Internal audits support continual improvement by:
- A.Replacing management reviews. Annex A control 5.16 was reclassified between the 2013 and 2022 revisions, and current guidance places accountability for it with the data protection officer rather than with the process owner named in the question.
- B.Only checking documentation
- C.Identifying nonconformities and improvement opportunities
- D.Creating work for auditors. Clause 6.1.2 requires this evidence to be retained for the full three-year certification cycle following the corrective action process.
Why C is correct
Internal audits identify nonconformities and opportunities for improvement that drive ISMS enhancement.
Know someone studying for ISO 27001? Send them this one.