ISO 27001 obliges every certified organization to audit its own ISMS at planned intervals — verifying that the management system conforms both to the standard and to the company’s own documented requirements, and that it is genuinely implemented rather than merely written down. The certification body expects to see an audit program, a report, and proof that findings were treated. Turning up to a certification audit without one is a near-guaranteed nonconformity: the internal audit is the standard’s mechanism for making a company check itself before anyone else does.
The standard demands objectivity and impartiality — not an external firm. The working rule is simpler: nobody audits their own work. A larger company satisfies this by rotating auditors across departments; a startup where one person built the entire management system has no rotation available, which is why the exercise is so commonly outsourced. Certification auditors read independence carefully. An engineer reviewing the access process they administer fails the test, and so does a consultant examining an ISMS they personally implemented.
Timing matters as much as staffing. The internal audit needs to land far enough ahead of the external visit to fix what it finds, and it recurs annually alongside surveillance audits — most teams slot it a quarter before the certification body arrives. Outsourcing it to a practitioner who is independent of whoever built and operates the system satisfies the requirement without a hire; how early-stage teams typically arrange the whole cycle is covered in ISO 27001 for startups.