Skip to content
Back to Blog
·10 min read·compliance

ISO 27001 Internal Audit Checklist for Indian Teams (2022 Update)

A practical ISO 27001 internal audit checklist for Indian IT and SaaS teams covering all 93 Annex A controls, nonconformities, and management reviews.

BR

Bachao.AI Research Team

Cybersecurity Research

Check DPDP Compliance

Compliance risk for Indian SMBs

Non-compliance with the DPDP Act 2023 carries penalties up to ₹250 crore. This post explains what's at stake and what action to take.

An ISO 27001 internal audit is a self-run, evidence-based check of your Information Security Management System (ISMS) against the ISO/IEC 27001:2022 requirements and its 93 Annex A controls, performed before a certification or surveillance audit. For Indian SaaS and IT SMBs, it means: scope the audit, sample evidence across the four Annex A themes (organizational, people, physical, technological), log every nonconformity, fix root causes, and feed results into management review. Skipping this step is the single most common reason certification audits fail on the first attempt.

Most Indian teams treat the internal audit as a formality — a checkbox exercise the week before the external auditor arrives. That approach gets flagged. Certification bodies expect a genuine, planned, documented internal audit programme under Clause 9.2 of ISO/IEC 27001:2022, not a retroactive paperwork exercise. This checklist walks through the full cycle the way an experienced lead auditor would run it.

Why the internal audit matters more than teams think

ISO/IEC 27001:2022, Clause 9.2, requires organizations to "conduct internal audits at planned intervals" to determine whether the ISMS conforms to the organization's own requirements and to the standard, and whether it is effectively implemented and maintained. External certification auditors will ask for internal audit records — audit plan, findings, corrective actions, and management review minutes — as the first evidence pack. A thin or missing internal audit trail is a near-automatic major nonconformity.

For Indian SMBs racing toward certification to unlock enterprise or government contracts, the internal audit is also the cheapest place to catch gaps. Fixing a missing access-review log or an unencrypted backup internally costs a config change. The same gap found by an external auditor costs a stage-2 audit delay, and possibly a re-audit fee. Teams that also handle personal data as defined under the Digital Personal Data Protection Act, 2023 should align internal audit evidence with those obligations too, since the control overlap is significant.

ℹ️
INFO
ISO/IEC 27001:2022 replaced the 2013 edition's 114 controls with a restructured set of 93 controls across 4 themes: Organizational (37), People (8), Physical (14), and Technological (34). If your ISMS documentation still references the 14 old Annex A domains (A.5–A.18), it is out of date and will be flagged.

The ISO 27001 internal audit cycle

Run the internal audit as a repeatable cycle, not a one-off event. The diagram below shows the flow this checklist follows.

graph TD A[Plan audit scope] --> B[Conduct audit] B --> C[Record findings] C --> D{Nonconformity found} D -->|Yes| E[Corrective action] D -->|No| F[Management review] E --> F[Management review] F --> G[Continual improvement] G --> A style A fill:#1e3a5f,stroke:#3B82F6,color:#e2e8f0 style B fill:#1e3a5f,stroke:#3B82F6,color:#e2e8f0 style C fill:#1e3a5f,stroke:#3B82F6,color:#e2e8f0 style D fill:#5f1e1e,stroke:#EF4444,color:#e2e8f0 style E fill:#5f1e1e,stroke:#EF4444,color:#e2e8f0 style F fill:#1e3d2f,stroke:#10B981,color:#e2e8f0 style G fill:#1e3d2f,stroke:#10B981,color:#e2e8f0

Step 1: Plan the audit scope

Before touching a single control, define and document:

    1. Scope — which business units, systems, locations, and third parties fall inside the ISMS boundary (your Statement of Applicability should already list this).
    2. Audit criteria — ISO/IEC 27001:2022 clauses 4–10, plus applicable Annex A controls from your Statement of Applicability (SoA), plus internal policies.
    3. Audit programme — frequency (most Indian SMBs run internal audits twice a year ahead of an annual surveillance cycle), auditor assignments, and a schedule that gives auditees at least two weeks' notice.
    4. Auditor independence — Clause 9.2 requires auditors who did not do the work being audited. A three-person engineering team auditing its own IAM controls is a common finding gap — bring in a peer team lead, a compliance consultant, or rotate auditors across departments.
💡
TIP
Build the audit plan as a spreadsheet mapped one row per Annex A control, with columns for owner, evidence type expected, and audit date. This single artifact becomes your evidence index during the external audit — auditors consistently ask for exactly this.

Step 2: Conduct the audit against the 93 Annex A controls

Walk each of the four themes systematically. Don't audit alphabetically by control number — group by theme so the same evidence source (e.g., HR records, the asset register, the DC provider's SOC 2 report) gets pulled once.

Organizational controls (37 controls, A.5.1–A.5.37) — policies, roles and responsibilities, supplier relationships, incident management, business continuity, legal and contractual requirements, threat intelligence. Sample evidence: information security policy sign-off, supplier security assessments, incident log with response times, records of legal/regulatory register review (relevant for Indian teams tracking DPDP Act obligations).

People controls (8 controls, A.6.1–A.6.8) — screening, terms of employment, security awareness training, disciplinary process, remote working, and confidentiality agreements. Sample evidence: signed NDAs, background-verification records, training completion logs, offboarding checklists confirming access revocation within a defined SLA.

Physical controls (14 controls, A.7.1–A.7.14) — physical security perimeters, entry controls, protection against environmental threats, equipment maintenance, secure disposal. For Indian teams on shared coworking or cloud-only infrastructure, this maps largely to data-center provider attestations (AWS/Azure/GCP compliance reports) plus office access logs and clean-desk checks.

Technological controls (34 controls, A.8.1–A.8.34) — access control, cryptography, vulnerability management, logging and monitoring, secure development, network security, malware protection, and backup. This is the theme where automated evidence collection pays off fastest — vulnerability scan reports, patch cadence records, MFA enforcement logs, and configuration baselines.

xychart-beta title "ISO 27001 2022 Annex A Controls by Theme" x-axis ["Organizational", "People", "Physical", "Technological"] y-axis "Number of controls" 0 --> 40 bar [37, 8, 14, 34]
93Total Annex A controls in ISO/IEC 27001:2022 (ISO 2022)
37Organizational controls, the largest theme (ISO 2022)
11New controls introduced vs. the 2013 edition, e.g. threat intelligence, cloud security (ISO 2022)

For each control, the auditor should record: is it implemented, is it operating effectively (not just "on paper"), and is there objective evidence (a log, a screenshot, a signed document, a ticket) to prove it. "The team says they do this" is not evidence.

⚠️
WARNING
A control marked "Not Applicable" in your Statement of Applicability without a documented justification is itself a common nonconformity. Every exclusion needs a written reason — auditors will ask why.

Common Annex A theme checklist

Theme# ControlsTypical evidence auditors ask forCommon Indian-SMB gap
Organizational37Policy register, supplier contracts, incident log, legal registerNo documented supplier risk assessment for outsourced dev/QA teams
People8Background checks, training logs, offboarding checklistOffboarding not tied to an HR trigger — access revoked days late
Physical14Access logs, DC provider attestations, asset disposal recordsNo formal clean-desk or clear-screen policy evidence
Technological34Vulnerability scan reports, MFA logs, backup test records, patch logsBackups exist but restore has never been tested

Step 3: Document nonconformities properly

Every gap found during the audit gets logged as a nonconformity (NC) with:

    1. Clause/control reference — which requirement was not met.
    2. Objective evidence — what was observed (a missing log, an expired certificate, an untested backup).
    3. Classification — major (systemic, or a complete absence of a required control) vs. minor (an isolated lapse in an otherwise working control).
    4. Root cause — not just the symptom. "MFA was disabled on one admin account" is a symptom; "no periodic access review process exists" is the root cause.
🛡️
SECURITY
Resist the temptation to write findings vaguely to avoid friction with the team being audited ("some improvement needed in access control"). External auditors reject vague internal audit reports outright — they expect the same rigor an external auditor would apply. A soft internal report is itself a red flag.

Step 4: Corrective action

For every nonconformity, Clause 10.1 requires a corrective action that addresses the root cause, not just the immediate symptom, plus a review to confirm the action worked. Track:

    1. Action owner and target date.
    2. Root-cause fix (e.g., implement a quarterly access review job) — not just a one-time patch (e.g., manually disabling one stale account).
    3. Verification evidence that the fix was effective, collected at a later date — not closed same-day on a promise.
🎯Key Takeaway
The internal audit's real value isn't the audit day itself — it's the corrective action trail that proves your ISMS actually improves over time. Certification bodies are increasingly evaluating the maturity of your corrective-action process as closely as the controls themselves.

Step 5: Management review

Clause 9.3 requires top management to formally review the ISMS — internal audit results, corrective action status, risk assessment changes, nonconformity trends, and resource needs — at planned intervals (typically annually, aligned with your certification cycle). Minute this meeting. Auditors will ask for management review minutes as standard evidence, and a missing or perfunctory review is a recurring finding in Indian SMB first-time certifications.

Feed management review outputs back into the next audit plan — new risks, new suppliers, or new regulatory obligations (like updated MeitY guidance or sector-specific RBI/SEBI cybersecurity frameworks for regulated entities) should reshape next cycle's scope. That's the continual improvement loop the standard requires.

ℹ️
NOTE
If your organization is a regulated entity — a bank or NBFC under the RBI Cyber Security Framework or a market participant under SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF) — your internal ISO 27001 audit should explicitly cross-reference those sector obligations, since auditors will expect alignment rather than two disconnected compliance tracks.

Know your vulnerabilities before attackers do

Run a free VAPT scan — takes 5 minutes, no signup required.

Book Your Free Scan

Where automation helps — and where it doesn't

Evidence collection for the technological theme (vulnerability scans, patch status, exposed services, misconfigurations) is where continuous automated scanning saves the most audit-prep time versus manual screenshotting once a year. Bachao.AI runs continuous VAPT scans that generate the kind of dated, timestamped evidence auditors want for A.8 controls — vulnerability management, logging, and network security — without a scramble the week before the audit. Automation cannot replace the organizational and people-theme evidence (contracts, training records, management sign-off), which still needs a human audit trail. Dhisattva AI Pvt Ltd built this platform specifically to close that automation gap for Indian SMB security teams stretched thin on headcount.

If your team hasn't run a security assessment recently, a free VAPT scan is a fast way to surface technological-theme gaps before your internal audit date, and for teams also tracking data protection obligations alongside ISO 27001, see the DPDP compliance guide for how the two overlap on data handling controls.

Building your internal audit checklist

A practical starting checklist for Indian SMB teams:

  1. Confirm Statement of Applicability is current and every exclusion is justified.
  2. Assign independent auditors per department — no one audits their own work.
  3. Pull evidence by theme, not by control number, to reduce duplicate evidence requests.
  4. Classify every gap as major/minor with a documented root cause.
  5. Set corrective action deadlines and re-verify before closing.
  6. Hold and minute the management review before the certification/surveillance date.
  7. Update the risk register and next audit scope based on management review outputs.
Read more on our blog for related guides on vulnerability management and continuous compliance monitoring.

Frequently Asked Questions

How often should we run an ISO 27001 internal audit?
Most organizations run it at least once per certification cycle, and many Indian SMBs run it twice a year — once as a full-scope audit ahead of the annual surveillance audit, and once as a targeted review of prior nonconformities. The exact frequency should be documented in your audit programme under Clause 9.2.
How many controls are in ISO/IEC 27001:2022 Annex A?
There are 93 controls, organized into four themes: 37 organizational, 8 people, 14 physical, and 34 technological. This replaced the 2013 edition's 114 controls across 14 domains.
Can the same person do the internal audit and fix the findings?
No. Clause 9.2 requires audit independence — the auditor cannot audit their own work. Small teams typically solve this by rotating auditors across departments or bringing in an external compliance consultant for the audit itself.
What's the difference between a major and minor nonconformity?
A major nonconformity is a systemic failure or complete absence of a required control — for example, no access review process at all. A minor nonconformity is an isolated lapse in an otherwise functioning control, like one account missing MFA. Major nonconformities typically require closure before certification can proceed.
Do we need to mark every Annex A control as applicable?
No, but every control marked "Not Applicable" in your Statement of Applicability needs a documented justification. Auditors specifically check for unjustified exclusions since this is a common way organizations try to skip inconvenient controls.
Does an ISO 27001 internal audit cover DPDP Act compliance too?
Not automatically — they are separate frameworks, though there's overlap on data handling, access control, and breach response. Indian teams pursuing both should cross-reference their DPDP compliance controls against relevant Annex A technological and organizational controls to avoid duplicate work.
BR

Bachao.AI Research Team

Cybersecurity Research

AI-powered security research and threat intelligence from the Bachao.AI team. Covering the latest vulnerabilities, CVEs, and cybersecurity developments affecting Indian businesses.

Get cybersecurity insights for Indian SMBs

Weekly vulnerability alerts, DPDP compliance tips, and security guides. No spam — unsubscribe anytime.

We respect your privacy. Your email is never shared.

See if your business is DPDP Act compliant

Free automated scan — risk score in under 2 hours. No credit card required.

Check DPDP Compliance
Find your vulnerabilitiesStart free scan →