ISO 27001 Internal Audit
A thorough, no-nonsense check from A to Z so your external audit runs smoothly, stress-free, and without a hitch.
Stopping 'brushing your teeth for the dentist': no more last-minute scrambling to clean up the books and act as if everything has been running perfectly all year.
Schedule your ISO Internal AuditThe ISO 27001 internal audit is an independent review under clause 9.2, performed by a senior auditor. Within 72 hours you receive a report with findings, recommendations and the improvements to make before the external audit. Fixed price: 1,600 euros for a small organization; mandatory every year for certificate holders.
A system that only works when the auditor shows up
We see it often: a management system that grinds to a halt between two audits. The backlog grows invisibly, the audit date approaches, and the certainty the certificate should give your clients starts to wobble internally.
This is the recurring problem with the traditional ISO approach: a system that only works when the auditor shows up. It is stressful, inefficient, and it proves one thing: your Information Security Management System (ISMS) is not working consistently.
- Lost focus you pull your best people away from their core tasks to tick boxes for the audit. This costs revenue.
- Uncertainty you are not sure whether the external auditor will find the gaps in your system. That uncertainty drains energy.
- The repetition without a sober, independent look, you stay stuck in the same chaos every year.
With an internal audit from AuditDirect, you know exactly what to expect.
The internal audit breaks that pattern. An independent senior auditor puts a finger on the sore spots while there is still time to fix them. The external audit changes from a nervous gamble into a dress rehearsal whose outcome you already know.
-
Documents and policy
We dive into your policy, your risk register, and the reports of earlier audits.
-
Conversations on the work floor
We talk to the people who carry out the policy: IT, HR, management. We look not only at the documents, but at how the processes really run.
-
Within 3 working days: report and explanation
Not a thick book with vague recommendations, but a directly usable document.
Your stress-free dress rehearsal.
The Internal Audit is a mandatory part of ISO 27001 (clause 9.2). But we do it differently. It is not a random checklist. It is your stress-free dress rehearsal by a party that knows exactly what the external auditor looks at and what they do not worry about. We are not looking for errors, but for certainty.
We make sure you are prepared for the audit. Our knowledge of the audit standards ensures that you can focus on continuous improvement and not on paper perfection.
You know exactly where you stand. No more panic, just a focused action list to take care of the final details.
The priorities are crystal clear. Teams stop wasting time on noise and unimportant side issues.
Sources
The standard texts and supervisory guidance this page is based on.
- ISO/IEC 27001:2022, the standard text NEN (Dutch standardisation institute)
- Frequently asked questions about ISO/IEC 27001 NEN
- ISO/IEC 27002:2022, the controls behind Annex A NEN
Schedule your ISO 27001 Internal Audit before the external auditor arrives.
- 01
Response within one business day
You hear from us personally, never from an autoresponder.
- 02
A call with a senior specialist
45 minutes with a consultant who knows your standard and sector. Free and without obligations.
- 03
A concrete proposal
You decide at your own pace. The engagement is concluded directly with the consultant.
Prefer direct contact? rob@auditdirect.nl +31 6 300 24 200