Internal audit against ISO 27001 or NIST
An independent internal audit of your management system and controls against ISO 27001 or NIST CSF. Gaps and nonconformities are found before the certification body, the customer or the regulator finds them.
Who it is for and when
Suits organisations about to be certified or already certified that need the internal audit the standard requires, and organisations that want an independent assessment ahead of a customer or regulatory review.
- ISO 27001 requires internal audit and you lack your own independent auditor.
- The certification audit is approaching and you want to find the nonconformities first.
- A customer or regulator is going to review you and you want to know how you stand.
- You built the management system yourselves and want an independent assessment that it works.
What we do
- Audit plan. We establish scope, criteria and schedule and request the documentation in advance.
- Document review. Policies, risk work, controls, internal audits, management review and the Statement of Applicability are reviewed against the standard.
- Interviews and sampling. We interview those responsible and take samples to verify that the controls are actually applied, for example access rights, supplier follow-up and incident handling.
- Assessment. Observations are classified as nonconformities, observations or improvement suggestions with clear references to requirements and evidence.
- Report and review. Management receives an audit report and a review with prioritised recommendations.
You get
- Audit plan and audit programme
- Audit report with nonconformities, observations and recommendations
- Evidence per observation
- Review with management
- Material for the management review and the certification audit
Scope and price
A defined engagement of one to two weeks depending on the scope of the management system, the number of sites and how many processes are audited.
The price varies from engagement to engagement and depends on the scope. You get a fixed price in the proposal. Recurring internal audit can be set up as an annual plan with a fixed price per year.
How it works
- A first conversation. We listen to your situation and explain how we usually set up the work. You get our assessment straight away, free of charge.
- A proposal with scope and price. A short written proposal with what is included, what you get, who does the work and what it costs.
- Delivery and handover. We work together with your organisation, report continuously and hand over so that you can maintain the result yourselves.
Frequently asked questions
May you audit us if you helped us build the management system?
An auditor must not review their own work. If we have built parts of the management system we use other consultants for the audit, or review only what we were not involved in. We are explicit about this in the proposal.
Is your internal audit enough for the certification?
Yes, a documented internal audit that covers the requirements of the standard is what the certification body asks for. We adapt the scope to your certification cycle.
How often do we need an internal audit?
The standard requires the whole management system to be audited within the certification cycle, in practice at least annually with an audit programme that covers all parts over time.
Want to know how your management system holds up?
Contact us