Information Security Management

ISO 27001 Internal Audit Service

My internal audit service will tell you quickly where your business stands against the ISO 27001 benchmark.

Alan Parker, ISO 27001 Consultant

I’m Alan Parker, UK-based, but delivering services globally.

My internal audit is designed for smaller businesses that want assurance before their external audit or cannot maintain the impartiality required by Clause 9 of ISO 27001.

I have over 30 years of IT experience, am an ANAB-accredited Certified ISO/IEC 27001:2022 Lead Auditor, and hold a CISMP qualification.

Alan from Iseo Blue truly came to our rescue. His support ahead of our internal audit was outstanding, and he helped us get our ISMS 100% ready for the Phase 2 audit.

– Jair Ross, Quartile
(Internal Audit Client)

Fully Remote Global Delivery

I work remotely with clients worldwide, supporting them with their internal audits.

You dictate the pace.

Urgent? No Problem. We can get right on it.

What you receive

A Formal Internal Audit Report

A structured report covering every clause and control of ISO 27001, findings for each area, and an overall conformance summary.

This is the document your certification body will request, and it should be used as an input to management reviews.

internal audit report screenshot

Internal Audit Programme

Required as part of the internal auditing criteria in 27001, an outline of how, when and who will undertake the audit.

The plan covers the method, a description of how objectivity will be maintained and a schedule of activities.

internal audit plan screenshot

Nonconformity Log

A list of all the findings with corrective in two parts: the main clauses and the controls of Annex A (The Statement of Applicability).

Each finding comes with your corrective action plan of what an appropriate rectification would look like.

internal audit log screenshot

Who it’s for


Organisations seeking confidence in their ISMS before commencing an expensive certification process.

SMEs that lack the resources to conduct an independent internal audit.

This service works well for organisations approaching their initial certification audit who want a dry run before the external audit, or for those already certified who want to conduct their routine internal audit in accordance with the standard’s requirements.

It is not the right fit for organisations that have not yet built their ISMS — if you are still building your management system, the ISO 27001 consultancy service is the more appropriate starting point — if you have it all built and haven’t yet pressed the ‘go’ button, then that also can be a good time.

The Importance of Auditor Impartiality

When approaching your internal audit, per the requirements of Clause 9.2, which states that auditors must maintain “objectivity and impartiality”, you must consider how you will separate ISMS creator(s), Certification Bodies (CB -your external auditor) and Internal Audit Services.

In short, you can’t mark your own homework, so you must hand it to someone else.

Iseo Blue is an independent auditor with experience tailoring internal audits for smaller businesses without breaking the bank. We are not affiliated with any certification body, and there is no commercial relationship with the CB that will assess you, so the internal audit meets the requirements.

Your Auditor

Alan Parker - ISO 27001 consultant
Alan Parker – ISO 27001 Consultant

Your audit will be conducted by Alan Parker, a Certified ISO/IEC 27001:2022 Lead Auditor (Mastermind Assurance, an ANAB-accredited certification body).

Alan has over 30 years of experience in IT governance and information security, and has delivered internal audits and certification support for SMEs across the UK, Europe, the US, and Australia. He also holds CISMP, ITIL Expert, and PRINCE2 Practitioner qualifications.

As an independent external auditor, Alan satisfies the impartiality requirements of Clause 9.2; he has no involvement in operating the controls he audits, which is precisely what certification bodies want to see.


luggage logistics logo
Alan helped us create an ISMS fit for purpose; his technical expertise and attention to detail exceeded Luggage Logistics’ expectations.
Matt Griffin
Luggage Logistics

Pricing

The ISO 27001 internal audit service is priced at a fixed fee of £2,500 + VAT (where applicable).

There are no hidden extras. The fee covers the scoping call, document review, audit interviews, and the final report.

Guarantee

If your certification body raises a nonconformity that I didn’t flag in my audit report, I’ll help you create a corrective action plan at no charge.

What an ISO 27001 internal audit actually involves

Why SMEs outsource their internal audit

The standard is explicit: internal auditors must be capable, objective and impartial.

If the same person who implemented your controls is also auditing them, you have a conflict of interest — and an auditor from your certification body will notice.

Many SMEs don’t have a spare qualified staff member who isn’t involved in the ISMS. The choices are: train someone in-house (time-consuming), hire a freelance auditor (expensive and often impersonal), or work with a specialist who understands both the standard and the SME context. That’s where I come in.

Frequently asked questions

How long does the audit take?

It depends, but the process typically runs over two to three weeks from scoping call to final report. The actual audit interviews are either conducted in a single day, or split into several sessions over perhaps a week, depending on team commitments and preferences.

Can you conduct the audit if we built our ISMS ourselves?

Yes — in fact, this is the most common scenario. Self-built ISMS implementations are exactly where independent audit adds most value, because objectivity is hardest to maintain internally.

Will this satisfy our certification body?

Yes. The audit report and nonconformity log I produce meet the documentary requirements of ISO 27001 Clause 9.2 and are formatted to align with what accredited certification bodies expect. Findings will be marked in alignment with Major and Minor Nonconformities, Opportunities for Improvement and Observations.

Do we need to have worked with you previously?

No. This is a standalone service. If you have an existing ISMS — whether you built it with my help, through the DIY course, or independently — I can conduct the audit.

Is this service available internationally?

Yes. Sessions are conducted remotely via video call, so location is no barrier. I have worked with organisations across the UK, EU, USA, New Zealand, and beyond.

Do you do on-site audits in the UK?

If geographically feasible (i.e., south of England), then yes. I’m happy to conduct an on-site audit and do so occasionally.

Are you a certified Lead Auditor for ISO 27001?

Yes. Alan Parker is a Certified ISO/IEC 27001:2022 Lead Auditor, certified by Mastermind Assurance, an ANAB-accredited certification body (ANAB is the US equivalent of UKAS). You can verify the credential online: view Lead Auditor credential here

If your surveillance audit is coming up, or you want to give your ISMS a proper independent review before it does, book a free 30-minute scoping call. I’ll confirm whether the service is right for your situation and answer any questions before you commit.