ISO 27001 internal audit for startups and small organisations

Your certification audit is coming up, a customer has asked for ISO 27001, or nobody in-house is independent enough to audit the system you built. I carry out an independent internal audit, sized to your organisation. For a team of up to five, that usually means one day onsite.

← Back to home

On the day onsite, I check whether paper matches practice

A startup preparing its first certification, or answering a customer who asked for ISO 27001, rarely needs an auditor who stays for a week. It needs one who checks whether the team actually works the way the management system says on paper.

I study your documentation before I arrive, so the whole onsite day goes to the implementation. I already know what you have committed to, and I spend the day checking whether it happens in practice.

In a team that small, I usually speak to four or five people, often the whole team. That is where the value lies: everyone hears the same questions and the same answers, so by the end of the day the whole team is on board, not just the person who wrote the policies.

With a scope this small, there is room to go beyond “are you ready for the certification audit”. Alongside the nonconformities, the report names what already works well and lists opportunities for improvement, based on what I have seen elsewhere. Those are suggestions. Whether you take them up is your call, and we all learn something from the conversation.

In a small organisation, the internal auditor comes from outside

Most SMEs build their management system with outside specialists, because information security is not their core business and they do not need that expertise full-time. But some of their own people are always involved, because they are the ones who have to keep it running.

In that setting, an internal audit is not an exam. I sit down with the people who implemented the system, and together we check whether it does what it was built to do. Sometimes that is certification. Sometimes it is being able to answer a customer’s security questionnaire truthfully and consistently. Both are good reasons, and I set up the audit to match.

What a small organisation usually cannot do is audit itself. The person who knows the system well enough to audit it is generally the person who runs it. So independence almost automatically means bringing in someone from outside.

The size of the organisation determines the effort. For a team of up to five, one day onsite is normally enough. With around twenty people, expect several days, because there are more processes, more people to speak to and more evidence to sample.

What a micro-audit gives you

Independence is what you bring me in for

One rule I do not bend: if I implemented your management system, I will not audit it. Auditing my own work would remove the very independence that makes the audit worth paying for.

The same applies to firms. If a firm implemented your system, a colleague from that firm is not independent either, because they would be assessing a colleague’s work. The implementer and the internal auditor should work for different companies.

The rule still applies after the audit. I report what I find and suggest where you could improve, but I do not decide what you change and I do not implement it. That keeps me independent for your next internal audit as well.

Questions I get

We are a team of four. Is one day really enough?

For a first certification, usually yes. I study your documentation beforehand, so the day onsite goes entirely to interviews and evidence. If the scope turns out to be wider than expected, for example because there are several sites, I tell you before the audit starts, not after.

What do you need from us before the onsite day?

Your documentation: scope, risk assessment, Statement of Applicability, and the policies and procedures that go with them, plus an overview of who runs which part. I study it beforehand, so on the day we can go straight to how it works in practice.

Who needs to be there on the day?

Everyone who runs a part of the management system. In a small team, that is usually the whole team. That is deliberate: when everyone hears the same questions, everyone is on board afterwards.

A customer sent us a security questionnaire, not a certification requirement. Is an internal audit useful?

Yes. An internal audit tells you whether what you would answer is actually true in practice. That is exactly what a customer’s questionnaire assumes, and it makes the next one quicker to fill in.

Can our own people do it?

Yes, provided they are competent and independent of the area they audit. In a small organisation, it is usually the second condition that fails. The person who knows the process well enough to audit it is generally the person who runs it.

We built our management system with a consultant. Why not let them do the internal audit?

Because they would be auditing their own work. Sending a different person from the same firm does not change that: a colleague would still be assessing a colleague’s work, within the same hierarchy. Independence is only guaranteed when the implementer and the internal auditor work for different companies. They may know each other, and may already have worked together this way for other clients. What matters is that neither reports to the other. It is the same rule I apply to myself.

Can you also help us fix what you find?

No. The findings and suggestions are yours to act on. If I implemented them, I could no longer guarantee my independence as your internal auditor to your external auditor.

Do we have to act on your improvement suggestions?

No. Nonconformities need corrective action, because the standard requires it. Opportunities for improvement are suggestions. You decide what you do with them.

What happens if you find a major nonconformity?

You deal with it while it is still cheap. A major finding raised internally is a task on your project plan. The same finding raised by the certification body means a delayed certificate and a return visit.

Can we hand your report to our certification body?

Yes. It is written for your management, it serves as evidence of your internal audit, and its results feed straight into your management review.

How often do we need an internal audit?

At planned intervals, covering the whole system over a defined cycle. Most SMEs run an annual programme, sometimes split into parts spread across the year. The standard does not set a frequency: your risk profile and the maturity of the system do.

Can you audit a CyFun implementation as well?

I can audit your implementation against the CyberFundamentals assurance level that applies to you, so you find the gaps yourself before the assessment body does. The verification or certification itself comes from an accredited assessment body, not from me.

How long does it take?

For a team of up to five, one day onsite plus preparation and the report. For a larger scope, we first talk about what it covers, and I then set out the effort in a proposal, before anything is planned. During the audit, interviews take between half an hour and an hour per person.

Start with a focused conversation

Fifteen minutes is usually enough to work out whether this is the right engagement, what the scope should be, and what it would realistically take.

Request an intro call