ISO 27001 Annual Internal Audit and Surveillance Preparation

A risk-based ISO/IEC 27001 internal audit, corrective-action program, and organized handoff for certification-body surveillance.

An ISO/IEC 27001 certificate normally sits inside a continuing certification cycle. The organization maintains an internal audit program and management review, while its certification body performs separate surveillance and recertification activities. These are related—but they are not the same audit.

What we examine

  • Changes to the ISMS scope, interested parties, business processes, technology, locations, and suppliers.
  • Risk assessment and treatment decisions, including whether the Statement of Applicability remains accurate.
  • Operation of selected controls and the quality, coverage, and age of supporting evidence.
  • Security objectives, measurement results, incidents, exceptions, legal and contractual obligations, and continual improvement.
  • Status and effectiveness of corrections and corrective actions from previous internal or certification-body findings.

Deliverables for the annual cycle

The engagement produces an approved audit plan, criteria and sampling record, interview and evidence trail, internal audit report, finding register, corrective-action tracker, and an evidence index suitable for management review and surveillance preparation. Your organization retains and controls the records; the certification body determines what it wants submitted or made available.

Independence matters

Internal auditors must be objective and impartial about the work they audit. Where Readiness Assessors previously helped design or implement a control, we identify the conflict and adjust assignments or scope rather than claiming independent assurance over our own work.

Surveillance-ready does not mean guaranteed

We can test readiness and organize evidence, but only the accredited certification body can make certification decisions or determine the classification and closure requirements for its findings.

Our audit method is informed by the management-system auditing principles in ISO 19011. Confirm the exact audit program and submission expectations with your certification body.

Discuss an ISO 27001 annual audit