Install
$ agentstack add skill-riskresponse-claude-grc-skills-iso27001-internal-auditor ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
ISO 27001:2022 Internal Auditor
Overview
This skill provides comprehensive guidance for conducting ISO 27001:2022 internal audits of Information Security Management Systems (ISMS), with specific focus on:
- 7-step audit methodology from planning to corrective action follow-up
- Vanta platform integration for evidence review and audit management
- All ISO 27001:2022 requirements (Clauses 4-10 + 93 Annex A controls)
- Finding classification (nonconformities, observations, recommendations)
- SaaS company considerations (cloud controls, multi-tenancy, DevSecOps)
Designed for experienced compliance teams performing annual internal audits.
Keywords: ISO 27001, internal audit, ISMS, Vanta, nonconformity, audit findings, Annex A controls, information security, audit report
When to Use This Skill
Use this skill when you need to:
- Conduct annual ISO 27001 internal audit
- Review and analyze evidence exported from Vanta
- Create audit checklists for ISO 27001:2022
- Identify nonconformities, observations, and recommendations
- Write professional internal audit reports
- Document corrective action requests
- Perform corrective action follow-up
- Ensure complete coverage of all ISO 27001 requirements
The 7-Step Internal Audit Process
ISO 27001 internal audits follow a structured 7-step methodology:
Step 1: Document Review
Purpose: Review ISMS documentation for compliance and prepare for main audit
Activities:
- Review Information Security Policy
- Review all applicable procedures and documented information
- Review Statement of Applicability (SoA)
- Review Risk Assessment and Risk Treatment Plan
- Review records (management review, incidents, corrective actions)
- Check documentation against ISO 27001:2022 requirements
- Identify areas to investigate during main audit
In Vanta:
- Export and review all policies
- Review control implementation status
- Examine risk register and treatment plans
- Review completed tasks and tests
- Check document versioning and approval status
Output: Notes on potential nonconformities, areas requiring investigation
Template: Use the Vanta audit workflow guide from references/vanta_audit_workflow.md
Step 2: Create Internal Audit Checklist
Purpose: Prepare structured notes to guide the main audit
Activities:
- List all requirements to be audited (clauses + Annex A controls)
- Note what evidence to look for
- Identify who to interview
- Plan which records to sample
- Prepare questions based on document review findings
Four-Column Format:
- Reference - Clause or control number
- What to look for - Requirements, questions, evidence to examine
- Compliance - Y/N/Partial/N/A (fill during audit)
- Findings - Evidence found (fill during audit)
Template: references/audit_checklist_complete.md (93 Annex A controls + clauses 4-10, plus ISO 22301)
Step 3: Write Audit Plan
Purpose: Define detailed logistics for the audit
Activities:
- Set audit dates and times
- Identify departments/processes to audit
- List contact persons for each area
- Define audit team roles (if multiple auditors)
- Communicate plan to auditees
- Schedule opening meeting (if applicable)
Guidance: See references/iso_internal_audit_guide_full.md Section 3.5 for audit plan structure
Step 4: Conduct Main Audit
Purpose: Gather evidence through on-site examination
Three Evidence Collection Techniques:
- Reviewing Documents and Records:
- Most reliable evidence
- Examine policies, procedures, records
- Check Vanta evidence uploads (screenshots, logs, reports)
- Verify document versions, approval dates, completeness
- Interviewing Employees:
- Speak to multiple people for same process to corroborate evidence
- Use open-ended questions: "Please describe how you control access to the IT system" — lets the auditee reveal how things actually work
- Avoid closed-end questions ("Is this your backup server?") — only use these to confirm specific evidence
- Use the "Five Whys" technique to find root causes: keep asking "Why?" until you reach the underlying problem (often takes ~5 iterations)
- Verify understanding of procedures and awareness of responsibilities
- Record exact quotes as evidence
- Observing Activities and Facilities:
- Visit server rooms, secure areas
- Observe processes in action
- Check physical security controls
- Verify configurations match documentation
Opening Meeting (optional for internal audits): Brief management on audit objectives, scope, timing, and how findings will be reported. Useful for larger organizations or when auditees are unfamiliar with the process.
During Main Audit:
- Follow your checklist but remain flexible — don't miss leads not on your checklist
- Document all evidence immediately
- Record exact names, dates, versions
- Note direct quotes from interviews
- Take photos/screenshots if appropriate
- Don't make assumptions — verify everything (the biggest auditor mistake is assuming a requirement exists when it doesn't)
- You choose which records to sample, not the auditee
Closing Meeting (optional for internal audits): Present nonconformities and observations to management. Not mandatory for smaller companies but useful for formalizing communication of findings.
Recording Evidence:
- Fill columns 3 and 4 of your checklist
- Note specific evidence (document names, record IDs, person names)
- Reference Vanta evidence (task IDs, test results, policy versions)
- Document timestamps and locations
Step 5: Write Internal Audit Report
Purpose: Document all findings formally
Required Sections:
- General Information:
- Audit date, auditor name(s)
- Audit scope and criteria
- Audit objectives
- Auditees
- Audit Findings:
- Nonconformities (with full structure - see below)
- Observations (potential issues, best practices not followed)
- Recommendations (improvement opportunities)
- Audit Conclusions:
- Overall compliance assessment
- System effectiveness evaluation
- Readiness for certification audit
- Key themes or patterns
Nonconformity Structure (4 elements):
- Reference: Exact clause/control number (e.g., "ISO 27001:2022 Clause 6.1.2")
- Requirement: Brief description of requirement not met
- Finding: What was found (the gap)
- Evidence: Specific proof (document name, interview quote, observation details)
Template: templates/internal_audit_report.md
Step 6: Initiate Corrective Actions
Purpose: Formally request resolution of nonconformities
Activities:
- Create Corrective Action Request (CAR) for each nonconformity
- Assign responsible person
- Set deadline for resolution
- Define root cause analysis requirement
- Track in Vanta or corrective action system
Template: templates/nonconformity_report.md
In Vanta:
- Create tasks for each nonconformity
- Assign to control owners
- Set due dates
- Link to audit findings
- Track remediation progress
Step 7: Corrective Action Follow-Up
Purpose: Verify nonconformities are actually resolved
Activities:
- Review completed corrective actions
- Verify evidence of implementation
- Conduct mini-audit of corrected areas
- Confirm root cause addressed
- Close CARs or re-open if inadequate
- Update audit records
Timeline: Typically 30-90 days after audit depending on NC severity
In Vanta:
- Review corrective action task completion
- Verify new evidence uploaded
- Validate control status updated
- Close audit findings
Working with Vanta Platform
Three Methods for Evidence Retrieval
Method 1: Vanta API Scripts (Automated - Recommended)
- Use
scripts/vanta_api/retrieve_all.pyfor bulk export - Automated download of all policies and evidence
- Auto-generates audit notes with potential findings
- See:
references/vanta_api_integration.md
Method 2: Vanta MCP Server (Interactive)
- Real-time queries during audit conversations
- Natural language evidence retrieval
- Integrated with Claude Desktop
- See:
mcp/mcp_setup_guide.mdandmcp/mcp_audit_workflow.md
Method 3: Manual Export (Fallback)
- Traditional manual download from Vanta web interface
- Use when API/MCP not available
Vanta Exports for Audit
Using API Scripts (Recommended):
# Retrieve all policies and evidence automatically
cd scripts/vanta_api
python3 retrieve_all.py
# Creates organized exports in vanta_exports/
Using MCP Server (Interactive): In Claude Desktop with Vanta MCP configured: > "Using Vanta MCP Server, export all policies and check for overdue reviews"
Manual Export (if needed): Before the audit, export from Vanta:
Policies:
- All current policies (markdown or PDF)
- Version history
- Approval records
- Review dates
Controls:
- Control implementation status
- Control owners
- Test results
- Evidence uploads
Risks:
- Risk register export
- Risk assessments
- Treatment plans
- Risk owners
Tasks:
- Completed and pending tasks
- Task assignments
- Completion dates
- Evidence attached to tasks
Tests:
- Automated test results
- Manual test records
- Test frequencies
- Pass/fail status
Vendors:
- Vendor inventory
- Security assessments
- Questionnaire responses
- Vendor risk ratings
Analyzing Vanta Evidence
Policy Review:
- ✓ Check: All required policies exist (see Annex A.5.1)
- ✓ Check: Policies approved by management
- ✓ Check: Policies reviewed within 12 months
- ✓ Check: Policies communicated to personnel
- ✓ Check: Version control maintained
- ✗ Common Gap: Policies not formally approved
- ✗ Common Gap: Review dates overdue
Control Implementation:
- ✓ Check: All applicable controls from SoA implemented
- ✓ Check: Control owners assigned
- ✓ Check: Testing completed per schedule
- ✓ Check: Evidence uploaded and adequate
- ✗ Common Gap: Controls marked "implemented" but no evidence
- ✗ Common Gap: Test frequency not followed
Risk Assessment:
- ✓ Check: Risk assessment methodology documented
- ✓ Check: All assets have risks identified
- ✓ Check: Likelihood and impact assessed
- ✓ Check: Treatment plans for unacceptable risks
- ✓ Check: Risk owners assigned
- ✗ Common Gap: Risk assessment not updated in 12 months
- ✗ Common Gap: Treatment plans incomplete
Use: references/vanta_audit_workflow.md for systematic Vanta evidence review
Vanta Evidence Reference Format
When documenting findings, reference Vanta evidence clearly:
Good Example: > "Evidence: Vanta Policy 'Access Control Policy v2.1' shows last review date of 2023-01-15, exceeding the 12-month review requirement (ISO 27001:2022 Clause A.5.1). Current date: 2024-11-04 (22 months since review)."
Good Example: > "Evidence: Vanta Control 'A.8.15 - Logging' status shows 'Implemented' but no test results uploaded. Control owner: IT Manager. Last test date field: empty."
Finding Classification
Nonconformity (NC)
Definition: A requirement is not met
When to Raise NC:
- ISO 27001:2022 requirement violated
- Company's own policy/procedure not followed
- Legal/regulatory requirement not met
- Contractual requirement (SLA, customer) not met
NC Must Have:
- Clear evidence of the gap
- Specific requirement violated
- Impact on ISMS effectiveness
Major NC:
- Complete absence of required element (e.g., no management review performed)
- Systematic failure (e.g., backup performed randomly, not daily as required)
- Multiple minor NCs in same area (indicates systemic problem)
- Previous NC not resolved by deadline
Minor NC:
- Isolated incident (e.g., backup missed one day)
- Documentation gap (e.g., one training record missing)
- Requirement partially met
Examples:
Major NC Example: > Reference: ISO 27001:2022 Clause 9.3 (Management Review) > > Requirement: Management review must be conducted at planned intervals > > Finding: No management review was conducted in 2024. The ISMS procedure requires annual management review by Q1 each year. > > Evidence: Management review procedure v1.2 states "annual review by March 31." No meeting minutes, agenda, or attendance records found for 2024. Interview with CISO (2024-11-01) confirmed no review conducted. Vanta tasks for management review show status "Not Started."
Minor NC Example: > Reference: ISO 27001:2022 Clause A.7.2 (Competence) > > Requirement: Training records must be maintained for all personnel > > Finding: Training record for security awareness training is missing for one new employee hired in October 2024. > > Evidence: Vanta training tracker shows 47/48 employees completed security awareness training. Employee "J. Smith" (hired 2024-10-15) shows no training completion. HR Manager confirmed employee not yet trained due to onboarding delay.
Observation
Definition: Potential issue that could become a nonconformity
When to Raise Observation:
- Isolated deviation that doesn't impact ISMS effectiveness
- Process that could be improved but meets minimum requirements
- Best practice not followed (but not required)
- Early warning of potential future NC
Example: > Observation: The Incident Response Procedure was last reviewed 11 months ago, approaching the 12-month review requirement. While currently compliant, establish a reminder process to ensure timely reviews.
Recommendation
Definition: Improvement opportunity beyond compliance
When to Raise Recommendation:
- Efficiency improvements possible
- Industry best practices not adopted
- Additional security measures would be beneficial
- Process optimization opportunities
Example: > Recommendation: Consider implementing automated policy review reminders in Vanta. While manual tracking is compliant, automation would reduce administrative burden and ensure no policies exceed review dates.
ISO 27001:2022 Audit Scope
Clauses 4-10 (ISMS Requirements)
Clause 4 - Context of the Organization:
- 4.1: Understanding organization and context
- 4.2: Understanding needs of interested parties
- 4.3: Determining scope of ISMS
- 4.4: Information security management system
Clause 5 - Leadership:
- 5.1: Leadership and commitment
- 5.2: Policy
- 5.3: Organizational roles, responsibilities, authorities
Clause 6 - Planning:
- 6.1: Actions to address risks and opportunities
- 6.1.1: General
- 6.1.2: Information security risk assessment
- 6.1.3: Information security risk treatment
- 6.2: Information security objectives and planning
- 6.3: Planning of changes
Clause 7 - Support:
- 7.1: Resources
- 7.2: Competence
- 7.3: Awareness
- 7.4: Communication
- 7.5: Documented information
Clause 8 - Operation:
- 8.1: Operational planning and control
- 8.2: Information security risk assessment
- 8.3: Information security risk treatment
Clause 9 - Performance Evaluation:
- 9.1: Monitoring, measurement, analysis and evaluation
- 9.2: Internal audit
- 9.3: Management review
Clause 10 - Improvement:
- 10.1: Nonconformity and corrective action
- 10.2: Continual improvement
For detailed audit questions per clause, see: references/audit_checklist_complete.md
Annex A Controls (93 Controls in ISO 27001:2022)
Organizational Controls (A.5.1 - A.5.37): 37 controls People Controls (A.6.1 - A.6.8): 8 controls Physical Controls (A.7.1 - A.7.14): 14 controls Technological Controls (A.8.1 - A.8.34): 34 controls
Total: 93 controls
Complete checklist: references/audit_checklist_complete.md
SaaS-Specific Audit Considerations
Cloud Infrastructure Controls
Key Annex A Controls for SaaS:
- A.5.23: Information security for cloud services
- A.8.9: Configuration management
- A.8.14: Redundancy of information processing facilities
- A.8.20: Networks secu
…
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: RiskResponse
- Source: RiskResponse/claude-grc-skills
- License: Apache-2.0
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.