9.2.2 — Internal audit programme
The requirement that turns "we should audit ourselves sometime" into a defined, repeatable programme an external auditor can actually inspect.
In plain language
In plain language: 9.2.2 requires you to plan, set up, run, and maintain an actual audit programme — not a single audit, but a recurring system that decides how often audits happen, what gets checked each time, who is qualified and independent enough to check it, and how the results get reported and kept.
Position in the standard
Why this requirement exists
A single thorough audit tells you about one moment in time. A programme is what makes internal audit a management tool rather than a one-time compliance exercise — it forces you to decide in advance how coverage will rotate across the ISMS, so high-risk areas actually get checked on a predictable cadence instead of whichever area someone happened to have time for.
Scenario: a company’s only internal audit in two years was performed by the same person who manages the ISMS day to day, focused entirely on documentation review, with no defined criteria and no report retained. At the certification audit, the external auditor asks for the internal audit programme and finds there effectively was not one — a major nonconformity, even though individual controls were in decent shape.
What the standard expects
The standard expects the organization to plan, establish, implement, and maintain an audit programme, including the frequency, methods, responsibilities, planning requirements, and reporting — taking into account the importance of the processes concerned and the results of previous audits. For each audit, you must define the audit criteria and scope; select auditors and conduct audits that ensure objectivity and impartiality of the process; ensure results are reported to relevant management; and retain documented information as evidence of the programme and the results.
In practice
- Write a one-page audit programme document: annual frequency (or more often for higher-risk areas), scope rotation across ISMS domains, and named responsibilities.
- Ensure whoever conducts the audit is independent of the area being audited — someone from a different team, or an external contractor for smaller organizations without enough internal separation.
- Define audit criteria before each audit (which clauses, which controls, which documents) instead of improvising scope on the day.
- Produce a written report for every audit and route it to the people who can act on it, not just to a file.
Evidence the auditor will ask for
- The documented internal audit programme: frequency, scope rotation, responsibilities.
- Audit reports showing criteria, scope, findings, and who conducted each audit.
- Evidence of auditor independence — an organization chart or statement showing the auditor was not reviewing their own work.
- Records showing findings were reported to relevant management and tracked to closure.
Common pitfalls
- An auditor who reviews their own area of responsibility — the single most common finding against this sub-clause.
- A "programme" that is really just one audit, done once, with no plan for repetition or full ISMS coverage over time.
- No defined criteria before the audit — the auditor decides what to check as they go, which makes results hard to compare year over year.
Related requirements
9.2.1 General
The general goal this programme is built to achieve.
9.3 Management review
Internal audit results are a required input to management review.
Parent link: 9.2 Internal audit
2013 → 2022 mapping
Frequently asked questions
Can a small company use an external contractor for internal audits?
How often should the internal audit programme run?
Do audit criteria have to be the same every time?
Build an internal audit programme that survives scrutiny.
Sentrix helps you define audit scope rotation, track findings, and keep the evidence an external auditor will ask for.