The internal audit that never finds anything
ISO 19011 changed edition in May 2026. The failure mode it exists to prevent did not: the internal audit that has, by drift, stopped disagreeing with management.

The scene repeats across certified organizations with small variations. The internal audit is held in the spring. The auditor, who in many small ISMSs is also the person who wrote the policies, works through a checklist derived from those same policies. The report records no nonconformities. Management review logs "no major findings", and the year proceeds. When a streak of these accumulates, it gets read as maturity: the ISMS works, the audits are quiet, the certificate stays in force through another surveillance.
On 2026-05-27, ISO published ISO 19011:2026, the fourth edition of the guidelines for auditing management systems, and withdrew the 2018 edition it replaces (published 2018-07-03, withdrawn the same day the new edition landed). For a year or two, many audit programmes will still point at 2018, and nothing in a certificate depends on that, because the certifiable text of ISO/IEC 27001:2022 requires an audit programme, not a particular edition of audit guidance. The edition change is simply a convenient moment to ask the question the guidance has always been built around, and one a zero-finding streak rarely asks: was that an audit, or a review of your own homework?
Our position is a stake, not a truism: when an internal audit programme has returned no findings for two or three cycles in a row, the most reasonable first hypothesis is not that the ISMS is excellent. It is that the programme has drifted toward agreement with the organization it audits. The opposite view, that clean audits are simply what a mature ISMS produces, is respectable and sometimes true, so we will give you the discriminator between the two rather than ask you to take our word for it.
What clause 9.2 actually asks for
ISO/IEC 27001:2022 (third edition, published 2022-10-25; the climate-action amendment Amd 1:2024, published 2024-02-23, leaves clause 9.2 untouched) requires the organization to conduct internal audits "at planned intervals" to provide information on whether the ISMS conforms to the organization's own requirements for it and to the standard's requirements, and whether it "is effectively implemented and maintained" (9.2.1). Clause 9.2.2 then requires an audit programme that is planned, established, implemented and maintained, covering frequency, methods, responsibilities, planning requirements and reporting; audit criteria and scope defined for each audit; auditors selected and audits conducted so that the audit process is objective and impartial; results reported to relevant management; and documented information kept as evidence of the programme and its results. One requirement in 9.2.2 does most of the quiet work: the programme is required to take into consideration the importance of the processes concerned and the results of previous audits.
Notice what the clause does not require: any particular number of findings. A clean report is not prohibited; the audit is asked to provide information, and no findings is one possible answer. What a clean report cannot do, on its own, is establish that the audit process itself did its job. And the clause loads the audit with two things a comfortable programme tends to shed: independence, in the form of objectivity and impartiality, and effectiveness, in the sense that the audit exists to produce information about whether the system works, not merely whether documents exist.
The programme is an instrument, and instruments drift
The contribution of ISO 19011, in both editions, is to treat the audit programme as its own managed system: objectives, scope, methods and frequency chosen deliberately, results fed back, the programme itself monitored and improved. ISO's own description of the standard calls it guidance for auditing management systems, covering the principles of auditing, managing audit programmes and conducting management system audits, and notes that it is guidance that does not itself lead to certification. The principles of auditing have long included independence: auditors are to be independent of the activity being audited where practicable, and where that is not achievable, every effort should go into removing bias and encouraging objectivity. Impartiality is where audit conclusions come from. That discipline exists for the same reason instrument calibration exists: an audit programme is a measurement device, and a measurement device that returns the same reading regardless of input has stopped measuring.
In our experience the drift toward the agreeable audit takes four recognizable forms. Two of them defeat explicit requirements in 9.2, one defeats the audit's required object, and one exploits a gap the text leaves open:
The auditor audits their own work. In small ISMSs the person who wrote the policies, implemented the controls and runs the checklist is often the same person, because the overlap of "understands the controls" and "has time" is nearly total. Clause 9.2.2 requires objectivity and impartiality of the audit process, and ISO 19011's independence principle is written for exactly this arrangement: be independent of the activity you audit where practicable, and where you cannot be, treat the bias as a risk to be removed rather than ignored. Grading your own work does not make an audit impossible; skipping the mitigation does. In our experience this is the drift that starts earliest, precisely because no single artifact proves it happened.
The criteria are the ISMS's own documents. An organization's policies are legitimate audit criteria, and testing operational evidence against them is exactly what an audit should do. The failure starts when the policies are the whole of the criteria. Then the audit asks one question, does practice match the policy, and never asks whether the policy itself meets the standard's requirements or whether the system is effective. That audit can run for years without a finding while the ISMS is nonconforming to the standard and ineffective in practice, because the only defendant was the document, and the document was also the judge. Clause 9.2.1 asks for information on conformity to the organization's own requirements and to the standard's, plus effectiveness. Auditing against the ISMS's own artifacts alone is how an audit comes back clean while shedding two of the three.
The scope froze in year one. The programme visits the same domains, at the same depth, with the same checklist, every cycle. A scope that never moves is not automatically nonconforming: what 9.2.2 requires is that the programme take the importance of the processes concerned and the results of previous audits into consideration, and consideration can legitimately return the same answer year after year. Our quarrel is with the programme carried forward without that reconsideration, while the organization changed underneath it: new products, a new region, an incident, suppliers turned over. A clean streak produced by an unconsidered plan is a fact about the plan, not about the system.
Findings get negotiated down. Nonconformities become observations, observations become "opportunities for consideration", and the register stays green. The standard leaves severity labels to the organization: nothing in the text prescribes how a finding is graded, and that discretion is the gap this failure lives in. The labels are free; the underlying result is not. Whatever the register calls it, the audit remains required to produce accurate information on conformity and report it to relevant management, and a green register that quietly holds a red problem defeats both. In our experience the negotiation rarely happens in a single meeting. It accretes, one "let's call it an observation" at a time.
The honest counter-position, and the test we would propose
The concession first: a good ISMS can genuinely produce few findings. Teams that implemented deliberately, verified their controls and fixed what they found during implementation can run audits that are quiet because the system is quiet. Zero findings is not proof of a broken programme, and treating every clean report as a red flag would be its own kind of noise.
Nothing in the standard settles the dispute for you, so here is the test we would propose, and it is ours, not the text's. A clean audit is evidence when it sits inside a programme that can show its work when asked: the audit plan responds to previous results, incidents and changes in the organization (9.2.2's consideration requirement covers process importance and previous audit results; incidents and organizational change are inputs a thinking programme weighs in deciding what matters); auditor assignments are traceable, so the organization can actually demonstrate objectivity and impartiality rather than assert them; and the results reach management review, which lists audit results among its inputs (9.3.2), in a form that lets the review reason about them. The programme need not change course every cycle, and it need not produce a finding: a review can legitimately conclude that no change is needed. Objectivity and impartiality, by contrast, are not optional in any cycle. The point is that the programme can produce its reasoning, not that it must produce a problem.
A clean audit that sits inside a programme with none of that is not evidence. It is a warning light with the bulb removed: the silence is real, but it does not carry the information it appears to carry.
Why this is the expensive audit to fake
Compare the other audits in the cycle. The certification body's audit is bounded: the required audit effort under ISO/IEC 27006-1:2024 (published 2024-03-01, Annex C) starts from the number of persons doing work under the organization's control within the scope and adjusts for complexity factors, and the CB normally relies on sampling, because a bounded visit cannot test everything; its independence is governed, and its accreditation depends on it. The internal audit has the opposite profile: no externally prescribed duration formula and no accreditation body watching it, though it still runs to a planned schedule. It is the one audit in the cycle where the audited organization chooses the auditor, sets the criteria, defines the scope and controls the evidence, which is exactly why clause 9.2 puts its objectivity and impartiality requirements there.
That is also why a hollow internal audit is the expensive one. The CB audit is a periodic, bounded inspection from outside, and monitoring, incident management and risk review watch continuously. The internal audit is the mechanism whose entire job is to go looking for your problems against defined requirements, on purpose. An internal audit that never disagrees with management has been repurposed into a ceremony that certifies the absence of news.
The 2026 edition of ISO 19011 will arrive in audit programmes over the next year or two, and updating the edition number on the programme's reference line is the cheapest part of the exercise. If that is the whole of the update, the organization has performed the drift this post describes, on schedule. If your zero-finding streak sits inside a programme that reconsiders its aim, manages the bias risk when auditors sit close to their own work, and audits against the standard rather than against itself, keep the streak. In our experience, streaks that can show that much are the exception, which is exactly why the exception is worth keeping.
Related Posts

Under NIS2, "important" is not a lighter security tier
Teams read the important label as NIS2-lite and scope their controls down. The security measures in Article 21 are the same either way; the tier changes supervision, some enforcement tools, and the floor on the national fine maximum.

Your ISO 27001 certificate does not start DORA's clocks
Financial entities keep mapping ISO 27001 controls onto DORA articles and calling the residue paperwork. DORA's real additions are duties that must be performed, to a specification and on a clock, that a certificate was never designed to test.

The scope statement is the certificate
"ISO 27001 certified" is not a yes-or-no fact about a company. The real claim is the scope statement on the certificate, and it is checkable.
