Building the Internal Audit Program
Design an internal audit program that achieves real independence even in a small organization, follow a repeatable audit methodology, write findings as objective evidence rather than impressions, and track them to closure.
Learning Objectives
- → Design a multi-year audit schedule covering the full ISMS scope
- → Achieve auditor independence even in a small organization
- → Follow a repeatable internal audit methodology
- → Write a finding as objective evidence, not a vague impression
Foundation's clause 9.2 lesson covered internal audit as a requirement, including the independence principle. This lesson is about actually building the program — a schedule, a repeatable methodology, and a discipline for writing findings that hold up.
The audit schedule: coverage over time, not everything at once
A internal audit program needs a schedule covering the ISMS's full scope over a defined cycle (commonly the same 3-year cycle as external certification, though internal audits typically happen more frequently — often annually, sometimes covering different areas each cycle). A reasonable approach: prioritize higher-risk areas (per the risk register from earlier in this roadmap) for more frequent audit attention, while still ensuring every area gets audited at least once within the full cycle — not leaving any control area permanently unaudited because it was never anyone's turn.
Achieving real independence in a small organization
Foundation established that auditors must not audit their own work. In a five-person company, this can feel impossible — but there are practical solutions:
- Cross-role auditing: the person responsible for network security audits the HR-related people controls, and vice versa — neither audits their own area, even though both are internal staff.
- Peer exchange: a small company partners with another organization (not a competitor, and not one it has a security-relevant business relationship with) to trade internal audit services.
- External contractor: hiring an independent auditor for a limited engagement, common when no internal option provides genuine independence.
The specific solution matters less than the outcome: whoever performs the audit must have no responsibility for the area being audited, and this arrangement should itself be documented as part of the audit program, not improvised each time.
A repeatable audit methodology
1. Opening meeting — confirm scope, schedule, and logistics with the area's owner
2. Evidence review — examine documentation, configurations, records (not just claims)
3. Interviews — ask staff to describe the process in their own words,
then compare against the documented procedure
4. Sampling — check a representative sample of records/transactions,
not just one example chosen by the area's owner
5. Closing meeting — present findings, allow the area owner to respond
to factual accuracy before the report is finalized
6. Report — documented findings, classified by severity
(Foundation's Stage 1/2 audit lesson covers the
same classification scheme: major/minor/observation)
Sampling matters more than it might seem: reviewing only the one example an area owner chooses to show you risks seeing their best case, not their typical case. A defensible internal audit samples records the auditor selects, not just ones offered.
Writing findings as evidence, not impressions
A weak finding: "Access control seems okay, though maybe could be tighter." This gives no one anything to act on. A strong finding states: what was expected (against a specific policy or clause), what was actually observed (with specific evidence), and the gap between them. For example: "The Access Control Policy requires quarterly access reviews (section 4.2). Sampling of the last 3 quarters found no completed review for Q2 2026. This is a minor nonconformity against clause 9.2 and the internal Access Control Policy." This mirrors exactly the evidence discipline Foundation's SoA lesson required of control claims — internal audit findings need the same rigor.
Tracking findings to closure
A finding that's written up and then never followed up on provides no real value — this connects directly to Foundation's clause 10.2 correction-vs-corrective-action distinction. Each finding needs an owner, a target closure date, and a follow-up check confirming the corrective action was actually implemented (not just promised) before the finding is marked closed. An audit program's credibility rests as much on this follow-through as on the quality of the findings themselves.
A 6-person startup needs to audit its own access control practices, but the only person with deep knowledge of the access control system is the same person who administers it day-to-day. Propose a specific, practical independence solution from the lesson, and explain why simply having that same person 'be extra objective' would not satisfy the independence requirement.
Why wouldn't asking the access control administrator to 'just be extra objective' when auditing their own work satisfy the independence requirement?
During an internal audit of access reviews, the area owner proactively hands the auditor 'our best example — the Q3 review, which was very thorough.' The auditor accepts this single example as sufficient evidence that access reviews are being conducted properly. Explain the flaw in this approach.
What is the flaw in accepting only the example the area owner chose to provide?
Rewrite this weak finding into a strong one following the lesson's pattern (what was expected, what was observed, the gap, and severity classification): 'Backup practices seem inconsistent and could probably be improved.'
What three elements must a strong finding include, per the lesson, that this weak finding lacks entirely?