Skip to content
Services · Security Development

Internal Audit

ISO 27001 compliance through an outside lens

€4,000 – 7,000 (excl. VAT)2–4 weeks from planning to reportFor organizations certified to ISO 27001 or pursuing it
Service path

Where does the internal audit fit?

The internal audit is the third stage in Braveson’s ISO 27001 service path, carried out after the GAP analysis and before the certification audit and ongoing support.

Why this service?

Surface blind spots before the certification audit

ISO 27001 requires an internal audit every year, but an organization can’t audit itself objectively. An outside auditor finds the blind spots your own staff has become used to, and gives you an honest picture of where you stand before an external certification auditor does the same.

An internal audit is also the best way to prepare for the certification audit: you find and fix nonconformities yourself, before they cost you.

What does the package include?

Step 1

Audit plan

  • Defining the audit scope and objectives
  • Audit schedule and responsibilities
  • Confirming audit criteria (ISO 27001:2022 + your SoA)
  • Document request to the client
Step 2

Document review

  • Information security policy, ISMS scope, SoA
  • Risk register and risk management process
  • Process descriptions: incident management, access management, change management
  • Results and corrective actions from previous audits
Step 3

Interviews and sampling

  • Management interview: commitment, resources, objectives
  • IT lead interview: technical controls
  • Process owner interviews
  • Sampling: logs, access rights, training records
Step 4

Report and review

  • Audit report: findings classified (major nonconformity / minor nonconformity / improvement opportunity)
  • Prioritized corrective action plan
  • Results review with management

What do you get, concretely?

Audit plan

A documented audit programme and criteria

Audit report

Findings, nonconformities, improvement opportunities

Nonconformity list

A prioritized list of items to fix

Corrective action plan

Responsibilities, timelines, tracking metrics

Who is this service for?

Ideal customer

  • ISO 27001 certified organization with an annual audit coming up
  • Pursuing certification and wants to know if they’re ready
  • Management wants an independent view of how well the ISMS works

Not a fit if

  • The organization has no ISMS or documentation at all: start with the ISO 27001 Starter

How does the project proceed?

Delivered remotely or on-site, as agreed.

Week 1

Audit plan + document request

Week 1–2

Remote document review

Week 2–3

Interviews and sampling (1–2 days)

Week 3–4

Report writing

Week 4

Results review with management

Price and terms

Price
€4,000 – 7,000 (excl. VAT) – confirmed during scoping
Billing
Monthly, based on work carried out
Delivery
Remotely or on-site, as agreed
Language
Finnish or English

Next step

Get in touch and we’ll schedule a free 30-minute scoping call.

Book a scoping call

The audit is based on the requirements of the ISO/IEC 27001:2022 standard.