9.2.1 — General
Two things an internal audit has to confirm: that the ISMS follows its own rules, and that it actually works — not just one or the other.
In plain language
In plain language: 9.2.1 sets the goal internal audits must achieve: at planned intervals, confirm that the ISMS meets both your own requirements and the requirements of the standard, and that it is genuinely implemented and kept up to date — not just documented on paper.
Position in the standard
Why this requirement exists
There is a real difference between an ISMS that looks correct on paper and one that is actually followed. This requirement targets both: conformity (does the documentation match the standard and your own stated rules?) and effective implementation (do people actually do what the documentation says?). An audit that only checks one of the two misses half the picture.
Scenario: a policy states that access reviews happen quarterly. An audit that only reads the policy document would find it conforming. An audit that also checks whether the last four quarterly reviews were actually performed and evidenced might find that only one of the last four happened — a conformity pass hiding an implementation failure.
What the standard expects
The standard expects internal audits to be conducted at planned intervals, providing information on whether the ISMS conforms both to the organization’s own requirements for its information security management system and to the requirements of the standard, and whether the ISMS is effectively implemented and maintained. This dual test — conformity and effectiveness — is what the programme in 9.2.2 is built to deliver on a repeatable basis.
In practice
- Design audit checklists that ask both "does the document say this?" and "does the evidence show it actually happens?"
- Sample actual records (recent access reviews, recent backup logs) rather than trusting the policy statement alone.
Evidence the auditor will ask for
- A record showing internal audits actually happened at planned intervals, not just that a plan existed.
- Findings that address effective implementation, not only documentation conformity.
Related requirements
9.2.2 Internal audit programme
The concrete programme that delivers on this general expectation.
9.3 Management review
Audit results feed directly into what leadership reviews.
Parent link: 9.2 Internal audit
Frequently asked questions
Does 9.2.1 require its own separate document?
Audit both conformity and reality.
Sentrix connects to your live systems, so internal audits can check what is actually happening, not just what the policy says.