ACloud.Solutions

ISO 27001 and compliance

ISO 27001 internal audit small company independence, without a second employee

You built the ISMS. You wrote the policies, ran the risk assessment, implemented the controls and collected the evidence. Clause 9.2 now requires an internal audit of all of it, conducted objectively and impartially.

The iso 27001 internal audit small company problem is that there is nobody else. Auditing your own work is not impartial by any definition, and an auditor who sees your name on both the implementation and the audit will treat the audit as not having happened. This is the single hardest structural constraint in a one-person ISMS, and it has no elegant answer, only four workable ones.

What clause 9.2 asks for

More than a checklist exercise, and the specifics matter because people under-deliver on the parts that are easy.

An audit programme covering frequency, methods, responsibilities, planning and reporting, which takes account of the importance of the processes and the results of previous audits. That last phrase means the programme is expected to change based on what previous audits found.

Defined criteria and scope for each audit. What you are auditing against and which parts of the ISMS this audit covers.

Auditors selected to ensure objectivity and impartiality. The wording of the constraint, and the whole difficulty.

Results reported to relevant management, and retained as documented information.

Note what it does not say. It does not require an external auditor, a qualification, or a full audit of everything every year. A programme that audits a third of the controls annually on a three-year cycle, weighted by importance, is compliant and is what most small companies do.

Four routes to iso 27001 internal audit small company independence

In rough order of how well they work at this scale.

A trained colleague from another function. Somebody in finance, operations or engineering who did not build the ISMS. They need enough understanding to audit, which is a day of training and a good checklist, not a qualification. This is the cheapest option and the one auditors are most used to seeing. It works because impartiality is about not having done the work, not about expertise.

The limitation is that they cannot meaningfully audit deeply technical controls, because they lack the knowledge to know when an answer is evasive. Split the programme: they audit the management system clauses and the organisational and people controls, and buy in the technical half.

A contractor. Half a day to two days depending on scope. Genuine independence, genuine expertise, and a report that reads like an auditor wrote it. The cost is real but it is the cheapest line in the certification budget and the easiest to justify.

A reciprocal arrangement with a peer. Somebody in a similar role at another company audits yours and you audit theirs. Free, genuinely independent, and mutually educational because you both see how somebody else solved the same problems. The practical obstacles are confidentiality, which needs an agreement in place, and finding the person.

Your certification body's own consulting arm, or a member of the group company. Be careful here. A certification body cannot both consult on and certify the same ISMS, and using an entity connected to your certification body for internal audit invites questions about the independence of the whole arrangement. Ask first.

What does not work: auditing your own work and describing it as a self assessment, then hoping the wording covers it. It does not, and it is the sort of finding that raises questions about everything else.

Book it early, because availability is the constraint

The practical failure is not choosing the wrong option, it is choosing late.

Internal audit has to happen before the certification audit, because Stage 1 will ask whether it has. Contractors and peers have diaries. Somebody leaving mid-arrangement, or a rebooked date that slips past your Stage 1, turns a solved problem back into an open one, and by then there is no slack.

Book it in the first fortnight of the project, for a date about two months before your target Stage 1. That leaves time to fix what it finds, which is the entire purpose.

Give the auditor the documents a week ahead: scope statement, risk register, Statement of Applicability and the evidence index. An auditor reading those beforehand spends the day testing rather than orienting, which roughly doubles what half a day buys you.

The programme, on one page

An audit programme does not need to be long. It needs to exist and to be followed.

Cycle: three years, all clauses and applicable controls covered
Frequency: annually, or after significant change
Auditor: [named contractor or colleague], not involved in ISMS operation

Year 1: Clauses 4-6, 9-10. Controls 5.1-5.23 (organisational),
        6.1-6.8 (people)
Year 2: Clauses 7-8. Controls 8.1-8.16 (technological, first half)
Year 3: Controls 8.17-8.34, 7.1-7.14 (physical). Full clause review

Weighting: access control, supplier management and incident response
  audited every year regardless of cycle position, on the basis of
  risk register scores R-01, R-04, R-09.
Inputs: previous audit findings, risk register, nonconformity log.
Reporting: written report to management review within 4 weeks.

The weighting line is what makes it a programme rather than a rota, and it is the part that satisfies "taking account of the importance of the processes".

The report, and what it must contain

Auditors read internal audit reports carefully, because a good one is evidence that the system examines itself.

It needs the scope and criteria, the dates, who conducted it, what was examined including which records were sampled, the findings classified consistently, and the agreed actions with owners and dates.

The most important property: it must contain findings. An internal audit report concluding that everything is satisfactory is not reassuring, it is implausible, and it suggests the audit was not searching. Every ISMS at this stage has something wrong with it. Finding three or four things and fixing them before Stage 2 is precisely the value, and it is also the story you want to tell the external auditor.

Then the findings have to go somewhere. Into a nonconformity and corrective action log, with dates, owners and evidence of closure. A finding raised and never closed is worse than not having found it, because you documented knowing about it.

Feeding management review

Clause 9.3 requires management review to consider internal audit results, so the two are connected by design and the sequence matters: audit, then review, then certification audit.

Management review is its own record, and the useful framing is that it produces decisions rather than a discussion. Decisions about resources, about risks accepted, about actions arising from the audit. Minutes with decisions and owners are the evidence; a calendar invite is not.

If you are running both alone, the review still needs actual managers in the room making actual decisions. That is the other place where a one-person ISMS cannot substitute effort for authority, and the book covers how to run a review that produces something an auditor recognises.

The ISO 27001 standard is worth reading directly for clause 9, which is short and precise, and which people routinely under-implement on the strength of a summary.

The security and compliance work includes internal audit as an independent party, which is the contractor option above, and is frequently the least painful way to satisfy a clause that has no good in-house answer at this size.