Get in touch

Get in touch

  • This field is for validation purposes and should be left unchanged.

Privacy Notice


When you submit an enquiry via our website, we use the personal data you supply to respond to your query, including providing you with any requested information about our products and services. We may also email you several times after your enquiry in order to follow up on your interest and ensure that we have answered your it to your satisfaction. We will do this based on our legitimate interest in providing accurate information prior to a sale. Your enquiry is stored and processed as an email which is hosted by Microsoft within the European Economic Area (EEA). We keep enquiry emails for two years, after which they are securely archived and kept for seven years, when we delete them.

Reveal Menu

Seven Essential Steps to Prepare for an Internal Audit

Internal audits are a necessary part of becoming, and staying, certified to an ISO standard. Although perhaps less scary than a visit from the certification auditor, internal audits can often be seen as a nuisance, something that stops you doing the busy day job and delivering ‘real work’. But there are a number of benefits to internal audits for the auditee that shouldn’t be ignored, such as:

  • They are a good practice run for the certification audit, both in terms of being audited and in knowing where your evidence is located
  • They find issues that you didn’t know about because you’ve been too busy
  • They give you a useful objective view on what you’re doing, sometimes saving you time in the long run
  • They provide official justification to get things fixed, possibly reducing resistance from others and lessening cost constraints
  • A good internal audit report makes Clause 9.2 of the standard a breeze with the certification auditor

So instead of being seen as a pest, we believe the internal auditor should be greeted with a healthy degree of appreciation and maybe even a cup of coffee.

But as the person being audited, what can you do to make this process as smooth as possible? Let’s look at the essential steps to preparing for the internal audit.

Step 1: Check the scope of the audit

You should have an audit programme that sets out the audits that will be performed, and the areas of the standard that they will cover. Have a look at this and get it straight in your own mind what you will be talking about when the internal auditor arrives (physically or virtually). Hopefully the auditor will have created an audit plan that states clearly what they are coming to discuss. Review the standard to refresh your memory about what the clauses and controls cover and what the requirements are so you can hit the ground running.

Step 2: Confirm the logistical details of the audit beforehand

Apart from the date, time and duration of the audit, the main question to be asked initially is whether the auditor is physically coming to see you or are they conducting the audit via Teams or similar collaboration software (and if so, do you have the chosen software installed?). If it’s an in person visit you may need to think about a room, parking, letting reception know, refreshments, how to show documents (for example on a big screen or via a projector) and other practical considerations. If it’s virtual, will it be via the “show and tell” method where the auditor stays on the line, or via the “provide and leave” method where you send the auditor relevant documentation, and they ponder it offline until they’re ready to talk to you again? A few emails exchanged for clarity can save a lot of confusion on the day.

Step 3: Make the right people available for the audit

Depending on the scope of the audit you may need to involve other people within your organization. Identify who they are and then check their availability on the day, ideally with a nominated deputy in case something unexpected happens in their department. Be as accurate as you can about timing, but allow for some flexibility if the audit runs over or another person isn’t available and the order has to be changed. Brief them about the areas to be covered and the audit process, especially if they haven’t been involved before.

Step 4: Make sure the nonconformities and observations from the last audit have been addressed

There are few things more irritating for an auditor than having their work ignored, so make sure you check on the progress of actions raised from the last audit that was carried out. If they have been completed, then make sure the relevant records have been updated. If they are still in progress then be aware of why they aren’t closed yet and how long they are likely to take.

Step 5: Think about what’s changed since the last audit

After the initial hellos and discussion about the weather the first question an auditor is likely to ask you is “what’s changed?”. They are interested in the way in which your ISMS adapts and copes with change so before the audit have a think about those areas in which something significant has happened; it could be a new project, a location move, some redundancies, a data breach, a change of suppliers or anything else that has an information security implication. For each of these things, put some thought into whether the right processes have been followed, and whether the evidence backs this up.

Step 6: Get your evidence ready

Sometimes it’s a long time between audits, and your familiarity with where information is located may fade a little. This is your chance to reacquaint yourself with the location and contents of policies, processes, technical controls and other items that will be the subject of the upcoming audit. This will save time on the day and make you look like you know what you’re doing. It’s also your chance to correct anything you find that hasn’t been updated or doesn’t follow due process, such as an unapproved policy or an incident record not closed.

Step 7: Provide evidence in advance

Depending on the auditor and the method of audit, it may be appropriate to provide at least some of the relevant documentation shortly before the audit. Perhaps the auditor will give you a list of desired documents or you could simply provide what you think they will want to see. Be careful to do this securely so that a nonconformity doesn’t result from your good intentions. The best way is via secure file sharing or a portal; less so via email.

Final Words

Conducting a smooth internal audit is very much a two-way street and it’s important that you as the auditee play your part in making it happen like a well-oiled machine. Your auditor will certainly appreciate your help and will be more prepared to give you the benefit of the doubt when issues arise. But above all, treat internal audits as a valuable improvement tool that makes your ISMS, and therefore your organization, better.


Written by CertiKit’s CEO, Ken Holmes CISSP, CIPP/E. Ken is the primary author of CertiKit’s toolkit range and has helped to implement, operate and audit ISO certifications over a varied 30-year career in the Information Technology industry. 

More ISO Resources

CertiKit is a provider of ISO toolkits, consultancy and internal auditing services, and has helped more than 4000 organizations worldwide with their compliance. If you’re looking to outsource your internal audit, we can conduct your internal audit and help prepare your team.

Find out more

We’ve helped more than 4000 businesses with their compliance


The structure is excellent, clear, precise and easy to digest. The content is professional and the guidance is extremely helpful. I cannot fault it!


View all Testimonials