Internal Audit & Control Assurance

Independent, evidence-based review of security and compliance controls before findings become surprises.

Control assurance

Test whether controls actually operate

Move beyond policy checks with defined criteria, walkthroughs, evidence testing and findings that management can turn into accountable corrective actions.

A practical audit flow

Plan → Understand → Test → Report → Follow up

Keep evidence, findings and remediation connected from planning through closure.

What an effective internal audit does

An audit should test the operating control environment, not simply confirm that documents exist.

Evidence-based testing

Gather sufficient evidence to evaluate whether controls are designed appropriately and operating as expected.

Actionable findings

Communicate condition, criteria, impact and recommendations so management can prioritize corrective action.

Where we can help

From audit planning through remediation follow-up.

01

Audit planning

Define objectives, scope, criteria, stakeholders, sampling approach and evidence requirements.

02

Walkthroughs

Understand how processes actually operate across people, technology and documentation.

03

Control testing

Test design and operating evidence against agreed criteria.

04

Finding analysis

Document condition, criteria, impact and practical recommendations.

05

Corrective actions

Translate findings into accountable actions, owners and target dates.

06

Follow-up

Review remediation evidence and update the closure status of findings.

Our audit approach

Six stages that keep testing rigorous and remediation actionable.

PlanEstablish scope, criteria, objectives and evidence needs.
UnderstandConduct interviews and walkthroughs to understand the environment.
TestExamine evidence using agreed procedures and sampling.
EvaluateDistinguish isolated documentation issues from systemic weaknesses.
ReportPresent findings with business context, risk and recommendations.

Typical deliverables

  • Audit scope, criteria and plan
  • Control test procedures and evidence request list
  • Working-paper and finding register
  • Management report with prioritized findings
  • Corrective-action / CAPA tracker
  • Follow-up and closure assessment

Common problems

  • Checklist auditing: document existence is checked instead of control operation.
  • Weak evidence criteria: requests do not specify what demonstrates effective operation.
  • Findings without owners: reports identify problems but leave remediation responsibility unclear.
  • Premature closure: a policy changes but operating evidence is still missing.

FAQs

Can an internal audit be performed before ISO 27001 certification?

Yes. An internal audit can help identify gaps and evidence weaknesses before an external certification audit, provided the scope and criteria are appropriate.

Can you audit against our own control framework?

Yes. The audit criteria can be an agreed framework, contractual requirement, policy baseline or combination of criteria.

Will an internal audit guarantee certification?

No. An internal audit improves readiness and identifies gaps, but certification or formal assessment outcomes remain the responsibility of the independent process.

Need an independent control review?

Tell us what framework, scope and assurance objective you need to evaluate.

Discuss an Internal Audit