iso-27001-internal-audit

Facilitates ISO 27001:2022 internal audits with a structured workflow for control assessment, evidence collection, and findings generation.

46|9|Updated Feb 9, 2026
One-click install
npx skills add https://github.com/open-agreements/open-agreements --skill iso-27001-internal-audit
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: iso-27001-internal-audit
Source: https://github.com/open-agreements/open-agreements/tree/main/skills/iso-27001-internal-audit
Command: npx skills add https://github.com/open-agreements/open-agreements --skill iso-27001-internal-audit

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) and scripts (resource) components.

What problem does it solve?

This Skill streamlines the complex process of conducting internal audits against the ISO 27001 standard, helping organizations identify compliance gaps and prepare for external certification.

Core Features & Use Cases

  • Guided Auditing Workflow: Walks users through scoping, control assessment, evidence collection, and findings generation.
  • Control Assessment: Provides detailed guidance for each ISO 27001 Annex A control and ISMS clause.
  • Evidence Collection: Offers commands and examples for gathering necessary audit evidence.
  • Use Case: A startup preparing for its first ISO 27001 certification can use this Skill to systematically assess its controls, document findings, and ensure all requirements are met before the external audit.

Quick Start

Begin an ISO 27001 internal audit by assessing the organizational controls.

Frequently Asked Questions about iso-27001-internal-audit

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I conduct an ISO 27001 internal audit?

To conduct an ISO 27001 internal audit, you follow a structured workflow for scoping, control assessment, evidence collection, and findings generation to identify compliance gaps before external certification.

What is included in an ISO 27001 control assessment?

An ISO 27001 control assessment provides detailed guidance for evaluating each Annex A control and ISMS clause, alongside commands and examples for gathering the necessary audit evidence.

Can I use one audit for ISO 27001, SOC 2 Type II, and NIST SP 800-53 compliance?

Yes, this internal audit process supports compliance with ISO 27001, SOC 2 Type II, and NIST SP 800-53 frameworks simultaneously by assessing controls across multiple standards.

Does the ISO 27001 audit workflow require a live compliance server connection?

No, the audit workflow can integrate with a compliance MCP server for live data, but it also falls back to embedded reference files for procedural guidance and control descriptions.

What is the best way to prepare a startup for its first ISO 27001 certification?

The best way to prepare for a first ISO 27001 certification is to systematically assess organizational controls, document findings, and ensure all ISMS requirements are met before the external audit.