Service
An independent audit of your management system, run by a certified ISO 27001 internal auditor. Findings you can act on, not a ticked checklist.
The certification audit tells you whether you pass. The internal audit is the one that tells you where you actually stand. It is not optional either: ISO 27001 requires internal audits at planned intervals, and the results have to feed into your management review. No internal audit means no certification.
In practice, it is the requirement most often reduced to theatre. Someone audits work they did themselves, findings are worded so that nobody has to act on them, and the report lands a week before the certification body arrives.
An internal audit earns its cost when it finds what the external auditor would have found, early enough that fixing it is still cheap and unhurried.
Four phases, agreed with you before anything starts. You know in advance what will be examined, how, and against which criteria.
Organisations with a management system in operation that need an independent internal audit: preparing for initial certification, heading into a surveillance or recertification audit, or simply due for the next cycle in their audit programme. It is also for organisations that have realised their internal audit is being done by the person who built the system.
One rule I do not bend: if I implemented your management system, I will not audit it. Auditing my own work would remove exactly the independence that makes the audit worth paying for. In that case I will refer you to a competent auditor instead.
At planned intervals, with the whole system covered over a defined cycle. Most SMEs run a yearly programme, sometimes split into parts across the year. The standard does not set a frequency; your risk profile and the maturity of your system determine it.
Yes, provided they are competent and independent of the area they audit. In a small organisation, that second condition is usually where it falls down. The person who knows the process well enough to audit it is generally the person who runs it.
You deal with it while it is still cheap. A major finding raised internally is a task on your project plan. The same finding raised by the certification body is a delayed certificate and a return visit.
I can audit your implementation against the applicable CyberFundamentals assurance level, so that gaps surface on your terms. The verification or certification itself is issued by an accredited assessment body, not by me.
That depends on your scope, the number of sites and how many teams run part of the system. After a first conversation about your scope, I set out the effort in a proposal, before anything is planned. You get a figure based on your organisation, not on an assumption.
Fifteen minutes is usually enough to work out whether this is the right engagement, what the scope should be, and what it would realistically take.
Request an intro call