ISO 27001 internal audit for SMEs with 10 to 100 employees

Your management system has to hold up long after the certification audit. An independent internal audit tells you whether it will, with evidence-based findings and recommendations you can act on. For organisations of 10 to 100 employees, where the system runs across several teams.

← Back to home

A management system that outlasts the certificate

A certificate shows that your management system worked on the day of the audit. It says nothing about whether it will still work next year. If the system only comes to life in the weeks before an audit, every cycle costs a week or two of all hands on deck: extra cost, and attention taken away from the work your organisation actually exists to do.

At this size, that is the first thing I look at: is the system built so your own people can run it as part of how they already work? If it is, the next certification audit becomes routine. If it is not there yet, the audit shows you where to start.

Findings are normal at this size

Even at twenty people, an internal audit turns up a fair number of findings. That is not a verdict on your organisation. Information security and certification are rarely anyone’s core business, and a system that has grown with the organisation will fit some parts better than others. Findings are where improvement starts, as long as they are reported in a way you can work with.

Recommendations you can act on, or set aside with good reason

Every finding in my report comes with the evidence behind it and, where useful, a recommendation. That gives you two sound options. You act on the recommendation, knowing why it matters. Or you weigh it and conclude, with your reasons on record, that it does not fit the way your organisation has set up its information security. Both are defensible. What matters is that the decision is yours and that it is well founded.

Four phases, agreed before anything starts

A larger system takes longer to observe as it is actually run, and it involves more people, with each team explaining how it works in its own interviews and discussions. That is why the audit follows four phases, agreed with you before anything starts.

  1. Plan and criteria We agree the audit programme: which parts of the management system this cycle covers, the criteria I audit against, how I sample, and who I need to speak to. Surprises belong in the findings, not in the logistics.
  2. The system as designed A review of the documented system: scope, risk assessment, Statement of Applicability, policies and procedures. This sets out what you have committed to, and that is the yardstick for everything that follows.
  3. The system as operated Interviews and discussions with the people who run the processes, team by team. This is where we see whether the system holds up in daily practice, and what helps it do so.
  4. Report and results meeting A report with evidence-based findings, what already works well, and recommendations, written for management to read. We then walk through the results with your team in a meeting, so the findings are understood and everyone knows what to do with them.

Independence is what you bring me in for

One rule I never bend: if I implemented your management system, I will not audit it. Auditing my own work would remove exactly the independence that makes the audit worth paying for.

The same applies to a firm. If a firm implemented your system, a colleague from that firm is not independent either, because they would be assessing a colleague’s work. The implementer and the internal auditor should work for different companies.

The rule still applies after the audit. I report what I find and suggest where you could improve, but I do not decide what you change and I do not implement it. That keeps me independent for your next internal audit too.

Questions I often get

How long does it take?

That depends on your scope, the number of sites and how many teams run part of the system. After a first conversation about your scope, I set out the effort in a proposal, before anything is planned. You get a figure based on your organisation, not on an assumption.

How many of our people are involved?

Everyone who runs part of the management system, team by team. At this size that is more people than in a small team, because each team explains in its own words how it works. An interview usually takes half an hour to an hour per person.

Do we have to follow every recommendation?

No. A nonconformity against the standard requires corrective action. A recommendation is a suggestion with its reasons. If you set one aside after weighing it, that is a sound decision.

We are already certified. Why an internal audit?

Because the standard requires one, and because it keeps the certificate meaningful between certification audits. The internal audit is when you see whether the system still runs on its own.

Can our own people do it?

Yes, provided they are competent and independent of the area they audit. In an organisation of this size, that second condition is usually where it falls down. The person who knows a process well enough to audit it is usually the person who runs it.

Can you also help us fix what you find?

No. Acting on the findings and suggestions is up to you. If I implemented them, I could no longer guarantee my independence as your internal auditor to your external auditor.

How does it feed into our management review?

The audit results are a required input to your management review. The report is written so that management can use it there directly.

Start with a focused conversation

Fifteen minutes is usually enough to work out whether this is the right engagement, what the scope should be, and what it would realistically take.

Request an intro call