Internal Audit
ISO 27001 compliance through an outside lens
Where does the internal audit fit?
The internal audit is the third stage in Braveson’s ISO 27001 service path, carried out after the GAP analysis and before the certification audit and ongoing support.
Kick-off
ISO 27001 Starter
€2,500 (excl. VAT)2Maturity assessment
ISO 27001 GAP Analysis
€5,850 (excl. VAT)Internal audit
ISO 27001 Internal Audit
€4,000 – 7,000 (excl. VAT)Ongoing support
Security Manager service
€3,000 / month (excl. VAT)Surface blind spots before the certification audit
ISO 27001 requires an internal audit every year, but an organization can’t audit itself objectively. An outside auditor finds the blind spots your own staff has become used to, and gives you an honest picture of where you stand before an external certification auditor does the same.
An internal audit is also the best way to prepare for the certification audit: you find and fix nonconformities yourself, before they cost you.
What does the package include?
Audit plan
- Defining the audit scope and objectives
- Audit schedule and responsibilities
- Confirming audit criteria (ISO 27001:2022 + your SoA)
- Document request to the client
Document review
- Information security policy, ISMS scope, SoA
- Risk register and risk management process
- Process descriptions: incident management, access management, change management
- Results and corrective actions from previous audits
Interviews and sampling
- Management interview: commitment, resources, objectives
- IT lead interview: technical controls
- Process owner interviews
- Sampling: logs, access rights, training records
Report and review
- Audit report: findings classified (major nonconformity / minor nonconformity / improvement opportunity)
- Prioritized corrective action plan
- Results review with management
What do you get, concretely?
Audit plan
A documented audit programme and criteria
Audit report
Findings, nonconformities, improvement opportunities
Nonconformity list
A prioritized list of items to fix
Corrective action plan
Responsibilities, timelines, tracking metrics
Who is this service for?
Ideal customer
- ISO 27001 certified organization with an annual audit coming up
- Pursuing certification and wants to know if they’re ready
- Management wants an independent view of how well the ISMS works
Not a fit if
- The organization has no ISMS or documentation at all: start with the ISO 27001 Starter
How does the project proceed?
Delivered remotely or on-site, as agreed.
Week 1
Audit plan + document request
Week 1–2
Remote document review
Week 2–3
Interviews and sampling (1–2 days)
Week 3–4
Report writing
Week 4
Results review with management
Price and terms
- Price
- €4,000 – 7,000 (excl. VAT) – confirmed during scoping
- Billing
- Monthly, based on work carried out
- Delivery
- Remotely or on-site, as agreed
- Language
- Finnish or English
Next step
Get in touch and we’ll schedule a free 30-minute scoping call.
The audit is based on the requirements of the ISO/IEC 27001:2022 standard.