IMS-Audit
Audit Software · ISO/IEC 27001 · Information Security

Audit Software for ISO 27001

An information security management system (ISMS) to ISO/IEC 27001 depends on the interplay of risk assessment, actions and review — and internal audits are the litmus test of whether all of this is truly lived. IMS-Audit Cloud brings ISMS audits into the same system as your quality and environmental audits: one programme, one action cockpit, audit-proof evidence.

What the standard requires

Internal audits under ISO/IEC 27001

Clause 9.2 of ISO/IEC 27001 requires internal audits as evidence that the ISMS conforms to the organisation’s own requirements and the requirements of the standard, and is effectively implemented:

  • Conduct internal audits at planned intervals
  • Plan and maintain audit programmes — taking into account the importance of the processes and the results of previous audits
  • Define the audit criteria and scope for each audit
  • Select auditors so as to ensure objectivity and impartiality
  • Report the results to the relevant management
  • Address nonconformities and take corrective action
  • Retain documented information as evidence of the programme and the audit results

Note: this overview summarises key requirements and does not replace the text of the standard.

Frequently asked questions

ISO 27001 and internal audits

How often are internal audits required under ISO 27001?

The standard requires audits “at planned intervals” — without a fixed frequency. The programme is based on the importance of the processes and the results of previous audits; a common approach is to cover the entire ISMS at least once per certification cycle. In IMS-Audit Cloud you plan this clearly as an annual or multi-year programme.

Does the software itself meet information security requirements?

IMS-Audit Cloud runs on our own dedicated server hardware in a certified German data centre — with a separate database per company, TLS encryption, daily backups to separate storage and optional two-factor authentication.

Is there a ready-made question catalogue for ISO 27001?

Yes. The ISO 27001 standard catalogue is one of the ready-made standard catalogues available from us separately — just get in touch. You create your own catalogues at any time or import them via Excel.

Can I combine ISO 27001 with ISO 9001?

Yes — both standards share the common high-level structure. In IMS-Audit Cloud you audit the ISMS and QMS in one system, with one audit programme and one action cockpit.

More answers — on pricing, hosting and contract terms — in the FAQ.

Internal audits under ISO 27001 — see it for yourself.

All modules included, no set-up fee — in a personal meeting we show you the cloud using your own topics.