Home / Services / ISO 27001 internal audit
service 07 — certification

The 5-Day Internal Audit.

You're on Sprinto, Vanta, Drata or Scrut. Your evidence is collected, your controls are mapped — and then Stage 2 stalls, because ISO/IEC 27001:2022 Clause 9.2 requires an internal audit by someone independent of the work being audited, and a platform structurally cannot audit its own customers' output. That's the audit we do: on top of the evidence your platform already holds, conducted and signed by a CQI/IRCA-certified ISO/IEC 27001:2022 Lead Auditor (Certificate No. ISMSLA/25/15/0124). Fixed fee. Five business days from evidence access to signed report.

CQI/IRCA27001:2022 Lead Auditor
5 daysEvidence to signed report
Clause 9.2Independent by design

Your platform can't audit itself.

Compliance platforms are excellent at what they do: continuous evidence collection, control mapping, task nagging. But Clause 9.2 asks for something they cannot supply — an audit that ensures objectivity and impartiality, performed by someone independent of the work audited. The platform designed your control set and gathers its evidence; it is the work being audited. Certification bodies know this, and an internal audit with no independent auditor behind it is one of the most common reasons Stage 2 gets deferred.

We close that gap without disturbing your stack. Your platform stays the system of record; we audit on top of its exports and read-only views, which is exactly why five days is enough.

How the five days run

  • Day 1 — scope & plan — ISMS scope, Statement of Applicability and risk assessment reviewed; a risk-based Clause 9.2 audit plan issued the same day.
  • Days 2–3 — controls testing — Annex A controls sampled and tested as operated, against the evidence in your platform plus targeted control-owner interviews.
  • Day 4 — findings — nonconformities classified major/minor with evidence, plus observations and opportunities for improvement, walked through with your team.
  • Day 5 — report — the signed internal audit report and Clause 9.3 management-review inputs delivered, with corrective-action guidance your team can actually close.

What you receive

  • Risk-based audit plan — a Clause 9.2 audit programme covering your ISMS scope, aligned to your certification calendar.
  • Annex A controls testing — controls examined as they actually operate, not just as documented in the SoA.
  • Nonconformity log — majors and minors with evidence, severity rationale, and practical corrective-action guidance.
  • Management-review inputs — the Clause 9.3 package your leadership review needs, ready to table.
  • Signed internal audit report — issued under a CQI/IRCA-certified Lead Auditor's signature, accepted by certification bodies including BSI, TÜV and DNV at Stage 2 and surveillance.

Who this is for

  • 25–150-employee SaaS and IT services firms — big enough to certify, too lean to staff an independent internal auditor.
  • First certification or surveillance cycle — pre-Stage 2 full-scope audits, or the recurring audit your certificate needs to stay healthy.
  • Evidence already in a compliance platform — Sprinto, Vanta, Drata or Scrut doing the collection; us doing the independent judgement.

Audited by people who break systems

Most internal audits are paperwork reviews — a second pair of eyes on the same documents. Ours aren't, because our auditors also run offensive security engagements: when we test an access-control or logging control, we probe how it behaves under the conditions an attacker creates, not whether a policy PDF exists. The finding you get describes how the control actually operates — which is what your certification auditor is going to check.

On a DPDP timeline too?

If India's DPDP Act is on your compliance roadmap, add a DPDP readiness review to the same audit cycle — same evidence base, same interviews, one engagement instead of two.

// questions we hear

Before you ask.

Why can't our compliance platform run the internal audit?

ISO/IEC 27001:2022 Clause 9.2 requires internal audits that ensure objectivity and impartiality — in practice, an auditor independent of the work being audited. Your platform built your control set, collects its evidence, and monitors it daily; asking it to audit its own output is exactly the conflict the clause exists to prevent, and certification bodies check for it. The platform is the system of record. The audit has to come from outside it.

Do we have to leave Sprinto, Vanta, Drata or Scrut?

No — keep it. The platform is where your evidence lives, and that's precisely what makes the five-day timeline possible: we audit on top of the exports and read-only views it already maintains instead of rebuilding an evidence trail from scratch. The audit makes the platform's work certifiable; it doesn't replace it.

What access do you need?

A read-only or auditor seat on your compliance platform (or its exports), your Statement of Applicability, risk assessment and core ISMS policies, and short scheduled interviews with a handful of control owners. No agents installed, no production access, no credentials handed over — the same evidence-access discipline we'd expect you to demand of any auditor.

First certification or surveillance — is the audit the same?

Same five-day shape, different emphasis. Before first certification we run the full-scope Clause 9.2 audit your Stage 2 auditor expects to see completed. On a surveillance cycle we audit a risk-based rotation of the scope and regression-check previously raised nonconformities — so the certificate stays healthy instead of surprising you at renewal.

Is this the certification audit?

No — certification (Stage 1, Stage 2 and surveillance) is performed by an accredited certification body such as BSI, TÜV or DNV. What we deliver is the independent internal audit Clause 9.2 requires you to have done before they arrive — the signed report and management-review inputs the certification auditor reviews as evidence.

// before stage 2

Your registrar will ask who audited you.

"Our compliance platform" is not an answer they accept. A signed, independent Clause 9.2 report is — and it's five days away.

Book the five days →