Internal audit services

Most frameworks that require an internal audit also require it to be independent of the people who run the controls. BD Emerson performs internal audits as an outsourced or co-sourced function: we plan from your risk assessment, test your controls, report findings with evidence, and verify that corrective actions closed them.
Talk to an auditor
Definition

What are internal audit services?

Internal audit services give a company the independent audit function that frameworks and regulators require, without hiring one. ISO 27001, ISO 42001, GLBA, SOX 404(a), PCI DSS, and NYDFS Part 500 all expect controls to be tested by someone who does not operate them, and most companies under 500 people cannot staff that separation. BD Emerson performs internal audits as an outsourced or co-sourced function within our audit practice: we plan from your risk assessment, test controls against the criteria, report exceptions with evidence, and verify that corrective actions closed the findings. We report exceptions, we do not correct them.

Requirements

Who requires an internal audit?

ISO 27001
ISO 42001
GLBA
SOX ITGC
PCI DSS
NYDFS and FFIEC

ISO 27001 Clause 9.2

ISO 27001 Clause 9.2 requires internal ISMS audits at planned intervals, and certification bodies sample the results at Stage 2 and at every surveillance audit. Our ISO 27001 internal audit covers the full scope across the certification cycle and classifies findings as major or minor nonconformities with observations.

ISO 42001 Clause 9.2

ISO 42001 Clause 9.2 carries the same requirement for AI management systems: internal audits at planned intervals, sampled by the certification body. Our ISO 42001 internal audit tests the management system clauses and the applicable controls before the certifier does.

GLBA Safeguards Rule

The Safeguards Rule at 16 CFR 314.4(d) requires regular testing or monitoring of key controls, and banking regulators expect independent testing under the Interagency Guidelines. Our GLBA internal audit tests the information security program element by element and reports exceptions with rule cites.

SOX 404(a) and IT general controls

SOX 404(a) requires management to assess internal control over financial reporting, and that assessment needs someone to actually test IT general controls: access, change management, and computer operations. Our SOX ITGC audit performs that testing with workpapers an external auditor can rely on.

PCI DSS periodic reviews

PCI DSS builds quarterly and periodic reviews into the standard, and Requirement 12 obligates service providers to confirm that the program operates as documented. We perform those reviews on the required cadence and report each exception with the evidence behind it.

NYDFS Part 500 and FFIEC

NYDFS 23 NYCRR 500 requires Class A companies to run independent cybersecurity audits, and the FFIEC expects banks and credit unions to keep an audit program commensurate with their size and complexity. We scope both to what the examiner will ask for.

Engagement models

How we deliver internal audit

01

Fully outsourced

We are your internal audit function. We build the annual audit plan from your risk assessment, execute every audit on it, and report to management review and the board on a set cadence.

02

Co-sourced

Your team owns the audit plan. We execute the audits that need independence from the control owners or specialist depth, and our workpapers file into your audit records.

03

Single engagement

We audit one standard before a certification or examination window, timed so your team has room to correct findings before the certifier or examiner arrives.

04

Independence preserved

An internal audit performed by the team that built the controls fails the independence test that certification bodies and examiners apply. Our audit practice is separate from our consulting practice, and where independence cannot be preserved we decline the work.

contact us

Schedule an internal audit

Tell an auditor which framework or regulator is asking, and we will scope the audit plan, the evidence sample, and the reporting date.

Our Advantage

Why BD Emerson for internal audit

A separate audit practice

Our auditors do not implement, advise, or remediate. If BD Emerson consultants built your program, a different team audits it, so the independence question never reaches your certifier or examiner.

Auditors who know the criteria

We test ISO 27001 and ISO 42001 clause by clause and tie GLBA, PCI DSS, and FFIEC procedures to the specific requirement, so every finding cites the criterion it fails.

Reports written to be read

Findings carry a severity, the evidence reference, and the requirement they fail, in a report built for the certification body, examiner, or board that will read it.

How We Work

How we run an internal audit

Every engagement follows the same testing sequence, sized to your scope, sites, and evidence maturity:
Reviews

What our customers say

Great consulting firms for scaling security, compliance, and appsec.

Outstanding partner in Technical and Cyber Due Diligence

Appsec maturity and application hardening.

BD Emerson helped us simplfiy our compliance management.

BD Emerson did such a phenomenal job. What started as privacy support quickly became a full partnership across compliance, engineering, and even business operations. They’re embedded with our team. They understand our product. They move fast. They’re simply invaluable.

Adam Ben Jacobs

CTO @ OneStep GPS

Great consulting firms for scaling security, compliance, and appsec.

Outstanding partner in Technical and Cyber Due Diligence

Appsec maturity and application hardening.

BD Emerson helped us simplfiy our compliance management.

BD Emerson did such a phenomenal job. What started as privacy support quickly became a full partnership across compliance, engineering, and even business operations. They’re embedded with our team. They understand our product. They move fast. They’re simply invaluable.

Adam Ben Jacobs

CTO @ OneStep GPS

We had a hard time finding the right company to partner with in support of our compliance journey. Some vendors sell the idea that they do the work, but then you end up doing everything. The ambiguity is what killed our last project. BD Emerson’s team has such great technical knowledge and understands the standard so well that they made us comfortable with moving fast. This has led to us closing major enterprise customers that were previously out of reach because of security and compliance.

Tom Watkins

CEO @ AMI AssetTrack

Lead an enterprise initiative to overhaul the organization's technology stack from ecommerce, corporate tech, and corporate security.

Supported ISO 42001 exercise and served as internal auditor.

Rubrik's privacy and compliance team began with the backbone of BD Emerson. BD Emerson supported building out the privacy program, GRC (ISO 27001, SOC 2, CMMC, FedRAMP), and the appsec function.

We needed a partner who could move quickly, without sacrificing precision. BD Emerson brought the expertise, structure, and speed we were looking for. Their team became an extension of ours, embedding themselves across the organization, guiding us step by step, and giving us confidence in areas we hadn’t tackled before. The internal audit they conducted was so detailed that even the external auditors called it out. Achieving ISO 27001 with zero nonconformities says everything you need to know about the quality of the partnership.

Walid Souilem

CTO @ FGI Worldwide

We had a hard time finding the right company to partner with in support of our compliance journey. Some vendors sell the idea that they do the work, but then you end up doing everything. The ambiguity is what killed our last project. BD Emerson’s team has such great technical knowledge and understands the standard so well that they made us comfortable with moving fast. This has led to us closing major enterprise customers that were previously out of reach because of security and compliance.

Tom Watkins

CEO @ AMI AssetTrack

Lead an enterprise initiative to overhaul the organization's technology stack from ecommerce, corporate tech, and corporate security.

Supported ISO 42001 exercise and served as internal auditor.

Rubrik's privacy and compliance team began with the backbone of BD Emerson. BD Emerson supported building out the privacy program, GRC (ISO 27001, SOC 2, CMMC, FedRAMP), and the appsec function.

We needed a partner who could move quickly, without sacrificing precision. BD Emerson brought the expertise, structure, and speed we were looking for. Their team became an extension of ours, embedding themselves across the organization, guiding us step by step, and giving us confidence in areas we hadn’t tackled before. The internal audit they conducted was so detailed that even the external auditors called it out. Achieving ISO 27001 with zero nonconformities says everything you need to know about the quality of the partnership.

Walid Souilem

CTO @ FGI Worldwide

BD Emerson didn’t just help us meet our compliance goals; they integrated security and privacy into the core of our operations. I highly recommend BD Emerson to anyone seeking SOC 2 or GDPR compliance, or simply looking to enhance their security team and boost customer trust in their product and services. Their dedication and expertise have been invaluable to our success.

Padraig Reilly

CEO, Boxcore

BD Emerson understood our business requirements and worked side-by-side with us. The policies and controls we developed together not only meet compliance standards but improve how we operate day to day.

Matt Meierdierks

IT Manager, Lincoln Industries

From day one, BD Emerson brought urgency, clarity, and a sharp understanding of what truly matters to our business — earning and keeping customer trust. They went beyond helping us meet compliance requirements; they helped build a foundation for secure, scalable growth. That kind of partnership is rare.

Jason Marker

CEO @ LifeLenz

BD Emerson didn’t just help us pass an audit—they helped us build a sustainable culture of security.

Alexey Indeev

CTO Spare

BD Emerson was essential in helping our company navigate the daunting process of leveling up our security infrastructure. BD Emerson’s impressive expertise and confidence throughout the process helped our team exceed HIPAA and SOC 2 Type 1 standards quickly, distilling what can be an overwhelming process into a streamlined, organized effort. From day one they began adding value and getting us on course. With their help we delivered on a massive security overhaul with both extreme efficiency and thorough attention to details. Because of BD Emerson’s support, we’ve increased our clients’ trust in Titan Intake and the life-changing work it accomplishes for those seeking specialist referrals.

Patrick Bruce

CEO, Titan Intake

BD Emerson didn’t just help us meet our compliance goals; they integrated security and privacy into the core of our operations. I highly recommend BD Emerson to anyone seeking SOC 2 or GDPR compliance, or simply looking to enhance their security team and boost customer trust in their product and services. Their dedication and expertise have been invaluable to our success.

Padraig Reilly

CEO, Boxcore

BD Emerson understood our business requirements and worked side-by-side with us. The policies and controls we developed together not only meet compliance standards but improve how we operate day to day.

Matt Meierdierks

IT Manager, Lincoln Industries

From day one, BD Emerson brought urgency, clarity, and a sharp understanding of what truly matters to our business — earning and keeping customer trust. They went beyond helping us meet compliance requirements; they helped build a foundation for secure, scalable growth. That kind of partnership is rare.

Jason Marker

CEO @ LifeLenz

BD Emerson didn’t just help us pass an audit—they helped us build a sustainable culture of security.

Alexey Indeev

CTO Spare

BD Emerson was essential in helping our company navigate the daunting process of leveling up our security infrastructure. BD Emerson’s impressive expertise and confidence throughout the process helped our team exceed HIPAA and SOC 2 Type 1 standards quickly, distilling what can be an overwhelming process into a streamlined, organized effort. From day one they began adding value and getting us on course. With their help we delivered on a massive security overhaul with both extreme efficiency and thorough attention to details. Because of BD Emerson’s support, we’ve increased our clients’ trust in Titan Intake and the life-changing work it accomplishes for those seeking specialist referrals.

Patrick Bruce

CEO, Titan Intake

Certificates

Our accreditations

At BD Emerson, we believe that our team's extensive certifications not only set us apart but also ensure that we provide the highest level of service to our clients.
FAQ

Frequently asked questions

What is the difference between outsourced and co-sourced internal audit?

Can the firm that implemented our controls also audit them?

Which frameworks require an internal audit?

How often do internal audits run?

What does an internal audit cost?

What evidence do we need to provide?

What do we receive at the end?

Blog

Related Articles

Insights on strategy, transactions, technology, security, and compliance from BD Emerson's practitioners