> For the complete documentation index, see [llms.txt](https://docs.cyberally.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.cyberally.com/internal-audit-your-practice-run-for-iso-certification.md).

# Internal Audit: Your Practice Run for ISO Certification

Internal audits are a **mandatory step** in achieving and maintaining ISO certifications such as **ISO 27001 (Information Security)**, **ISO 27701 (Privacy)**, and **ISO 42001 (AI Management)**.

Think of the internal audit as your **"dress rehearsal"**: it's where you test your management system, find gaps, and fix them **before** the external auditor arrives. Done well, it makes certification smoother, less stressful, and more predictable.

## Why This Matters for Your Organisation

ISO certification is increasingly expected by enterprise and government clients worldwide, often as a prerequisite for procurement, vendor onboarding, or entering regulated industries. Regardless of where you operate, ISO 27001 and ISO 27701 align closely with major privacy and security obligations such as the **GDPR** (EU), **Privacy Act** (Australia), **CCPA** (US), and similar frameworks across APAC, the UK, and beyond.

If your organisation is pursuing or maintaining ISO 27001, an annual internal audit isn't just best practice, it's a **certification requirement**.

## Why Internal Audit Matters

* **Certification Requirement**: No internal audit = no certification.
* **Early Warning System**: Identifies issues before your external audit.
* **Continuous Improvement**: Keeps your ISMS/PIMS/AIMS effective and relevant.
* **Risk Confidence**: Verifies that risks are treated properly and residual risk is acceptable to management.

## The Internal Audit Process (Step by Step)

1. **Plan the Audit**\
   Define scope, objectives, schedule, and auditor(s).
2. **Documentation Review**\
   Examine policies, procedures, standards, and records to ensure they are complete, up to date, and aligned with ISO requirements.
3. **Evidence Sampling**\
   Collect proof that processes are actually followed (for example, logs, tickets, meeting minutes, reports).
4. **Analysis**\
   Compare evidence against ISO requirements and your own policies.
5. **Audit Report (Clause 9.2)**\
   Summarise findings, highlighting any **non-conformances** (gaps) and improvement opportunities.
6. **Management Review (Clause 9.3)**\
   Senior leadership reviews the audit results and agrees on corrective actions.

## Preparing for Your Internal Audit

Here's what you should have ready for the auditor:

| Requirement                          | What Auditor Looks For                                        | Typical Evidence                                                                           |
| ------------------------------------ | ------------------------------------------------------------- | ------------------------------------------------------------------------------------------ |
| **Organisational Context**           | Scope of the ISMS/PIMS/AIMS and interested parties identified | Scope document, stakeholder list                                                           |
| **Leadership Commitment**            | Proof management is actively involved                         | Information security/privacy policy signed by leadership, meeting notes                    |
| **Risk and Opportunity Management**  | Risks identified, assessed, and treated                       | Risk register, treatment plan                                                              |
| **Statement of Applicability (SoA)** | Controls selected/excluded with justification                 | SoA document                                                                               |
| **Policies and Evidence**            | Policies exist and are followed in practice                   | Access control policy + user access review records, incident response plan + incident logs |

## Common Internal Audit Findings

These are the most frequent issues we see:

1. ISMS scope is unclear or incomplete.
2. Risk assessment doesn't align with treatment plan.
3. Objectives are missing, vague, or not measured.
4. Statement of Applicability lacks detail.
5. "Say-do gap": policies exist, but no evidence they're followed.

## Dealing with Non-conformances

Non-conformances aren't failures. They're opportunities.

* **Minor**: A small gap (for example, policy not reviewed in 12 months). Fix before certification.
* **Major**: A significant gap (for example, no risk assessment). Must be corrected before certification can continue.

**How to fix them:**

1. Identify the root cause.
2. Define corrective actions and assign ownership.
3. Implement and track progress.
4. Re-test to confirm effectiveness.

## Pro Tips for a Smooth Audit

{% hint style="success" %}

* Treat it as a **practice run**. Don't hide issues, surface them early.
* Schedule your internal audit **1 to 2 months before your external audit** so you have time to fix findings.
* Use **Vanta** to organise your evidence, track control status, and demonstrate audit readiness at a glance.
* Document everything. Auditors love traceability.
  {% endhint %}

## FAQ

<details>

<summary>How often do we need to run internal audits?</summary>

At least once per year and before each certification audit. Larger organisations often audit quarterly by area but it is not mandatory.

</details>

<details>

<summary>How long does an internal audit typically take?</summary>

For a small-to-mid-size organisation, expect 2 to 4 weeks from planning to report. This includes scheduling interviews, reviewing documentation, collecting evidence, and drafting findings. Using a compliance platform like Vanta significantly reduces this time.

</details>

<details>

<summary>Can we audit ourselves?</summary>

You can, but the auditor must be **competent and independent** (not auditing their own work). Many organisations use an external vCISO partner for objectivity and this also satisfies the ISO requirement for independence without the cost of hiring a dedicated internal auditor.

</details>

<details>

<summary>What if we fail the internal audit?</summary>

There's no "fail." Findings are opportunities to fix issues before the external audit, where they actually count.

</details>

<details>

<summary>What's the difference between ISO 27001, ISO 27701, and ISO 42001 in terms of internal audit scope?</summary>

The process is the same but the scope differs. ISO 27001 covers your information security management system (ISMS). ISO 27701 extends this to a privacy information management system (PIMS), and is particularly relevant given Australia's Privacy Act obligations. ISO 42001 addresses AI management systems (AIMS) and is increasingly relevant for organisations developing or deploying AI. Cyber Ally can support internal audits across all three.

</details>

## How Cyber Ally Can Help

Cyber Ally conducts independent internal audits for ISO 27001, ISO 27701, and ISO 42001. As your external vCISO partner, we bring both the technical expertise and the auditor independence that ISO requires, without the overhead of a full-time hire.

Our internal audit service includes:

* Scoping and audit planning
* Documentation and evidence review
* Interviews with key personnel
* Findings report with prioritised corrective actions
* Management review facilitation
* Follow-up support ahead of your external certification audit

We also use **Vanta** to streamline evidence collection and keep your compliance posture visible year-round.

[Book a conversation with our team](https://meetings-ap1.hubspot.com/meetings/cyberally/engage)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.cyberally.com/internal-audit-your-practice-run-for-iso-certification.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
