Services

ISMS internal audit, surveillance support and maintenance

For organisations that are already certified: an independent internal audit, preparation for surveillance and recertification visits, the transition from the 2013 edition to ISO/IEC 27001:2022, and a retained ISMS manager when you do not have one.

What we do

  1. Internal audit (clause 9.2)

    A full audit of your ISMS against the standard and your own policies, with a report your certification body will accept as evidence. We audit, and we keep the audit independent: we do not fix the findings in the same engagement unless you ask us to.

  2. Surveillance and recertification preparation

    A readiness review three to six weeks before the external audit: open nonconformities, overdue risk reviews, missing records and controls that have drifted since the last visit.

  3. Transition to ISO/IEC 27001:2022

    Restructuring the Statement of Applicability to the 93 controls, updating the risk treatment plan and policies, and briefing your team on what the auditor will look for under the new edition.

  4. ISMS manager as a service

    A retained number of days each month to run risk reviews, supplier reviews, incident follow-up, metrics and the management review on your behalf.

What you receive

  • Internal audit plan, checklist and report with graded findings
  • Corrective action log
  • Pre-audit readiness report
  • Updated Statement of Applicability, risk register and policies (transition projects)
  • Monthly ISMS status report (retainers)

Common questions

Can you audit an ISMS you helped us build?
Not in the same cycle. If we implemented your ISMS, the clause 9.2 internal audit should be done by someone else, and we will tell you that up front. We are glad to audit systems built by other consultants or in house.
How often does the certification body visit?
Once a year in each of the two years between recertification audits. Your internal audit and management review must take place before each visit.

Related services

Business continuity and ISO 22301

Business impact analysis, continuity plans and exercises that prove the plans work. Certifiable to ISO 22301 if you need the certificate.

Not sure where you stand? Start with a scoping call.

Forty-five minutes, no charge. We ask about your organisation, what is driving the project and what you already have in place, then send a written proposal with a fixed scope and fee.