internal-audit

Document ISO 27001:2022 internal audit processes and evidence requirements.

Updated Apr 28, 2026
One-click install
npx skills add https://github.com/gombing/ISO27001Agent --skill internal-audit
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: internal-audit
Source: https://github.com/gombing/ISO27001Agent/tree/main/internal-audit
Command: npx skills add https://github.com/gombing/ISO27001Agent --skill internal-audit

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps ISO 27001:2022 internal auditors plan, execute, and document the complete Clause 9.2 internal audit cycle, including building an audit programme, creating an audit plan per cycle, guiding evidence collection, recording findings, and producing a dated Internal Audit Report with corrective actions.

Core Features & Use Cases

  • Audit Programme Setup: Establish an auditable programme covering scope, frequency, responsibilities, and reporting requirements.
  • Audit Plan Creation: Generate a structured audit plan with sessions, durations, areas, and methods.
  • Clause-by-Clause Evidence & Findings: Guide evidence gathering and classification of findings for each clause group, including NCRs and observations.
  • Engagement Context Loading: Load client engagement context from engagement documents to tailor the audit.
  • Audit Report Generation: Produce a dated Internal Audit Report with findings, actions, and owner assignments.

Quick Start

Run the internal-audit skill to start an end-to-end internal audit workflow.

Frequently Asked Questions about internal-audit

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I plan an ISO 27001 internal audit programme?

An ISO 27001 internal audit programme defines the audit scope, frequency, responsibilities, and reporting requirements. You establish this auditable programme framework to systematically cover Clause 9.2 compliance cycles and structure subsequent audit plans.

How do I collect evidence for ISO 27001 clause 9.2 internal audits?

To collect evidence for ISO 27001 clause 9.2 internal audits, follow a structured audit plan guiding clause-by-clause evidence gathering. You classify findings into nonconformities and observations to ensure compliance documentation is thorough.

What is included in an ISO 27001 internal audit report?

An ISO 27001 internal audit report includes dated findings, assigned corrective actions, and responsible owners. It documents the complete audit cycle results from evidence collection to identified nonconformities for Clause 9.2 compliance tracking.

Can I use client engagement context to tailor an internal audit plan?

Yes, you can load client engagement context from engagement documents to tailor the internal audit plan. This customizes the audit sessions, focus areas, and evidence collection methods to fit specific organizational compliance requirements.

Does the internal audit workflow support tracking nonconformities and corrective actions?

Yes, the internal audit workflow supports tracking nonconformities and corrective actions. It records findings during evidence collection and assigns owners to corrective actions within the final dated Internal Audit Report.

What is the best way to structure an internal audit plan for ISO 27001?

The best way to structure an ISO 27001 internal audit plan is to define specific sessions, durations, target areas, and audit methods. This structured approach ensures complete Clause 9.2 evidence collection and accurate reporting workflow.