ISO 27001 Internal Audit Services

ISO 27001 requires an internal audit program under Clause 9.2, run by someone independent of the ISMS being audited. We run it: the audit program, fieldwork against Clauses 4 to 10 and Annex A, and nonconformities documented with the evidence behind each one, so your certification body's Stage 1 and Stage 2 visits find nothing you did not already know about. BD Emerson is not a certification body, and an accredited registrar issues the certificate.
Contact us
Definition

What is an ISO 27001 internal audit?

An ISO 27001 internal audit is the audit the standard itself requires. Clause 9.2 obligates the organization to audit its ISMS at planned intervals, using auditors who are objective and impartial about the work they review. BD Emerson runs that program as your independent internal auditor: we plan the audit cycle, test clauses 4-10 and the Annex A controls in your Statement of Applicability against real evidence, write findings with corrective actions, and prepare you for Stage 1, Stage 2, and the surveillance audits that follow. One boundary is worth stating plainly: BD Emerson is not a certification body and does not issue ISO certificates. We audit and prepare; your accredited CB certifies. If we built parts of your ISMS, we will tell you what we can and cannot independently audit.

Services

What does the internal audit service include?

Annual internal audit program
Clause and Annex A fieldwork
Findings and CAPA
Management review support
Stage 1 and Stage 2 readiness
Surveillance and recertification prep

Annual internal audit program

Clause 9.2 asks for an audit program, not a one-off event. We plan the cycle for the year, scope each audit by risk and prior results, and execute on schedule. The program is planned and executed, not improvised each year when the certification visit gets close.

Clause and Annex A fieldwork

Evidence-based testing of clauses 4-10 and the Annex A controls in your Statement of Applicability. We sample tickets, review configurations and logs, and interview control owners. It is fieldwork against real records, not questionnaire theater.

Findings and CAPA

Nonconformities written so they close: each finding states the requirement, the evidence, and the gap, then gets a corrective action with an owner and a date. We track corrective actions to verification, because an open CAPA at Stage 2 is a finding waiting to repeat.

Management review support

Clause 9.3 requires management review with specific inputs: audit results, nonconformity status, risk treatment progress, and changes from interested parties. We prepare those inputs properly and document the outputs, so the review is a working meeting rather than a signature exercise.

Stage 1 and Stage 2 readiness

We prepare you for what CB auditors actually look for: documentation completeness at Stage 1, evidence of operation at Stage 2. You get a readiness check against both, a fix list in priority order, and coaching for the people who will sit in the interviews.

Surveillance and recertification prep

Year 2 and year 3 are where certificates get lost. Surveillance audits expect the ISMS to keep running: internal audits done, management reviews held, corrective actions closed. We keep the program on schedule through the full three-year cycle, including recertification.

Our approach

How the audit runs

01

Plan the program

We build the audit program from your ISMS scope, risk assessment, and prior results: what gets audited, when, by whom, and against which criteria. The program plan is the first thing a certification auditor asks to see.

02

Test against evidence

Fieldwork runs on records, not recollection: tickets, logs, configurations, training records, and interviews with control owners. Every conclusion traces to evidence you can show the certification body.

03

Report findings that close

Findings are written against specific clauses and controls, graded as major, minor, or opportunity for improvement, and paired with corrective actions. We verify closure instead of filing the report and moving on.

04

Stand ready for the CB

We assemble the evidence pack, brief your team on what Stage 1 and Stage 2 will ask, and stay available during the certification audit. When the CB reviews your internal audit program, the work holds up.

contact us

Certification audit on the calendar?

Speak with BD Emerson about your audit program, your Statement of Applicability, and what your certification body will expect to see at the next visit.

Our Advantage

Why BD Emerson for internal audit

Independence you can document

Clause 9.2 requires auditors who are objective and impartial, and we put our independence in writing. If BD Emerson built parts of your ISMS, we tell you what we can and cannot independently audit, and we scope the engagement accordingly.

Auditors who know the CB playbook

Our team runs ISO 27001 programs and sits across from certification bodies all year. We know which findings CB auditors write most, so the internal audit catches them first, while they are still yours to fix quietly.

A program, not a visit

You get a standing audit calendar, tracked corrective actions, and management review inputs delivered on schedule across the three-year certification cycle. The ISMS stays audit-ready between CB visits, not just before them.

Reviews

What our customers say

Great consulting firms for scaling security, compliance, and appsec.

Outstanding partner in Technical and Cyber Due Diligence

Appsec maturity and application hardening.

BD Emerson helped us simplfiy our compliance management.

BD Emerson did such a phenomenal job. What started as privacy support quickly became a full partnership across compliance, engineering, and even business operations. They’re embedded with our team. They understand our product. They move fast. They’re simply invaluable.

Adam Ben Jacobs

CTO @ OneStep GPS

Great consulting firms for scaling security, compliance, and appsec.

Outstanding partner in Technical and Cyber Due Diligence

Appsec maturity and application hardening.

BD Emerson helped us simplfiy our compliance management.

BD Emerson did such a phenomenal job. What started as privacy support quickly became a full partnership across compliance, engineering, and even business operations. They’re embedded with our team. They understand our product. They move fast. They’re simply invaluable.

Adam Ben Jacobs

CTO @ OneStep GPS

We had a hard time finding the right company to partner with in support of our compliance journey. Some vendors sell the idea that they do the work, but then you end up doing everything. The ambiguity is what killed our last project. BD Emerson’s team has such great technical knowledge and understands the standard so well that they made us comfortable with moving fast. This has led to us closing major enterprise customers that were previously out of reach because of security and compliance.

Tom Watkins

CEO @ AMI AssetTrack

Lead an enterprise initiative to overhaul the organization's technology stack from ecommerce, corporate tech, and corporate security.

Supported ISO 42001 exercise and served as internal auditor.

Rubrik's privacy and compliance team began with the backbone of BD Emerson. BD Emerson supported building out the privacy program, GRC (ISO 27001, SOC 2, CMMC, FedRAMP), and the appsec function.

We needed a partner who could move quickly, without sacrificing precision. BD Emerson brought the expertise, structure, and speed we were looking for. Their team became an extension of ours, embedding themselves across the organization, guiding us step by step, and giving us confidence in areas we hadn’t tackled before. The internal audit they conducted was so detailed that even the external auditors called it out. Achieving ISO 27001 with zero nonconformities says everything you need to know about the quality of the partnership.

Walid Souilem

CTO @ FGI Worldwide

We had a hard time finding the right company to partner with in support of our compliance journey. Some vendors sell the idea that they do the work, but then you end up doing everything. The ambiguity is what killed our last project. BD Emerson’s team has such great technical knowledge and understands the standard so well that they made us comfortable with moving fast. This has led to us closing major enterprise customers that were previously out of reach because of security and compliance.

Tom Watkins

CEO @ AMI AssetTrack

Lead an enterprise initiative to overhaul the organization's technology stack from ecommerce, corporate tech, and corporate security.

Supported ISO 42001 exercise and served as internal auditor.

Rubrik's privacy and compliance team began with the backbone of BD Emerson. BD Emerson supported building out the privacy program, GRC (ISO 27001, SOC 2, CMMC, FedRAMP), and the appsec function.

We needed a partner who could move quickly, without sacrificing precision. BD Emerson brought the expertise, structure, and speed we were looking for. Their team became an extension of ours, embedding themselves across the organization, guiding us step by step, and giving us confidence in areas we hadn’t tackled before. The internal audit they conducted was so detailed that even the external auditors called it out. Achieving ISO 27001 with zero nonconformities says everything you need to know about the quality of the partnership.

Walid Souilem

CTO @ FGI Worldwide

BD Emerson didn’t just help us meet our compliance goals; they integrated security and privacy into the core of our operations. I highly recommend BD Emerson to anyone seeking SOC 2 or GDPR compliance, or simply looking to enhance their security team and boost customer trust in their product and services. Their dedication and expertise have been invaluable to our success.

Padraig Reilly

CEO, Boxcore

BD Emerson understood our business requirements and worked side-by-side with us. The policies and controls we developed together not only meet compliance standards but improve how we operate day to day.

Matt Meierdierks

IT Manager, Lincoln Industries

From day one, BD Emerson brought urgency, clarity, and a sharp understanding of what truly matters to our business — earning and keeping customer trust. They went beyond helping us meet compliance requirements; they helped build a foundation for secure, scalable growth. That kind of partnership is rare.

Jason Marker

CEO @ LifeLenz

BD Emerson didn’t just help us pass an audit—they helped us build a sustainable culture of security.

Alexey Indeev

CTO Spare

BD Emerson was essential in helping our company navigate the daunting process of leveling up our security infrastructure. BD Emerson’s impressive expertise and confidence throughout the process helped our team exceed HIPAA and SOC 2 Type 1 standards quickly, distilling what can be an overwhelming process into a streamlined, organized effort. From day one they began adding value and getting us on course. With their help we delivered on a massive security overhaul with both extreme efficiency and thorough attention to details. Because of BD Emerson’s support, we’ve increased our clients’ trust in Titan Intake and the life-changing work it accomplishes for those seeking specialist referrals.

Patrick Bruce

CEO, Titan Intake

BD Emerson didn’t just help us meet our compliance goals; they integrated security and privacy into the core of our operations. I highly recommend BD Emerson to anyone seeking SOC 2 or GDPR compliance, or simply looking to enhance their security team and boost customer trust in their product and services. Their dedication and expertise have been invaluable to our success.

Padraig Reilly

CEO, Boxcore

BD Emerson understood our business requirements and worked side-by-side with us. The policies and controls we developed together not only meet compliance standards but improve how we operate day to day.

Matt Meierdierks

IT Manager, Lincoln Industries

From day one, BD Emerson brought urgency, clarity, and a sharp understanding of what truly matters to our business — earning and keeping customer trust. They went beyond helping us meet compliance requirements; they helped build a foundation for secure, scalable growth. That kind of partnership is rare.

Jason Marker

CEO @ LifeLenz

BD Emerson didn’t just help us pass an audit—they helped us build a sustainable culture of security.

Alexey Indeev

CTO Spare

BD Emerson was essential in helping our company navigate the daunting process of leveling up our security infrastructure. BD Emerson’s impressive expertise and confidence throughout the process helped our team exceed HIPAA and SOC 2 Type 1 standards quickly, distilling what can be an overwhelming process into a streamlined, organized effort. From day one they began adding value and getting us on course. With their help we delivered on a massive security overhaul with both extreme efficiency and thorough attention to details. Because of BD Emerson’s support, we’ve increased our clients’ trust in Titan Intake and the life-changing work it accomplishes for those seeking specialist referrals.

Patrick Bruce

CEO, Titan Intake

Certificates

Our accreditations

At BD Emerson, we believe that our team's extensive certifications not only set us apart but also ensure that we provide the highest level of service to our clients.
FAQ

Frequently asked questions

Why is an internal audit mandatory for ISO 27001?

Can the people who built our ISMS audit it?

How is an internal audit different from the certification audit?

How often should internal audits run?

What do Stage 2 auditors focus on?

What do you need from our team?

Do you issue the ISO 27001 certificate?

Blog

Related Articles

Insights on strategy, transactions, technology, security, and compliance from BD Emerson's practitioners