Service area

Assurance & Internal Audit

Kristensson i Skåne AB carries out independent reviews of IT, information security and data protection: ISO 27001 internal audits and independent NIST CSF assessments, maturity assessments, control testing, evidence collection, pre-audits before certification and support during external audits, as a project or as an ongoing service.

ISO 27001 auditNISTControl testingPre-auditInternal Audit as a Service

In today’s digital landscape, independent IT and security audits play a critical role in protecting organizations. By providing an unbiased review of your controls and practices, assurance services verify that you meet industry standards and regulatory requirements, reducing the risk of non-compliance penalties or security incidents. Just as importantly, they strengthen stakeholder trust – customers, investors, and regulators gain confidence knowing you take data protection and risk management seriously. In short, effective assurance and internal audit services not only support compliance, but also uncover hidden risks, build credibility, and support better decision-making.

In brief

Who
Organisations that need to show customers, owners, auditors or regulators that their controls work
What
Internal audit, maturity assessment, control testing, evidence and documentation, pre-audit, third-party assurance, ongoing internal audit as a service
How
Independent review against the chosen framework, clear observations and prioritised recommendations, hands-on support to close the gaps

Common situations

This is how it usually starts. If you recognise yourselves in one of them, we know roughly where to begin.

Offers in assurance

Six ways to start. Each offer can be bought on its own or combined into an ongoing assurance arrangement.

Review

ISO 27001 internal audit or NIST CSF assessment

Independent review of controls, policies and procedures against leading frameworks, with gaps and nonconformities identified before they become problems.

You get: an audit report with observations, nonconformities and recommendations, presented to management.

Scope: defined engagement, one to two weeksRead more →
Current state

Security maturity assessment

Evaluation of people, processes, governance and technology against established maturity models, with a maturity level per area.

You get: a scorecard per area, gaps against the target state and a prioritised roadmap.

Scope: defined engagement, a few weeksRead more →
Verification

Control testing

Testing of technical controls with scanning, configuration review and penetration testing, and of procedural controls through interviews and document review.

You get: test results per control, evidence and remediation proposals.

Scope: defined engagement, or recurringRead more →
Readiness

Pre-audit before certification

A mock audit against the standard or audit criteria, the way an external auditor works, before the real audit.

You get: a completed mock audit and an action plan for all findings.

Scope: defined engagement before the auditRead more →
Ongoing

Internal Audit as a Service (IAaaS)

Continuous access to experienced auditors with periodic audits, control follow-up and compliance checks during the year.

You get: an annual plan, completed audits, control follow-up and reporting to management.

Scope: ongoing, a number of days per quarterRead more →
Third party

Support during customer audits and questionnaires

Coordinated responses to customer security assessments, documentation before regulatory inspections and support as host during on-site audits.

You get: coordinated responses, compiled documentation and support during the audit.

Scope: on demandRead more →

See all offers →

Frequently asked questions

What is the difference between an internal audit and an external audit?

The internal audit is done on behalf of the organisation itself to check that the management system and controls work and to prepare for external reviews. The external audit is done by a certification body, a customer or a regulator and results in a certificate, an approval or a supervisory decision. A good internal audit makes the external audit predictable.

Can you be our internal auditor if you also helped us build the management system?

An auditor must not review their own work. If we have helped build parts of the management system we use other consultants for the audit, or review only the parts we were not involved in. We are explicit about this in every engagement.

What is a SOC 2 report and do we need one?

SOC 2 is an independent attestation report on controls at service providers, common when customers in the US or international groups set requirements. In Sweden and the EU, ISO 27001 certification is requested more often. We help you judge which evidence your customers actually accept before you invest.

How often should controls be tested?

It depends on how important the control is and how often the environment changes. Critical controls such as access rights, backups and logging should be tested at least annually and after major changes, preferably more often. An annual plan for internal audit and control testing makes sure nothing falls between the cracks.

How we work with assurance and internal audit, in detail

For those who want to know how we set up the work in each part. Jump to a section in the menu, or read from the top. About 9 minutes of reading

ISO 27001 Internal Audits and Independent NIST CSF Assessments

One of our core offerings is independent internal audits aligned with leading frameworks such as ISO/IEC 27001, NIST Cybersecurity Framework, and other relevant standards. Our experienced auditors conduct in-depth reviews of your IT and information security controls, policies, and procedures to evaluate whether they conform to these best practices. By mapping your Information Security Management System (ISMS) against recognized criteria, we identify gaps and non-conformities before they become problems. This process ensures you are well-prepared for formal certifications or external assessments. In fact, structured audits against standards like ISO 27001 make it easier to demonstrate compliance during external evaluations. Our internal audit reports provide management with clear findings and recommendations, helping you strengthen controls and align with global security benchmarks – ultimately building confidence that your organization’s security and privacy controls are effective.

In brief

  • Independent internal audits against ISO/IEC 27001, NIST CSF and other standards
  • The management system mapped to the criteria, gaps and nonconformities identified in advance
  • Reports with clear observations and recommendations for management

Security Maturity Assessments (Process, Technology, Governance)

We help organizations understand their current capability and readiness through comprehensive security maturity assessments. This involves evaluating your security posture across people, processes, governance, and technology domains. Using industry maturity models and best-practice frameworks, our consultants assess how well-developed your processes are (e.g. risk management, incident response, governance structure) and how robust your technology controls and tools are. The assessment highlights strengths and gaps, assigning a maturity level to each area and providing a clear, actionable roadmap for improvement. You receive a detailed scorecard comparing your current maturity vs. target maturity, along with prioritized recommendations. This structured approach allows you to benchmark against peers, focus resources on the right areas, and track progress over time. Whether it’s improving governance practices or deploying advanced security technologies, our maturity assessment guides your journey toward a stronger, more resilient security program.

In brief

  • Evaluation of people, processes, governance and technology
  • Maturity level per area with strengths and gaps
  • Scorecard against the target state and prioritised recommendations

Control Testing & Verification (Technical & Procedural Controls)

A key part of assurance is testing and verifying controls to ensure they operate as intended. We perform rigorous control testing that covers both technical controls and procedural controls. For technical security measures, our team uses tools and techniques like vulnerability scanners, configuration reviews, and penetration tests to validate that systems are properly secured (e.g. checking for unpatched software, misconfigurations, or weaknesses in networks and applications). At the same time, we verify non-technical controls by interviewing staff and reviewing policies, processes, and training programs – for example, assessing whether security policies are understood and whether user access reviews or incident response drills are happening in practice. This comprehensive testing provides objective evidence of which controls are effective and which may need improvement. By verifying technical safeguards and procedural practices side by side, we give you assurance that security is not just well-designed on paper, but also consistently implemented in daily operations. Any control weaknesses or lapses discovered are documented with clear recommendations so you can remediate them and strengthen your overall risk management.

In brief

  • Technical controls tested with scanning, configuration review and penetration testing
  • Procedural controls verified through interviews and document review
  • Objective evidence of what works and what needs improvement

Evidence Collection & Documentation Support

Preparing for audits – whether internal or external – often requires assembling a mountain of documentation. Our team supports you in collecting and organizing the evidence needed to demonstrate compliance and control effectiveness. We help maintain comprehensive records, policies, and audit logs, ensuring that mandatory documentation and evidence logs are up-to-date and complete. This includes guidance on version-controlling your policies, tracking control implementations, and compiling proof of activities (such as screenshots, configurations, training records, or incident tickets) that auditors or regulators may request. By creating an “audit-ready” repository of evidence mapped to each requirement, you can quickly retrieve what’s needed during an assessment. Our documentation support minimizes scramble and stress when an audit or regulatory inquiry occurs – everything is structured and readily accessible. Ultimately, robust evidence collection not only streamlines the audit process but also reinforces internally that security and compliance processes are being followed. With our help, you stand prepared to answer auditor questions and satisfy regulatory scrutiny with well-organized, credible documentation.

In brief

  • Collection and structuring of evidence for compliance and control effectiveness
  • Order in registers, policies, version control and audit logs
  • An audit-ready evidence library mapped to every requirement

Audit Readiness Reviews (Pre-Audit Assessments)

Before undergoing a major external audit or certification review, it’s wise to conduct a readiness assessment – essentially a practice audit to catch any issues in advance. We offer thorough audit readiness reviews to evaluate how prepared your organization is for an upcoming ISO certification, customer audit, or regulatory examination. Think of it as a dry run for the real audit: our experts assess your controls, processes, and documentation against the relevant standard or audit criteria, mimicking what an external auditor would do. This pre-audit review identifies any gaps, weaknesses, or non-compliant areas before the official audit takes place. For example, we might discover missing policy approvals, inadequate monitoring logs, or employees not fully following a procedure – findings that can be corrected ahead of time. According to industry experts, a structured readiness assessment pinpoints potential challenges early so you can remediate weaknesses and avoid surprises during the formal audit. We provide a detailed action plan to address all findings. By fixing these issues beforehand, you approach the actual certification or audit with confidence, knowing there’s a much lower risk of failures or costly delays. Our readiness reviews significantly improve your chances of a smooth, successful audit outcome on the first attempt.

In brief

  • Mock audit before ISO certification, customer audit or regulatory review
  • Gaps, weaknesses and nonconformities identified before the formal audit
  • A detailed action plan for all findings

Third-Party Assurance & External Audit Support

In today’s interconnected environment, organizations often need to demonstrate their security and compliance to third parties – whether it’s customers requiring assurance before trusting you with data, or regulators and partners expecting transparency. Our Third-Party Assurance services help you meet those demands. We assist in responding to external audits and questionnaires, acting as your advocate to ensure accurate and sufficient information is provided. This can include coordinating responses to client security assessments, preparing documentation for regulator inspections, or even hosting on-site audits by your customers. We make sure you can present a complete and credible picture of your control environment, backed by evidence. Additionally, we guide clients in obtaining independent attestation reports (such as SOC 2, ISO 27001 certification, or other audit reports) that many stakeholders accept as proof of security. Having a recognized service auditor’s report or certification can satisfy a broad range of customers and regulators with a single, standardized assurance document, avoiding the need for each customer to conduct their own audit. This not only saves your team from answering repetitive questionnaires but also builds trust by showing you meet industry-standard criteria. In summary, our third-party assurance support streamlines the process of proving your compliance to others – reducing audit fatigue and allowing you to focus on your business while we help manage the overview requirements.

In brief

  • Support in responding to external audits and security questionnaires
  • Documentation before inspections and hosting of on-site audits
  • Guidance towards attestation reports such as SOC 2 or ISO 27001 certification

Flexible Engagement Models (Projects or Ongoing “As-a-Service”)

Kristensson i Skåne AB offers flexible delivery for all our assurance and internal audit services to suit your needs. Engagements can be structured as one-time project-based audits or assessments targeting specific areas, or as an ongoing support arrangement akin to an “Assurance-as-a-Service” model. In a one-time engagement, we execute a defined review with a clear scope and deliverable. Alternatively, many clients choose our ongoing Internal Audit as a Service (IAaaS) offering, which provides continuous access to experienced audit professionals and regular assurance activities throughout the year. Under this model, we operate as an extension of your team – conducting periodic audits, control monitoring, and compliance check-ups on a subscription or retainer basis. This proactive approach ensures that internal controls remain effective, risks stay mitigated, and you maintain audit readiness year-round. Ongoing support can be especially valuable for organizations that need to meet multiple frameworks or frequent audits, as we coordinate a unified strategy to keep you compliant across all requirements continuously. Whether you need a one-off deep dive or continuous overview, our engagement model is tailored to provide the right level of support and frequency. The goal is to give you peace of mind that trust, compliance, and control are not just one-time achievements, but sustained strengths of your organization.

In brief

  • One-off engagements with a clear scope and deliverable
  • Internal Audit as a Service with periodic audits and control follow-up
  • Audit-ready all year round, also against several frameworks

Kristensson i Skåne AB helps you gain clarity and confidence in how well your controls work in practice. We perform structured reviews, internal audits, and maturity assessments across IT, information security, and data protection, aligned with frameworks such as ISO 27001, NIST, and relevant regulatory requirements. Our work combines control design review with hands-on control testing, evidence collection, and readiness checks, so you can demonstrate compliance and reduce risk. We deliver clear findings, prioritized recommendations, and practical support to close gaps, whether you need a one-time review or ongoing assurance “as-a-service”. The result is better governance, stronger stakeholder trust, and a continuously audit-ready organization.

Want to know what it would look like for you? Contact us and we will tell you more. Read more about how we work and about internal audit against ISO 27001 or NIST.

Do you need to prepare for an audit or assessment?

Contact us