Regulated Incident Management Ecosystem Versão portuguesa

Service sheet SO-08

Internal Audit and Third-Party Audit Readiness

Independent internal audit of the management system and its controls, with a report, a corrective plan and preparation for external audits.

The problem it solves

Client audits arrive at short notice and find exactly what the organisation already knew was missing. Internal audit exists so that this does not happen twice.

Who it is for

  • Certified organisations, or those seeking certification;
  • Suppliers audited by their clients;
  • Public entities subject to oversight.

Deliverables

  • Audit programme and scope;
  • Report with classified findings;
  • Corrective plan with owners and deadlines;
  • Mock external audit.

Method

  1. 01

    Plan

    Scope and criteria.

  2. 02

    Audit

    Evidence and interviews.

  3. 03

    Report

    Findings and risks.

  4. 04

    Correct

    Actions and verification.

Regulatory basis

  • ISO/IEC 27001:2022 and ISO/IEC 27002:2022;
  • ISO 19011, on auditing management systems.

Expected results

  • Gaps found before the client finds them;
  • External audits without surprises;
  • An improvement cycle that actually runs.

Security that is not measured is not managed

Start with a maturity assessment or ask for a proposal to structure the role.