Can You Outsource Your ISO 27001 Internal Audit?
Yes, and most small companies should. ISO/IEC 27001:2022 clause 9.2 requires internal audits of the information security management system at planned intervals; it requires the audit programme to be planned and the auditors selected so that objectivity and impartiality of the audit process are ensured. It does not require an employee. The word "internal" describes the audit's subject, not the auditor's payroll status: it is an audit of your own management system, performed on your behalf, as distinct from the external certification audit performed by an accredited certification body.
The constraint that follows is the one companies break: auditors must not audit their own work. If the consultancy that wrote your ISMS also performs its internal audit, the impartiality requirement is not satisfied, and a certification auditor who notices will raise it. That single rule decides most of the practical questions below.
Key takeaways
- Yes, and most small companies should. Clause 9.2 requires internal audits at planned intervals, not internal auditors, and says nothing about employment.
- "Internal" describes the audit's subject, not the auditor's payroll status: your own management system, as distinct from the external certification audit.
- The binding constraint is impartiality. Auditors must not audit their own work, which is why the firm that built your ISMS cannot audit it.
- The audit has to be evidence-based fieldwork, not a document review. An auditor who never asks to see an access review is auditing your documentation, not your management system.
- Findings are a feature. A report with no findings invites the obvious question, and a certification finding in an area your internal audit passed becomes a second finding against clause 9.2 itself.
What clause 9.2 actually asks for
Strip away the vocabulary and the clause requires four things.
1. A planned programme, not an event
You define frequency, methods, responsibilities, planning requirements and reporting, taking into account the importance of the processes concerned and the results of previous audits. A programme that audits the whole ISMS once a year is valid. So is one that audits a third of it every four months. What is not valid is auditing whatever somebody had time for.
2. Defined criteria and scope for each audit
Which clauses, which Annex A controls, which sites, which processes, measured against what. "We reviewed security" is not an audit; it is a meeting.
3. Objective and impartial auditors
The standard's own instruction. In a twenty-person company this is precisely why outsourcing is common: there is frequently nobody internal who is impartial about an ISMS they personally built.
4. Results reported to relevant management, and retained as documented information
Those results are also a required input to the management review under clause 9.3, and any nonconformity found feeds the corrective action requirements in clause 10.2. An internal audit that produces a document nobody reviews has satisfied the letter of one clause and failed two others.
The three ways companies break impartiality
The implementer audits their own build. One consultancy scopes the ISMS, writes the Statement of Applicability, drafts the policies, and then performs the internal audit of that same system. This is the most common version and the least defensible, because the auditor is checking their own deliverables.
The ISMS owner audits themselves. A security manager who runs the risk assessment, maintains the SoA, and owns the corrective actions also performs the internal audit. Even with genuine integrity, the person cannot be impartial about their own decisions, and the audit's findings tend to be about other people's areas.
The firewall exists on paper only. A larger consultancy assigns a "different team", which turns out to be the same partner, the same working papers, and a colleague at the next desk. Separation has to be real enough that the auditor can write a finding against the implementation without it becoming an internal argument.
The workable structures are simple. Use a different firm from the one that implemented. Use an internal person from a different function with no ownership of the ISMS, which works surprisingly well when the person is a good process auditor from finance or operations. Or co-source: an external lead auditor plus your own staff performing parts they had no hand in building.
What you are actually buying
An outsourced internal audit that earns its fee produces, at minimum:
- An audit plan naming criteria, scope, dates and the people to be interviewed, agreed before anyone shows up
- Evidence-based fieldwork, which means sampling records rather than reading policies. An auditor who never asks to see an access review is auditing your documentation, not your management system
- A report with findings classified as major nonconformity, minor nonconformity, or opportunity for improvement, each traced to the clause or control it fails
- Input formatted for management review, so clause 9.3 is fed rather than reinvented
- A corrective action starting point for each nonconformity: enough root cause to satisfy clause 10.2 without pretending the auditor can fix your process for you
The last one has a limit worth knowing. An internal auditor can tell you a control is inadequate. If they then design the replacement, they have compromised their impartiality for the next cycle, exactly as the implementation firm did. Expect findings and recommendations, not implementation.
How to price it, and how to compare quotes
We are not going to publish a market range here, because we could not source one we would stand behind, and a made-up range is worse than none. What we can give you is the way to make quotes comparable, which is more useful anyway.
Ask every bidder for the same three numbers: days of effort, the seniority and certifications of the person performing the audit (a lead auditor qualification against ISO/IEC 27001 is the relevant one), and what is included beyond fieldwork (report writing, the management review pack, a follow-up check on corrective actions). Quotes that look wildly different usually differ on days and on who does the work, not on hourly rate.
Then price the alternative honestly. Doing it internally is not free; it is a senior person's time, and at a loaded cost of $100 an hour a properly run audit of a small ISMS is still real money plus the opportunity cost of what that person was doing instead. Our budget planner is the place to model the surrounding programme cost. The comparison people get wrong is quoting an external day rate against an internal hourly salary rate, which flatters the internal option by ignoring everything except base pay.
Scope drives the number more than anything else: how many sites, how many products in the ISMS scope, whether the audit covers the full clause set and Annex A or one slice of a rolling programme, and whether your evidence is organised or has to be excavated. That last one is entirely within your control and is the cheapest lever you have.
What the certification auditor does with it
Worth knowing, because it changes what a good internal audit looks like.
Your certification body does not simply note that an internal audit happened. Clause 9.2 is itself auditable, so the external auditor examines the programme: was it planned, did it cover the ISMS over the cycle, were the auditors impartial, were results reported to management, and did nonconformities feed corrective action under clause 10.2. An internal audit report with no findings at all invites the obvious question, because a management system of any size has something to improve, and a report that found nothing usually means the audit did not look hard.
The second thing they do is compare. If the certification audit raises a nonconformity in an area your internal audit reviewed and passed three months earlier, the finding is no longer only about that control. It is also evidence that your internal audit is not effective, which is a finding against clause 9.2 in its own right. This is the mechanism that punishes a cheap, shallow internal audit twice: once when the underlying problem surfaces, and again when the programme that should have caught it is shown not to work.
It follows that findings are a feature. An internal audit that produces three well-evidenced minor nonconformities you then close is a stronger artifact at certification time than a clean report nobody believes.
When to keep it in-house
Against our own interest, three cases.
You have a competent process auditor in another function. Internal audit, quality, or finance people who audit for a living are often better at this than security specialists, because the skill being tested is evidence discipline rather than security knowledge. If that person had no hand in building the ISMS, use them.
Your ISMS is small, stable and mature. Second or third certification cycle, no new sites, no new products, no significant changes. The audit is largely confirmatory, and an internal auditor who knows the environment covers it faster than an outsider getting up to speed.
You are using the internal audit as a training exercise on purpose. Some companies rotate staff through internal audit precisely so that more people understand the ISMS. That is a legitimate reason to keep it in-house even when an external auditor would be sharper, as long as impartiality holds.
The case for outsourcing is the mirror image: nobody internal is impartial, the ISMS changed materially, the last certification audit raised findings your internal audit had missed, or you simply do not have the days.
Where Top Floor fits
We will do one of these for you, not both. If we helped build your ISMS, we are the wrong party to audit it, and we will tell you that rather than take the engagement. Where we do fit is either the ISO 27001 implementation or, for a system somebody else built, the internal audit and the wider audit readiness work around it. If what you are really weighing is whether to buy a rehearsal before the certification audit rather than an internal audit inside the cycle, that is a different purchase and we cover it in do you need a readiness assessment.
If you already hold SOC 2 and are adding ISO 27001, note that the internal audit programme is one of the requirements with no SOC 2 equivalent at all, which is why it tends to be a surprise line item. The full list of what does and does not transfer is in reusing evidence across frameworks, and the sequencing argument is in ISO 27001 versus SOC 2.
Frequently asked questions
Does ISO 27001 require internal staff to perform the internal audit?
No. Clause 9.2 requires internal audits of the ISMS at planned intervals and requires that auditors be selected so objectivity and impartiality are ensured. It says nothing about employment. "Internal" describes what is being audited, your own management system, in contrast to the external certification audit performed by an accredited certification body. Outsourcing is entirely conformant, and for small organisations it is often the only way to satisfy the impartiality requirement at all.
Can the consultancy that built our ISMS also audit it?
No. Auditing your own work fails the impartiality requirement in clause 9.2, and a certification auditor who spots the arrangement can raise it as a nonconformity. If one firm implemented, use a different firm, an internal person from a function with no ownership of the ISMS, or a genuinely separated team where the auditor can write a finding against the implementation without it becoming an internal dispute. A separation that exists only in the proposal is not a separation.
How often do we need an internal audit?
At planned intervals, with the plan justified by the importance of the processes and the results of previous audits. Most certified organisations cover the full ISMS across a twelve-month cycle, either as one audit or as a rolling programme of partial audits. What matters to a certification auditor is that the programme is defined, that it covers everything over the cycle, and that you followed it. An unplanned audit performed because the certification visit is next month satisfies nobody.
What does an outsourced internal audit cost?
We are not publishing a range, because we could not source one we would stand behind, and an invented figure is worse than none. Make quotes comparable instead: ask each bidder for days of effort, the auditor's seniority and lead auditor qualification, and what is included beyond fieldwork, then compare those rather than headline prices. Scope is the biggest driver, followed by how organised your evidence is, which is the one variable you control.
Related Services
Need help with your compliance program?
Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.
Schedule a Free ConsultationGet insights like this in your inbox
Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.
Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.