
Evaluate
ISO/IEC 27001 audit
An independent audit against ISO/IEC 27001 that issues a conformity opinion and classified findings. We run it as your internal audit under clause 9.2, as a second-party audit of a supplier, or as a dry run before your certification body arrives.
Duration
1–3 weeks depending on scope
Built on
ISO/IEC 27001:2022 · ISO 19011 · ISO/IEC 17021-1
Indicative price
€8,500–19,000 per engagement
Who this is for
Internal audit or assurance
Owns clause 9.2 and needs it performed by someone independent of the people who built the system.
CISO
Wants to know what the certification body will find, before they find it.
Procurement or supplier management
Needs a supplier's claims tested rather than taken on trust.
Managing director
Is signing a management review and wants the record to be real.
Three different things are called an audit
The word covers three distinct engagements and confusing them is expensive. The certification audit is performed by an accredited certification body and only they can issue the certificate. The internal audit is mandatory under clause 9.2 and must be performed by someone independent of the activity being audited. The second-party audit is you auditing a supplier, or a client auditing you.
We perform the second and third. We cannot perform the first, and neither can anyone who implemented your management system — the independence requirement exists precisely to prevent it. Any firm offering to both build and certify your ISMS is telling you something about how it works.
The internal audit is the one most often done badly. It is a mandatory clause, it must be planned as a programme rather than a single event, and it must produce records. Done as a box-tick in the fortnight before Stage 1, it is transparently a box-tick, and a certification auditor recognises the pattern immediately. Done properly it is the cheapest possible way to find your nonconformities while they are still yours to fix.
What separates a useful audit from a performative one is the evidence standard. An auditor who accepts 'yes, we do that' produces a clean report and no value. We ask to see the artefact — the ticket, the log, the signed record, the actual configuration — and where it does not exist, that is the finding.
Findings are classified and written to be defended. A nonconformity that cannot survive being challenged by the person it is aimed at is not worth raising.
How we do it
- 01
Audit programme and plan
2–3 days
Scope, criteria, objectives and the sampling approach, agreed in writing. For an internal audit we set the annual programme so that the whole ISMS is covered across the cycle rather than the same easy areas every year.
- 02
Document review
2–3 days
The management system documentation against the clauses, before any fieldwork. This is where most of the preparatory findings come from.
- 03
Fieldwork
3–8 days
Interviews, observation and evidence sampling across the scope. We follow the process as it actually runs, including asking the person doing the work rather than the person who wrote the procedure.
- 04
Findings and classification
2 days
Each finding classified as a major nonconformity, a minor nonconformity, or an observation, with the clause or control it relates to and the evidence supporting it.
- 05
Closing meeting and report
1 day
Findings presented to management with the reasoning, then the written report. No finding appears in the report that was not raised in the room.
- 06
Corrective action follow-up
scheduled
Root cause, correction, corrective action and verification. An audit whose findings are never closed is an audit that achieved nothing.
Named artefacts
What you receive
- Audit programme covering the certification cycle, where this is an internal audit
- Audit plan with scope, criteria and sampling approach
- Working papers and the evidence examined
- Findings report with each finding classified and traced to a clause or control
- Nonconformity reports, written to be defensible
- Corrective action tracker with owners and dates
- Closing presentation for management
- Clause 9.2 records, complete, for your certification audit
What we need from you
- Access to the management system documentation, and to the systems and records we will sample.
- The people who actually operate the processes, not only the people who documented them.
- Independence — if we are auditing, we cannot also have built the thing we are auditing.
- A management commitment to act on findings. An audit nobody intends to act on is an expensive way to produce paper.
What changes
- 01You know what the certification body will find, while it is still yours to fix.
- 02Your clause 9.2 obligation is met with records that will withstand inspection.
- 03Findings are classified consistently, so the serious ones are visible as serious.
- 04Corrective actions are tracked to closure rather than to acknowledgement.
- 05Where we audit a supplier, you have tested their claims rather than filed them.
What it costs
€8,500–19,000 per engagement
All prices exclude VAT.
Questions
Can you issue our ISO 27001 certificate?
No. Certificates are issued only by accredited certification bodies, and they must be independent of whoever built the management system. We audit, we prepare you, and we support you through the external audit — but the certificate comes from the certification body.
Can you audit a system you implemented for us?
Not as your internal audit — that would breach the independence requirement and a certification auditor would raise it. We can run a readiness review and say plainly that it is not an independent audit, or we can bring in an auditor who was not part of the implementation.
How much of our time does it take?
Roughly an hour each from the people in scope, plus the system access. The document review and reporting happen without you.
What happens if you find a major nonconformity?
You find out from us rather than from your certification body, which is the entire point. We agree root cause and corrective action with you, and we verify the fix rather than take your word for it.

Leave with your top three risks documented
Thirty minutes with a senior practitioner. No slideware, no sales engineer.