Skip to content
ISO 27001:2022 Internal Audit

Pass your certification audit the first time.

ISO 27001 requires an independent internal audit before a certification body ever opens your ISMS. We run it the way your external auditor will, find the nonconformities while they still cost you days instead of a quarter, and hand over the signed report your certification body expects.

No surprises at Stage 2. Gap assessment first, formal audit second — findings arrive with time to fix them, not attached to a certificate decision.
Two to three weeks, kickoff to signed report. Coordinated in a shared Slack channel with our team doing the work, not a queue of scheduled calls.
One price, however many rounds it takes. Remediation cycles are included, and the engagement renews for every surveillance year.
100% in-house, US-based auditorsWorks with any GRC platformFixed fee, quoted in a day
internal audit / ISO 27001:2022 / findings
Certification readiness
Management system · all applicable controls
READY FOR STAGE 1
MAJOR NC
0
MINOR NC
3
OBSERVATIONS
11
CONFORMS
79
MINOR NC
Risk treatment plan not re-approved after scope change
Risk management · owner: CTO
CAP open
MINOR NC
Supplier assessments missing for two critical vendors
Vendor management · owner: Operations
Verified
OBS
Management review minutes light on ISMS performance data
Management review · owner: CEO
Guidance sent
OBS
Physical access review not evidenced for the office
Physical security · owner: IT
Guidance sent
Every finding cites the requirement it maps to, the evidence reviewed, and the corrective action expected.
In-house US auditors · #1 Secureframe MSP partnerISO 27001SOC 2HIPAA
The problem

A failed Stage 2 costs you a quarter.

ISO 27001 is pass or fail. One major nonconformity means corrective action, a re-visit, and a certificate that slips past the customer deadline that started the project. Your internal audit exists to catch those findings while they still cost days.

Independence

You cannot audit the controls you built

On a small team the person who built the ISMS is the only person who understands it, and that is exactly who the standard disqualifies from auditing it. An outside auditor is not a nice-to-have. It is how you meet the requirement.

Evidence

A green dashboard will not get you certified

Your platform tracks whether a control exists. An auditor asks whether it operated, who approved it, when it was reviewed, and where the record is. We test you against the second standard, because that is the one waiting at Stage 2.

Findings

A list of gaps does not tell you what to do Monday

Most audit reports tell you what is wrong and stop there. Every finding you get from us carries the requirement it maps to, the root cause, a corrective action with an owner and a date, and a verification step that confirms it closed.

The solution

Assess, remediate, re-test, report.

Two to three weeks from kickoff to signed report. Throughout, you are in a shared Slack Connect channel with our team doing the work, so your questions get answered the same day instead of on the next call.

1
Plan

Nothing gets tested before you agree what is in scope

You get an audit plan built around your ISMS scope, your risk context, and your certification date. Systems, locations, and applicable controls are confirmed up front.

2
Assess

You see the findings while you can still fix them

The gap assessment is an early read, not a verdict. Findings come back as a working list, so you know exactly what has to move before the formal audit begins.

3
Remediate

You get the fix, not just the finding

Every gap comes with root cause, the specific change that closes it, and an effort estimate. Your team applies the change, which is what keeps the audit independent.

4
Test

We test you the way your certification body will

Evidence-based testing across the full management system and every applicable control. Policies, procedures, records, system configurations, and whether they actually operated.

5
Report

You walk into Stage 1 with the signed report in hand

The internal audit report your certification body asks for, plus a final review against auditor expectations so nothing in your ISMS surprises you or them.

Ninety percent ready is the right time to reach out.

Waiting for a perfect dashboard means waiting past your certification date, and several of the items teams stall on can be closed during the audit window rather than before it.

You can start a couple of days after the statement of work is signed.

Where teams usually are when they reach out
80–85%Start with the gap assessment, remediate, then audit
90–100%Ideal window — straight into the full internal audit
CertifiedAnnual internal audit for your surveillance cycle
What you get

Six deliverables. One flat fee.

Scoped to your size and systems — not billed by the hour, and not re-quoted when remediation takes another round.

Audit planning and scope definition

A tailored audit plan aligned with your ISMS scope, risk context, and certification goals.

Independent, objective assessment

Evaluation of ISMS controls against ISO 27001:2022 by qualified auditors with no stake in the outcome.

Evidence-based control testing

Policies, procedures, records, system configurations, and operational effectiveness — not just documentation.

Findings and gap analysis report

A clear breakdown of conformities, nonconformities, and improvement opportunities.

Corrective action guidance

Actionable remediation steps, prioritized by what actually blocks certification.

Readiness check for certification

A final review against auditor expectations, so the certification body finds nothing you have not already seen.

Securest
ISO 27001:2022 Internal Audit Report
Acme Health, Inc.
Audit period: Aug 18 – Sep 05, 2026
Scope: ISMS, production environment
Lead auditor: Securest, independent
Contents
Audit plan, scope, and criteria02
Methodology and evidence reviewed04
Management system conformity summary06
Control testing results09
Nonconformities and corrective actions21
Certification readiness statement26
0
MAJOR
3
MINOR
11
OBS
79
CONF

Signed, dated, and structured the way a certification body expects to receive it.

Why Securest

We already know what your certification body accepts.

Internal audit is one of the services we offer inside a full compliance practice, and we partner with the certification bodies and audit firms our clients use. So your findings are written by people who know how each one reads evidence — not by someone guessing at it from a checklist.

The auditors on your kickoff call write your report

100% in-house and US-based. No offshore delivery team, no subcontracted assessors, no handoff to someone you have never met after you sign.

Keep the platform you already pay for

Secureframe, Vanta, Drata, ControlMap, Scrut, Sprinto, or a folder of spreadsheets. We work inside whatever you use, so nothing has to be migrated before we start.

Three rounds of remediation cost the same as one

One flat fee, scoped up front to your headcount, systems, and locations. If closing a finding takes another pass, the price does not move and neither does the invoice.

Next year’s audit is already handled

Certification is not the end — surveillance audits need an internal audit every year. The engagement renews with the same team and the same working papers, so year two is faster than year one.

Our audit partnerships open the door for you

We work alongside accredited certification bodies and audit firms year round. If you have not selected one, you get warm introductions that fit your timeline and budget instead of a cold search.

Cover SOC 2 while we are already in your environment

SOC 2 does not require an internal audit, but roughly seventy percent of the controls overlap with ISO 27001. If you are pursuing both, we review the remainder on the same engagement.

Independence, kept intact

You get corrective guidance on every finding.

Root cause, the specific change that closes the gap, an effort estimate, and a re-test to verify it worked. You are never handed a finding without a path to closing it.

Your team makes the change, and that is what keeps the audit independent — the same separation your certification body expects to see. Advisory on one side, implementation on yours, and a clean line between them.

We own
You own
Testing the control and documenting the finding
Approving the corrective action plan
Specifying exactly what closes it
Making the configuration change
Re-testing and verifying it closed
Sign-off and the move to certification
Questions we get

Know what you need before you move forward.

What is an internal audit for ISO 27001?+

A structured, evidence-based review of your ISMS against ISO 27001:2022, conducted by someone independent of the controls being tested. The standard requires it at planned intervals, and your certification body will ask to see the report and the audit programme behind it.

When do I need one?+

Before your Stage 1 audit, and every year after that to support surveillance. Practically: once you are around ninety percent complete in your GRC platform and have a certification date in mind. Waiting for a hundred percent usually costs you the date.

How is it different from the certification audit?+

The certification audit is performed by an accredited body and decides whether you are certified. The internal audit is yours — it finds the problems first so the external one does not. Same rigor, no consequences beyond a corrective action you have time to complete.

What evidence do I need to provide?+

Your ISMS documentation and Statement of Applicability, published policies and procedures, risk assessment and treatment plan, management review and training records, access and vendor reviews, and read access to the systems in scope. We send a structured request list at kickoff — most of it already lives in your GRC platform.

How long does it take?+

Typically two to three weeks from kickoff to signed report, plus whatever time your team needs for remediation between the gap assessment and the final audit. You can start a couple of days after the statement of work is signed.

Do you help us fix the findings?+

Yes. Every finding comes with corrective action guidance — root cause, the specific change that closes it, effort, and sequence — and we verify the fix on re-test. Your team applies the change, which is what keeps the audit independent and the report credible to your certification body. If you want hands-on implementation, our compliance practice covers that as a separate engagement.

What happens after the internal audit?+

You get the signed report and a readiness statement, and you go to your certification body. If you have not picked one, we will introduce you. A year later we run it again for your surveillance cycle.

Can you cover SOC 2 at the same time?+

Yes. SOC 2 does not require an internal audit, but around seventy percent of the controls overlap with ISO 27001. Adding an independent review of the remaining SOC 2 controls is an option on the same engagement.

Who actually does the work?+

Our own auditors, all in-house and US-based. Nothing is subcontracted or sent offshore, and the people on your kickoff call are the people who write your report.

Get a quote for your internal audit.

Send us your headcount, systems, platform, and target certification date. You get a fixed-fee statement of work within one business day.

Flat fee, scoped up frontUnlimited remediation rounds100% in-house, US-based team