Skip to content

ISO 27001 & ISO 42001 Internal Audit

Clause 9.2 of ISO/IEC 27001:2022 (ISMS) and ISO/IEC 42001:2023 (AIMS) requires internal audits at planned intervals, and a weak audit programme is a common major nonconformity. Our fixed-price, deep-dive audit meets the requirement and uncovers the minute gaps standard audits miss.

What is an internal audit?

An internal audit is an independent, systematic review of an organisation's management system — an ISMS under ISO/IEC 27001 or an AIMS under ISO/IEC 42001 — against the standard's requirements. Required before certification and surveillance audits, it identifies non-conformities and opportunities for improvement.

Our Approach

An Internal Audit That Actually Finds Things

Most internal audits confirm what you already know. Ours is built to find what you don't.

Depth over checklists

Standard internal audits sample the obvious. Our methodology goes deeper, tracing controls into day-to-day operations to surface the minute gaps most audits walk straight past.

Findings you can act on

Every nonconformity and observation is classified by severity and paired with a recommended corrective action, so your remediation effort goes where it matters most.

External-audit ready

We audit the way certification bodies do. Close our findings before your external audit and there should be no surprises on the day.

Delivered by ISO/IEC 27001 and ISO/IEC 42001 Lead Auditor certified consultants, working to ISO 19011 audit guidelines. We audit against ISO/IEC 27001:2022 and ISO/IEC 42001:2023.

Who This Is For

When to Book an Internal Audit

If any of these sound familiar, an independent internal audit is your next step.

Your first certification audit is approaching and you need an internal audit on the record.

A surveillance audit is due and your internal audit programme has fallen behind.

Your internal auditor has left, or is too close to the ISMS to audit it impartially.

Your last internal audit found nothing, and you doubt that reflects reality.

What You Receive

Deliverables

Everything you need to close findings before your external audit, delivered at completion of the engagement.

Internal Audit Report

A comprehensive report covering the audit scope, methodology, and results against ISO/IEC 27001:2022 or ISO/IEC 42001:2023.

Nonconformity & Observation Log

A structured log of every finding, with each nonconformity and observation clearly classified by severity.

Prioritised Remediation Plan

Recommended corrective actions, prioritised so you can close findings ahead of your external audit.

Findings Walkthrough

A dedicated walkthrough session with your team to explain the findings and agree on next steps.

Pricing

One Fixed Price. No Surprises.

A complete internal audit engagement for your ISMS (ISO/IEC 27001:2022) or AIMS (ISO/IEC 42001:2023).

Internal Audit Engagement

ISMS (ISO/IEC 27001:2022) or AIMS (ISO/IEC 42001:2023)

$7,000 + GST
  • Typically completed in two to four weeks
  • Internal Audit Report
  • Nonconformity & Observation Log
  • Prioritised Remediation Plan
  • Findings Walkthrough

Fixed-price engagement. Price in AUD, exclusive of GST.

FAQ

Frequently Asked Questions