Internal audit independence: the conflict that fails Stage 2
Internal audit independence: the conflict that fails Stage 2
By Kellwick Team · October 2, 2026 · 6 min read
Stage 2 certification audits for ISO 27001 surface one specific internal audit finding more consistently than almost any other. It is not a gap in your controls. It is not an incomplete risk register. It is a fundamental structural problem: the person who wrote the controls audited them.
This is not a technicality. ISO 27001 clause 9.2 requires that auditors are objective and impartial. The standard's intent is that internal audits function as genuine assurance - a real check on whether the ISMS is working, not a confirmation of the author's own work. When the same person writes the access control policy and then audits whether the access control policy is being followed, the audit provides no independent assurance at all. A certification auditor will note this as a nonconformity.
The difficulty for small SaaS teams is real. When you have five people in engineering and one person who owns security, genuine independence is structurally hard to achieve. This post explains what independence actually requires, why the common workarounds fail, and how to build something that holds up.
What impartiality means in practice
ISO 27001 does not require a dedicated internal audit function. It does not require an external auditor. It requires that the person conducting the internal audit is not auditing their own work.
The scope of "their own work" is broader than many teams assume. If the head of engineering designed your network segmentation controls, defined your patch management procedure, and decided how logging is implemented, that person cannot credibly audit network segmentation, patch management, or logging. Those are their controls. Even if they conduct the audit honestly and find real issues, a certification auditor will observe the structural conflict and require a finding.
The same applies to whoever wrote the ISMS documentation. The person who drafted your policies, your statement of applicability, your risk treatment plan - that person cannot audit against those documents. They are evaluating their own authorship.
The workarounds that do not work
Several common approaches to internal audit independence look plausible but fail on examination.
Self-review with a manager sign-off: The engineer audits their own controls, and a manager reviews and approves the audit report. The manager's review does not create independence. It creates a second layer of review on the same person's work. The conflict is in who conducted the audit, not who approved the report.
Rotating between team members within the same function: Two members of the engineering team audit each other's controls. This is closer, but a certification auditor will ask whether these individuals share design responsibility for the controls being audited. In small teams, they usually do. If both engineers jointly decided how authentication works, neither of them is independent on authentication.
Limiting audit scope to avoid the conflict: Some teams address independence by simply not auditing the controls where the conflict is most obvious. This replaces an independence finding with a coverage finding. The internal audit programme must cover the controls in scope for the ISMS. An audit that deliberately excludes major control domains is an incomplete audit.
What actually creates independence
Independence comes from a genuine structural separation between who designed and implemented a control and who is auditing it.
For a team of five to fifteen people, the realistic options are:
Cross-functional audit pairs: The operations lead audits engineering controls; the engineering lead audits operational controls. This works when these individuals genuinely did not co-design the controls in question. Document the basis for independence explicitly in your audit programme: state who is auditing what and why they are considered independent for that domain.
Using a department head to audit another department's controls: If your marketing or finance lead is willing to audit information security controls in their area - physical security, clear desk, access to shared systems - this creates genuine independence for those domains. It does not solve independence for technical controls, but it helps coverage.
A fractional or advisory external resource for the internal audit role: Engaging someone outside the organisation to conduct the internal audit satisfies independence requirements definitively. This does not need to be a full-time engagement. An independent ISO 27001 auditor conducting a structured internal audit programme on an annual or semi-annual basis is a common model for early-stage companies that do not have internal audit capacity.
Bringing in an independent advisor: An external party who played no role in designing your ISMS or implementing your controls can conduct a legitimate internal audit. This is not the same as hiring your certification body to do it - certification bodies are generally restricted from providing implementation or internal audit services to organisations they certify, to protect their own independence.
Documenting independence
Whatever approach you take, document the basis for your claim of independence in the internal audit programme. A certification auditor reviewing your internal audit records will look for this. They will ask who conducted each audit, what their role is in the organisation, and why they are considered independent for that scope.
A brief independence statement at the start of each audit report is enough: "This audit was conducted by [name], [role]. [Name] did not design or implement the controls audited in this report. The basis for independence is [brief explanation]."
If you used cross-functional pairing, explain which domains each auditor covered and what their connection to those domains is. If you used an external resource, state their independence from the ISMS design. If you rotated, explain why the rotation creates genuine independence rather than superficial separation.
Common Stage 2 findings on internal audit independence
Across the audit findings Kellwick has worked with companies to address, these are the most frequent independence-related issues:
The internal audit was conducted entirely by the CISO or security lead, who owns the ISMS. This is the most common. The same person who built the system is assessing whether the system they built is working.
The audit records exist, but there is no indication of who conducted each section or what their independence basis is. A certification auditor cannot verify independence if it is not documented.
The internal audit programme exists on paper, but only one cycle has been completed and it was conducted immediately before the Stage 2 audit, which raises questions about whether the programme is genuinely embedded.
The internal audit covered policy compliance but not control effectiveness. Independence on policy compliance is easier to achieve, but clause 9.2 requires auditing whether the ISMS conforms to the organisation's own requirements and to ISO 27001. That includes controls, not just documents.
Planning the audit programme, not just a single audit
ISO 27001 requires an internal audit programme - a planned series of audits across the ISMS scope, not a single event. The programme should define what will be audited, when, by whom, and on what basis that person is independent for each scope area.
For a small company, an annual programme that covers all ISMS scope areas in two or three audit sessions is realistic. Plan it at the start of the year. Execute on the plan. Record what you found. Record what you did with what you found.
A certification auditor at Stage 2 will review the programme, the individual audit reports, and the evidence that findings were addressed. A programme that was planned but never executed is as much a problem as no programme at all.
Where Kellwick fits: Kellwick provides independent internal audit services for SaaS companies whose teams do not have the structural separation to conduct genuinely independent audits themselves. Kellwick conducts the internal audit programme, produces conformant audit records, and surfaces findings before your certification body does. If your Stage 2 is approaching and internal audit independence is not resolved, see how Kellwick's ongoing support works.
Where this fits
ISO 27001
Pass the audit. We find what blocks Stage 1 before the certification body does.
Read the ISO 27001 hubNeed a second pair of eyes before the auditor does?
A readiness review shows exactly where your ISMS stands - and what to fix first - while there is still time to act on it.
Stay audit-ready
Occasional, practical notes on ISO 27001 readiness and ISMS maintenance. No noise.