Clause 9.2

Internal audits

Plan an internal audit, work a clause-by-clause checklist generated from the framework, record findings, and export an auditor-ready report, the ISO 27001 / 9001 Clause 9.2 requirement.

Start free See pricing
app.keelgrc.com/audits
Compliance
Internal audits
8
Planned
5
Completed
7
Findings open
1
Overdue
AuditScopeAuditorFindingsStatus
Access managementISMSJ. Okafor2 minorComplete
Change managementISMSExternal1 majorComplete
Supplier controlsQMSA. RiveraIn progressFieldwork
Physical securityISMSIT leadNot startedPlanned

Every ISO 27001 and ISO 9001 program has to audit itself before the certification body shows up. That’s Clause 9.2. Keel makes the internal audit a guided workflow instead of a spreadsheet: pick a framework, and Keel builds the checklist from that framework’s own clauses; work through them recording a result and a note for each; and turn any nonconformity into a tracked corrective action in a click. Then export the whole thing as an auditor-ready report.

The internal audit is a from-scratch project every time

Someone rebuilds a checklist in a spreadsheet, emails it around, and pastes findings into a doc that doesn’t connect to anything. When the external auditor asks to see your last internal audit, and its follow-up, you’re reassembling it from memory and inboxes.

What internal audits does

A checklist generated from the framework

Pick any framework you’ve enabled and Keel builds the audit checklist from that framework’s actual clauses and controls, grouped by section, so you’re auditing against the real requirements, not a hand-made list.

Record findings as you go

For each clause, capture a result (conforming, nonconformity, observation, or opportunity for improvement) with a note, in real time. A running tally shows how much you’ve reviewed and what you found.

Findings become corrective action

Promote any nonconformity finding straight into the CAPA register (pre-filled with the clause and note, and linked back to the audit), so a finding never dies in a report.

Plan and track the audit

Give the audit a scope, an auditor, and a planned date, and move it from planned → in progress → completed, so your audit programme is visible and on cadence.

Auditor-ready report

Export a branded internal audit report (PDF) with the scope, conclusion, and every finding grouped by section, the artifact your certification auditor asks to see.

Why it matters

  • Audit against the framework’s real clauses, not a hand-built checklist
  • Turn nonconformity findings into tracked corrective action in one click
  • Keep an internal audit programme on cadence with planned dates and status
  • Hand your external auditor a branded internal audit report on demand

Get audit-ready, and prove it

Internal audits is one module of a full GRC platform: controls crosswalked across every framework, so you collect evidence once and comply everywhere. Start free, no credit card, no sales call.

Start free

Frequently asked questions

What is an internal audit under Clause 9.2?

ISO 27001 and ISO 9001 require you to audit your own management system at planned intervals to check it conforms and is effectively implemented. Keel gives you the checklist, finding capture, and report to do exactly that.

Where does the checklist come from?

From the framework itself. Choose a framework you’ve enabled and Keel derives the checklist from its clauses and controls, grouped by section, so it stays accurate to the standard.

What happens to a nonconformity I find?

You can promote it into the CAPA (corrective action) register in one click. It’s created pre-filled from the finding and linked back to the audit, so the follow-up is tracked to closure with an effectiveness check.

Can I hand the result to my external auditor?

Yes. Export a branded internal audit report (PDF) with scope, conclusion, and all findings. It’s the record a certification auditor expects to see for Clause 9.2.