Skip to content
  ISO 27001:2022 Internal Audit

Pass your certification audit the first time.

ISO 27001 requires an independent internal audit before a certification body opens your ISMS. We run it the way your external auditor will, and ensure you pass on the first try.

✓No surprises at Stage 2. Gap assessment first, formal audit second — findings arrive with time to fix them, not attached to a certificate decision.
✓One to three weeks, and a few hours of your time. We review evidence directly in your GRC platform. One kickoff call, one results review, and a shared Slack channel for everything else.
✓One remediation round or fifteen, same price. Remediation cycles are included, and the engagement renews for every surveillance year.
internal audit / ISO 27001:2022 / findings
Certification readiness
Management system · all applicable controls
READY FOR STAGE 1
MAJOR NC
0
MINOR NC
3
OBSERVATIONS
11
CONFORMS
79
MINOR NC
Risk treatment plan not re-approved after scope change
Risk management · owner: CTO
CAP open
MINOR NC
Supplier assessments missing for two critical vendors
Vendor management · owner: Operations
Verified
OBS
Management review minutes light on ISMS performance data
Management review · owner: CEO
Guidance sent
OBS
Physical access review not evidenced for the office
Physical security · owner: IT
Guidance sent
Every finding cites the requirement it maps to, the evidence reviewed, and the corrective action expected.
In-house US-based auditorsISO 27001ISO 42001SOC 2HIPAA
The problem

A failed Stage 2 costs you a quarter.

ISO 27001 is pass or fail. One major nonconformity means corrective action, a re-visit, and a certificate that slips past the customer deadline that started the project. Your internal audit exists to catch those findings while they still cost days.

Independence

You can't audit the controls you built

On a small team the person who built the ISMS is the only person who understands it, and that is exactly who the standard disqualifies from auditing it. An outside auditor is not a nice-to-have. It is how you meet the requirement.

Evidence

A green dashboard doesn't get you certified

Your platform tracks whether a control exists. An auditor asks whether it operated, who approved it, when it was reviewed, and where the record is. We test you against the second standard, because that is the one waiting at Stage 2.

Findings

A list of gaps does not tell you what to do Monday

Most audit reports tell you what is wrong and stop there. Every finding you get from us carries the requirement it maps to, the root cause, a corrective action with an owner and a date, and a verification step that confirms it closed.

The solution

Assess, remediate, re-test, report.

Our goal is to make sure you pass. We do not send you to your external audit until we are confident you will, and we keep re-testing until you get there.

One to three weeks from kickoff to signed report, depending on how much remediation there is. We review your evidence directly inside your GRC platform, so your team gives us about an hour at kickoff and an hour to review results. Everything in between happens in a shared Slack Connect channel.

1
Plan

Nothing gets tested before you agree what is in scope

You get an audit plan built around your ISMS scope, your risk context, and your certification date. Systems, locations, and applicable controls are confirmed up front.

↓
2
Assess

You see the findings while you can still fix them

The gap assessment is an early read, not a verdict. Findings come back as a working list, so you know exactly what has to move before the formal audit begins.

↓
3
Remediate

You get remediation guidance, and the decisions stay yours

For every finding we explain what we found, what needs to be addressed, and a couple of approaches you could take to close it. We do not implement controls or dictate the exact fix — that would be a conflict of interest. Your team chooses the approach and makes the change, which is what keeps the audit independent.

↓
4
Test

We test you the way your certification body will

Evidence-based testing across the full management system and every applicable control. Policies, procedures, records, system configurations, and whether they actually operated.

↓
5
Report

You walk into Stage 1 with the signed report in hand

The internal audit report your certification body asks for, plus a final review against auditor expectations so nothing in your ISMS surprises you or them.

Ninety percent ready is the right time to reach out.

Waiting for a perfect dashboard means waiting past your certification date, and several of the items teams stall on can be closed during the audit window rather than before it.

You can start a couple of days after the statement of work is signed.

Where teams usually are when they reach out
80–85%Start with the gap assessment, remediate, then audit
90–100%Ideal window — straight into the full internal audit
CertifiedAnnual internal audit for your surveillance cycle
What you get

Six deliverables. One flat fee.

Scoped to your size and systems — not billed by the hour, and not re-quoted when remediation takes another round.

Audit planning and scope definition

A tailored audit plan aligned with your ISMS scope, risk context, and certification goals.

Independent, objective assessment

Evaluation of ISMS controls against ISO 27001:2022 by qualified auditors with no stake in the outcome.

Evidence-based control testing

Policies, procedures, records, system configurations, and operational effectiveness — not just documentation.

Findings and gap analysis report

A clear breakdown of conformities, nonconformities, and improvement opportunities.

Corrective action guidance

Actionable remediation steps, prioritized by what actually blocks certification.

Readiness check for certification

A final review against auditor expectations, so the certification body finds nothing you have not already seen.

Securest
ISO 27001:2022 Internal Audit Report
Acme Health, Inc.
Audit period: Aug 18 – Sep 05, 2026
Scope: ISMS, production environment
Lead auditor: Securest, independent
Contents
Audit plan, scope, and criteria02
Methodology and evidence reviewed04
Management system conformity summary06
Control testing results09
Nonconformities and corrective actions21
Certification readiness statement26
0
MAJOR
3
MINOR
11
OBS
79
CONF

Signed, dated, and structured the way a certification body expects to receive it.

Why Securest

We already know what your certification body accepts.

We partner with the certification bodies and audit firms our clients use, so your findings are written by people who know how each one reads evidence — not by someone guessing from a checklist.

The auditors on your kickoff call write your report

100% in-house and US-based. No offshore delivery team, no subcontracted assessors, no handoff to someone you have never met after you sign.

Keep the platform you already pay for

Secureframe, Vanta, Drata, ControlMap, Scrut, Sprinto, or a folder of spreadsheets. We work inside whatever you use, so nothing has to be migrated before we start.

Three rounds of remediation cost the same as one

One flat fee, scoped up front to your headcount, systems, and locations. If closing a finding takes another pass, the price does not move and neither does the invoice.

Next year’s audit is already handled

Certification is not the end — surveillance audits need an internal audit every year. The engagement renews with the same team and the same working papers, so year two is more efficient than year one.

Our audit partnerships open the door for you

We work alongside accredited certification bodies and audit firms year round. If you have not selected one, you get warm introductions that fit your timeline and budget instead of a cold search.

Add SOC 2 or ISO 42001 while we are already in your environment

Roughly seventy percent of SOC 2 controls overlap with ISO 27001, so we review the remainder on the same engagement. ISO 42001 shares ISO 27001’s management-system structure, so your AI management system can be audited alongside your ISMS.

Independence, kept intact

You get corrective guidance on every finding.

Root cause, the specific change that closes the gap, an effort estimate, and a re-test to verify it worked. You are never handed a finding without a path to closing it.

Your team makes the change, and that is what keeps the audit independent — the same separation your certification body expects to see. Advisory on one side, implementation on yours, and a clean line between them.

We own
You own
Testing the control and documenting the finding
Approving the corrective action plan
Specifying exactly what closes it
Making the configuration change
Re-testing and verifying it closed
Sign-off and the move to certification
Questions we get

Know what you need before you move forward.

What is an internal audit for ISO 27001?+

A structured, evidence-based review of your ISMS against ISO 27001:2022, conducted by someone independent of the controls being tested. The standard requires it at planned intervals, and your certification body will ask to see the report and the audit programme behind it.

When do I need one?+

Before your Stage 1 audit, and every year after that to support surveillance. Practically: once you are around eighty to ninety percent complete in your GRC platform and have a certification date in mind. You do not need to be at a hundred percent, and waiting for it usually costs you the date.

How is it different from the certification audit?+

The certification audit is performed by an accredited body and decides whether you are certified. The internal audit is yours — it finds the problems first so the external one does not. Same rigor, no consequences beyond a corrective action you have time to complete.

What evidence do I need to provide?+

Your ISMS documentation and Statement of Applicability, published policies and procedures, risk assessment and treatment plan, management review and training records, access and vendor reviews, and read access to the systems in scope. Most of it already lives in your GRC platform, and we review it there directly as auditors, so there is little to export or send.

How long does it take, and how much of our time?+

One to three weeks from kickoff to signed report, depending on how much remediation there is. Your team typically spends about an hour on the kickoff call and an hour reviewing results; clarifying questions happen async in a shared Slack Connect channel. You can start a couple of business days after the statement of work is signed.

Do you help us fix the findings?+

Yes. Our goal is to make sure you pass, so we do not send you to your external audit until we are confident you will. Every finding comes with corrective action guidance — root cause, the specific change that closes it, and a couple of approaches to get there — and we verify the fix on re-test. Whether that takes one remediation cycle or fifteen, the price is the same. Your team applies the change, which is what keeps the audit independent. If you want hands-on implementation, our compliance practice covers that as a separate engagement.

What happens after the internal audit?+

You get the signed report and a readiness statement, and you go to your certification body. If you have not picked one, we will introduce you. A year later we run it again for your surveillance cycle.

Can you cover SOC 2 at the same time?+

Yes. SOC 2 does not require an internal audit, but around seventy percent of the controls overlap with ISO 27001. Adding an independent review of the remaining SOC 2 controls is an option on the same engagement.

Do you support ISO 42001 internal audits?+

Yes, we do. ISO/IEC 42001 requires an internal audit of your AI management system (AIMS) at planned intervals, just as ISO 27001 does for your ISMS. We run it the same way: plan, gap assessment, corrective action guidance, evidence-based testing, and a signed report for your certification body. The two standards share the same management-system structure, so if you hold or are pursuing ISO 27001, we can audit both together.

Who actually does the work?+

Our own auditors, all in-house and US-based. Nothing is subcontracted or sent offshore, and the people on your kickoff call are the people who write your report.

Get a quote for your internal audit.

Send us your headcount, systems, platform, and target certification date. You get a fixed-fee statement of work within one business day.

Flat fee, scoped up frontUnlimited remediation rounds100% in-house, US-based team