The important thing about a 27001 internal audit is that the purpose of the audit is to ensure that the management system is effective. It is not specifically about checking security. The management system is supposed to ensure that security is effective and thus so long as the management system is working then the organization should be appropriately secure. Its not that security is not looked at, after all the state of security was “caused” by the management system and thus it will reflect its health. But intensive security auditing, possibly appropriate for other reasons, is not the goal of ISO 27001.

