ISO/IEC 27001:2022 · Internal Audit
An internal audit that looks like the real thing.

ISO 27001 clause 9.2 requires planned internal audits by someone objective and impartial. Small teams rarely have that person. We run your internal audit programme as an independent provider, using lead auditors who also audit on behalf of certification bodies, so findings surface before Stage 2 or surveillance, not during it.

ISO/IEC 27001:2022Certified · SANCERT ISO/IEC 42001:2023Certified · SANCERT Cyber EssentialsCertified Government Commercial AgencyApproved Supplier · G-Cloud 15
What we deliver

Independent, evidence-led and audit-body ready.

The same rigour a certification body applies, delivered early enough for you to act on it.

Audit programme

A risk-based plan covering clauses 4 to 10 and your applicable Annex A controls across the certification cycle.

Fieldwork

Remote or on-site interviews, sampling and evidence review, scheduled around your team.

Clear findings

Graded nonconformities, observations and opportunities, each tied to the requirement and the evidence.

Corrective action follow-up

We check that root causes are addressed and actions are effective before your next external audit.

Pre-certification audit

A full readiness audit before Stage 1 or Stage 2, so there are no surprises on the day.

Integrated audits

One audit across ISO 27001, ISO 27701, ISO 42001 and ISO 9001 where you run an integrated system.

Why Cybercontrols

Auditors who know what the certification body will ask.

100%Certification success for ISO 27001 and ISO 42001 clients
Lead auditorsWho audit for certification bodies
Remote or on-siteWhatever suits your operation
G-Cloud 15UK Government approved supplier
How it works

Plan, audit, report, close out.

Plan

Agree scope, risks and the audit programme, then book fieldwork dates.

Audit

Interview owners, sample records and test controls against the standard.

Report

Receive a clear report with graded findings and a summary for management review.

Close out

Verify corrective actions so findings are closed before the external audit.

Questions

Internal audit, answered plainly.

Can our own staff carry out the internal audit?

Yes, if they are competent and objective. Auditors must not audit their own work, and small organisations often cannot guarantee that independence, which is why many outsource the internal audit.

How often do we need an internal audit?

At planned intervals. Most organisations run an annual programme so that every clause and applicable Annex A control is covered within the three-year certification cycle.

Will our certification body accept an outsourced internal audit?

Yes, provided the audit is planned, carried out by competent and impartial auditors, documented, and its results reported to management. That is exactly how we deliver it.

Is there a conflict of interest if you also audit for certification bodies?

We never act as your internal auditor and your certification body auditor. Impartiality rules are strict and we follow them to the letter.

Can you audit ISO 27701 or ISO 42001 at the same time?

Yes. Where you run an integrated management system, one combined audit saves time and gives management a single view of conformity.

Find the findings before the auditor does.

Book a short call and we will scope your internal audit programme.