workflow

ISMS Internal Audit & Management Review

Runs one ISO 27001 clause 9.2 internal audit and clause 9.3 management review cycle — including clause 10.1 corrective actions — against the existing Audit item for this cycle (audit_type=internal), whose scope, lead_auditor, and period dates already carry the ISMS audit-programme entry: the workflow enriches that Audit item and its findings, never creates a duplicate audit. Upstream it consumes the Annex A control population (Control items, framework iso-27001) and the applicability decisions in the Statement of Applicability, the risk register (Risk items) and treatment plan, the prior-cycle Audit and open Issue records, and the org's ISMS policies and procedures (Policy items) as audit criteria. Named deliverables: the internal audit findings report, the clause 10.1 corrective-action records (recorded on the finding Issue items), the management review pack, and the approved clause 9.3 minutes and action register. Out of scope: the certification-body external audit and day-to-day control operation. No upstream workflow feeds this cycle and no single downstream workflow consumes its output; at close the cycle is archived on the Audit item as retained ISMS documented information, and carry-forward items re-enter the audit programme (the next PLANNED Audit item), the risk register, or the next review's inputs.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
controls
department
internal-audit
lineOfDefense
assure

Details

teams
  • internal-audit
  • it
  • executive
domains
  • controls
standards
  • iso-27001
sourceTemplateId
workflow-library:controls-isms-internal-audit-management-review
releaseId
sha256:742d77471fcfb9e129cd8c2c7bf4a77d76efc0dc9e0982900aaa8c182a577076
canonicalUrl
https://workflow-library.com/all/?w=controls-isms-internal-audit-management-review
capabilities
    mappingStatus
    mapped
    lineOfDefense
    assure
    controls
    • UC-AUDIT-23
    • UC-AUDIT-22
    • UC-GOV-15
    • UC-AUDIT-17
    roleIntegrity
    activityCount
    0
    ermPhases
      lineRoles
        serviceModes
          warnings
          • code
            reliance-basis-incomplete
            title
            Reliance basis is incomplete
            message
            Template-design warning: material reliance is mapped without a tagged step covering the full provider-reliance basis.
            missing
            • independence
            • competence
            • evidence
            • recency
            • reliance rationale
            nodeIds

            Source

            No record-specific source URL is provided.

            Download workflow template · Release: sha256:742d77471fcfb9e129cd8c2c7bf4a77d76efc0dc9e0982900aaa8c182a577076

            Connections