# Iso27001 Internal Auditor

> Expert guidance for conducting ISO 27001:2022 internal audits using Vanta platform. Covers the complete 7-step audit process, evidence analysis, nonconformity identification, and audit reporting for SaaS companies. Use when performing annual ISMS internal audits, reviewing Vanta-exported evidence, or documenting audit findings.

- **Type:** Skill
- **Install:** `agentstack add skill-riskresponse-claude-grc-skills-iso27001-internal-auditor`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [RiskResponse](https://agentstack.voostack.com/s/riskresponse)
- **Installs:** 0
- **Category:** [Agent Skills](https://agentstack.voostack.com/c/agent-skills)
- **Latest version:** 0.1.0
- **License:** Apache-2.0
- **Upstream author:** [RiskResponse](https://github.com/RiskResponse)
- **Source:** https://github.com/RiskResponse/claude-grc-skills/tree/main/skills/iso27001-internal-auditor

## Install

```sh
agentstack add skill-riskresponse-claude-grc-skills-iso27001-internal-auditor
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# ISO 27001:2022 Internal Auditor

## Overview

This skill provides comprehensive guidance for conducting ISO 27001:2022 internal audits of Information Security Management Systems (ISMS), with specific focus on:

- **7-step audit methodology** from planning to corrective action follow-up
- **Vanta platform integration** for evidence review and audit management
- **All ISO 27001:2022 requirements** (Clauses 4-10 + 93 Annex A controls)
- **Finding classification** (nonconformities, observations, recommendations)
- **SaaS company considerations** (cloud controls, multi-tenancy, DevSecOps)

Designed for experienced compliance teams performing annual internal audits.

**Keywords**: ISO 27001, internal audit, ISMS, Vanta, nonconformity, audit findings, Annex A controls, information security, audit report

## When to Use This Skill

Use this skill when you need to:
- Conduct annual ISO 27001 internal audit
- Review and analyze evidence exported from Vanta
- Create audit checklists for ISO 27001:2022
- Identify nonconformities, observations, and recommendations
- Write professional internal audit reports
- Document corrective action requests
- Perform corrective action follow-up
- Ensure complete coverage of all ISO 27001 requirements

## The 7-Step Internal Audit Process

ISO 27001 internal audits follow a structured 7-step methodology:

### Step 1: Document Review

**Purpose**: Review ISMS documentation for compliance and prepare for main audit

**Activities**:
- Review Information Security Policy
- Review all applicable procedures and documented information
- Review Statement of Applicability (SoA)
- Review Risk Assessment and Risk Treatment Plan
- Review records (management review, incidents, corrective actions)
- Check documentation against ISO 27001:2022 requirements
- Identify areas to investigate during main audit

**In Vanta**:
- Export and review all policies
- Review control implementation status
- Examine risk register and treatment plans
- Review completed tasks and tests
- Check document versioning and approval status

**Output**: Notes on potential nonconformities, areas requiring investigation

**Template**: Use the Vanta audit workflow guide from `references/vanta_audit_workflow.md`

### Step 2: Create Internal Audit Checklist

**Purpose**: Prepare structured notes to guide the main audit

**Activities**:
- List all requirements to be audited (clauses + Annex A controls)
- Note what evidence to look for
- Identify who to interview
- Plan which records to sample
- Prepare questions based on document review findings

**Four-Column Format**:
1. **Reference** - Clause or control number
2. **What to look for** - Requirements, questions, evidence to examine
3. **Compliance** - Y/N/Partial/N/A (fill during audit)
4. **Findings** - Evidence found (fill during audit)

**Template**: `references/audit_checklist_complete.md` (93 Annex A controls + clauses 4-10, plus ISO 22301)

### Step 3: Write Audit Plan

**Purpose**: Define detailed logistics for the audit

**Activities**:
- Set audit dates and times
- Identify departments/processes to audit
- List contact persons for each area
- Define audit team roles (if multiple auditors)
- Communicate plan to auditees
- Schedule opening meeting (if applicable)

**Guidance**: See `references/iso_internal_audit_guide_full.md` Section 3.5 for audit plan structure

### Step 4: Conduct Main Audit

**Purpose**: Gather evidence through on-site examination

**Three Evidence Collection Techniques**:

1. **Reviewing Documents and Records**:
   - Most reliable evidence
   - Examine policies, procedures, records
   - Check Vanta evidence uploads (screenshots, logs, reports)
   - Verify document versions, approval dates, completeness

2. **Interviewing Employees**:
   - Speak to multiple people for same process to corroborate evidence
   - **Use open-ended questions**: "Please describe how you control access to the IT system" — lets the auditee reveal how things actually work
   - **Avoid closed-end questions** ("Is this your backup server?") — only use these to confirm specific evidence
   - **Use the "Five Whys" technique** to find root causes: keep asking "Why?" until you reach the underlying problem (often takes ~5 iterations)
   - Verify understanding of procedures and awareness of responsibilities
   - Record exact quotes as evidence

3. **Observing Activities and Facilities**:
   - Visit server rooms, secure areas
   - Observe processes in action
   - Check physical security controls
   - Verify configurations match documentation

**Opening Meeting** (optional for internal audits): Brief management on audit objectives, scope, timing, and how findings will be reported. Useful for larger organizations or when auditees are unfamiliar with the process.

**During Main Audit**:
- Follow your checklist but remain flexible — don't miss leads not on your checklist
- Document all evidence immediately
- Record exact names, dates, versions
- Note direct quotes from interviews
- Take photos/screenshots if appropriate
- Don't make assumptions — verify everything (the biggest auditor mistake is assuming a requirement exists when it doesn't)
- You choose which records to sample, not the auditee

**Closing Meeting** (optional for internal audits): Present nonconformities and observations to management. Not mandatory for smaller companies but useful for formalizing communication of findings.

**Recording Evidence**:
- Fill columns 3 and 4 of your checklist
- Note specific evidence (document names, record IDs, person names)
- Reference Vanta evidence (task IDs, test results, policy versions)
- Document timestamps and locations

### Step 5: Write Internal Audit Report

**Purpose**: Document all findings formally

**Required Sections**:
1. **General Information**:
   - Audit date, auditor name(s)
   - Audit scope and criteria
   - Audit objectives
   - Auditees

2. **Audit Findings**:
   - **Nonconformities** (with full structure - see below)
   - **Observations** (potential issues, best practices not followed)
   - **Recommendations** (improvement opportunities)

3. **Audit Conclusions**:
   - Overall compliance assessment
   - System effectiveness evaluation
   - Readiness for certification audit
   - Key themes or patterns

**Nonconformity Structure** (4 elements):
1. **Reference**: Exact clause/control number (e.g., "ISO 27001:2022 Clause 6.1.2")
2. **Requirement**: Brief description of requirement not met
3. **Finding**: What was found (the gap)
4. **Evidence**: Specific proof (document name, interview quote, observation details)

**Template**: `templates/internal_audit_report.md`

### Step 6: Initiate Corrective Actions

**Purpose**: Formally request resolution of nonconformities

**Activities**:
- Create Corrective Action Request (CAR) for each nonconformity
- Assign responsible person
- Set deadline for resolution
- Define root cause analysis requirement
- Track in Vanta or corrective action system

**Template**: `templates/nonconformity_report.md`

**In Vanta**:
- Create tasks for each nonconformity
- Assign to control owners
- Set due dates
- Link to audit findings
- Track remediation progress

### Step 7: Corrective Action Follow-Up

**Purpose**: Verify nonconformities are actually resolved

**Activities**:
- Review completed corrective actions
- Verify evidence of implementation
- Conduct mini-audit of corrected areas
- Confirm root cause addressed
- Close CARs or re-open if inadequate
- Update audit records

**Timeline**: Typically 30-90 days after audit depending on NC severity

**In Vanta**:
- Review corrective action task completion
- Verify new evidence uploaded
- Validate control status updated
- Close audit findings

## Working with Vanta Platform

### Three Methods for Evidence Retrieval

**Method 1: Vanta API Scripts (Automated - Recommended)**
- Use `scripts/vanta_api/retrieve_all.py` for bulk export
- Automated download of all policies and evidence
- Auto-generates audit notes with potential findings
- See: `references/vanta_api_integration.md`

**Method 2: Vanta MCP Server (Interactive)**
- Real-time queries during audit conversations
- Natural language evidence retrieval
- Integrated with Claude Desktop
- See: `mcp/mcp_setup_guide.md` and `mcp/mcp_audit_workflow.md`

**Method 3: Manual Export (Fallback)**
- Traditional manual download from Vanta web interface
- Use when API/MCP not available

### Vanta Exports for Audit

**Using API Scripts** (Recommended):
```bash
# Retrieve all policies and evidence automatically
cd scripts/vanta_api
python3 retrieve_all.py

# Creates organized exports in vanta_exports/
```

**Using MCP Server** (Interactive):
In Claude Desktop with Vanta MCP configured:
> "Using Vanta MCP Server, export all policies and check for overdue reviews"

**Manual Export** (if needed):
Before the audit, export from Vanta:

**Policies**:
- All current policies (markdown or PDF)
- Version history
- Approval records
- Review dates

**Controls**:
- Control implementation status
- Control owners
- Test results
- Evidence uploads

**Risks**:
- Risk register export
- Risk assessments
- Treatment plans
- Risk owners

**Tasks**:
- Completed and pending tasks
- Task assignments
- Completion dates
- Evidence attached to tasks

**Tests**:
- Automated test results
- Manual test records
- Test frequencies
- Pass/fail status

**Vendors**:
- Vendor inventory
- Security assessments
- Questionnaire responses
- Vendor risk ratings

### Analyzing Vanta Evidence

**Policy Review**:
- ✓ Check: All required policies exist (see Annex A.5.1)
- ✓ Check: Policies approved by management
- ✓ Check: Policies reviewed within 12 months
- ✓ Check: Policies communicated to personnel
- ✓ Check: Version control maintained
- ✗ Common Gap: Policies not formally approved
- ✗ Common Gap: Review dates overdue

**Control Implementation**:
- ✓ Check: All applicable controls from SoA implemented
- ✓ Check: Control owners assigned
- ✓ Check: Testing completed per schedule
- ✓ Check: Evidence uploaded and adequate
- ✗ Common Gap: Controls marked "implemented" but no evidence
- ✗ Common Gap: Test frequency not followed

**Risk Assessment**:
- ✓ Check: Risk assessment methodology documented
- ✓ Check: All assets have risks identified
- ✓ Check: Likelihood and impact assessed
- ✓ Check: Treatment plans for unacceptable risks
- ✓ Check: Risk owners assigned
- ✗ Common Gap: Risk assessment not updated in 12 months
- ✗ Common Gap: Treatment plans incomplete

**Use**: `references/vanta_audit_workflow.md` for systematic Vanta evidence review

### Vanta Evidence Reference Format

When documenting findings, reference Vanta evidence clearly:

**Good Example**:
> "Evidence: Vanta Policy 'Access Control Policy v2.1' shows last review date of 2023-01-15, exceeding the 12-month review requirement (ISO 27001:2022 Clause A.5.1). Current date: 2024-11-04 (22 months since review)."

**Good Example**:
> "Evidence: Vanta Control 'A.8.15 - Logging' status shows 'Implemented' but no test results uploaded. Control owner: IT Manager. Last test date field: empty."

## Finding Classification

### Nonconformity (NC)

**Definition**: A requirement is not met

**When to Raise NC**:
- ISO 27001:2022 requirement violated
- Company's own policy/procedure not followed
- Legal/regulatory requirement not met
- Contractual requirement (SLA, customer) not met

**NC Must Have**:
1. **Clear evidence** of the gap
2. **Specific requirement** violated
3. **Impact** on ISMS effectiveness

**Major NC**:
- Complete absence of required element (e.g., no management review performed)
- Systematic failure (e.g., backup performed randomly, not daily as required)
- Multiple minor NCs in same area (indicates systemic problem)
- Previous NC not resolved by deadline

**Minor NC**:
- Isolated incident (e.g., backup missed one day)
- Documentation gap (e.g., one training record missing)
- Requirement partially met

**Examples**:

**Major NC Example**:
> **Reference**: ISO 27001:2022 Clause 9.3 (Management Review)
>
> **Requirement**: Management review must be conducted at planned intervals
>
> **Finding**: No management review was conducted in 2024. The ISMS procedure requires annual management review by Q1 each year.
>
> **Evidence**: Management review procedure v1.2 states "annual review by March 31." No meeting minutes, agenda, or attendance records found for 2024. Interview with CISO (2024-11-01) confirmed no review conducted. Vanta tasks for management review show status "Not Started."

**Minor NC Example**:
> **Reference**: ISO 27001:2022 Clause A.7.2 (Competence)
>
> **Requirement**: Training records must be maintained for all personnel
>
> **Finding**: Training record for security awareness training is missing for one new employee hired in October 2024.
>
> **Evidence**: Vanta training tracker shows 47/48 employees completed security awareness training. Employee "J. Smith" (hired 2024-10-15) shows no training completion. HR Manager confirmed employee not yet trained due to onboarding delay.

### Observation

**Definition**: Potential issue that could become a nonconformity

**When to Raise Observation**:
- Isolated deviation that doesn't impact ISMS effectiveness
- Process that could be improved but meets minimum requirements
- Best practice not followed (but not required)
- Early warning of potential future NC

**Example**:
> **Observation**: The Incident Response Procedure was last reviewed 11 months ago, approaching the 12-month review requirement. While currently compliant, establish a reminder process to ensure timely reviews.

### Recommendation

**Definition**: Improvement opportunity beyond compliance

**When to Raise Recommendation**:
- Efficiency improvements possible
- Industry best practices not adopted
- Additional security measures would be beneficial
- Process optimization opportunities

**Example**:
> **Recommendation**: Consider implementing automated policy review reminders in Vanta. While manual tracking is compliant, automation would reduce administrative burden and ensure no policies exceed review dates.

## ISO 27001:2022 Audit Scope

### Clauses 4-10 (ISMS Requirements)

**Clause 4 - Context of the Organization**:
- 4.1: Understanding organization and context
- 4.2: Understanding needs of interested parties
- 4.3: Determining scope of ISMS
- 4.4: Information security management system

**Clause 5 - Leadership**:
- 5.1: Leadership and commitment
- 5.2: Policy
- 5.3: Organizational roles, responsibilities, authorities

**Clause 6 - Planning**:
- 6.1: Actions to address risks and opportunities
- 6.1.1: General
- 6.1.2: Information security risk assessment
- 6.1.3: Information security risk treatment
- 6.2: Information security objectives and planning
- 6.3: Planning of changes

**Clause 7 - Support**:
- 7.1: Resources
- 7.2: Competence
- 7.3: Awareness
- 7.4: Communication
- 7.5: Documented information

**Clause 8 - Operation**:
- 8.1: Operational planning and control
- 8.2: Information security risk assessment
- 8.3: Information security risk treatment

**Clause 9 - Performance Evaluation**:
- 9.1: Monitoring, measurement, analysis and evaluation
- 9.2: Internal audit
- 9.3: Management review

**Clause 10 - Improvement**:
- 10.1: Nonconformity and corrective action
- 10.2: Continual improvement

For detailed audit questions per clause, see: `references/audit_checklist_complete.md`

### Annex A Controls (93 Controls in ISO 27001:2022)

**Organizational Controls (A.5.1 - A.5.37)**: 37 controls
**People Controls (A.6.1 - A.6.8)**: 8 controls
**Physical Controls (A.7.1 - A.7.14)**: 14 controls
**Technological Controls (A.8.1 - A.8.34)**: 34 controls

**Total**: 93 controls

Complete checklist: `references/audit_checklist_complete.md`

## SaaS-Specific Audit Considerations

### Cloud Infrastructure Controls

**Key Annex A Controls for SaaS**:
- **A.5.23**: Information security for cloud services
- **A.8.9**: Configuration management
- **A.8.14**: Redundancy of information processing facilities
- **A.8.20**: Networks secu

…

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [RiskResponse](https://github.com/RiskResponse)
- **Source:** [RiskResponse/claude-grc-skills](https://github.com/RiskResponse/claude-grc-skills)
- **License:** Apache-2.0

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-riskresponse-claude-grc-skills-iso27001-internal-auditor
- Seller: https://agentstack.voostack.com/s/riskresponse
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
