ISO 27001 Internal Audit

We conduct ISO 27001 internal audits - identifying nonconformities and preparing your organization for a successful certification audit.


More than a checkbox exercise

An ISO 27001 internal audit is a mandatory part of your information security management system - and that’s exactly why it deserves more than a formality. We conduct audits that genuinely show you where you stand, what’s working, and what needs improvement.

We don’t show up with a ready-made checklist. We come with an understanding of your business and experience from dozens of audits across organizations of different sizes and complexity.

Our approach

Audit planning

Every audit starts with a plan. We define the scope, criteria, and schedule tailored to your organization:

Conducting the audit

We work on-site or remotely - whichever suits you best. The audit includes:

The goal isn’t to “catch” you doing something wrong. The goal is to see the real picture before the certification auditor does.

Report and action plan

After the audit, you receive a clear, structured report:

We don’t leave you with a 50-page document and “Good luck!” We walk through everything we found with you and help you understand what’s urgent, what can wait, and what you’re already doing well.

When you need an internal audit

If you already have an ISO 27001 ISMS in place, an internal audit is the natural next step. And if you’re still in the planning stage, a readiness audit will save you time and headaches down the road.

Why choose us

Next step

Not sure if your internal audit is truly effective? Let’s talk - we’ll look at your specific situation and tell you what we’d do differently.


Frequently Asked Questions

Can we do the internal audit ourselves?
Technically yes, but clause 9.2 requires auditor independence - you can't audit your own work. If a small team built the ISMS, there's often nobody left who qualifies as independent. An external internal auditor solves that problem cleanly.
How often do we need an internal audit?
ISO 27001 requires audits at planned intervals - most organizations do it annually. You should also consider an audit after significant changes like infrastructure migrations, acquisitions, or scope changes.
What's the difference between an internal audit and the certification audit?
The internal audit is your own check - it's required by the standard and meant to find issues before the certification body does. The certification audit is conducted by an accredited external body and determines whether you get or keep your certificate.
How long does an internal audit take?
For a small to mid-sized organization, typically 3 to 5 days of audit work plus reporting. The exact duration depends on the scope of your ISMS, number of locations, and complexity of your operations.
What happens if the internal audit finds nonconformities?
That's actually the point - finding issues before the certification auditor does. We help you understand each finding, prioritize by severity, and develop corrective actions. Most nonconformities are straightforward to resolve when caught early.