Glossary

Internal audit

An internal audit is a self-examination of your security program, required by ISO 27001 before certification and throughout the certificate’s life. Someone independent of the work being audited checks whether the ISMS conforms to the standard and your own documentation, and the findings feed management review and corrective action.
Assemble Your GRC Team
Last updated July 26, 2026