ISO/IEC 27001 Internal Audit
A full internal audit of your ISMS against ISO/IEC 27001:2022, clauses 4 to 10 and the Annex A controls declared in your Statement of Applicability.
An audit is only worth having if the person running it is willing to tell you something you would rather not hear. We assess what you have built, evidence what we find, and hand you a report you can act on.
ZULTIV runs your internal audit, your readiness assessment and your third-party review against the same standards we teach. You finish with the evidence pack, the corrective plan and the confidence to book the certification audit.
Our independence is what makes that verdict worth having. We have no certificate to sell you and no implementation of our own to defend, so nothing is softened. You get an honest read on where you stand before a certification body, a regulator or a customer forms their own.
Scope note: ZULTIV is not an accredited certification body. Your accredited certificate is issued by the registrar you appoint. Our job is to make sure that audit is one you pass.
Category 01
Clause 9.2 requires an internal audit programme. Running it with your own people is allowed, and often the wrong call, nobody audits the system they built with a straight face.
A full internal audit of your ISMS against ISO/IEC 27001:2022, clauses 4 to 10 and the Annex A controls declared in your Statement of Applicability.
Business continuity management audited against ISO/IEC 22301: BIA, recovery objectives, continuity strategy, and whether the exercises actually test anything.
Quality management system audit against ISO/IEC 9001: process interactions, risk-based thinking, and evidence of improvement rather than intention.
Category 02
Before the certification audit, the customer security review or the regulator's question, find out what the answer is going to be.
Administrative, physical and technical safeguards reviewed against the HIPAA Security and Privacy Rules, with a gap register you can work through.
Trust Services Criteria walked control by control, so your CPA firm's examination is not the moment you discover the evidence does not exist.
A structured look at your risk universe and control environment against the obligations that actually apply to you, including India's DPDP Act.
Your suppliers hold your data and your uptime. We assess them properly, on evidence, rather than on a returned questionnaire nobody read.
Category 03
When a customer, an investor or a regulator asks for proof, a signed independent attestation answers the question in one document.
An Attestation of Compliance (AOC) is a formal statement, issued and signed by ZULTIV, confirming that we examined your controls against a named framework on a named date and found them implemented and operating.
It is the document you hand to a client security team that will not accept a self-assessment questionnaire, and the one that keeps a deal moving while a full certification audit is still months away.
A signed attestation letter, the scope statement it rests on, the control testing summary behind it, and a findings log for anything that had to be fixed first.
Typically three to six weeks from scoping to signature, depending on the size of the estate and how much evidence already exists.
ISO/IEC 27001, ISO/IEC 27701, ISO/IEC 42001, ISO/IEC 22301, HIPAA, SOC 2 criteria and India's DPDP Act, individually or combined.
An Attestation of Compliance is ZULTIV's own independent attestation. It sits alongside, and is not a substitute for, an accredited ISO management system certificate issued by a certification body.
How we work
No two organisations look alike, but the discipline does not change. Every assessment we run follows ISO 19011 audit principles: evidence-based, impartial, and reported in language you can hand to a board.
We agree what is in scope, what is deliberately out, and what "good" looks like before anything is examined.
Documents, interviews, system evidence and sampling, enough to reach a conclusion that survives challenge.
Findings with the requirement, the evidence and the gap kept separate, each graded and each traceable.
A prioritised remediation path, and a follow-up review when you are ready to show the gaps are shut.
What you receive
Scope, method, sample, and every finding with its evidence trail, written so a third-party can follow your reasoning without you in the room.
Each gap mapped to the clause or criterion it breaches, graded, and ranked by the risk it actually carries rather than how easy it is to fix.
A sequenced plan with owners and realistic effort, plus a management summary your leadership will read to the end.
Questions
Request an assessment
Describe the scope in your own words: a system, a standard, a customer's security questionnaire, or just a deadline you have been handed. We will tell you what it takes.
Hello! Happy to help.
Chat with us on WhatsApp for Training, Certification and Assurance.