Articles

Support during an external ISO 27001 audit

How I support organisations as a consultant before, during and after an external ISO 27001 certification audit.

An external audit is an important milestone towards ISO/IEC 27001 certification. It involves more than presenting documents: auditors want to understand whether the information security management system (ISMS) fits the organisation and works in practice.

As a consultant, I help prepare the audit process, coordinate participants and turn findings into effective improvements afterwards. The independent audit itself is carried out by the certification body.

Before the audit: create clarity

We first clarify the framework. What scope is to be certified? Which sites, processes, services and participants are included? What does the certification body expect, and who needs to answer questions on each topic?

We then review the ISMS together, including risk assessment and treatment, the Statement of Applicability, objectives and responsibilities, internal audit results and management review. Evidence from daily operations is equally important: access rights, training, incidents, suppliers and implementation of agreed actions, for example.

My aim is to identify where processes are reliable and where a gap remains between documentation and practice. We prioritise outstanding items with named owners and realistic dates. Practical preparation also includes an agreed schedule, available contacts and easy-to-find evidence.

During the audit: provide guidance while preserving independence

Initial certification typically involves two stages. Stage 1 covers matters such as scope, ISMS documentation and readiness for detailed assessment. Stage 2 focuses more closely on implementation and effectiveness through interviews, sampling and evidence review.

I can be alongside you as a specialist contact, helping interpret questions, bring together the right people and evidence, and record open points. Managers and process owners remain responsible for statements about their own activities. The audit should show how the organisation actually works.

Auditors make their own independent assessment. I neither replace their work nor speak for the certification body. I therefore cannot promise certification.

After the audit: act effectively on findings

The closing meeting does not necessarily end the work. Where nonconformities or opportunities for improvement are identified, I help you understand the findings and examine their causes. Together, we agree appropriate corrections and corrective actions, assign responsibility and decide how effectiveness will be checked. The certification body’s requirements govern formal responses and deadlines.

Even after successful certification, the ISMS continues to evolve. Organisational changes, new risks and surveillance audits require current processes and evidence. Effective audit support strengthens your ability to manage information security over time.

My approach: the structure you need, grounded in practical work, so you can demonstrate an ISMS that genuinely supports your organisation.

← Latest articles