Many organisations with an ISO 27001 or ISO 27701 certificate know they have to carry out internal audits, but struggle with how to set them up in a planned and risk-based way. The result is often an ad-hoc approach: the same topics every year, tested superficially, mainly intended to tick the box for the external auditor. That is a missed opportunity. A well-designed audit programme is one of the few instruments through which management gains independent insight into whether the controls actually work in practice. In this article we explain how to build an audit programme and accompanying annual plan that meets the standard's requirements and demonstrably adds value.
The difference between an audit programme and an annual plan
These two terms are often used interchangeably, but they are not the same. The audit programme is the overarching, multi-year whole: which topics, systems and processes are covered at least once over a period of, say, three years, and at what frequency and depth. The annual plan is the concrete elaboration for a single year: which audits take place when, who carries them out and what scope each audit has. The programme provides coverage over time, the annual plan provides short-term feasibility. ISO 27001 explicitly refers in clause 9.2 to an audit programme that takes into account the importance of the processes concerned and the results of previous audits.
Step 1: define the audit universe
Start by mapping everything that is in principle worth auditing: the controls from the Statement of Applicability (SoA), the core processes, the main information systems and the suppliers that deliver critical services. This whole is what we call the audit universe. The goal is not to test everything every year, but to have a complete picture of what falls within scope, so you can make a substantiated choice about what is and is not audited.
Step 2: prioritise based on risk
This is where a mature audit function distinguishes itself from a formality. Not every topic deserves the same attention or frequency. Weigh the risk per component: how critical is the process or system, what was the outcome of previous audits, have there been recent incidents, has much changed (new systems, reorganisations, new suppliers) and what does regulation expect? Components with a high risk you audit more often and in more depth, low-risk components less often. This risk-based rationale is exactly what an external auditor wants to see, and it ensures that your scarce audit time goes to the places where it matters.
Step 3: build the multi-year programme and the annual plan
Distribute the audit universe across a cycle, for example three years, so that all relevant topics are covered at least once and the high-risk topics more often. Then translate the first year into a concrete annual plan with, per audit, a topic, an outline scope, an indication of the time required and an assigned auditor. Deliberately keep room free for unforeseen audits, because something always happens during the year that demands attention. An annual plan filled to the last day is not sustainable in practice.
Step 4: safeguard independence
A fundamental principle of internal audit is that the auditor does not assess their own work. Someone responsible for managing a system cannot audit that system objectively. In smaller organisations this is a challenge, because people wear multiple hats. Solutions include crossing roles (one person audits another's domain), bringing in a colleague from another department, or outsourcing the internal audit to an external party. The latter is particularly common for IT audits, where the required expertise is often not available internally. Document the independence and its rationale, because it is one of the first things an external auditor checks.
Step 5: execute, report and ensure follow-up
The execution of an audit follows a fixed rhythm: an opening meeting in which scope and approach are aligned, the gathering of evidence (documentation, interviews, observations, samples), the testing of the design and operating effectiveness of controls, and a closing with the findings. The report is the visible product, but the real value lies in the follow-up. Every finding should be given an owner, an agreed measure and a deadline. Without a structured process to follow up and close findings, the effect of the audit evaporates. In practice we see that it is precisely this follow-up that is most often left undone, while it is the place where the improvement actually happens.
Step 6: evaluate and improve the programme itself
At the end of the cycle, or annually, the audit programme itself should be reviewed. Were the right topics audited? Was the risk assessment correct in hindsight? Were the audits deep enough, or too superficial? The results of this evaluation feed the next annual plan. This creates a learning audit function that grows with the organisation, rather than a static annual obligation.
What an external auditor wants to see
At the certification or recertification audit, the external auditor checks not only that internal audits were carried out, but whether the programme is well-considered and risk-based, whether the auditors were independent, whether the findings were demonstrably followed up and whether the results feed into the management review. An audit programme that meets these requirements makes the external audit considerably smoother, simply because you show that the organisation takes checking itself seriously.
Would you like to set up an internal audit programme that goes beyond a formality, or have the IT audits carried out by independent specialists? We help to build a risk-based programme and carry out internal IT audits that both meet the standard and deliver concrete points for improvement. Feel free to contact us for a no-obligation conversation.
Frequently asked questions
What is the difference between an audit programme and an annual audit plan?+
The audit programme is the multi-year, overarching whole that determines which topics are audited at least once over a period of, say, three years and at what frequency. The annual plan is the concrete elaboration for a single year: which audits take place when, by whom and with what scope.
What does ISO 27001 require regarding internal audits?+
Clause 9.2 requires the organisation to conduct internal audits at planned intervals and to establish an audit programme that takes into account the importance of the processes concerned and the results of previous audits. Auditors must be objective and impartial, and the results must be reported to management.
How do I ensure independence in a small organisation?+
By crossing roles (one person audits another's domain), bringing in a colleague from another department, or outsourcing the internal audit to an external party. The principle is that no one assesses their own work. For IT audits, outsourcing is common because of the specialist knowledge required.
How often should I audit a topic?+
That depends on the risk. Critical processes and systems, areas with previous findings or recent changes are audited more often and in more depth; low-risk areas less often. The risk-based rationale matters more than a fixed frequency.
What is the most common mistake with internal audits?+
The absence of structured follow-up. Organisations carry out the audit and write a report, but findings are given no owner, measure or deadline. Without follow-up the value of the audit evaporates, whereas that is exactly where the improvement happens.
Need help with it-audit?
Independent assurance reports for service organizations. We work with you to determine which type of report fits your situation and what your clients or regulators expect.
Explore IT-Audit ServicesAbout the author
Partner | IT Auditor