Information security

Internal and verification audits

A management system that is not audited degrades quietly. We verify that what was defined is being applied, that the evidence exists, and that the controls mitigate the risks they claim to mitigate.

Typical duration
2 to 5 weeks per cycle
Independence
Auditors outside the advisory team
Standards
ISO/IEC 27001 · 20000-1 · 37001 · 37301 · 42001
Deliverable
Audit report and findings

Objective and scope

We carry out internal audits with expert auditors independent of the advisory team, and support and guide the handling of the findings identified. When the organisation decides to prepare its own internal audit staff, we deliver the training and knowledge transfer they need to perform effectively.


Project phases

Phase 1

Audit programme and plan

We define objective, scope, criteria and schedule, taking into account the state of the processes, the results of previous audits and any changes in the organisation.

Phase 2

Fieldwork

Interviews, direct observation, record review and technical verification that the controls operate as required against the defined criteria.

Phase 3

Findings report

We document non-conformities, observations and opportunities for improvement with objective evidence, classified by severity.

Phase 4

Treatment and follow-up

We support the root cause analysis, the definition of corrective actions and the verification of their effectiveness, recorded in SORT Redmine.


What the implementation includes

  • Annual audit programme
  • Audit plan per cycle
  • Management system audit
  • Technical verification of controls
  • Report with objective evidence
  • Findings classified by severity
  • Support for root cause analysis
  • Verification of the effectiveness of actions

Frequently asked questions

Does it replace the certification audit?

No. The internal audit is a requirement of the standard and preparation for the external one, but certification is issued by an accredited certification body, which is independent of us.

Can you audit a system you implemented yourselves?

Yes, using auditors from the audit team, independent of the advisory team that worked on the implementation. That separation is what preserves the impartiality the standard requires.

Do you also audit suppliers?

Yes. Audits of critical third parties are increasingly requested, both because of contractual requirements and because of control A.5.22 of ISO/IEC 27001.

your business partner

Protecting you today, innovating for tomorrow