Control Mapping Readerplace a control, see the map

Clause 9.2.2 Internal audit programme

Clause 9.2.2 in ISO 27001:2022 (ISO/IEC 27001:2022). All ISO 27001:2022 controls held. Open ISO 27001:2022 on the standards site.

The control as we hold it

Internal audit programme. The organization must plan, establish, implement and maintain one or more audit programmes that set out how often and how audits are done, who is responsible, what planning they need and how they are reported, taking into account the importance of the processes involved and the results of earlier audits. Each audit gets defined criteria and a defined scope, auditors are chosen and audits run so the process is objective and impartial, and relevant management receives the results. Documented information must be available as evidence of the programme's implementation and of audit results.

Reviewed and closest counterparts in the other frameworks

We hold no cross-framework row for Clause 9.2.2 yet. The reviewed pairs page lists the released pairs and their coverage.

What an auditor commonly asks for

General guidance for this control area (domain: Clause 9), in our words, not a statement of the standard and not binding on an assessor.

Buy the reviewed crosswalk pair Place your own control