ISO/IEC 27001 Internal Audit

Independent ISMS audit, with less audit stress.

An independent internal audit of your information security management system — testing the Statement of Applicability, risk treatment and operating controls so your audit programme and certification preparation hold up to scrutiny.

ISO/IEC 27001 Lead Auditor
ISO/IEC 42001 Lead Auditor
JASANZ Technical Expert & Assessor
ASD IRAP Assessor

What you gain

Assurance your team can use.

Defensible findings

Conclusions linked to the criteria and evidence examined.

Clear priorities

Know what matters first and what can wait.

Less disruption

Evidence is reviewed before follow-up begins.

Minimum prerequisites

What needs to be in place.

The system does not need to be perfect, but there must be enough in place to audit.

Defined ISMS scope

A documented boundary identifying the organisational context, relevant systems and interested parties.

Statement of Applicability

A current record of applicable controls, implementation status and justified exclusions.

Risk assessment and treatment plan

Documented risk assessment, treatment decisions, risk owners and residual risk acceptance.

Internal audit programme

An audit programme and prior results, where the ISMS is already certified or in a surveillance cycle.

Operating evidence

Evidence that selected controls operate in practice, not only policies describing intent.

Audit coverage

Built around your ISMS and certification path.

The audit can cover clauses 4–10, applicable Annex A (2022) controls, your security policies, the internal audit programme and specifically agreed contractual or regulatory criteria.

Remote-first does not mean document-only.

Samples, demonstrations or focused interviews are used where documents do not establish how arrangements operate.

Typical evidence

  • Defined ISMS scope and organisational context
  • Statement of Applicability and selected control evidence
  • Risk assessment and treatment plan records
  • Policies, procedures and assigned responsibilities
  • Monitoring, review and improvement records
  • Representative evidence that controls operate

Delivery

From scope to report in four steps.

The standard engagement is remote-first and uses a controlled evidence workspace.

Scope

Confirm criteria, boundaries, timetable, responsibilities and handling.

Collect

Complete the questionnaire and upload requested evidence once.

Clarify

Respond only to focused gaps, conflicts or verification requests.

Report

Receive professionally reviewed findings, limitations and priorities.

What this is

An independent ISMS audit.

  • An internal audit against agreed ISO/IEC 27001 criteria
  • Assessment of ISMS requirements and applicable Annex A controls
  • Document review, operating evidence, sampling and targeted verification
  • A final report setting out findings and agreed priorities
What it is not

It is not certification, not an automated document score and not implementation disguised as audit.

Good fit / Not a fit

Is an ISO/IEC 27001 internal audit right for you?

Good fit
Maturity
Your ISMS is established or substantially established
What you want
Independent assurance over conformance, not implementation
Evidence
Policies, risk records and control evidence are mostly digital
Delivery
A remote-first review suits the scope
Not a fit
Maturity
The ISMS is not built yet
What you want
Help building the ISMS or urgent remediation
Evidence
Physical site inspection is central to the work
Delivery
Classified handling must be agreed before any engagement

FAQ

ISO/IEC 27001 internal audit questions.

Common questions before you start the fit check.

Is this an audit or implementation support?

It is an independent internal audit. We assess your ISMS against the agreed criteria; we do not design or implement the management system being audited.

Can it be done remotely?

Yes. The standard engagement is remote-first and evidence-led, with targeted clarification, samples or demonstrations only where documents do not show how a control operates.

What evidence is needed?

Typically the ISMS scope, Statement of Applicability, risk assessment and treatment records, security policies and evidence that selected controls operate. Nothing is shared until after acceptance, through a secure workspace.

Do we need everything ready first?

The ISMS does not need to be perfect, but there must be enough in place to audit. Where the SoA or risk treatment is only partly in place, those areas are reported as gaps rather than conformance findings.

What happens after the fit check?

You submit a single Request engagement form with your result. If TRUSTYCYBER accepts the engagement, you receive confirmed scope, terms, a payment link and access to the evidence workspace.

Is this suitable before certification?

Yes. A pre-certification internal audit is framed to surface what would fail a stage-2 or surveillance audit, so you can close it first. Certification itself remains with an accredited body.

What happens if TRUSTYCYBER does not accept the engagement?

No evidence is requested and no payment is taken. Where part of your scope may still fit, or another provider is better placed, we say so.

Ready to test the fit for ISO/IEC 27001?

Tell us about your information security management system, scope and timing before sharing evidence.

Check your fit →