
Independent review of your ISMS
Does your ISMS work as intended?
An internal audit ISO 27001 shows whether your ISMS is well described and is working. Kynexis Information Security objectively assesses how the management system is set up, what measures have actually been introduced and what evidence shows that they work over time.
- You're working towards a first ISO 27001 certification.
- Phase 1, phase 2, surveillance or recertification is approaching.
- You want to periodically independent tests or controls to work demonstrably.
- Board or management wants certainty about the design, existence and functioning of ISMS.
What are the risks? If policies, implementation and evidence are not consistent, deviations are often detected only during the certification audit. This causes repair work under time pressure and gives management insufficient certainty about the actual functioning of ISMS.
Our promise of service
Security before an external auditor asks questions
The internal audit shall make available in good time any deviations, lack of evidence and administratively relevant points of improvement.
- Objective audit findings
- Assessment of evidence and effect
- Priorities for follow-up
ISO 27001 internal audit
What is Internal Audit ISO 27001?
An internal audit ISO 27001 shows whether your ISMS is well described and is working. Kynexis Information Security objectively assesses how the management system is set up, what measures have actually been introduced and what evidence shows that they work over time.
When does this service fit?
Periodic review or preparation for certification
This audit fits with organisations with an equipped ISMS that have to periodically check whether the management system is demonstrably satisfactory and functioning. The audit may be used before stage 1 or phase 2, in the case of surveillance or recertification and as part of the internal audit programme.
Research area
The ISMS, the controls and the evidence examined in conjunction
We set the precise scope and audit criteria in advance. Depending on your organisation, the following parts can be examined.
Scope, context and governance
Demarcation, stakeholders, objectives, roles, responsibilities and board-level engagement.
Risk analysis and treatment
Methodology, topicality, criteria, ownership, treatment choices, residual risk and link between risk and measure.
Statement of Application
Coherence between risks, chosen controls, actual design and justification of exclusions.
Policies and procedures
Usability, awareness and connection of fixed agreements to the daily execution.
Controls and evidence
Access, vulnerabilities, logging, backup, incidents, suppliers, awareness and continuity, among others.
Monitoring and improvement
Controls, management information, audit findings, corrective measures, management review and improvement cycle.
Evidence of control
Design, existence and operation
These concepts make it visible whether a measure goes beyond a description on paper.
Is the measure properly designed?
The chosen method is consistent with risk, organisation and purpose.
Has the measure actually been implemented?
Rolls, processes and technical or organisational facilities are provided.
Does the measure work demonstrably?
Sampling and evidence show that the measure was carried out during the relevant period.
Your result
A substantiated picture of deviations and operation
The report follows the agreed scope and gives management and ISMS-responsible direction for follow-up.
- Audit plan with scope, criteria and approach
- Management summary with conclusions and risks
- Underlying anomalies and observations
- Evidence assessment of design, existence and operation
- Priorities before certification or subsequent audit
- Final discussion with management and ISMS responsible
Choose based on your question
GAP analysis, audit readiness or internal audit?
The right shape depends on your starting point, the moment and the certainty you need.
Where are we?
Gaps and roadmap at the beginning or at the restart of the route.
See this route →Are we ready for the external audit?
Last vulnerabilities shortly before certification.
Does it meet and work with ISMS?
Objective audit findings within the internal audit programme.
Independent securing roleHow we work
This is how the internal audit is conducted
- 01
Entry and Scope
Capture purpose, audit criteria, parts, roles, planning and available evidence.
- 02
Document Review
Scope, risk analysis, SoA, policy, management review, previous audits and improvement register review.
- 03
Interviews and samples
With relevant roles practical examples and actual execution tests.
- 04
Evidence and re-examination
Findings underpin and verify facts and context before conclusions become final.
- 05
Reporting and discussion
Deviations, observations, risks and priorities management-oriented.
Choose based on your question
Which form of research suits your decision-making needs?
The routes differ in purpose, depth and the type of support you need.
Cyber Security Baseline Assessment
Compact and broad starting point for overview and priorities.
View Cyber Security Baseline Assessment →Cybersecurity Assessment
Focused floor for improvement and investment choices.
View Cybersecurity Assessment →Cyber Security Audit
Independent review of predefined criteria with traceable evidence and audit conclusion.
View Cyber Security Audit →ISO 27001 GAP Analysis
Standard diagnosis for a working and demonstrable ISMS.
View ISO 27001 GAP Analysis →NIS2 GAP Analysis
Legal diagnosis for duty of care, governance and chain.
View NIS2 GAP Analysis →NIS2 audit
Evidence-based testing of detectable NIS2 control.
View NIS2 audit →Discuss the audit objective, scope, evidence available and planning towards the external certification audit.
Schedule an audit intake →Frequently Asked Questions
Practical answers on ISO 27001 internal audit
Is an internal audit mandatory for ISO 27001?
ISO/IEC 27001 requires the organisation to conduct internal audits at scheduled intervals to assess whether the ISMS meets relevant requirements and own agreements and is effectively implemented and maintained.
Can Kynexis conduct the internal audit?
Yes, if sufficient objectivity and impartiality can be secured. If Kynexis Information Security was materially responsible for the establishment of the components to be audited, another auditor may be more appropriate for the formal internal audit.
What is the difference between a GAP analysis and internal audit?
A GAP analysis is mainly investigating what is missing from the desired standard position. An internal audit will assess whether the existing ISMS is demonstrably satisfactory and works in practice.
Can the audit be used as preparation for certification?
Yes. The audit may reveal gaps, missing evidence and deviations before phase 1, phase 2, surveillance or recertification.
Does Kynexis also audit technical controls?
When they fall within the agreed scope, relevant technical controls and evidence of their operation may be included. We determine the exact depth in advance.
How long does an internal audit take?
This depends on the scope, scope and complexity of ISMS. We will determine the required audit size after the intake.

An internal audit shall not be valid until it looks beyond the documents available. The core is to determine independently whether agreements are being made, proof is reliable and it really helps steer ISMS.