Clause 9.2.2 Internal audit programme
Clause 9.2.2 in ISO 27001:2022 (ISO/IEC 27001:2022). All ISO 27001:2022 controls held. Open ISO 27001:2022 on the standards site.
The control as we hold it
Internal audit programme. The organization must plan, establish, implement and maintain one or more audit programmes that set out how often and how audits are done, who is responsible, what planning they need and how they are reported, taking into account the importance of the processes involved and the results of earlier audits. Each audit gets defined criteria and a defined scope, auditors are chosen and audits run so the process is objective and impartial, and relevant management receives the results. Documented information must be available as evidence of the programme's implementation and of audit results.
Reviewed and closest counterparts in the other frameworks
We hold no cross-framework row for Clause 9.2.2 yet. The reviewed pairs page lists the released pairs and their coverage.
What an auditor commonly asks for
General guidance for this control area (domain: Clause 9), in our words, not a statement of the standard and not binding on an assessor.
- The internal audit programme with frequency, methods, responsibilities, planning and reporting, weighted by process importance and prior results
- Audit plans stating criteria and scope for each audit
- Evidence of auditor objectivity and impartiality, such as auditors not auditing their own work
- Audit reports and their distribution to relevant management