improvement mechanisms
Review incidents, nonconformities, corrective actions, performance information and management-review outputs. A functioning management system should demonstrate that issues are identified and used to improve the ISMS.
Write findings that can be acted on
A useful finding explains the criteria, observed condition, evidence, impact and recommended direction. Assigning an owner and tracking corrective action makes the audit useful beyond the final report.
Final readiness question
If an external auditor selected a sample tomorrow, could the organization show how the control is designed, who owns it, how it operates and what evidence demonstrates operation? That is a better readiness test than the size of the policy library.
Need an independent control review?
Explore BlueLock's internal audit and control assurance approach.