Skip to content

Internal audit for ISO 27001 and TISAX®

Knowing where your ISMS stands before the certification body arrives

An audit that takes your ISMS further

An information security management system is only as good as its implementation in day-to-day operations. This is precisely what the internal audit checks: Is your ISMS fully documented? Is it actually being put into practice? And are the measures you have defined effective?

For certified companies, the internal audit is not optional. ISO/IEC 27001 mandates that you regularly review your ISMS internally, and the certification body checks whether this has been done. When carried out properly, however, it is more than just a box-ticking exercise: it reveals non-conformities while you still have time to fix them.

We carry out internal audits in accordance with ISO/IEC 27001:2022 and for TISAX®-labelled companies. We audit using the methodology of an external assessment, evaluate comprehensibly and deliver an action plan that you can continue working with directly.

Laptop 1024x683

Arrange a free and non-binding consultation appointment now:

Your goal

You want to be sure that your ISMS will withstand an external audit. This can be before initial certification, before the next surveillance audit, or after changes within your company.

Our performance

We independently audit your ISMS against the requirements of ISO/IEC 27001:2022, and against the VDA ISA catalogue if required. This includes document review, interviews and on-site sample checks. Every finding is documented with evidence and reference to the standard.

The result

You know your maturity level, your non-conformities and the next steps, prioritised by risk and effort. You can present the evidence of the internal audit to the certification body.

When an internal audit makes sense

Prior to initial certification

Your ISMS is established, and the stage-1 audit is approaching. The internal audit is the dress rehearsal. Ideally, it takes place three to six months before the date so that there is enough time for corrections.

While running

An ISMS is not a project that finishes with the certificate. Processes change, employees move on, new systems are added, and measures that once worked lose their effectiveness in daily operations. Regular internal audits keep your ISMS alive: they show early on where policies and actual practice diverge, and provide you with the basis for targeted improvements. On request, we can spread the assessments throughout the year so that every area is reviewed regularly and everything has been checked by the surveillance audit.

Prior to recertification

After three years, your ISMS will be completely reassessed. A prior internal audit will show whether gaps have crept into everyday operations.

Following a takeover or merger

With an acquisition, locations, systems, responsibilities and often the scope of the ISMS also change. We check whether your ISMS covers the new organisation and where the acquired entity is not yet integrated. We combine this with our experience from the Post-merger IT integration.

Following a carve-out

A spun-off entity often falls out of the former parent company's ISMS. The internal audit shows what is missing for a standalone ISMS and what can be adopted from the previous network. Find out more on our page about Carve-Out.

Following a security incident

An incident has exposed weaknesses. A targeted audit clarifies whether the cause is systemic and which measures need to be refined.

What we check

We carry out a complete review of your ISMS: firstly, whether the fundamentals are correct, i.e. objectives, responsibilities, risk assessment and regular review. Secondly, whether the specific security measures that you have defined for your company have been implemented. Measures that are not relevant to you and which you have excluded with justification will not be examined.

ISMS Governance and Leadership

An IT carve-out is the context of the organisation, scope, information security policy, roles and responsibilities, and management commitment.

Risk management

risk assessment methodology, asset inventory, risk treatment plan, acceptance criteria and the justifications in the Statement of Applicability.

Organisational measures

Policies, supplier management, information classification, security incident management, business continuity.

Personnel measures

Awareness raising and training, confidentiality agreements, onboarding and offboarding.

Physical measures

Access control, protection of rooms and equipment.

Technological measures

Access and authorisation management, data backup, logging and monitoring, vulnerability and patch management, network security.

Effectiveness and improvement

Key performance indicators, management review, handling of previous findings, continuous improvement.

For TISAX®-labelled companies, we also audit against the VDA ISA catalogue, including the requirements for prototype protection and data protection, insofar as they are relevant to your label.

This is how the internal audit works

1. Scoping and audit planning
Together, we determine the scope, locations and processes to be audited. You will receive an audit plan setting out dates, topics and points of contact. This saves your departments time, as everyone knows when they are required.

2. Document check
First, we will review your ISMS documentation: policy, risk assessment, Statement of Applicability, guidelines and evidence. Even at this stage, gaps and inconsistencies will become apparent. This allows us to use the time on-site specifically to focus on the critical points.

3. On-site audit
Through interviews with those responsible, spot checks and site visits, we assess whether your ISMS is being put into practice. The key question is not whether a policy exists, but whether it is adhered to in day-to-day operations.

4. Audit report and action plan
All findings are documented and classified with evidence and reference to standards: deviation, observation or strength. In a closing meeting, we explain the results and agree the prioritised action plan with you.

5. Follow-up
We will support you in implementing the corrective actions and check before the external audit whether the non-conformities have been resolved.

What you receive

Audit report
An executive summary for senior management, all findings with evidence and standard references, and an overall assessment of your certification readiness. The report is structured in such a way that your management can use it directly for the annual management review which they are required to conduct under ISO 27001.

Prioritised action plan
Concrete measures with persons responsible, deadlines and an assessment of the effort involved, sorted by risk. You can use it as a working list until the external audit.

Evidence for the certification body
By documenting the execution, you prove to the certification body that your internal audit has taken place. Following the follow-up process, we also confirm which non-conformities have been resolved.

For which standard do you require an internal audit?

Based on the audit principles of ISO 19011 – independently assessed, traceably documented, and with clearly prioritised recommendations for action.

Annual internal audit

ISO 27001 – ISMS Internal Audit
from 2,900 €
  • Audit of clauses 4–10 according to ISO 27001:2022
  • Sample check of 20–30 Annex A controls (prioritised)
  • Interview with ISMS team, management and employee sample
  • Document review: guidelines, risk register, SoA
  • Inspection of selected locations (on-site or remote)
  • Deviation categorisation (major / minor / observation)
  • Audit Report compliant with DIN EN ISO 19011 + Management Presentation

Self-assessment of the 10 minimum measures

NIS 2 – Internal Cybersecurity Audit
Audit from 3,500 €
  • Assessment of all 10 NIS-2 minimum measures (Art. 21 NIS-2)
  • Incident response and business continuity processes
  • Supply chain security and third-party management
  • Reporting documentation (24-hour / 72-hour / 1-month reports)
  • Executive management responsibility pursuant to Section 38 of the German Act on the Federal Office for Information Security (BSI Act)
  • Review of BSI registration (if required)
  • Audit Report + Management Presentation

Automotive suppliers facing TISAX assessment

Assessment preparation according to the VDA ISA catalogue
Audit from 3,500 €
  • Audit according to VDA-ISA catalogue (Level 2 or 3)
  • Review of all relevant ISA controls for your scope
  • Prototype protection and access concepts
  • Spot check of suppliers and service providers
  • Interfaces with ISO 27001 (if applicable)
  • Readiness assessment for the official TISAX assessment
  • Audit Report + Gap Roadmap

Frequently asked questions

Is an internal audit mandatory according to ISO 27001?

Yes. ISO/IEC 27001 requires you to review your ISMS internally at regular, planned intervals. This involves two questions: Does the ISMS meet the requirements of the standard and your own specifications? And does it function in everyday operations? Without documented internal audits, neither initial certification nor maintaining the certificate is possible.

How often must an internal audit take place?

The standard does not specify a fixed frequency, but requires a planned audit programme. In practice, the entire scope is audited within one year, i.e. by the respective surveillance audit. Many companies distribute the checks throughout the year and audit critical areas more frequently.

Are we allowed to conduct the internal audit ourselves?

Basically yes. However, the auditors must be objective and impartial and must not audit their own work. In small and medium-sized enterprises, this is often difficult to implement internally because the information security experts helped build the ISMS themselves.

What is the difference between an internal audit and a certification audit?

You arrange the internal audit yourself to review and improve your ISMS. The certification audit is carried out by an accredited certification body, and it decides on the issuance or maintenance of the certificate. In terms of methodology and depth, our internal audit is aligned with the external audit so that you experience no surprises there.

How does the internal audit differ from the IT quick audit?

The Quick Audit IT is a status analysis of your information security. It is suitable if you want to know where you stand or are just setting up an ISMS. The internal audit formally checks an existing ISMS against the requirements of ISO/IEC 27001 and is the evidence expected of you by the certification body.

Is there also an internal audit for TISAX®?

Yes. Regular review of the ISMS is also one of the requirements for TISAX®-labelled companies. We audit against the VDA ISA catalogue and prepare you for the assessment by the TISAX® audit provider. Find out more on our TISAX page.

What changes for the ISMS after an acquisition?

If new locations, companies or systems are added, you must check whether the scope of the ISMS is changing. Material changes generally need to be communicated to the certification body. An internal audit shows where the new entity already meets the requirements and where there is a need for integration.

How long does an internal audit take?

The Audit takes approx. 1 - 3 days. The duration depends on the scope, number of locations and maturity level of your ISMS. We will determine the exact timeframe during scoping.

How much does an internal audit cost?

The costs depend on the scope and complexity of the ISMS to be audited. After scoping, you will receive a fixed-price quotation.

Do you also check technical measures?

Yes. Alongside policies and processes, we check technical controls such as permissions, data backup, logging and patch management using spot checks. If you also want to know which vulnerabilities are recognisable from the outside, the audit can be combined with our Vulnerability analysis combine.

YOUR CONTACT PERSON

Connect with our expert.
Non-binding, uncomplicated, but always with
added value for you.

RALPH DÖRFLER

Head of IT Security

Ralphdoerfler1 2 857x1024

TISAX® is a registered trademark of the ENX Association; there is no connection between bitformer and the ENX Association.