Clause 9 · Performance evaluation

9.2.1 — General

Two things an internal audit has to confirm: that the ISMS follows its own rules, and that it actually works — not just one or the other.

Mandatory requirementDocumented information required: No

In plain language

In plain language: 9.2.1 sets the goal internal audits must achieve: at planned intervals, confirm that the ISMS meets both your own requirements and the requirements of the standard, and that it is genuinely implemented and kept up to date — not just documented on paper.

Position in the standard

Clause 9 · Performance evaluation
9.2.1 · General ← you are here
See also: 9.2.2

Why this requirement exists

There is a real difference between an ISMS that looks correct on paper and one that is actually followed. This requirement targets both: conformity (does the documentation match the standard and your own stated rules?) and effective implementation (do people actually do what the documentation says?). An audit that only checks one of the two misses half the picture.

Scenario: a policy states that access reviews happen quarterly. An audit that only reads the policy document would find it conforming. An audit that also checks whether the last four quarterly reviews were actually performed and evidenced might find that only one of the last four happened — a conformity pass hiding an implementation failure.

What the standard expects

The standard expects internal audits to be conducted at planned intervals, providing information on whether the ISMS conforms both to the organization’s own requirements for its information security management system and to the requirements of the standard, and whether the ISMS is effectively implemented and maintained. This dual test — conformity and effectiveness — is what the programme in 9.2.2 is built to deliver on a repeatable basis.

In practice

  • Design audit checklists that ask both "does the document say this?" and "does the evidence show it actually happens?"
  • Sample actual records (recent access reviews, recent backup logs) rather than trusting the policy statement alone.

Evidence the auditor will ask for

  • A record showing internal audits actually happened at planned intervals, not just that a plan existed.
  • Findings that address effective implementation, not only documentation conformity.

Related requirements

Parent link: 9.2 Internal audit

Frequently asked questions

Does 9.2.1 require its own separate document?
No. It is usually satisfied by showing that your internal audit programme (9.2.2) and its results actually test both conformity and effective implementation.

Audit both conformity and reality.

Sentrix connects to your live systems, so internal audits can check what is actually happening, not just what the policy says.