Expert Advice Community

Guest

Planning internal audit

  Quote
Guest
Guest user Created:   Jun 22, 2019 Last commented:   Jun 22, 2019

Planning internal audit

Question about internal audit. Do I have to audit all clauses each year, or can I sample like in any other corporate audit? This is an existing certified ISMS, so surveillance takes place annually.
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Jun 22, 2019

Answer:

You do not have to audit you certified ISMS against all clauses each year. For certification purposes you only have to ensure that all ISO 27001 requirements had been audited at least once before the next certification audit. Considering that, you can audit only part of the requirements on each annual internal audit, provided that at the next certification audit all requirements had been audited at least once. It will be acceptable for surveillance audits.

The best approach would be for you to check the surveillance audits schedule to verify which requirements will be covered by the next surveillance audit, so you can focus on them.

These articles will provide you further explanation about internal and surveillance audits:
- How to prepare for an ISO 27001 internal audit https://advisera.com/27001academy/blog/2016/07/11/how-to-prepare-for-an-iso-27001-internal-audit/
- Surveillance visits vs. certification audits https://advisera.com/27001academy/knowledgebase/surveillance-visits-vs-certification-audits/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jun 21, 2019

Jun 21, 2019

Suggested Topics