Internal Audits

Independent ISO 27001 & 42001 Internal Audits

Both standards require a periodic internal audit to keep your certification — a separate, independent check on your ISMS or AIMS, distinct from the certification body's external audit. If your program is already built (by us or anyone else), we can run this as a standalone engagement.

ISO 27001 ISO 42001
Why It's Required

Clause 9.2, Not Optional

Both ISO 27001 (clause 9.2) and ISO 42001 require you to conduct internal audits at planned intervals — typically annually — to check that your management system still conforms to the standard and is effectively implemented. Certification bodies expect to see evidence of this at every surveillance audit.

Auditors must be independent of the area being audited — you generally can't audit your own work.

Who This Is For

  • Already ISO 27001 or 42001 certified and due for your annual internal audit
  • Built your ISMS/AIMS in-house and need an independent auditor
  • Used a different consultant to build the program and need a separate reviewer for independence
  • Preparing for your first certification audit and want a dry run
What's Included

A Complete Internal Audit Cycle

Planned, executed, and documented to the standard your certification body expects.

🗂️

Audit Planning & Scope

A risk-based audit plan and schedule covering all required clauses and Annex A / Annex controls over your audit cycle.

🔍

Control Sampling & Testing

Interviews, evidence sampling, and walkthroughs to verify controls are implemented and operating as documented.

⚠️

Nonconformity Identification

Findings classified by severity, with root cause context so corrective action actually resolves the issue.

📋

Corrective Action Tracking

We track remediation to closure so open findings don't surface for the first time in front of your certification auditor.

📄

Internal Audit Report

A formal report suitable for your certification body and management review — the exact artifact auditors ask for.

🎯

Management Review Prep

Findings packaged into the inputs your leadership team needs for the required management review meeting.

🌐

ISO 27001 Internal Audit

Covers your ISMS against the clause requirements and the Annex A controls in your Statement of Applicability.

  • ISMS clause conformance (Clauses 4–10)
  • Annex A control sampling
  • Risk treatment plan review
🤖

ISO 42001 Internal Audit

Covers your AI Management System — governance, risk treatment, and controls over how AI systems are developed, deployed, and monitored.

  • AIMS clause conformance
  • AI risk & impact assessment review
  • Model lifecycle & data governance controls
Common Questions

Internal Audit FAQ

How often do I need an internal audit? +
At minimum once per certification cycle — most companies run it annually, timed a few months ahead of their surveillance or recertification audit so there's time to close any findings.
Can Nysa audit an ISMS or AIMS we built ourselves, or that another consultant built? +
Yes — that's the most common case. The internal audit standard requires independence from the process being audited, so we're often a better fit as auditor than the team (internal or external) that built the program.
Can you audit a program Nysa itself built for us? +
We'll flag it during scoping — independence rules mean the specific consultant who implemented your controls generally shouldn't also be the one auditing them. In that case we bring in a different auditor on our team, or can recommend a partner firm.
How is this different from your Hands-On vCISO service? +
Hands-On vCISO builds your entire program from scratch through first certification. Internal Audits is a lighter, standalone engagement for companies whose ISMS/AIMS already exists and just need the periodic independent audit to stay certified.

Due for your internal audit?

Book a free 30-minute consultation. We'll scope your audit cycle and give you a fixed-price quote — no obligation.