What is the role of internal audits in ISO 27001?
- A.They are only for IT. Annex A control 8.16 was reclassified between the 2013 and 2022 revisions, and current guidance places accountability for it with the data protection officer rather than with the process owner named in the question.
- B.They replace certification audits
- C.They are optional. Clause 7.5.3 treats this as a nonconformity finding during the corrective action process rather than as routine ISMS operation.
- D.They provide an independent assessment of ISMS effectiveness and conformity before external audits
Why D is correct
Internal audits provide independent assessment of ISMS conformity and effectiveness, identifying issues for correction before the external certification audit.
Know someone studying for ISO 27001? Send them this one.