AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified Apache-2.0 Self-run

Iso27001 Internal Auditor

skill-riskresponse-claude-grc-skills-iso27001-internal-auditor · by RiskResponse

Expert guidance for conducting ISO 27001:2022 internal audits using Vanta platform. Covers the complete 7-step audit process, evidence analysis, nonconformity identification, and audit reporting for SaaS companies. Use when performing annual ISMS internal audits, reviewing Vanta-exported evidence, or documenting audit findings.

No reviews yet
0 installs
17 views
0.0% view→install

Install

$ agentstack add skill-riskresponse-claude-grc-skills-iso27001-internal-auditor

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-riskresponse-claude-grc-skills-iso27001-internal-auditor)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
6mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Iso27001 Internal Auditor? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

ISO 27001:2022 Internal Auditor

Overview

This skill provides comprehensive guidance for conducting ISO 27001:2022 internal audits of Information Security Management Systems (ISMS), with specific focus on:

  • 7-step audit methodology from planning to corrective action follow-up
  • Vanta platform integration for evidence review and audit management
  • All ISO 27001:2022 requirements (Clauses 4-10 + 93 Annex A controls)
  • Finding classification (nonconformities, observations, recommendations)
  • SaaS company considerations (cloud controls, multi-tenancy, DevSecOps)

Designed for experienced compliance teams performing annual internal audits.

Keywords: ISO 27001, internal audit, ISMS, Vanta, nonconformity, audit findings, Annex A controls, information security, audit report

When to Use This Skill

Use this skill when you need to:

  • Conduct annual ISO 27001 internal audit
  • Review and analyze evidence exported from Vanta
  • Create audit checklists for ISO 27001:2022
  • Identify nonconformities, observations, and recommendations
  • Write professional internal audit reports
  • Document corrective action requests
  • Perform corrective action follow-up
  • Ensure complete coverage of all ISO 27001 requirements

The 7-Step Internal Audit Process

ISO 27001 internal audits follow a structured 7-step methodology:

Step 1: Document Review

Purpose: Review ISMS documentation for compliance and prepare for main audit

Activities:

  • Review Information Security Policy
  • Review all applicable procedures and documented information
  • Review Statement of Applicability (SoA)
  • Review Risk Assessment and Risk Treatment Plan
  • Review records (management review, incidents, corrective actions)
  • Check documentation against ISO 27001:2022 requirements
  • Identify areas to investigate during main audit

In Vanta:

  • Export and review all policies
  • Review control implementation status
  • Examine risk register and treatment plans
  • Review completed tasks and tests
  • Check document versioning and approval status

Output: Notes on potential nonconformities, areas requiring investigation

Template: Use the Vanta audit workflow guide from references/vanta_audit_workflow.md

Step 2: Create Internal Audit Checklist

Purpose: Prepare structured notes to guide the main audit

Activities:

  • List all requirements to be audited (clauses + Annex A controls)
  • Note what evidence to look for
  • Identify who to interview
  • Plan which records to sample
  • Prepare questions based on document review findings

Four-Column Format:

  1. Reference - Clause or control number
  2. What to look for - Requirements, questions, evidence to examine
  3. Compliance - Y/N/Partial/N/A (fill during audit)
  4. Findings - Evidence found (fill during audit)

Template: references/audit_checklist_complete.md (93 Annex A controls + clauses 4-10, plus ISO 22301)

Step 3: Write Audit Plan

Purpose: Define detailed logistics for the audit

Activities:

  • Set audit dates and times
  • Identify departments/processes to audit
  • List contact persons for each area
  • Define audit team roles (if multiple auditors)
  • Communicate plan to auditees
  • Schedule opening meeting (if applicable)

Guidance: See references/iso_internal_audit_guide_full.md Section 3.5 for audit plan structure

Step 4: Conduct Main Audit

Purpose: Gather evidence through on-site examination

Three Evidence Collection Techniques:

  1. Reviewing Documents and Records:
  • Most reliable evidence
  • Examine policies, procedures, records
  • Check Vanta evidence uploads (screenshots, logs, reports)
  • Verify document versions, approval dates, completeness
  1. Interviewing Employees:
  • Speak to multiple people for same process to corroborate evidence
  • Use open-ended questions: "Please describe how you control access to the IT system" — lets the auditee reveal how things actually work
  • Avoid closed-end questions ("Is this your backup server?") — only use these to confirm specific evidence
  • Use the "Five Whys" technique to find root causes: keep asking "Why?" until you reach the underlying problem (often takes ~5 iterations)
  • Verify understanding of procedures and awareness of responsibilities
  • Record exact quotes as evidence
  1. Observing Activities and Facilities:
  • Visit server rooms, secure areas
  • Observe processes in action
  • Check physical security controls
  • Verify configurations match documentation

Opening Meeting (optional for internal audits): Brief management on audit objectives, scope, timing, and how findings will be reported. Useful for larger organizations or when auditees are unfamiliar with the process.

During Main Audit:

  • Follow your checklist but remain flexible — don't miss leads not on your checklist
  • Document all evidence immediately
  • Record exact names, dates, versions
  • Note direct quotes from interviews
  • Take photos/screenshots if appropriate
  • Don't make assumptions — verify everything (the biggest auditor mistake is assuming a requirement exists when it doesn't)
  • You choose which records to sample, not the auditee

Closing Meeting (optional for internal audits): Present nonconformities and observations to management. Not mandatory for smaller companies but useful for formalizing communication of findings.

Recording Evidence:

  • Fill columns 3 and 4 of your checklist
  • Note specific evidence (document names, record IDs, person names)
  • Reference Vanta evidence (task IDs, test results, policy versions)
  • Document timestamps and locations

Step 5: Write Internal Audit Report

Purpose: Document all findings formally

Required Sections:

  1. General Information:
  • Audit date, auditor name(s)
  • Audit scope and criteria
  • Audit objectives
  • Auditees
  1. Audit Findings:
  • Nonconformities (with full structure - see below)
  • Observations (potential issues, best practices not followed)
  • Recommendations (improvement opportunities)
  1. Audit Conclusions:
  • Overall compliance assessment
  • System effectiveness evaluation
  • Readiness for certification audit
  • Key themes or patterns

Nonconformity Structure (4 elements):

  1. Reference: Exact clause/control number (e.g., "ISO 27001:2022 Clause 6.1.2")
  2. Requirement: Brief description of requirement not met
  3. Finding: What was found (the gap)
  4. Evidence: Specific proof (document name, interview quote, observation details)

Template: templates/internal_audit_report.md

Step 6: Initiate Corrective Actions

Purpose: Formally request resolution of nonconformities

Activities:

  • Create Corrective Action Request (CAR) for each nonconformity
  • Assign responsible person
  • Set deadline for resolution
  • Define root cause analysis requirement
  • Track in Vanta or corrective action system

Template: templates/nonconformity_report.md

In Vanta:

  • Create tasks for each nonconformity
  • Assign to control owners
  • Set due dates
  • Link to audit findings
  • Track remediation progress

Step 7: Corrective Action Follow-Up

Purpose: Verify nonconformities are actually resolved

Activities:

  • Review completed corrective actions
  • Verify evidence of implementation
  • Conduct mini-audit of corrected areas
  • Confirm root cause addressed
  • Close CARs or re-open if inadequate
  • Update audit records

Timeline: Typically 30-90 days after audit depending on NC severity

In Vanta:

  • Review corrective action task completion
  • Verify new evidence uploaded
  • Validate control status updated
  • Close audit findings

Working with Vanta Platform

Three Methods for Evidence Retrieval

Method 1: Vanta API Scripts (Automated - Recommended)

  • Use scripts/vanta_api/retrieve_all.py for bulk export
  • Automated download of all policies and evidence
  • Auto-generates audit notes with potential findings
  • See: references/vanta_api_integration.md

Method 2: Vanta MCP Server (Interactive)

  • Real-time queries during audit conversations
  • Natural language evidence retrieval
  • Integrated with Claude Desktop
  • See: mcp/mcp_setup_guide.md and mcp/mcp_audit_workflow.md

Method 3: Manual Export (Fallback)

  • Traditional manual download from Vanta web interface
  • Use when API/MCP not available

Vanta Exports for Audit

Using API Scripts (Recommended):

# Retrieve all policies and evidence automatically
cd scripts/vanta_api
python3 retrieve_all.py

# Creates organized exports in vanta_exports/

Using MCP Server (Interactive): In Claude Desktop with Vanta MCP configured: > "Using Vanta MCP Server, export all policies and check for overdue reviews"

Manual Export (if needed): Before the audit, export from Vanta:

Policies:

  • All current policies (markdown or PDF)
  • Version history
  • Approval records
  • Review dates

Controls:

  • Control implementation status
  • Control owners
  • Test results
  • Evidence uploads

Risks:

  • Risk register export
  • Risk assessments
  • Treatment plans
  • Risk owners

Tasks:

  • Completed and pending tasks
  • Task assignments
  • Completion dates
  • Evidence attached to tasks

Tests:

  • Automated test results
  • Manual test records
  • Test frequencies
  • Pass/fail status

Vendors:

  • Vendor inventory
  • Security assessments
  • Questionnaire responses
  • Vendor risk ratings

Analyzing Vanta Evidence

Policy Review:

  • ✓ Check: All required policies exist (see Annex A.5.1)
  • ✓ Check: Policies approved by management
  • ✓ Check: Policies reviewed within 12 months
  • ✓ Check: Policies communicated to personnel
  • ✓ Check: Version control maintained
  • ✗ Common Gap: Policies not formally approved
  • ✗ Common Gap: Review dates overdue

Control Implementation:

  • ✓ Check: All applicable controls from SoA implemented
  • ✓ Check: Control owners assigned
  • ✓ Check: Testing completed per schedule
  • ✓ Check: Evidence uploaded and adequate
  • ✗ Common Gap: Controls marked "implemented" but no evidence
  • ✗ Common Gap: Test frequency not followed

Risk Assessment:

  • ✓ Check: Risk assessment methodology documented
  • ✓ Check: All assets have risks identified
  • ✓ Check: Likelihood and impact assessed
  • ✓ Check: Treatment plans for unacceptable risks
  • ✓ Check: Risk owners assigned
  • ✗ Common Gap: Risk assessment not updated in 12 months
  • ✗ Common Gap: Treatment plans incomplete

Use: references/vanta_audit_workflow.md for systematic Vanta evidence review

Vanta Evidence Reference Format

When documenting findings, reference Vanta evidence clearly:

Good Example: > "Evidence: Vanta Policy 'Access Control Policy v2.1' shows last review date of 2023-01-15, exceeding the 12-month review requirement (ISO 27001:2022 Clause A.5.1). Current date: 2024-11-04 (22 months since review)."

Good Example: > "Evidence: Vanta Control 'A.8.15 - Logging' status shows 'Implemented' but no test results uploaded. Control owner: IT Manager. Last test date field: empty."

Finding Classification

Nonconformity (NC)

Definition: A requirement is not met

When to Raise NC:

  • ISO 27001:2022 requirement violated
  • Company's own policy/procedure not followed
  • Legal/regulatory requirement not met
  • Contractual requirement (SLA, customer) not met

NC Must Have:

  1. Clear evidence of the gap
  2. Specific requirement violated
  3. Impact on ISMS effectiveness

Major NC:

  • Complete absence of required element (e.g., no management review performed)
  • Systematic failure (e.g., backup performed randomly, not daily as required)
  • Multiple minor NCs in same area (indicates systemic problem)
  • Previous NC not resolved by deadline

Minor NC:

  • Isolated incident (e.g., backup missed one day)
  • Documentation gap (e.g., one training record missing)
  • Requirement partially met

Examples:

Major NC Example: > Reference: ISO 27001:2022 Clause 9.3 (Management Review) > > Requirement: Management review must be conducted at planned intervals > > Finding: No management review was conducted in 2024. The ISMS procedure requires annual management review by Q1 each year. > > Evidence: Management review procedure v1.2 states "annual review by March 31." No meeting minutes, agenda, or attendance records found for 2024. Interview with CISO (2024-11-01) confirmed no review conducted. Vanta tasks for management review show status "Not Started."

Minor NC Example: > Reference: ISO 27001:2022 Clause A.7.2 (Competence) > > Requirement: Training records must be maintained for all personnel > > Finding: Training record for security awareness training is missing for one new employee hired in October 2024. > > Evidence: Vanta training tracker shows 47/48 employees completed security awareness training. Employee "J. Smith" (hired 2024-10-15) shows no training completion. HR Manager confirmed employee not yet trained due to onboarding delay.

Observation

Definition: Potential issue that could become a nonconformity

When to Raise Observation:

  • Isolated deviation that doesn't impact ISMS effectiveness
  • Process that could be improved but meets minimum requirements
  • Best practice not followed (but not required)
  • Early warning of potential future NC

Example: > Observation: The Incident Response Procedure was last reviewed 11 months ago, approaching the 12-month review requirement. While currently compliant, establish a reminder process to ensure timely reviews.

Recommendation

Definition: Improvement opportunity beyond compliance

When to Raise Recommendation:

  • Efficiency improvements possible
  • Industry best practices not adopted
  • Additional security measures would be beneficial
  • Process optimization opportunities

Example: > Recommendation: Consider implementing automated policy review reminders in Vanta. While manual tracking is compliant, automation would reduce administrative burden and ensure no policies exceed review dates.

ISO 27001:2022 Audit Scope

Clauses 4-10 (ISMS Requirements)

Clause 4 - Context of the Organization:

  • 4.1: Understanding organization and context
  • 4.2: Understanding needs of interested parties
  • 4.3: Determining scope of ISMS
  • 4.4: Information security management system

Clause 5 - Leadership:

  • 5.1: Leadership and commitment
  • 5.2: Policy
  • 5.3: Organizational roles, responsibilities, authorities

Clause 6 - Planning:

  • 6.1: Actions to address risks and opportunities
  • 6.1.1: General
  • 6.1.2: Information security risk assessment
  • 6.1.3: Information security risk treatment
  • 6.2: Information security objectives and planning
  • 6.3: Planning of changes

Clause 7 - Support:

  • 7.1: Resources
  • 7.2: Competence
  • 7.3: Awareness
  • 7.4: Communication
  • 7.5: Documented information

Clause 8 - Operation:

  • 8.1: Operational planning and control
  • 8.2: Information security risk assessment
  • 8.3: Information security risk treatment

Clause 9 - Performance Evaluation:

  • 9.1: Monitoring, measurement, analysis and evaluation
  • 9.2: Internal audit
  • 9.3: Management review

Clause 10 - Improvement:

  • 10.1: Nonconformity and corrective action
  • 10.2: Continual improvement

For detailed audit questions per clause, see: references/audit_checklist_complete.md

Annex A Controls (93 Controls in ISO 27001:2022)

Organizational Controls (A.5.1 - A.5.37): 37 controls People Controls (A.6.1 - A.6.8): 8 controls Physical Controls (A.7.1 - A.7.14): 14 controls Technological Controls (A.8.1 - A.8.34): 34 controls

Total: 93 controls

Complete checklist: references/audit_checklist_complete.md

SaaS-Specific Audit Considerations

Cloud Infrastructure Controls

Key Annex A Controls for SaaS:

  • A.5.23: Information security for cloud services
  • A.8.9: Configuration management
  • A.8.14: Redundancy of information processing facilities
  • A.8.20: Networks secu

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.