Internal Audit

Cybersecurity internal audit — an honest look at where you actually stand.

Independent internal audit, scoped to the framework that matters. PECB-accredited Lead Auditors, evidence-grade reports, and a remediation plan you can actually act on.

The case for internal audit

The clearest view you can get of where your security program actually stands.

Versus where you think it stands. ISO 27001 mandates an internal audit (Clause 9.2). NIS2 expects one. Customers and insurers increasingly ask for evidence of one. And every quarter you go without one, you're operating on assumptions about controls that may or may not still work.

A good internal audit isn't an event to dread — it's a structured, evidence-led check that your security program does what your policies say it does. We run it independently, end the findings into a corrective action plan.

ISO/IEC 42001 also mandates an internal audit (Clause 9.2 of the AIMS) — the same audit discipline now applies to your AI estate. Our audit scope extends to AI Act Article 26 deployer duties, Article 27 FRIA evidence, Annex IV technical documentation, and ISO 42001 readiness. See our AI Governance & Security service for the broader AI audit and governance package.

What we deliver

Audit, evidence, action plan.

Scoped audit programme

Audit objectives, criteria, scope (sites, departments, processes), methods, and reporting protocols — agreed upfront so the audit measures what matters to you and your auditor.

Independent audit execution

Document review, employee interviews, control walkthroughs, evidence collection — conducted by a Lead Auditor who is not the person who built your controls. Objectivity is the whole point.

Conformance assessment

A clause-by-clause or control-by-control evaluation against the target framework. Every finding linked to evidence; every gap mapped to the requirement it sits against.

Executive summary

A non-technical overview of scope, findings, and management decisions required — designed to be read at the board table, not buried in an annex.

Corrective action plan

Prioritised list of findings with recommended owners, timelines, and effort estimates. Turns the audit report into a roadmap your team can actually execute.

Certification-body-ready file

For ISO 27001 engagements: an audit evidence file structured to satisfy your certification body during Stage 1/2 review — so the internal audit they require is the internal audit they accept.

How we work

Four phases, three to five weeks.

  1. 01

    Scoping & audit programme

    Week 1

    We agree the audit objectives, applicable framework(s), scope (sites, departments, systems, processes), criteria, and methods. Output: an audit programme that the certification body or regulator will recognise.

  2. 02

    Document review & checklists

    Weeks 1–2

    A structured review of your information security policies, procedures, and supporting evidence against the framework requirements. Output: prepared checklists that drive the on-the-ground audit.

  3. 03

    Main audit

    Weeks 2–4

    Employee interviews, observation of controls in operation, evidence collection, and verification that documented procedures match operational reality. Conducted on-site or remote depending on your setup.

  4. 04

    Audit report & corrective action plan

    Weeks 4–5

    A complete audit report — executive summary, conformance status, findings with evidence references, and a prioritised corrective action plan with recommended owners and timelines. Delivered with a debrief session for management.

When you need this

Some signals an internal audit is overdue.

Most engagements come from one of these triggers. If two or three apply at once, the audit is usually well-timed.

  • You are pursuing or maintaining ISO 27001 certification — Clause 9.2 mandates a documented internal audit.
  • You fall under NIS2 and need to demonstrate effective risk management and governance.
  • You haven't had an independent security review in the past 12 months.
  • A customer, partner, or insurer is asking for evidence of your security program effectiveness.
  • You experienced a security incident — or near-miss — and need to verify which controls held and which did not.
  • Your external certification audit is approaching and you want gaps closed before the certification body finds them.
  • You went through an organisational change (acquisition, rapid growth, switch to remote) that altered your control surface.
  • You are subject to DORA or PCI DSS and an independent review is a regulatory expectation.

Internal hire vs independent auditor

Two ways to do an internal audit. Different cost, different result.

FactorCyber-Management (independent)Internal auditor (internal employee)
CostFixed fee, scoped to framework and organisation size; no ongoing employment costSalary + training + tooling + management time; difficult to justify for SMB scale
Time to start1–2 weeks from scoping callMonths — recruitment, training, framework certification
ObjectivityNo skin in the game — findings are findingsSame employer as the team being audited; bias risk inherent
AccreditationPECB ISO/IEC 27001 and ISO/IEC 42001 Lead Auditor in every engagementDepends on hire; often not framework-certified
Multi-framework breadthISO 27001, NIS2, GDPR, DORA, PCI DSS — practitioners work across allTypically deep in one framework, thin in the others
Acceptance by certification bodiesAudit file structured to certification-body evidence requirementsVariable — auditor independence sometimes challenged at Stage 2

FAQ

Common questions.

How is an internal audit different from a penetration test?
Different question entirely. A pen test answers 'can someone break into our systems?' — it's a technical exploitation exercise. An internal audit answers 'are we managing security correctly?' — it's a governance and compliance evaluation against a documented framework. ISO 27001 and NIS2 require documented internal audits; neither mandates penetration testing. Most mature security programs do both, but they're complementary, not substitutes.
Is there an acceptable number of non-conformities?
There's no prescribed limit, and zero findings is usually a sign the audit wasn't rigorous enough. The value of an audit is in three things: that the findings are documented with evidence, that root cause is properly analysed, and that corrective actions have owners and timelines. An audit with five well-documented findings and a tight action plan is worth more than an audit with zero findings and no follow-through.
Can you provide both the implementation and the audit?
Yes — with formal objectivity management. ISO 27001 Clause 9.2 and NIS2 both require auditor independence from the function being audited. We address this by assigning a different practitioner to the audit than the one who supported the implementation, and by documenting the segregation in the audit programme. Certification bodies accept this arrangement when properly evidenced.
What's the difference between an internal (first-party) and external (third-party) audit?
A first-party audit is your organisation evaluating itself (internal). A third-party audit is conducted by an accredited certification body (external). The two are sequenced: certification bodies require documented evidence of an internal audit before they will conduct the Stage 2 external audit. Internal audit also runs ongoing — it is part of the year-on-year ISO 27001 maintenance after certification.
How long does an internal audit take for an SMB?
Three to five weeks of elapsed time is the usual range, end-to-end — from scoping call to the delivered corrective action plan. Auditor effort within that window depends on scope: a tightly-scoped audit (one regulation, narrow process scope) might be 2–3 days of auditor time; a typical SMB engagement runs 5–10 days of auditor work spread across the elapsed weeks. We confirm both figures in the proposal after the scoping call.
What qualifications should an internal auditor have?
For ISO 27001 work the practical answer is PECB ISO/IEC 27001 Lead Auditor accreditation — that is what certification bodies look for in your evidence file. For ISO 42001 the equivalent is PECB ISO/IEC 42001 Lead Auditor accreditation. For NIS2, GDPR, DORA, PCI DSS the requirement is demonstrable knowledge of the regulation plus a credible audit methodology. Our practitioners hold both Lead Auditor accreditations as standard, plus the EU GDPR Data Protection Officer certification; framework-specific knowledge varies by audit but is always documented in the audit programme.
How is the engagement priced?
A fixed fee for the audit project, milestone-based: scoping call free, then 50% on signature, 50% on report delivery. Optionally followed by a smaller retainer if you want quarterly check-in audits or annual cycle support. All numbers fixed and shared in the proposal after the scoping call. No surprise bills, no hourly tracking.