Home / Internal audit
Internal audit · ISO 27001 and HDS

ISO 27001 and HDS internal audits, run like a certification audit.

ISO 27001 requires an internal audit of your ISMS at planned intervals (clause 9.2). Ours is led by a practising ISO 27001 and HDS certification auditor, so it follows the same method as your certification audit: same sampling, same questions, same grading. You get a report your team can act on and your certification body can rely on.

ISO 27001 & HDS certification auditor40+ ISO 27001 internal auditsISO 27001 Lead Auditor
How the audit runs
01
Audit planScope, criteria, sampling and schedule agreed upfront.
02
Document reviewPolicies, risk assessment, SoA and records.
03
Interviews and evidenceProcess owners interviewed, controls sampled.
04
Audit reportGraded findings with evidence and references.
05
Closing meetingFindings explained, next steps agreed.
40+ISO 27001 internal audits delivered
Across
FinTechHealthTechAIHR servicesMarketplaces
Partners who trust us with their clients' audits
When you need it

The audit that keeps your certificate safe.

Before your initial certification

Certification bodies expect a full internal audit and a management review before stage 2. Finding gaps now costs far less than a nonconformity.

Every year, before surveillance

Surveillance audits check that your ISMS keeps running. A yearly internal audit shows it does, and catches drift early.

When your team can't audit itself

Internal auditors must be objective and impartial. In a small team, the people who built the ISMS can't audit their own work.

What's included

What you get

One report, readable by your team and by your certification auditor.

01

Audit programme and plan

Scope, criteria, sampling and interview schedule, agreed with you before the audit starts.

02

Full ISMS coverage

Clauses 4 to 10 and a risk-based sample of Annex A controls, plus the HDS requirements when they apply.

03

Graded findings

Major and minor nonconformities, observations and improvement opportunities, each with evidence and references.

04

Audit report

A clear report you can show your certification auditor as evidence of your internal audit.

05

Closing meeting

Every finding walked through with your team, so nothing comes as a surprise.

06

Prioritised recommendations

Practical next steps to close each finding before your next certification or surveillance audit.

Need help closing the findings? We can support your corrective actions as a separate engagement. Ask on a call →
The auditor's advantage

An internal audit with certification audit rigour.

Cyberbits Consulting is led by an ISO 27001 Lead Auditor who also audits for an accredited certification body. Your internal audit follows the same method, so your certification audit holds no surprises.

Same method as a certification audit. Sampling, interviews and evidence, not a document checklist.
Findings written the way auditors write them. Clear requirement, clear evidence, clear grading.
Objective by design. We never audit a management system we built ourselves.
“He supported us throughout our ISO 27001 implementation, from prioritizing clauses and controls to shaping our documentation approach and preparing for the external audit. What stood out beyond his technical expertise was his style: responsive, genuinely supportive, and always available when we needed guidance.”
Kevin KonrathCo-Founder, Basqo
FAQ

Internal audit questions

Can our own team run the internal audit?

Yes, if the auditors are competent, objective and impartial. In small teams, almost everyone helped build the ISMS, which is why many companies outsource the internal audit.

Does it cover HDS?

Yes. If you are HDS certified or preparing for it, we audit the HDS requirements along with ISO 27001.

How much does it cost?

Pricing is on request. It depends on your scope, number of sites and whether HDS is included. We send a fixed-fee proposal after a short call.

Is the audit remote?

Yes. Interviews and evidence reviews run by video call, in English or French.

Can you also fix the findings?

Yes, as a separate engagement. The audit itself stays objective: we report what we find.

Let's plan your internal audit.

30 minutes, free, no commitment. You leave with a timeline and scope estimate.

  • Your context, your deadline, a realistic scope
  • ISO 27001, HDS or both: what applies to you
  • In English or French, by video call
Prefer email? info@cyberbitsconsulting.com Calendar not loading? Open the booking page
Cyberbits Consulting
ISO 27001 and HDS certification, internal audit