ISO 27001 Internal Audits
Internal audits by qualified Lead Auditors that reduce real risk and avoid surprises during certification audits.


operating since 2017.
ISO 27001 requires certified organisations to undertake internal audits, typically annually, and to ensure those audits are performed competently and objectively. Many organisations lack the internal capacity, technical expertise, or independence to do this well on their own.
Our audits are led by a qualified ISO 27001 Lead Auditor who understands the risks relevant to your business, identifies nonconformities before the certification audit, and familiarises your team with the evidence and processes they'll encounter during certification and surveillance audits.
The audit is run with the expectations of certification bodies in mind, so findings reflect what a certification auditor is likely to challenge. Issues are identified while there's still time to address them.
Best for
Organisations meeting their annual ISO 27001 internal audit requirement and looking for senior, independent auditors who deliver findings their team can act on with confidence, whether you're preparing for initial certification, working through a surveillance year, or approaching recertification.
Why choose us for your ISO 27001 internal audit
Independence by design
The ISO 27001 standard requires internal audits to be impartial. Acumenis is structured to deliver that, with appropriate consultant segregation from any implementation work, with no commercial interest in glossing over what the audit finds.
Qualified Lead Auditors with technical depth
Your audit is led by qualified ISO 27001 Lead Auditors who also bring hands-on technical background in IT, software development, and cloud platforms. They understand the systems being audited rather than just the clauses being checked, and often surface technical vulnerabilities and other control gaps that have otherwise gone unnoticed.
No surprises during certification audits
The audit is run with the expectations of certification bodies in mind, so findings reflect what a certification auditor is likely to challenge. Issues are surfaced in your ISO 27001 implementation while there's still time to address them.
Audits that prepare your team for certification
Workshops are deliberately structured to familiarise your team with the audit process, evidence expectations, and the kinds of questions they'll be asked during certification. First-time clients benefit from procedural rehearsal as well as the audit.
Senior consultants, based in Australia
Scoped and delivered by experienced consultants based in Brisbane and surrounds, working with clients across Australia. On-shore data handling, local context, and clear accountability.
How your ISO 27001 internal audit runs
Planning
You and your lead auditor agree the audit scope, schedule, and participants. An audit plan is issued two to four weeks before the audit window to allow time to schedule workshops with the relevant people. An audit checklist is prepared from the agreed criteria and your documented ISMS scope.
Opening meeting
Your audit begins with a short opening meeting that introduces the auditor to participants, walks through the audit process and schedule, confirms access to documentation and evidence, and sets expectations for both the audit team and your participants.
Documentation review and workshops
Your auditor reviews your policies, procedures, and available evidence against the requirements of ISO 27001 and your documented contextual requirements, and runs workshops with the people who operate the relevant ISMS processes. Workshops complete the picture formed during the documentation review and identify where current practices don't align with stated requirements. Screen sharing is used where evidence sits in systems the auditor doesn't have access to. These workshops also familiarise your team with the audit process and evidence expectations they'll encounter during certification audits.
Closing meeting
At the conclusion of the audit, your auditor summarises and prioritises findings and recommendations, with time for your team's questions. You'll know what the report will say before it's written.
Reporting
You receive a comprehensive audit report describing the outcome of the audit, how your organisation complies (or doesn't) with the ISO 27001 standard, and documenting any nonconformities and other opportunities for improvement. The report is reviewed by a second senior Lead Auditor before delivery, and is written to support your internal audit processes and the conversations you'll have with your certification body.
Challenges we help you address
Internal audits done as a checkbox exercise
A clean report from an audit that didn't look hard isn't useful, and the certification body will look hard. Our audits are structured to find what's there to find, with workshops, documentation review, and evidence testing that reflect what the certification body will do, and meaningfully reduce risk.
Independence concerns with in-house auditors
The ISO 27001 standard requires audits to be impartial, and impartiality is hard to demonstrate when the auditor is part of the team being audited. Our audits are delivered by a Lead Auditor with no working relationship with your team, segregated from any Acumenis implementation work, and reviewed by a second Lead Auditor before delivery.
Audits that check clauses but miss the systems
ISO 27001 clauses describe what should be true; the evidence of whether it's true sits in systems, configurations, and day-to-day practice. Our audit team has hands-on technical background in IT, software development, and cloud platforms, so the systems being audited are understood as well as the clauses being checked.
Material change since the last audit
Acquisitions, restructures, technology changes, or ISMS team changes can introduce gaps that the certification body will find. Where material change has happened since your last audit, the scope and approach are calibrated to help identify those gaps, rather than treating the audit as a repeat of last year's.
Outcomes
After your ISO 27001 internal audit, you'll have:
- A comprehensive audit report covering compliance against ISO 27001, identified nonconformities, and opportunities for improvement
- An evidence-backed view of where your ISMS actually stands
- Findings prioritised so you can address what matters before the certification body sees it
- A team familiar with the audit process and evidence expectations they'll encounter during certification
- Confidence that the audit was conducted to the same standard a certification auditor would apply
Proof in practice.
A snapshot of how we've helped Australian organisations strengthen security, meet stakeholder expectations, and move forward with confidence.


Frequently asked questions.
Straight answers to the questions we hear most. Can't find yours? We're happy to help.
Most internal audits run between three and six days of audit activity, plus reporting time. The right duration depends on your ISMS scope, the size of your organisation, and the depth of evidence to be reviewed. You'll get a recommendation during scoping rather than a fixed package.
Most audits are conducted remotely, which works well for the document review, workshops, and evidence testing that make up the bulk of the engagement. Where you'd like the audit to evaluate physical security aspects of your ISMS, an on-site visit can be scoped as an add-on.
Yes. Where your ISMS has been extended with ISO 27701 (privacy) or integrated with ISO 42001 (AI), we can audit those components in the same engagement. The audit team holds the relevant Lead Auditor credentials for each standard.
You'll receive the audit report, with findings prioritised and discussed during the closing meeting before delivery. From there, addressing nonconformities sits with your team, since closing findings as part of the audit engagement would compromise independence at the next audit cycle. You're welcome to come back with questions as you work through the findings.
While we have certified lead auditors in our team, we don't perform certification audits for our clients to avoid a conflict of interest.
All Acumenis consultants are based in Australia, with team members in Brisbane and Toowoomba. We support clients nationally and internationally, meeting in person across South East Queensland and travelling as engagements require. Engagements are handled by the same consultant from start to finish, giving you clear accountability and on-shore data handling throughout.
Let's talk about where you are and where you need to be.
Whether you're preparing for certification, validating your controls, or building security foundations for growth, we'll help you get there with clarity and confidence.
