A free internal audit worksheet for ISO/IEC 27001:2022. Every clause and control comes with the exact questions to ask, plus result grading and a live audit dashboard.
Prefer done-for-you? Get the ISO 27001 toolkit or explore training.
First published in 2005 and last revised in 2022, ISO/IEC 27001 is the world’s best known standard for an Information Security Management System, or ISMS. It gives organisations a risk-based way to protect information.
At its heart is a simple idea. You manage information security through a continual cycle of risk assessment and risk treatment, rather than a fixed checklist. You decide which risks matter, then select the controls that treat them.
The 2022 edition follows the harmonised structure of Clauses 4 to 10, and its Annex A sets out 93 reference controls grouped into four themes: organisational, people, physical and technological. These align with ISO/IEC 27002:2022.
It applies to any organisation that handles information worth protecting, from cloud providers to hospitals to professional firms. Certification is often a contractual or tender requirement, and it underpins trust with customers and regulators.
Current edition, the third
Annex A reference controls
Control themes
Clauses, numbered 4 to 10
Every clause and control comes with the exact questions an auditor asks. Record the evidence and a result, and the dashboard tracks conformity and nonconformities for you.
375 verification questions in total, grounded in the actual requirements, so nothing is missed.
Record how you audited each item and the objective evidence you examined, for a defensible trail.
Mark each requirement Conforms, Observation, Minor NC or Major NC from a simple drop-down.
See majors, minors and observations at a glance, ready to feed a corrective action.
Conformity rate, nonconformities raised and results by section, updating as you go.
Open it and audit. Standard Excel, no macros, works on desktop and in the browser.
375 verification questions drawn straight from the standard, so your audit is thorough and defensible, not a box-tick.
Grade every result and watch the conformity rate and the count of nonconformities update live.
Front page to capture the audit scope, dates, auditor and auditee.
How to run the audit, the audit method and the results key.
Audit progress, conformity rate, nonconformities and results by section.
Every requirement with its verification questions, plus method, evidence and result.
The same audit approach applied to every Annex A control.
Set the scope, criteria and areas to sample on the Cover sheet.
Work through the questions, gathering objective evidence for each requirement.
Grade each requirement and note the finding or nonconformity detail.
Feed the nonconformities into corrective action and re-audit to close.
The free tool shows where you stand. When you are ready to build the ISMS, these paid resources from Risk Professionals get you there faster.
A complete, editable ISO 27001 document kit, mapped to the standard and ready to implement, so you never start from a blank page.
Accredited ISO 27001 training for your team, from foundation through lead implementer and lead auditor.
Hands-on help, from a gap assessment to a virtual executive who helps run the system with you.
Not sure what certification will cost? Try the free ISO 27001 cost calculator.
Yes. The tool is offered free for your organisation’s own internal use, with no sign-up wall and no macros. You may use and reproduce it internally, but not sell, rebrand or redistribute it for commercial gain. Full terms are on the Cover sheet.
ISO 14001:2026, the fourth edition. This edition adds a separate risks and opportunities requirement and planning of changes, so the tool is built to the 2026 structure, not the 2015 one.
The tool includes plain-English guidance so you can start straight away. For a formal implementation or certification you should still obtain the official standard from ISO or an authorised reseller. The tool summarises the requirements and is not a substitute for the standard.
Compliance asks whether you meet the requirement today. Maturity asks how embedded, documented and repeatable the approach is. They are rated separately, because you can be compliant on paper yet immature in practice, or maturing but not yet compliant. Rating both gives a truer picture.
No. This self-assessment helps you understand your position and prioritise improvements. Certification can only be granted by an accredited certification body after a formal audit.
Need help? Our team is just a message away