Internal Audit
Independent assurance that your controls are working the way your policies say they are. Risk-based internal audit of cybersecurity and IT, with rated findings and agreed management actions.
Overview
Internal audit provides independent, objective assurance that your controls are designed correctly and operating effectively. For cybersecurity and IT, that means control testing against what your policies and procedures and frameworks describe, compared to what is actually happening in your environment. Internal audit services deliver the insight that self-assessment cannot, because objectivity is the point. Auditors who are independent of the teams they review find things that internal reviews miss.
We deliver internal audit services as a standalone service or co-sourced alongside your team. The engagement follows a risk-based audit plan agreed with you, tests controls with evidence, and reports findings rated by risk with practical recommendations and root causes identified. Documentation of control environments and gap assessments gives leadership the transparency they need to manage potential risks. We track agreed management actions through to closure, not just to the point of issuing the report.
This service satisfies the internal audit requirements of ISO/IEC 27001 and ISMS governance, supports the periodic review expectations of SOC 2 readiness programs, and meets any governance structure that calls for independent control assurance. Regulatory compliance depends on being able to demonstrate that controls are not just documented but actually operating. Internal auditors provide that evidence. Financial statements and operational efficiency both benefit when IT internal control environments are demonstrably sound.
What’s included
- Risk-based internal audit plan
- Control testing against policies and procedures, frameworks, and obligations
- Evidence-backed findings rated by risk
- Root-cause analysis and practical recommendations
- Agreed management action plan
- Follow-up on remediation progress
- Regulatory compliance assessment where applicable
- Gap analysis documentation for identified control weaknesses
How we work
-
01
Plan
We build a risk-based audit plan and agree the scope, objectives, and criteria with you before any testing begins. The audit process starts with planning because scope determines what assurance the report can actually provide.
-
02
Test
We test control design and operating effectiveness with evidence, using sampling where appropriate and documenting every finding with its source. Internal auditors evaluate both what the policies and procedures say and what the evidence shows.
-
03
Report
We deliver rated findings with root causes and recommendations written for the people who own the controls. Insight is most useful when it reaches the people who can act on it. Stakeholder communication is part of the reporting phase.
-
04
Follow up
We track agreed management actions to closure so the audit findings translate into actual improvement. The audit team does not close engagement until management actions have been verified.
What you get
- Internal audit plan and scope
- Audit report with rated findings and root causes
- Management action plan
- Remediation follow-up tracking
Frequently asked questions
Can your internal audit service satisfy the ISO 27001 internal audit requirement?
Yes. ISO/IEC 27001 requires periodic internal audits of the Information Security Management System. We can perform these as internal audit services independently on your behalf. Independent delivery also strengthens objectivity when your certification body reviews the audit evidence. Our auditing team maintains the separation from operational teams that the standard requires.
Do you replace our existing internal audit function?
We can provide the function fully as a service, or co-source alongside an existing internal audit team, depending on your governance model, resourcing, and the independence requirements of your audit charter. The option to outsource internal audit is chosen by many organisations that want specialist cybersecurity expertise without building a permanent function.
How is internal audit different from a penetration test?
Internal audit tests whether your documented controls are designed and operating as intended, using evidence and interviews. The audit process evaluates information systems, policies and procedures, and operational compliance. A penetration test simulates an attack to find technical vulnerabilities that controls may have missed. They answer different questions and are often used together to build a complete picture of control effectiveness.
Credentials held by our team










How ready is your security and compliance?
Answer 15 quick questions across the controls auditors actually check, and get an instant readiness score with tailored next steps. No call required.
Ready to simplify security and compliance?
Pick a service, book a scope call, or ask a question. Whatever order works.