Internal and certification-support audits of your Information Security Management System against ISO/IEC 27001:2022 and its Annex A controls.
ISO 27001 certification signals a mature, risk-based approach to information security. Maintaining it requires regular internal audits and clean surveillance and recertification audits.
We audit your ISMS against the management-system clauses and Annex A controls, verifying that your risk treatment, policies and controls are implemented and effective — and that you’re ready for the certification body.
Context, leadership, planning, support and operation.
Methodology and documented risk decisions.
Organisational, people, physical and technological.
Justification and coverage review.
Programme effectiveness and management review.
Where this engagement tends to add the most value.
ISO/IEC 27001 certification is achieved and maintained through independent audit and is increasingly required by clients, tenders and regulators; the audit verifies that your ISMS is both well-designed and operating effectively.
A disciplined sequence that ends in a clear, evidence-backed outcome.
Confirming the ISMS scope, Statement of Applicability and documentation.
Reviewing the ISMS design and readiness for certification.
Testing that the ISMS operates effectively in practice.
Raising and classifying nonconformities against the standard.
A clear audit report with findings and required actions.
Certification recommendation and the ongoing surveillance plan.
We tie this engagement to the frameworks and regulations you answer to.
What to have in place before we begin.
Explore this offering in detail.
Learn more →Explore this offering in detail.
Learn more →Explore this offering in detail.
Learn more →Back to the full pillar.
View pillar →Talk us through your needs, and we’ll tailor the engagement to match.