Insights
Ask who may perform an ISO 27001 internal audit and the answer is usually short: anyone competent who does not audit their own work. That answer is correct. It also leaves most of the value of the audit on the table.
ISO 27001 does not require an external auditor. It asks the organisation to select auditors and run audits in a way that keeps the process objective and impartial. In practice that comes down to the one line most people remember: auditors do not audit their own work.
An employee can do it. So can a colleague from another department. ISO 19011, the general guidance on auditing management systems, adds that auditors should be independent of the activity they audit wherever practicable, and free from bias and conflict of interest in every case.
In a small organisation, "wherever practicable" carries a lot of weight. The person who knows a process well enough to audit it is usually the one who runs it.
Not auditing your own work is the floor. Is that enough? For the standard, yes. I set the bar one step higher.
When I act as internal auditor, the people who implemented the management system work for a different company from mine. We may know each other, and we may have worked this way before. But a colleague assessing a colleague’s work stays within the same hierarchy, with the same management and the same interest in a clean report.
The standard does not require that separation. It is my choice, and I make it because an audit is only worth something when nobody involved has a stake in the outcome.
The same logic applies after the audit: I do not implement the improvements I recommend. Once I start fixing my own findings, I can no longer guarantee my independence towards the external certification auditor.
Independence is usually discussed as a safeguard: it keeps the audit honest.
There is a second effect that gets less attention. Someone who was not part of the implementation looks at the management system from a different angle and asks the questions the team has stopped asking. That tends to make the whole considerably richer, and it can sharply increase the pace at which real security improves.
This only works on one condition. The auditor needs enough experience, and must have seen enough situations, to recognise which options are still open in the context being audited. An auditor who has only seen one way of doing things will mostly check whether yours matches it.
An internal auditor who works across organisations sees the work of many different implementers. That is what makes comparison possible. Someone who builds a management system sees their own approach. Someone who audits many of them sees where approaches differ and what that difference produces.
That comparison has a strict limit. What travels from one organisation to the next is the pattern, never the data. Nothing an auditor brings into an audit should allow anyone to work out which organisation it came from, what was in place there or what went wrong. If it cannot be abstracted that far, it stays where it was found.
When ISO 27001 was revised in 2022, one of the changes was that the management system now explicitly has to include the processes it needs and their interactions.
Many organisations had not read it that way.
I came across this several times, in different organisations. That meant I could do more than note the gap: I could point out where processes would add most to the system as a whole. Those processes then fitted the management system far better than if they had been defined whenever someone happened to think of them.
An implementer with the same knowledge could have spotted it too. But an implementer works on one system at a time, from the inside. The recommendation came from having seen the same requirement play out in several places, without any of those places being recognisable in it.
Larger organisations often have their own internal audit department, and that can be independent enough. It is funded from the same budget that paid for the implementation, which weakens its position slightly. In a large organisation it can still work perfectly well.
The risk lies elsewhere. When both sides of the audit, the auditor and the team being audited, stay the same for years, familiarity creeps in. The auditor already knows everything, takes a less fresh look at what is running and how, and accepts things because they have always been that way. That is certainly not always the case, but the risk is real.
This is not an argument against long relationships. If the team changes, the auditor can keep coming back and provide continuity. If the team stays the same for years, it may be time to change auditors.
Before your next internal audit, it is worth asking three questions.
The first two are about independence. The third is about whether the audit will tell you anything you did not already know.
When I implement a management system myself, I do not perform its internal audit. If it helps, I can suggest an experienced auditor from my network, but the choice is entirely the client’s. I do not decide who audits my work.
Who may perform the internal audit is a question with a short answer. The more useful question is who can still see what you have stopped seeing, and in most organisations that answer takes a little longer to find.