Add your offcanvas content in here

The Company

Simplifying your IT-security journey.

ISO/IEC 27001 – Internal Audits

ISO/IEC 27001 requires regular internal audits of your ISMS. mgm security partners conducts these as independent internal audits, performed by certified auditors who understand the technology—not just the standard. Pragmatic, tailored to your needs, and delivering reliable results for your next surveillance or certification audit.

Internal audits are mandatory: ISO/IEC 27001 requires them at scheduled intervals to ensure that your ISMS remains effective and that you successfully pass external audits.

Our Internal Audit in Detail

Offer

A comprehensive internal audit in accordance with ISO/IEC 27001, from planning through follow-up on corrective actions.

  • Align the audit program and plan with your certification cycle
  • Define the scope, audit criteria, and relevant controls
  • Risk-Based Priorities Instead of a One-Size-Fits-All Approach
  • Efficiently Coordinate Schedules and Points of Contact
  • Verify compliance with guidelines, policies, and procedures
  • Evaluate the Statement of Applicability and Risk Treatment
  • Check supporting documents and records for completeness
  • Verify consistency between documentation and actual practice
  • Interviews with Process Owners and Management
  • Spot checks on the actual implementation of controls
  • On-site or remote audit, depending on the scope
  • Gather objective, verifiable findings
  • Thoroughly Test Access Management, Hardening, Logging, and Backup
  • Verify configurations and documentation on a random basis
  • Evaluate Vulnerability and Patch Management
  • Identifying Gaps Between Policy and Technical Reality
  • Comprehensive audit report with findings and supporting documentation
  • Classification into Major and Minor Deviations, and Notes
  • Prioritized, specific recommendations for action
  • Preparation as Input for the Management Review
  • Monitor corrective actions for deviations
  • Assess the effectiveness of implemented measures in a follow-up evaluation
  • Preparing for the External Surveillance Audit
  • Embed Continuous Improvement in the Audit Cycle

The challenge

  • No independent, qualified auditors on our own team
  • Internal audits tend to take a back seat in day-to-day operations
  • Internal audits remain superficial or purely formal
  • Technical controls aren't really checked due to a lack of expertise
  • Unpleasant surprises only revealed during the external compliance audit

Our Added Value

  • Independent internal audit with no conflict of interest
  • Certified auditors with a genuine understanding of technology
  • An audit that actually tests controls, not just reviews documents
  • Pragmatic audits tailored specifically to your company
  • A clear audit report with prioritized, actionable recommendations

Here's How Your Internal Audit Works

Structured, independent, and yielding reliable results. The internal audit is part of the continuous ISMS improvement cycle.

  • 1 – Planning: We work with you to determine the audit program, scope, and criteria based on risk, and define the key areas of focus.
  • 2 – Implementation: Document reviews, interviews, and technical spot checks verify whether your ISMS is truly effective.
  • 3 – Report: You will receive a clear audit report detailing findings, nonconformities, and prioritized actions.
  • 4 – Follow-up: We monitor corrective actions, verify their effectiveness, and prepare you for the external audit.

Internal Audits: Quick Answers to Your Questions

Yes. ISO/IEC 27001 requires that internal audits be objective and impartial, and that no one audit their own work. An outsourced internal audit conducted by external, certified auditors meets this requirement particularly well and is the pragmatic solution, especially for small and medium-sized teams.

No. The internal audit is your own mandatory review of the ISMS in accordance with Section 9.2. Certification is performed by an accredited certification body during a separate external audit. We conduct the internal audit for you, thereby ensuring you are optimally prepared for the external audit.

The standard requires internal audits at scheduled intervals, without specifying a fixed frequency. In practice, the ISMS is usually audited—either in its entirety or in specific areas—at least once a year, based on risks and the certification cycle. We can help you set up a suitable audit program.

That depends on the scope, locations, and complexity. A focused audit is often completed in just a few days, while larger ISMS audits take correspondingly longer. After the planning phase, you will receive a clear estimate of the effort and timeline.

Deviations are normal and represent the true value of an audit. They are clearly documented in the report, prioritized, and accompanied by specific recommendations. Upon request, we assist with the corrective actions and verify their effectiveness during a follow-up review.

Why mgm security partners?

  • 25+ Years of Enterprise Security Consulting
  • Certified ISO 27001 auditors on the team
  • We review implementation, not just the paperwork
  • No external certification audit, no conflict of interest

Our auditors are certified and also experienced security professionals. Drawing on over 25 years of experience working on projects for banks, insurance companies, industrial firms, and software manufacturers, they don’t just check whether a policy exists—they verify whether the control is actually effective from a technical standpoint. We deliberately do not conduct external certification audits and, as an independent internal auditor, are fully on your side.

Maximiliane Mayer

Let's talk about your internal ISO 27001 audit! Schedule your appointment!

DeepDive

Why Internal Audits Are Mandatory

ISO/IEC 27001 requires, in Section 9.2, that organizations conduct internal audits of their information security management system at planned intervals. The goal is to verify whether the ISMS meets the organization’s own requirements and those of the standard, and whether it is effectively implemented and maintained. The internal audit is therefore not a bureaucratic end in itself, but rather the central mechanism through which an ISMS improves on its own.

Two principles are crucial: Auditors must be independent and objective, and no one may audit their own work. This is precisely where small and medium-sized teams often run into difficulties. An outsourced internal audit conducted by external, certified auditors solves this problem, provides a fresh, outside perspective, and identifies nonconformities before the certification body does so during a surveillance or recertification audit.

Section 9.2
Internal audits are a mandatory requirement of ISO/IEC 27001
Annually
Typical frequency, tailored to the audit program and certification cycle
Independent
No one is allowed to review their own work; external auditors ensure objectivity
Before the Audit
Identify discrepancies before the certification body finds them