Define objectives and scope
Identify systems, processes, departments and criteria, distinguishing advisory work, readiness assessment and internal audit.
SERVICE / 11
Audit preparation starts with knowing the systems in scope, their owners and existing evidence. We review IT readiness and prioritise improvements so the team works from shared information.
For businesses preparing for IT audit, answering customer or partner control requirements, or preparing IT functions relevant to an ISO/IEC 27001 information security management system.
A readiness overview, gaps and missing evidence, plus an improvement plan, owners and follow-up priorities within your organisational scope.
Identify systems, processes, departments and criteria, distinguishing advisory work, readiness assessment and internal audit.
Interview stakeholders and review selected areas such as accounts, changes, backups, incidents and outsourced services.
Map requirements to policies, procedures, records and actual practice, identifying document owners and missing items.
Summarise evidence-backed findings, prioritise by business impact and note where information is insufficient.
List tasks, owners, timeframes and progress evidence, with agreed review cycles.
Cost depends on systems, processes, evidence readiness, stakeholders and follow-up rounds. Document preparation and system changes are additional items where needed.
Agree on scope and information first, then schedule interviews, evidence review and reporting. Timing depends on people and documents being available.
This is assessment and preparation within an agreed scope. Certification audits are performed by external certification bodies; issuing or guaranteeing certification is not included.
The initial scope focuses on relevant IT readiness and controls. Organisation-wide ISMS work requires reviewing people, processes and the expertise needed before proposing additional scope.
We first assess competence, impartiality and conflicts from prior advice or work in scope. If an independent auditor is needed, we agree on an approach with the organisation.
Yes. Start with a control or readiness review for customer requirements, setting objectives and criteria to match the work.
Let’s discuss your project
Tell us about your business, goals and concerns
Then we’ll work out a scope that fits