SERVICES
Internal audit
ISO 27001 and ISO/IEC 42001 both require an internal audit before certification and every year afterwards. It cannot be carried out by the body that certifies you.
Why it is usually outsourced
The auditor has to be competent in the standard and independent of the work being audited. In a company of thirty people, the person who built the management system is usually the only person who understands it, and they cannot audit their own work.
The requirement does not go away, and a missing or superficial internal audit is a common finding at certification.
What we do
- We plan the audit against the clauses and controls in your scope.
- We examine the evidence, interview the people who operate the controls, and test whether what is documented matches what happens.
- We report findings, distinguishing what must be corrected before certification from what is an opportunity to improve.
- We agree corrective actions and verify that they have been completed.
Before certification, and every year after
The first internal audit sits between implementation and Stage 1. After that it repeats annually for as long as you hold the certificate. Companies that treat it as a formality tend to meet the same findings again at surveillance.
RELATED SERVICES