Scoped audit programme
Audit objectives, criteria, scope (sites, departments, processes), methods, and reporting protocols — agreed upfront so the audit measures what matters to you and your auditor.
Internal Audit
Independent internal audit, scoped to the framework that matters. PECB-accredited Lead Auditors, evidence-grade reports, and a remediation plan you can actually act on.
The case for internal audit
Versus where you think it stands. ISO 27001 mandates an internal audit (Clause 9.2). NIS2 expects one. Customers and insurers increasingly ask for evidence of one. And every quarter you go without one, you're operating on assumptions about controls that may or may not still work.
A good internal audit isn't an event to dread — it's a structured, evidence-led check that your security program does what your policies say it does. We run it independently, end the findings into a corrective action plan.
ISO/IEC 42001 also mandates an internal audit (Clause 9.2 of the AIMS) — the same audit discipline now applies to your AI estate. Our audit scope extends to AI Act Article 26 deployer duties, Article 27 FRIA evidence, Annex IV technical documentation, and ISO 42001 readiness. See our AI Governance & Security service for the broader AI audit and governance package.
What we deliver
Audit objectives, criteria, scope (sites, departments, processes), methods, and reporting protocols — agreed upfront so the audit measures what matters to you and your auditor.
Document review, employee interviews, control walkthroughs, evidence collection — conducted by a Lead Auditor who is not the person who built your controls. Objectivity is the whole point.
A clause-by-clause or control-by-control evaluation against the target framework. Every finding linked to evidence; every gap mapped to the requirement it sits against.
A non-technical overview of scope, findings, and management decisions required — designed to be read at the board table, not buried in an annex.
Prioritised list of findings with recommended owners, timelines, and effort estimates. Turns the audit report into a roadmap your team can actually execute.
For ISO 27001 engagements: an audit evidence file structured to satisfy your certification body during Stage 1/2 review — so the internal audit they require is the internal audit they accept.
How we work
Week 1
We agree the audit objectives, applicable framework(s), scope (sites, departments, systems, processes), criteria, and methods. Output: an audit programme that the certification body or regulator will recognise.
Weeks 1–2
A structured review of your information security policies, procedures, and supporting evidence against the framework requirements. Output: prepared checklists that drive the on-the-ground audit.
Weeks 2–4
Employee interviews, observation of controls in operation, evidence collection, and verification that documented procedures match operational reality. Conducted on-site or remote depending on your setup.
Weeks 4–5
A complete audit report — executive summary, conformance status, findings with evidence references, and a prioritised corrective action plan with recommended owners and timelines. Delivered with a debrief session for management.
When you need this
Most engagements come from one of these triggers. If two or three apply at once, the audit is usually well-timed.
Frameworks and regulations audited
Internal hire vs independent auditor
| Factor | Cyber-Management (independent) | Internal auditor (internal employee) |
|---|---|---|
| Cost | Fixed fee, scoped to framework and organisation size; no ongoing employment cost | Salary + training + tooling + management time; difficult to justify for SMB scale |
| Time to start | 1–2 weeks from scoping call | Months — recruitment, training, framework certification |
| Objectivity | No skin in the game — findings are findings | Same employer as the team being audited; bias risk inherent |
| Accreditation | PECB ISO/IEC 27001 and ISO/IEC 42001 Lead Auditor in every engagement | Depends on hire; often not framework-certified |
| Multi-framework breadth | ISO 27001, NIS2, GDPR, DORA, PCI DSS — practitioners work across all | Typically deep in one framework, thin in the others |
| Acceptance by certification bodies | Audit file structured to certification-body evidence requirements | Variable — auditor independence sometimes challenged at Stage 2 |
FAQ