Attestware

The internal audit readiness checklist

Thirty-nine plain-English checks that tell you whether your internal audit programme would satisfy Clause 9.2 of ISO 27001, ISO 42001 or ISO 22301, and survive the certification body's scrutiny. Written by Lead Auditor trained practitioners.

Get the checklist

Enter your name and work email and your personal copy of the checklist activates right here, ready to tick off and print. Your progress saves as you go and is shared with us, so any follow-up starts from where you actually are. No mailing list.

Tick items off as you go: your progress saves automatically and helps us tailor any follow-up conversation. Anything you cannot tick is worth that conversation.

1. The audit programme

Clause 9.2 asks for a programme, not an event. External auditors read the programme first.

2. Independence and competence

An organisation cannot mark its own homework. This is where small-company programmes most often fail.

3. Scope, criteria and planning

Each audit needs its own definition of done before fieldwork starts.

4. Evidence and fieldwork

A finding you cannot trace to evidence will not survive scrutiny, yours or anyone else's.

5. Findings and reporting

Consistent classification is what separates an audit from a list of opinions.

6. Corrective action and follow-through

The most common external audit finding about internal audit: closures without root cause.

7. Feeding management review

Internal audit results are a mandatory management review input. The loop has to visibly close.

8. What the external auditor will check

When the certification body examines your internal audit, this is the short list.

What to do with the gaps

If several of these are unticked, your internal audit programme is the finding. This is exactly the work we do: independent internal audits under Clause 9.2 for ISO 27001, ISO 42001 and ISO 22301, delivered at a fixed fee agreed at scoping. Request an audit or read about the internal audit service.