Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
All Tools

Internal Audit Programme Planner

Pick ISO 27001 or ISO 42001, your cycle length and how many audits you run a year. The planner spreads clauses 4 to 10 and every Annex A theme across the cycle so nothing is missed.

Three years matches the certification cycle.
Higher-risk themes to audit every year (optional)
0
Year 1
AuditWhenIn scopeSize
Programme notes
    Internal audit, From $3,000 CAD
    A planning aid, not an audit. The plan spreads areas by their relative size. Your own risk assessment, previous audit results and changes to the management system should decide the final order.

    Questions

    Does ISO 27001 require every clause and control to be audited every year?

    No. Clause 9.2 asks for internal audits at planned intervals under an audit programme that takes into account the importance of the processes concerned and the results of previous audits. Covering everything over a cycle, usually aligned to the three-year certification cycle, is common practice. Higher-risk areas are often audited every year.

    Why are clauses 4 to 10 audited every year by default?

    The management system clauses are where certification bodies tend to look at every surveillance visit, and they are small enough to fit into each year without crowding out the Annex A themes. You can turn that off if your risk picture says otherwise.

    Who can perform the internal audit?

    Anyone competent who is objective and impartial. In practice that means auditors do not audit their own work. Small teams often use an external internal auditor for this reason.

    Does this work for ISO 42001?

    Yes. Choose ISO 42001 and the planner uses its clauses 4 to 10 and the Annex A themes A.2 to A.10 for an AI management system.

    Is this planner free?

    Yes, free and no signup. Your choices stay in your browser.

    Not ready for a call yet?

    Get your audit programme by email

    Your plan to keep, then a few short notes from Jacob on running internal audits that hold up at certification. Unsubscribe in one click. Reply anytime; it reaches him directly.

    From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.

    Want it done for you?

    Internal Audit

    An independent internal audit against your programme, with findings your certification body can rely on.

    Explore Internal Audit →

    An internal audit that stands up at certification.

    We run your internal audits as an independent auditor, against the programme you planned, and write findings and nonconformities your certification body can follow. From $3,000 CAD.

    See internal audit Book a call

    Want the full picture on ISO 27001?

    This gives you the shape of the problem. The full picture is all 93 Annex A controls and 25 ISMS clauses (4-10) of ISO 27001, each one explained in plain English, with somewhere to attach the evidence and a readiness score that moves as you close gaps. Start a free assessment and walk every control.

    Start your free ISO 27001 assessment See what is in the Workspace

    No credit card, no trial clock, no locked features. TrazTech makes money when someone wants help closing the gaps, not from the Workspace itself.

    Track record

    Who is actually doing the work

    5
    Published CVEs, including a CVSS 9.1
    Zero
    Exceptions on a SOC 2 Type II built from nothing in-house

    Published vulnerability research

    Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

    A SOC 2 Type II built from nothing

    At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.