Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Independent assurance

Internal audit for ISO 27001 and ISO 42001

From $3,000 CAD per audit · scoped to you

An independent clause 9.2 internal audit of your management system, ahead of your certification or surveillance audit. You get a report with nonconformities and observations, and we check your corrective actions before it is final.

Scope an internal audit See pricing
Independence first. We only offer internal audit where we have not operated your controls, and we never fix what we audited.

Plan, fieldwork, report

01

Audit plan

Scope, criteria, sampling approach, who we will interview and when, agreed with you before fieldwork starts.

02

Remote fieldwork

Interviews by video, document review, and samples of your records tested against the clauses and controls in scope. We test what you do, not only what the policy says.

03

Draft report

Nonconformities, graded major or minor, and observations, each tied to the clause or control it concerns.

04

Corrective action check

You respond with a root cause and corrective actions. We check them once, before the final report, and record what we saw.

05

Final report

Ready for your management review and for the certification body at your next audit.

Audit all of it, or part of it each time

Clause 9.2 asks for audits at planned intervals, so the programme can be spread across the certification cycle. Pick the scope that fits this audit.

Full

Clauses 4 to 10 and every applicable Annex A control in one audit.

Clauses only

The management system requirements, clauses 4 to 10, without the Annex A controls.

Annex only

The Annex A controls in your Statement of Applicability, without the clauses.

Rotating programme

Selected Annex themes each time, rotated so every clause and control is covered across the certification cycle. We track coverage so nothing is missed before recertification.

Not a gap analysis, not remediation

A gap analysis tells you what is missing before you build. An internal audit tests whether the system you already run conforms, and only an internal audit counts as clause 9.2 evidence. Not built yet? Start with a gap analysis for ISO 27001 or ISO 42001.

Consultancies and MSPs have the same independence problem with their own clients. We take internal audit referrals on a ring-fenced basis: we audit, report to the client's management, and do not offer them our readiness work. See the MSP partner programme.

The natural next step is next year's internal audit, or the next themes in your rotation.

Internal audit questions, answered

Does ISO 27001 require an internal audit?

Yes. Clause 9.2 requires internal audits at planned intervals and an audit programme, and it cannot be excluded the way an Annex A control can. ISO 42001 has the same clause for an AI management system. The certification body will ask for your internal audit records at the certification audit and at each surveillance audit.

Why can you not audit a programme you run?

Clause 9.2 requires auditors to be chosen so the audit is objective and impartial, and nobody is impartial about controls they operate. So we only offer internal audit where we have not operated your controls. If we run your programme, we will say so and help you find an independent auditor.

Can you audit only part of the standard?

Yes. Choose a full audit, the clauses only, the Annex A controls only, or selected Annex themes in a rotating programme. With the rotation we track coverage across the cycle so every clause and control is audited before recertification.

Do you fix the nonconformities you find?

No. Fixing what we audited would end our independence. You, or whoever runs your programme, correct them; we check the corrective actions once before the final report.

Is fieldwork done on site?

Fieldwork is remote: interviews by video, and documents and records sampled through your workspace or a shared screen. The audit plan sets out how each control in scope will be tested.

Book the audit before the auditor arrives

Tell us the standard, your certification or surveillance date and the scope you have in mind. We will confirm we are independent of your controls and send a fixed price.

Scope an internal audit Book a 30-minute call

Free PDFs, no card

Get the checklists that go with this

The SOC 2 readiness checklist, the ISO 27001 gap checklist and the vendor security questionnaire, as PDFs you can print or hand to your team. Free, no card.

From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.