Clause 9 · Performance evaluation

9.2 — Internal audit

The requirement that gives your ISMS an independent check-up before an external auditor gets the chance to find something you missed.

Mandatory requirement

In plain language

In plain language: sub-clause 9.2 requires you to periodically check, through an audit independent of the people who run the ISMS day to day, whether the system actually conforms to your own rules and to the standard — and to run that checking through a defined, repeatable programme rather than an ad hoc exercise.

Position in the standard

9.2 · Internal audit ← you are here
See also: 9.1 · 9.3

The sub-requirements of 9.2

How these requirements fit together

9.2.1 sets the destination: your ISMS needs planned, periodic internal audits confirming it conforms to your own requirements and to the standard, and that it is effectively implemented and maintained. 9.2.2 is the vehicle that gets you there — the actual programme defining how often audits happen, what criteria and scope apply each time, who is qualified to conduct them objectively, and how results get reported and retained. An organization that skips 9.2.2 and just does an audit "when there is time" technically has no internal audit programme at all, regardless of how thorough any individual audit was.

Run internal audits that actually predict your certification result.

Sentrix helps you build a defensible internal audit programme and track findings through to closure.