Gap analysis, internal audit or pre-audit for ISO 27001 – what do you actually need?

Gap analysis, internal audit or pre-audit for ISO 27001 – what do you actually need?

Gap analysis, internal audit, control testing and pre-audit answer different questions. How to choose the right review depending on where you are in your ISO 27001 journey.

Summary: Gap analysis, internal audit, control testing and pre-audit are sometimes used as if they were the same thing. They are not. A gap analysis helps the organisation understand what is missing. The internal audit examines whether the management system meets the audit criteria and works as intended. A pre-audit instead focuses on how ready the organisation is for a forthcoming external audit. The right type of review therefore depends on where the organisation is in its journey.

An organisation says: ”We need an ISO 27001 audit.” The first question should really be: what do you want answered?

  • How far do we have left to go? Then a gap analysis is relevant.
  • Does our management system work according to the requirements? Then it is more a matter of internal audit.
  • Are we ready to face the certification body? Then a readiness review or pre-audit may be more relevant.

They can look similar in execution: interviews, documents, sampling, controls. But the purpose is different.

The gap analysis – where do we stand and what is missing?

A gap analysis is usually used early on or midway through an improvement effort. The organisation compares its current state with a target or a requirement, for example ISO/IEC 27001, the Swedish Cybersecurity Act, DORA or an internal security framework. The result should show:

  • what is in place
  • what is partly in place
  • what is missing
  • what should be prioritised

That makes the gap analysis a tool for change. It can happily be advisory. The consultant can say: ”Here is a practical way to solve this.” That is often exactly what the customer needs.

The internal audit has a different mandate

The internal audit is not primarily there to build the system. It is there to examine it.

ISO 19011:2026, the fourth edition of the standard for auditing management systems, describes audit principles and an evidence-based, risk-based approach, as well as matters such as independence, audit programmes, conduct and reporting. ISO/IEC 27001, in turn, is a standard for a management system that is established, implemented, maintained and continually improved based on the organisation’s information security risks. The internal audit becomes part of the organisation’s ability to verify that the system actually works.

Independence matters

Here is an important difference from the gap analysis. Someone who built a process may find it hard to review their own work objectively. That does not mean an external consultant must always perform the internal audit. But the organisation needs to handle objectivity and independence credibly. ISO 19011 explicitly lists independence as one of the principles of auditing.

It is therefore important to ask already at the planning stage:

  • Who implemented the area?
  • Who will audit it?
  • Is there a risk that the person is in practice reviewing their own decisions?

What should the internal audit deliver?

A good internal audit provides more than ”OK” or ”not OK”. It should provide structured material on, for example:

  • audit criteria
  • scope
  • evidence
  • observations
  • nonconformities
  • strengths
  • opportunities for improvement

The result should be usable in the continued improvement of the management system. The latest edition of ISO 19011 emphasises that effective audits are more than a pure conformity check; they can also help strengthen management systems and improve the business.

So what is a pre-audit?

Terms such as pre-audit, readiness review and pre-assessment are used in slightly different ways in practice. It is normally not a substitute for the organisation’s formal internal audit. The purpose is rather to answer: how are we likely to fare in the next external audit? The reviewer can then work more like a dress rehearsal:

  • Is the documentation in place?
  • Can the organisation show evidence?
  • Have the most important nonconformities been addressed?
  • Can the responsible people describe how the process actually works?
  • Has the management review been carried out?
  • Is the audit trail coherent?

The pre-audit should not promise certification

A pre-audit can reduce surprises. But it cannot guarantee what the certification body’s auditor will conclude.

The ISO/IEC 27001 certification itself is carried out by a certification body. ISO/IEC 27006-1:2024 sets specific requirements for bodies that audit and certify information security management systems, including competence, consistency and impartiality. In Sweden, Swedac accredits certification bodies for ISO/IEC 27001 among other standards and maintains a register of accredited bodies.

A consultant who helps the organisation get ready is therefore not the same as the certification body that issues the certificate.

And control testing?

Control testing is more focused. The question is not necessarily ”does the whole management system work?” but ”does this particular control work?”. Take the requirement that MFA must apply to all privileged users. The review can then check:

  • Which privileged accounts exist?
  • Which ones are covered?
  • Are there exceptions?
  • How are new accounts followed up?

In the same way, the organisation can test backup, patching, access reviews, supplier follow-up, security training and incident exercises. Control testing is therefore central to assurance. We describe how to work with design, implementation and operational effectiveness in more detail in our insight on assurance and control testing.

Which type does the organisation need?

ReviewThe question it answersSuitable when
Gap analysisWhat are we missing and what should we do?The organisation is early on or midway through implementation.
Control testingDoes a specific control work?Ongoing assurance and verification.
Internal auditDoes our management system meet and follow the audit criteria, and does it work as intended?As part of the regular ISMS cycle.
Pre-audit / readiness reviewHow ready are we for the external audit?Certification or another external review is approaching.
Certification auditDoes the organisation’s ISMS meet the requirements for certification?Carried out by the certification body.

Organisations may need several steps

A common sequence can be:

  1. gap analysis
  2. implementation
  3. control testing
  4. internal audit
  5. corrective actions
  6. readiness review
  7. certification audit

That does not mean every organisation needs each step as a separate consulting project. But it helps to understand which question each activity is meant to answer. Otherwise there is a risk that the customer orders an ”audit” when what is really needed is a workshop and an action plan – or an advisory gap analysis when what is really needed is an independent internal audit.

How Kristensson i Skåne can help

Kristensson i Skåne works with both implementation and assurance. We can help organisations with, for example:

When the same organisation needs both implementation and independent review, the engagement needs to be designed so that roles and objectivity are handled clearly. Our starting point is that the customer should get the right type of review at the right time – not more audits than necessary.

Frequently asked questions

Is a gap analysis the same as an internal audit?

No. A gap analysis is normally more advisory and forward-looking. An internal audit is a structured review against defined audit criteria, with requirements for objectivity and independence.

Does the internal audit have to be performed by an external consultant?

No. It can be done internally if the organisation can ensure sufficient objectivity and competence, and that nobody is in practice reviewing their own decisions.

Is a pre-audit mandatory for ISO 27001?

No. It is a practical preparatory step ahead of the certification audit, not a separate mandatory activity under the standard.

Is an internal audit the same as a certification audit?

No. The certification audit is carried out by an accredited certification body and is a separate third-party process. The internal audit is the organisation’s own review of its management system.

Unsure which type of review you need right now? Read more about our assurance and internal audit services or contact us for an informal conversation.

Sources: ISO 19011:2026, Guidelines for auditing management systems (fourth edition, published May 2026); ISO/IEC 27001:2022; ISO/IEC 27006-1:2024, requirements for bodies providing audit and certification of information security management systems; Swedac, register of accredited certification bodies.

This text is general information and does not constitute advice in an individual matter.