Clause 9 · Performance evaluation

9.2.2 — Internal audit programme

The requirement that turns "we should audit ourselves sometime" into a defined, repeatable programme an external auditor can actually inspect.

Mandatory requirementDocumented information required: Yes

In plain language

In plain language: 9.2.2 requires you to plan, set up, run, and maintain an actual audit programme — not a single audit, but a recurring system that decides how often audits happen, what gets checked each time, who is qualified and independent enough to check it, and how the results get reported and kept.

Position in the standard

Clause 9 · Performance evaluation
9.2.2 · Internal audit programme ← you are here
See also: 9.2.1

Why this requirement exists

A single thorough audit tells you about one moment in time. A programme is what makes internal audit a management tool rather than a one-time compliance exercise — it forces you to decide in advance how coverage will rotate across the ISMS, so high-risk areas actually get checked on a predictable cadence instead of whichever area someone happened to have time for.

Scenario: a company’s only internal audit in two years was performed by the same person who manages the ISMS day to day, focused entirely on documentation review, with no defined criteria and no report retained. At the certification audit, the external auditor asks for the internal audit programme and finds there effectively was not one — a major nonconformity, even though individual controls were in decent shape.

What the standard expects

The standard expects the organization to plan, establish, implement, and maintain an audit programme, including the frequency, methods, responsibilities, planning requirements, and reporting — taking into account the importance of the processes concerned and the results of previous audits. For each audit, you must define the audit criteria and scope; select auditors and conduct audits that ensure objectivity and impartiality of the process; ensure results are reported to relevant management; and retain documented information as evidence of the programme and the results.

In practice

  • Write a one-page audit programme document: annual frequency (or more often for higher-risk areas), scope rotation across ISMS domains, and named responsibilities.
  • Ensure whoever conducts the audit is independent of the area being audited — someone from a different team, or an external contractor for smaller organizations without enough internal separation.
  • Define audit criteria before each audit (which clauses, which controls, which documents) instead of improvising scope on the day.
  • Produce a written report for every audit and route it to the people who can act on it, not just to a file.

Evidence the auditor will ask for

  • The documented internal audit programme: frequency, scope rotation, responsibilities.
  • Audit reports showing criteria, scope, findings, and who conducted each audit.
  • Evidence of auditor independence — an organization chart or statement showing the auditor was not reviewing their own work.
  • Records showing findings were reported to relevant management and tracked to closure.

Common pitfalls

  • An auditor who reviews their own area of responsibility — the single most common finding against this sub-clause.
  • A "programme" that is really just one audit, done once, with no plan for repetition or full ISMS coverage over time.
  • No defined criteria before the audit — the auditor decides what to check as they go, which makes results hard to compare year over year.

Related requirements

Parent link: 9.2 Internal audit

2013 → 2022 mapping

2022 version 2013 version Nature of change
9.2.1 / 9.2.29.2 Internal audit (single clause)Split into two numbered sub-clauses; requirements largely carried over

Frequently asked questions

Can a small company use an external contractor for internal audits?
Yes, and it is common practice when the organization is too small to have staff independent of the ISMS. What matters is objectivity and impartiality, not whether the auditor is an employee.
How often should the internal audit programme run?
The standard does not set a fixed frequency. Most organizations audit the full ISMS at least once a year, often spreading coverage across quarterly audits of different domains.
Do audit criteria have to be the same every time?
No — criteria and scope can and should vary by audit, targeting different processes or controls, as long as the overall programme provides full ISMS coverage over time.

Build an internal audit programme that survives scrutiny.

Sentrix helps you define audit scope rotation, track findings, and keep the evidence an external auditor will ask for.