Internal Audits and Management Reviews: The Two Artefacts RFFR Never Asks For
Search the Department's RFFR pages for "internal audit". You won't find it. Search them for "management review". You won't find that either — not in the core expectations, not in the process for accreditation, not even in DEWR's own guidance on using ISO 27001 to meet your RFFR requirements.
Which is exactly why providers arrive at Milestone 3 without them.
Because here is the thing the Department doesn't need to spell out: RFFR requires your ISMS to conform with ISO/IEC 27001. Internal audit and management review are conformance requirements of that standard. They are not optional extras for mature organisations. They are part of what the word "conforms" means — and conformance is not something you can do partially.
This guide covers what each one actually has to achieve, the confusion that costs providers most, and how to run both when you don't have an audit department.
Why they're missing from the Department's list — and still mandatory
DEWR's published expectations describe outcomes: understand your risks, control them, protect information and assets, respond to a breach. They describe the personnel, physical and cyber security baselines. They do not walk you through the management-system clauses of ISO 27001, because they don't have to — they simply require the standard.
At Milestone 3, the Department's stated expectation is that a provider's ISMS conforms with ISO/IEC 27001 and that applicable controls are implemented. For Category 1 providers and TPES vendors, that conformance is tested by an independent assessor's Stage 2 report from a JAS-ANZ accredited body. For Category 2A and 2B providers, it's self-assessed and attested — but the expectation of conformance doesn't soften.
So the obligation arrives sideways. Nobody sends you a template for it. And an ISMS with no internal audit and no management review does not conform, no matter how good the controls are.
There's an uncomfortable corollary for self-assessing providers. If no certification body is coming to test your conformance, the internal audit is the only independent check that your ISMS actually works before you sign a Management Assertion Letter saying it does. The providers with the least external scrutiny need these two artefacts most, and are the most likely to skip them.
Your certification audit is not your internal audit
This is the single most common and most expensive confusion in the whole topic.
"We've had an audit" almost always means the certification body came and audited you — a Stage 1 or Stage 2 under the accreditation journey. That is their audit of you. It is not your internal audit.
Internal audit is your audit of yourself, run on your own programme, to your own schedule, for your own benefit. The certification body will then ask to see it — because it's a clause requirement, and because your internal audit programme tells them, faster than anything else, whether your ISMS is a living system or a folder of documents.
If you have never run one, the finding lands before the auditor even reaches your controls. You will have failed to demonstrate conformance with the management system itself, which is a far worse conversation than a gap in a control.
The two are not substitutes in either direction, and they answer different questions:
| Internal audit | Certification (Stage 1 / Stage 2) | |
|---|---|---|
| Whose | Yours | The certification body's |
| Purpose | Find your own problems | Test conformance for a certificate |
| Cadence | Your programme, ongoing | Milestone-driven, then surveillance |
| Findings are | Free information | On the record |
| Skipping it | A nonconformity in its own right | Not an option under Category 1 |
What an internal audit actually has to do
Strip away the mystique and an internal audit has three jobs: check that the ISMS meets the standard's requirements, check that it meets your own documented requirements, and check that it's actually being carried out — not merely written down.
That last clause is where the real value is. Your Statement of Applicability says a control is implemented. Your risk register says a treatment is in place. The internal audit is how you discover that the control quietly stopped operating in March, before an assessor discovers it for you.
Three things matter more than the paperwork:
It's a programme, not an event. You are not required to audit everything, every time. You are expected to plan coverage over a cycle — informed by the importance of the processes and by what previous audits found. A risk-based programme that covers the whole ISMS across a cycle is credible. One heroic all-in audit the month before Stage 2 is not, and reads exactly like what it is.
The auditor must be independent of the work. Not senior, not certified, not external — independent. You cannot audit your own work, because you cannot see your own blind spots. That's the entire mechanism.
The results have to go somewhere. Findings that don't reach management and don't turn into corrective actions with owners and dates are a filing exercise. The audit is the input; the fix is the point.
Independence when you're a small provider
This is where small organisations panic, and the panic is unwarranted. Independence does not mean an internal audit function, a qualified auditor, or an expensive consultant. It means the person auditing didn't do the thing being audited.
Realistic options, in rough order of cost:
- Cross the org chart. Someone from finance, operations or quality audits the IT controls. They don't need deep technical knowledge to ask "show me the evidence this happened" and notice that nobody can.
- Swap with a peer. Two providers of similar size audit each other. Free, and both sides learn more than either would alone. Mind your confidentiality obligations and scope the arrangement in writing.
- Buy a day. A contractor for one or two days a year is the cheapest external assurance you will ever buy, and dramatically cheaper than discovering the same gaps at Stage 2.
What isn't acceptable is the IT manager auditing the IT controls they built and run, and calling it independent. Auditors spot that immediately — the giveaway is an audit report with no findings.
Management review is a decision-making forum, not a status update
The second artefact is more often present in name than in substance. A meeting happened. Slides were shown. Everyone agreed security is important. That is not a management review.
A management review is where top management looks at whether the ISMS is still suitable, adequate and effective — and then decides things. It takes defined inputs: the status of actions from last time, changes in issues and risks, feedback on security performance including audit results and control effectiveness, the state of your risks and treatments, and opportunities to improve.
But the inputs are not the requirement people fail. The outputs are. A management review has to produce decisions — about improvements, about changes to the ISMS, about resources. If your minutes record information presented and nothing decided, you have held a briefing, and an assessor will read it as one.
This is also the forum that makes the rest of your programme real. A risk treatment plan with no funding is a wish. Management review is where it either gets resourced or gets consciously deferred with a reason. Both are legitimate answers. Silence is not.
The leadership commitment that RFFR expects is not demonstrated by a signed policy alone. It's demonstrated here, in a record of executives engaging with real information and making real calls.
Findings are the product, not the failure
The instinct is to want a clean internal audit. Resist it.
An internal audit that finds nothing is far more likely to be evidence that the audit was superficial than that the ISMS is flawless. Experienced assessors know this. A clean internal audit report in a first-year ISMS raises an eyebrow, not a smile — it invites them to look harder, because either the auditor wasn't independent, the scope was trivially narrow, or nobody wanted to write anything down.
Findings you generate yourself are the cheapest information in your entire programme. You choose the timing, you control the disclosure, and you fix them on your own schedule. The same finding discovered at Stage 2 costs you a nonconformity, a corrective action plan on someone else's clock, and a conversation with the Department about residual risk.
Your internal audit is the only audit where finding problems is a win. Treat it that way and the whole exercise stops feeling like an exam.
When these need to have happened
Timing is what catches people, because neither artefact can be retro-fitted. They must have occurred, with records that show when and what came out of them.
Work backwards from your Stage 2 assessment. By the time an assessor tests conformance, they expect to see an audit programme with real coverage, at least one completed internal audit with findings and their treatment, and at least one management review with decisions and resourcing attached. A few months of genuine operating history is worth more than a thick binder assembled in a fortnight — and it is visible which one you have.
The practical move, if you're approaching Milestone 3 and neither has happened: schedule both now, scope the audit narrowly enough to actually finish it, and let it find things. One honest, narrow audit with three real findings and a management review that funds two of them is stronger evidence than an ambitious programme that never ran.
After accreditation, both settle into the annual rhythm that runs off your anniversary date, alongside the SoA and ISM review cadence.
The bottom line
RFFR never asks for an internal audit or a management review by name, and that silence is exactly why they're the two things most often missing. They arrive through the requirement that your ISMS conforms with ISO 27001 — and conformance is not partial.
Run an audit someone independent can stand behind, however small your organisation. Hold a review where executives actually decide something and write down what they decided. Let both find problems, because problems found at home are free.
Do that and you're not preparing for an audit any more. You're running an ISMS — which is all the Department was asking for.
- DEWR — Process for accreditation
- DEWR — RFFR core expectations
- DEWR — Using ISO 27001 to meet your RFFR accreditation requirements
- ISO/IEC 27001 — Information security management
- JAS-ANZ Register — accredited bodies
External sources are provided for reference and are maintained by their respective bodies. Always confirm current requirements against the official source.
CHAIOS GRC Practitioner — Governance, risk & compliance
Written by a governance, risk and compliance practitioner on the CHAIOS team who has run RFFR and ISO 27001 programmes end to end — from risk registers and Statements of Applicability to DEWR accreditation. These guides come from hands-on experience, not theory.