Internal audit of your SMSI
The ISO 27001 requires regular internal audits. BCIT carries them out for you, with the required independence and objectivity, and prepares you with confidence for the management review and the certification audit.
Why conduct an internal audit?
The Clause 9.2 of ISO/IEC 27001 requires the organization to conduct internal audits at planned intervals, to verify that the SMSI complies with the standard, with its own requirements, and is effectively implemented and maintained.
The standard also requires these audits to be conducted with independence and objectivity: an auditor cannot audit their own work. This is precisely where many organizations lack neutral internal resources, and where BCIT acts as a competent third party.
What we audit and deliver
Audit program
We establish an audit program and audit plan tailored to your scope, your risks and the status of your SMSI.
Document review
Review of the policy, the SoA, procedures and records against the requirements of the standard.
Interviews & findings
Field interviews and evidence collection, followed by the formulation of conformities, nonconformities and opportunities for improvement.
Report & action plan
A clear, prioritized audit report, accompanied by a concrete, prioritized action plan.
Who is it for?
This service is intended for already certified organizations ISO 27001 that need to maintain their internal audits, as well as those undergoing certification that wish to validate their SMSI before the certification body's audit. It is particularly useful when you lack independent internal resources or want an expert and impartial view of your system.
Our auditor stance
Our audits are conducted by certified Lead Auditors, in accordance with the principles of ISO 19011, with rigor and care. Our objective is not to point out faults, but to give you a faithful view of your actual compliance and the levers for improvement. A factual, evidence-based approach resolutely focused on the success of your certification.
How the audit is carried out
Scoping
Definition of the scope, objectives and audit program with your teams.
Document review
Analysis of the documentation of the SMSI and preparation of the verification points.
Field interviews
Meeting the relevant stakeholders and collecting evidence of process effectiveness.
Findings
Identification of conformities, nonconformities and opportunities for improvement.
Report & action plan
Delivery of a prioritized report and a prioritized action plan.
Review & certification preparation
Support for the management review and preparation for the certification audit.
Why entrust your internal audits to BCIT?
A truly independent perspective
A neutral third party that fully meets the objectivity requirement of §9.2, with no conflict of interest.
Certified auditors
Experienced Lead Auditors who speak the language of certification bodies.
Ready for certification
You approach the certification body's audit with confidence and no unpleasant surprises.
Need an independent internal audit?
BCIT carries out your internal audits ISO 27001 with complete objectivity and prepares you for certification. Let's discuss your scope and timeline.
Internal audit of your SMSI
The ISO 27001 requires regular internal audits. BCIT carries them out for you, with the required independence and objectivity, and prepares you with confidence for the management review and the certification audit.
Why conduct an internal audit?
The Clause 9.2 of ISO/IEC 27001 requires the organization to conduct internal audits at planned intervals, to verify that the SMSI complies with the standard, with its own requirements, and is effectively implemented and maintained.
The standard also requires these audits to be conducted with independence and objectivity: an auditor cannot audit their own work. This is precisely where many organizations lack neutral internal resources, and where BCIT acts as a competent third party.
What we audit and deliver
Audit program
We establish an audit program and audit plan tailored to your scope, your risks and the status of your SMSI.
Document review
Review of the policy, the SoA, procedures and records against the requirements of the standard.
Interviews & findings
Field interviews and evidence collection, followed by the formulation of conformities, nonconformities and opportunities for improvement.
Report & action plan
A clear, prioritized audit report, accompanied by a concrete, prioritized action plan.
Who is it for?
This service is intended for already certified organizations ISO 27001 that need to maintain their internal audits, as well as those undergoing certification that wish to validate their SMSI before the certification body's audit. It is particularly useful when you lack independent internal resources or want an expert and impartial view of your system.
Our auditor stance
Our audits are conducted by certified Lead Auditors, in accordance with the principles of ISO 19011, with rigor and care. Our objective is not to point out faults, but to give you a faithful view of your actual compliance and the levers for improvement. A factual, evidence-based approach resolutely focused on the success of your certification.
How the audit is carried out
Scoping
Definition of the scope, objectives and audit program with your teams.
Document review
Analysis of the documentation of the SMSI and preparation of the verification points.
Field interviews
Meeting the relevant stakeholders and collecting evidence of process effectiveness.
Findings
Identification of conformities, nonconformities and opportunities for improvement.
Report & action plan
Delivery of a prioritized report and a prioritized action plan.
Review & certification preparation
Support for the management review and preparation for the certification audit.
Why entrust your internal audits to BCIT?
A truly independent perspective
A neutral third party that fully meets the objectivity requirement of §9.2, with no conflict of interest.
Certified auditors
Experienced Lead Auditors who speak the language of certification bodies.
Ready for certification
You approach the certification body's audit with confidence and no unpleasant surprises.
Need an independent internal audit?
BCIT carries out your internal audits ISO 27001 with complete objectivity and prepares you for certification. Let's discuss your scope and timeline.