Evidence
Running an internal audit that is worth the day it costs
An internal audit that finds nothing has told you nothing, and the external auditor will notice the coincidence.
Facts checked — 2026-09-11
How do you run an internal audit that finds things?
Internal audit is a mandatory clause and it has to be performed by someone sufficiently independent of the work being audited — which in a small organisation usually means swapping areas between people, or bringing in an outside auditor.
Its value is diagnostic. Sample the way an external auditor samples: ask for specific records from specific dates, follow a control from the policy to the artefact, and interview someone outside the security team. Then raise what you find as real nonconformities and close them. A clean internal audit report immediately before a Stage 2 that finds six things is not a good look.
The bottom line
Audit to find problems. Findings closed before Stage 2 cost a morning; the same findings at Stage 2 cost the schedule.
Related services
ISO/IEC 27001 — Information Security Management
Build an information security management system that survives Stage 2 — and the three years of surveillance that follow.
ISO 22301 — Business Continuity Management
Know which activities cannot stop, how long they can be down, and what you will actually do — tested before you need it.
ISO/IEC 27701 — Privacy Information Management
Turn privacy from a policy document into a management system, with the records a regulator or an enterprise buyer will ask to see.
Related insights
Evidence
Corrective action is not the same as fixing it
A fix addresses the instance. Corrective action addresses why it happened.
Evidence
Evidence that collects itself
If producing evidence is a separate task, it will be skipped in a busy quarter.
Evidence
Access reviews that survive an auditor’s sample
The most sampled control in both frameworks, and the most commonly half-done.