Compliance Framework Alignment
ISO/IEC 27001:2022 — Clause 9.2.1 (Internal audit — general) ISO/IEC 27001:2022 — Clause 9.2.2 (Internal audit programme) ISO/IEC 27001:2022 — Clause 10.2 (Nonconformity and corrective action) ISO/IEC 19011:2018 (Guidelines for auditing management systems) This report is the documented output of a Clause 9.2 internal audit of the ISMS. It records the audit programme, scope, criteria, methodology, evidence and classified findings, and feeds the corrective-action process under Clause 10.2.
ACME TECHNOLOGIES PVT LTD ISMS INTERNAL AUDIT REPORT
Report Reference IA-2026-01
Report Date [Report Date]
Audit Period Covered [start] to [end]
Fieldwork Dates 12–16 May 2026
Locations / Sites Bengaluru HQ; AWS ap-south-1 (remote)
Audit Criteria ISO/IEC 27001:2022 and the organisation's ISMS documentation
Lead Auditor Priya Nair — ISO 27001 Lead Auditor (IRCA A17024) 1. Audit Scope, Objectives and Criteria
This is a full internal audit covering all ISMS clauses and applicable Annex A controls, conducted under Clause 9.2 of ISO/IEC 27001:2022. The audit objectives were to determine whether the ISMS of Acme Technologies Pvt Ltd (a) conforms to the organisation's own requirements for its ISMS and to the requirements of ISO/IEC 27001:2022, and (b) is effectively implemented and maintained (Clause 9.2.1). The ISMS scope audited was: The provision of the Acme SaaS platform and supporting corporate IT, per the Statement of Applicability v3.1. The audit criteria comprised ISO/IEC 27001:2022 (Clauses 4–10 and applicable Annex A controls), the current Statement of Applicability, and the organisation's ISMS policies, procedures and legal, regulatory and contractual obligations. Boundaries, extent and locations are as recorded above.
2. Audit Programme and Frequency
This audit forms part of the ISMS audit programme established, implemented and maintained under Clause 9.2.2 a). The programme is risk-based: it defines the frequency, methods, responsibilities, planning requirements and reporting for audits, taking into account the importance of the processes concerned and the results of previous audits. Internal audits are conducted at planned intervals such that the entire ISMS (all clauses and applicable Annex A controls) is audited at least once within each 12-month certification cycle, whether in a single full audit or as a series of partial audits. Areas of higher risk, and areas with open findings from prior cycles, are audited more frequently.
3. Auditor Selection and Independence
Each auditor was independent of, and held no operational responsibility for, the areas they examined, so that objectivity and impartiality of the audit process were preserved (Clause 9.2.2 c)). Auditors were selected for competence against ISO/IEC 19011:2018, holding recognised auditor qualification (lead auditor: ISO 27001 Lead Auditor (IRCA A17024) ) and appropriate technical knowledge of information security. This selection and the independence basis satisfy Clause 9.2.2 c), which requires the organisation to select auditors and conduct audits that ensure objectivity and the impartiality of the audit process.
4. Audit Methodology
The audit was planned and performed in accordance with ISO/IEC 19011:2018. A risk-based approach was applied throughout planning, conduct, reporting and follow-up. Methods used were: (a) review of documented information (policies, procedures, the Statement of Applicability, risk assessment and risk treatment plan, records and prior audit and management-review outputs); (b) structured interviews with control and process owners; (c) direct observation of activities and physical controls; and (d) technical sampling and inspection of system configurations, logs and tickets. Sampling was judgemental and risk-weighted; sample sizes and populations are recorded in the auditor working papers. An opening meeting communicated scope, criteria and plan; a closing meeting presented preliminary findings and agreed timelines.
5. Classification of Audit Findings
Findings were determined by evaluating audit evidence against the audit criteria (ISO/IEC 19011:2018, 3.10) and classified as follows. CONFORMITY — the requirement is met and effectively implemented. MINOR NONCONFORMITY — a single or isolated lapse, or a partial failure to meet a requirement, that does not represent a systemic breakdown or significantly impair ISMS effectiveness. MAJOR NONCONFORMITY — the total absence of, or a systemic breakdown in, a required process or control, or a number of related minor nonconformities indicating a systemic failure, such that there is significant doubt that effective control is in place. OPPORTUNITY FOR IMPROVEMENT (OFI) — a conforming area that could be strengthened; corrective action is recommended but not required. Every nonconformity references the specific clause or Annex A control breached and the objective evidence supporting it.
6. Audit Evidence and Records
Findings are supported by verifiable, objective audit evidence — records, factual statements, sampled configurations and observations — retained in the auditor working papers and cross-referenced by finding. Evidence was assessed for sufficiency and appropriateness before a finding was raised. Documented information retained as evidence of the audit programme and its results is kept for a minimum of three (3) years (or the full certification cycle where longer) as required by Clause 9.2.2 f), and is available to the certification body and, where applicable, to the SOC 2 service auditor.
7. Results — Management System Clauses (4–10)
Each management-system requirement was tested and its result recorded in the Findings Register (Annex 1 to this report). Clauses assessed: 4 Context of the organisation; 5 Leadership; 6 Planning (including risk assessment, risk treatment and the Statement of Applicability); 7 Support (resources, competence, awareness, communication, documented information); 8 Operation (operational planning and control, information security risk assessment and treatment); 9 Performance evaluation (monitoring, measurement, analysis and evaluation, internal audit, management review); and 10 Improvement (nonconformity and corrective action, continual improvement). The result (conformity / minor NC / major NC / OFI), the clause reference and the supporting evidence are stated per clause in the Register.
8. Results — Annex A Controls (Statement of Applicability)
Applicable Annex A controls were audited against the current Statement of Applicability. ISO/IEC 27001:2022 Annex A comprises 93 controls across four themes: A.5 Organizational (37 controls), A.6 People (8 controls), A.7 Physical (14 controls) and A.8 Technological (34 controls). For each applicable control the audit recorded whether it is implemented and operating effectively, and each excluded control was checked against a documented and justified exclusion in the Statement of Applicability. Per-control results (conformity / minor NC / major NC / OFI), the A.x control reference and supporting evidence are recorded in the Annex A results table within the Findings Register.
9. Summary of Findings Raised
This audit raised 0 major nonconformity(ies), 0 minor nonconformity(ies) and 0 opportunity(ies) for improvement. Each nonconformity is uniquely numbered in the Findings Register with its clause / control reference, evidence, classification and required response date. A finding raised as a major nonconformity where several related minor findings recur against the same requirement is treated as a single systemic issue.
10. Audit Conclusion
The ISMS conforms to the audit criteria and is effectively implemented and maintained. No nonconformities affecting overall effectiveness were identified. This conclusion reflects the audit evidence truthfully and accurately (ISO/IEC 19011:2018) and is limited to the scope, criteria and sample examined during the fieldwork period 12–16 May 2026 .
11. Link to Corrective Action (Clause 10.2)
Every nonconformity in this report is transferred to CAPA-Log-2026 (Clause 10.2) for action under Clause 10.2. For each nonconformity the responsible owner must: (a) react to it, taking action to control and correct it and to deal with its consequences; (b) evaluate the need to eliminate the cause so that it does not recur or occur elsewhere, by reviewing the nonconformity, determining its root cause and determining whether similar nonconformities exist or could occur; (c) implement the action needed; (d) review the effectiveness of the corrective action taken; and (e) make changes to the ISMS if necessary. Target dates: major nonconformities require a root-cause analysis and corrective-action plan within thirty (30) days and demonstrable closure within ninety (90) days; minor nonconformities require an agreed plan within thirty (30) days. OFIs are logged for consideration. Closure is verified by re-audit or documented evidence and recorded in the register.
12. Reporting, Communication and Retention
In accordance with Clause 9.2.2 e), the results of this audit are reported to relevant management and to top management, who are accountable for ensuring the necessary corrective actions are taken without undue delay. The audit outputs are an input to the next management review (Clause 9.3). This report and all supporting working papers are retained as documented information and made available to the certification body on request.
13. Limitations and Auditor's Statement
This audit was performed on a sampling basis; absence of a finding for an unsampled item is not assurance of conformity for that item. The conclusions rest on evidence available and representations made during the fieldwork period and do not constitute a guarantee against future nonconformity or security incident. Where independence was partial, the affected area is disclosed above. The lead auditor confirms that this report reflects the audit activities, findings and conclusions truthfully and accurately.
Lead Auditor
Priya Nair
______________________
Reviewed by (CISO / ISMS Manager)
A. Kumar, CISO
______________________
Received by (Top Management)
M. Rao, COO
______________________