workflow
ISMS Internal Audit & Management Review
Runs one ISO 27001 clause 9.2 internal audit and clause 9.3 management review cycle — including clause 10.1 corrective actions — against the existing Audit item for this cycle (audit_type=internal), whose scope, lead_auditor, and period dates already carry the ISMS audit-programme entry: the workflow enriches that Audit item and its findings, never creates a duplicate audit. Upstream it consumes the Annex A control population (Control items, framework iso-27001) and the applicability decisions in the Statement of Applicability, the risk register (Risk items) and treatment plan, the prior-cycle Audit and open Issue records, and the org's ISMS policies and procedures (Policy items) as audit criteria. Named deliverables: the internal audit findings report, the clause 10.1 corrective-action records (recorded on the finding Issue items), the management review pack, and the approved clause 9.3 minutes and action register. Out of scope: the certification-body external audit and day-to-day control operation. No upstream workflow feeds this cycle and no single downstream workflow consumes its output; at close the cycle is archived on the Audit item as retained ISMS documented information, and carry-forward items re-enter the audit programme (the next PLANNED Audit item), the risk register, or the next review's inputs.
Record JSON · Open in map · Data retrieval guide
Catalog revision: f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e. A connection does not establish full coverage.
Attributes
- domain
- controls
- department
- internal-audit
- lineOfDefense
- assure
Details
- teams
- internal-audit
- it
- executive
- domains
- controls
- standards
- iso-27001
- sourceTemplateId
- workflow-library:controls-isms-internal-audit-management-review
- releaseId
- sha256:58b6da1ad83d634bb57b1df5b9cdc890aaded75096ac52a7c7d541c7f7a600cf
- canonicalUrl
- https://assureswarm.com/workflows/all/?w=controls-isms-internal-audit-management-review
- capabilities
- mappingStatus
- mapped
- lineOfDefense
- assure
- controls
- UC-AUDIT-23
- UC-AUDIT-22
- UC-GOV-15
- UC-AUDIT-17
- roleIntegrity
- activityCount
- 0
- ermPhases
- lineRoles
- serviceModes
- warnings
- code
- reliance-basis-incomplete
- title
- Reliance basis is incomplete
- message
- Template-design warning: material reliance is mapped without a tagged step covering the full provider-reliance basis.
- missing
- independence
- competence
- evidence
- recency
- reliance rationale
- nodeIds
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:58b6da1ad83d634bb57b1df5b9cdc890aaded75096ac52a7c7d541c7f7a600cf
Connections
- ISMS Internal Audit & Management Review operates UC-AUDIT-23 — Coordinate independent assurance reviews across providers
- ISMS Internal Audit & Management Review operates UC-AUDIT-17 — Follow up on findings and escalate risk acceptance
- ISMS Internal Audit & Management Review tests UC-GOV-15 — Operate a management-approved information security program
- ISMS Internal Audit & Management Review operates UC-AUDIT-22 — Review risk strategy and performance with leadership