ISO/IEC 27001 Internal Audit
Independent ISMS audit, with less audit stress.
An independent internal audit of your information security management system — testing the Statement of Applicability, risk treatment and operating controls so your audit programme and certification preparation hold up to scrutiny.
What you gain
Assurance your team can use.
Defensible findings
Conclusions linked to the criteria and evidence examined.
Clear priorities
Know what matters first and what can wait.
Less disruption
Evidence is reviewed before follow-up begins.
Minimum prerequisites
What needs to be in place.
The system does not need to be perfect, but there must be enough in place to audit.
Defined ISMS scope
A documented boundary identifying the organisational context, relevant systems and interested parties.
Statement of Applicability
A current record of applicable controls, implementation status and justified exclusions.
Risk assessment and treatment plan
Documented risk assessment, treatment decisions, risk owners and residual risk acceptance.
Internal audit programme
An audit programme and prior results, where the ISMS is already certified or in a surveillance cycle.
Operating evidence
Evidence that selected controls operate in practice, not only policies describing intent.
Audit coverage
Built around your ISMS and certification path.
The audit can cover clauses 4–10, applicable Annex A (2022) controls, your security policies, the internal audit programme and specifically agreed contractual or regulatory criteria.
Samples, demonstrations or focused interviews are used where documents do not establish how arrangements operate.
Typical evidence
- Defined ISMS scope and organisational context
- Statement of Applicability and selected control evidence
- Risk assessment and treatment plan records
- Policies, procedures and assigned responsibilities
- Monitoring, review and improvement records
- Representative evidence that controls operate
Delivery
From scope to report in four steps.
The standard engagement is remote-first and uses a controlled evidence workspace.
Scope
Confirm criteria, boundaries, timetable, responsibilities and handling.
Collect
Complete the questionnaire and upload requested evidence once.
Clarify
Respond only to focused gaps, conflicts or verification requests.
Report
Receive professionally reviewed findings, limitations and priorities.
What this is
An independent ISMS audit.
- An internal audit against agreed ISO/IEC 27001 criteria
- Assessment of ISMS requirements and applicable Annex A controls
- Document review, operating evidence, sampling and targeted verification
- A final report setting out findings and agreed priorities
It is not certification, not an automated document score and not implementation disguised as audit.
Good fit / Not a fit
Is an ISO/IEC 27001 internal audit right for you?
FAQ
ISO/IEC 27001 internal audit questions.
Common questions before you start the fit check.
Is this an audit or implementation support?
It is an independent internal audit. We assess your ISMS against the agreed criteria; we do not design or implement the management system being audited.
Can it be done remotely?
Yes. The standard engagement is remote-first and evidence-led, with targeted clarification, samples or demonstrations only where documents do not show how a control operates.
What evidence is needed?
Typically the ISMS scope, Statement of Applicability, risk assessment and treatment records, security policies and evidence that selected controls operate. Nothing is shared until after acceptance, through a secure workspace.
Do we need everything ready first?
The ISMS does not need to be perfect, but there must be enough in place to audit. Where the SoA or risk treatment is only partly in place, those areas are reported as gaps rather than conformance findings.
What happens after the fit check?
You submit a single Request engagement form with your result. If TRUSTYCYBER accepts the engagement, you receive confirmed scope, terms, a payment link and access to the evidence workspace.
Is this suitable before certification?
Yes. A pre-certification internal audit is framed to surface what would fail a stage-2 or surveillance audit, so you can close it first. Certification itself remains with an accredited body.
What happens if TRUSTYCYBER does not accept the engagement?
No evidence is requested and no payment is taken. Where part of your scope may still fit, or another provider is better placed, we say so.
Ready to test the fit for ISO/IEC 27001?
Tell us about your information security management system, scope and timing before sharing evidence.
