Skip to content

Plan and run an internal audit

Applies to
  • Managers
  • Admins
  • Auditors and auditees
Before you start
  • You know which standard the audit covers
  • The people auditing and being audited are active members

Internal Audit runs the ISO 9.2 audit cycle: plan an annual programme for a standard, schedule and conduct audits against it, record findings that raise non-conformities where they need to, and close each audit with a conclusion. Every audit gets a reference like AUD-0001 and carries its scope, plan, findings and conclusion with it.

Find it under GovernanceInternal Audit. The desk has three tabs — Programmes, Audits and Reports.

A programme is your annual internal-audit plan for one standard.

The Internal Audit desk on the Programmes tab, listing annual audit programmes with their standard, year, status and audit count.
  1. On Programmes, select New programme.
  2. Enter the Name — for example, ISO 27001 Annual Internal Audit — 2026.
  3. Choose the Standard — ISO 27001:2022, ISO 45001:2018, ISO 22301:2019, All standards or Custom.
  4. Set the Year.
  5. Assign an Owner from your team.
  6. Add Objectives — one line each, up to 20.
  7. Save. New programmes start in Draft; set the status to Active to schedule audits against it, and Closed when the year’s work is done.

From a programme you can Schedule audit to open the audit form with the programme already linked. The scheduled-audits roster on the programme shows every audit booked against it.

  1. On Audits, select New audit (or Schedule audit from a programme).
  2. Choose the Audit type — Internal, Supplier, Pre-certification, Surveillance, Recertification, Penetration test or ASV scan. The type is fixed once the audit is created.
  3. Choose the Standard — ISO 27001:2022, ISO 45001:2018, ISO 22301:2019, SOC 2 (2017) or PCI DSS v4.
  4. Link a Programme if this audit belongs to one.
  5. Set Scheduled for and name the Lead auditor — both are required.
  6. Add Co-auditors and Auditees, and set the Opening meeting.
  7. Under Scope, add the Locations, Module refs and Control refs the audit covers. Under Criteria, add Control refs and Legal requirements.
  8. Build the Audit plan — a day-by-day breakdown of date, area and auditors.
  9. Save.

A penetration test also needs a pen-test scope: a Methodology — Black box, Grey box, White box or Red team — and a scope narrative.

An ASV scan always uses PCI DSS v4 and needs its full scan block: vendor, initiated and completed times, a result (Pass, Fail or Pass with exceptions), whether a rescan is required, and the scan report file.

Open the audit and select Start conduct. This moves it from Scheduled to In progress and stamps the opening meeting — the audit must have a scheduled date first.

Once findings exist, the audit sits at Findings raised. Use Advance to move it on to Follow-up while corrective work is tracked.

Add findings from the audit’s Findings section. Each finding has a type, grouped into three families:

  • Non-conformities — Major non-conformity, Minor non-conformity.
  • Vulnerabilities — Critical, High, Medium or Low vulnerability.
  • Other — Observation, Opportunity for improvement, Positive finding, Informational.

For each finding, give a Description and the Evidence that supports it — both are required. You can also link a control ref and a legal requirement. Vulnerability findings additionally require a CVSS score between 0 and 10, and take an optional CVE ID.

Select Close audit, then:

  1. Choose a Conclusion — Certified recommended, Satisfactory, Minor NCs issued, Major NCs issued, Not recommended or Critical findings open. It must be consistent with the findings raised.
  2. Write a Summary of the outcome, scope covered and key findings.
  3. Attach the Report file if you have one.

Closing stamps the closing meeting and finalises the record. You can’t close while any major finding still lacks a linked non-conformity — link one to each from the findings section first.

Scheduled → In progress → Findings raised → Follow-up → Closed. The lifecycle stepper on each audit shows where it stands.

Only a Scheduled audit that hasn’t been conducted can be deleted. A programme can only be deleted once all its open audits are closed or removed.

Reports breaks audits down by status, type or standard, charts findings by type, and shows closure stats — total audits, how many are closed, how many carried findings, and the closure rate. Filter by a date range. Export the register itself from Audits with Export CSV or Export PDF.