How to Run an ISO 27001 Internal Audit: A Step-by-Step Guide for 2026

Why the 2026 ISO 27001 Internal Audit is Different
The days of ticking a box to satisfy audit requirements are over. In 2026, especially with the rise of AI driven threats and the enforcement of the EU AI Act and NIS2, your ISO 27001 Internal Audit must be more than a compliance check, it must be a demonstration of Risk Assurance.
An internal audit is your organisation’s pre audit and readiness check. Done correctly, it finds the gaps before a certification body or a high value client does. Here is our executive guide to running a professional and compliant internal audit.
Step 1: Construct a Risk Based Audit Programme
You don’t have to audit every single control every single year. Clause 9.2 of ISO 27001:2022 requires you to plan audits based on the importance of the processes and the results of previous audits.
The 2026 Approach: Prioritise high risk areas such as Supplier Relationships (A.5.19) and Cloud Security (A.5.23).
The Strategy: Focus 70% of your effort on your "Crown Jewels"—which are the systems that hold your client data and proprietary AI models.
Step 2: Ensure Auditor Independence & Competence
The biggest mistake companies make is having the IT Manager audit the IT department.
Independence: The auditor cannot audit their own work. If you’re a small team, this is where you should bring in an external Associate Auditor to avoid conflict of interest.
Competence: Your auditor needs to understand the 2022 version of the standard. In 2026, they should also have a working knowledge of how AI Governance (ISO 42001) intersects with your security controls.
Step 3: The Show and Tell

An audit isn't a conversation; it’s an evidence gathering mission. For every policy you have, you need to see the operational reality as an auditor.
Interviews: “Show me how you revoke access when an employee leaves."
Observation: Observe a developer committing code to see if the Security by Design policy is actually followed in practice.
Sampling: Don’t just look at one record. Pick 3-5 random samples from the last six months.
Step 4: Grading Findings
We don't just find errors; we find opportunities for resilience. Categorise your findings clearly:
Major Non-Conformity: A total breakdown of a requirement (e.g., no Risk Assessment was performed).
Minor Non-Conformity: A single lapse (e.g. one employee didn't sign the Non Disclosure Agreement).
Opportunity for Improvement (OFI): The process works, but it could be streamlined for better
Step 5: The Management Review & CAPA
The audit doesn't end when the report is written. It ends when the Corrective Action Plan (CAPA) is agreed upon by leadership.
Present the audit findings as a risk landscape overview to the board. Show them how fixing these gaps directly protects the company’s valuation and contract readiness.
Conclusion: From Compliance to Assurance
Running an internal audit is the best way to sleep soundly before your Stage 2 Certification Audit. It turns the hope that you’re secure into knowing you can actually prove and evidence compliance and conformity.
Sampson ISO Audit & Consult Ltd



Comments