ISO 27001 internal audit

An independent audit of your management system, run by a certified ISO 27001 internal auditor. Findings you can act on, not a ticked checklist.

← Back to home

The audit that tells you the truth

The certification audit tells you whether you pass. The internal audit is the one that tells you where you actually stand. It is not optional either: ISO 27001 requires internal audits at planned intervals, and the results have to feed into your management review. No internal audit means no certification.

In practice, it is the requirement most often reduced to theatre. Someone audits work they did themselves, findings are worded so that nobody has to act on them, and the report lands a week before the certification body arrives.

An internal audit earns its cost when it finds what the external auditor would have found, early enough that fixing it is still cheap and unhurried.

How I run an audit

Four phases, agreed with you before anything starts. You know in advance what will be examined, how, and against which criteria.

  1. Plan and criteria We agree the audit programme: which parts of the management system this cycle covers, the criteria I audit against, the sampling approach, and who I need to speak to. Surprises belong in the findings, not in the logistics.
  2. The system as designed A review of the documented system: scope, risk assessment, Statement of Applicability, policies and procedures. This establishes what you have committed to, and that becomes the yardstick for everything that follows.
  3. The system as operated Interviews and evidence sampling with the people who actually run the processes. This is where design and practice tend to part company, and where an audit either earns its keep or does not.
  4. Report and results meeting A report you can hand to management and to your certification body. We then walk your team through the results in a meeting, so everyone understands the findings and knows what they can do with them.

What you get

Who this is for

Organisations with a management system in operation that need an independent internal audit: preparing for initial certification, heading into a surveillance or recertification audit, or simply due for the next cycle in their audit programme. It is also for organisations that have realised their internal audit is being done by the person who built the system.

One rule I do not bend: if I implemented your management system, I will not audit it. Auditing my own work would remove exactly the independence that makes the audit worth paying for. In that case I will refer you to a competent auditor instead.

Questions I am often asked

How often do we need an internal audit?

At planned intervals, with the whole system covered over a defined cycle. Most SMEs run a yearly programme, sometimes split into parts across the year. The standard does not set a frequency; your risk profile and the maturity of your system determine it.

Can our own people do it?

Yes, provided they are competent and independent of the area they audit. In a small organisation, that second condition is usually where it falls down. The person who knows the process well enough to audit it is generally the person who runs it.

What happens if you find a major nonconformity?

You deal with it while it is still cheap. A major finding raised internally is a task on your project plan. The same finding raised by the certification body is a delayed certificate and a return visit.

Can you audit a CyFun implementation as well?

I can audit your implementation against the applicable CyberFundamentals assurance level, so that gaps surface on your terms. The verification or certification itself is issued by an accredited assessment body, not by me.

How long does it take?

That depends on your scope, the number of sites and how many teams run part of the system. After a first conversation about your scope, I set out the effort in a proposal, before anything is planned. You get a figure based on your organisation, not on an assumption.

Start with a focused conversation

Fifteen minutes is usually enough to work out whether this is the right engagement, what the scope should be, and what it would realistically take.

Request an intro call