9.2 — Internal audit
The requirement that gives your ISMS an independent check-up before an external auditor gets the chance to find something you missed.
In plain language
In plain language: sub-clause 9.2 requires you to periodically check, through an audit independent of the people who run the ISMS day to day, whether the system actually conforms to your own rules and to the standard — and to run that checking through a defined, repeatable programme rather than an ad hoc exercise.
Position in the standard
The sub-requirements of 9.2
9.2.1 General
The baseline expectation: planned internal audits checking conformity and effective implementation.
9.2.2 Internal audit programme
The structured programme — frequency, criteria, auditor selection, reporting — that carries out those audits.
How these requirements fit together
9.2.1 sets the destination: your ISMS needs planned, periodic internal audits confirming it conforms to your own requirements and to the standard, and that it is effectively implemented and maintained. 9.2.2 is the vehicle that gets you there — the actual programme defining how often audits happen, what criteria and scope apply each time, who is qualified to conduct them objectively, and how results get reported and retained. An organization that skips 9.2.2 and just does an audit "when there is time" technically has no internal audit programme at all, regardless of how thorough any individual audit was.
Need hands-on support running your internal audit programme? See our ISO 27001 certification support service
← 9.1 Monitoring and measurement · 9.3 Management review → · ↑ Clause 9 · Performance evaluation
Run internal audits that actually predict your certification result.
Sentrix helps you build a defensible internal audit programme and track findings through to closure.