SERVICE / 11

IT audit & ISO 27001 readiness.

Audit preparation starts with knowing the systems in scope, their owners and existing evidence. We review IT readiness and prioritise improvements so the team works from shared information.

Discuss this serviceSee the scope
01 / WHO IT’S FOR

Prepare systems and evidence for an audit

For businesses preparing for IT audit, answering customer or partner control requirements, or preparing IT functions relevant to an ISO/IEC 27001 information security management system.

A readiness overview, gaps and missing evidence, plus an improvement plan, owners and follow-up priorities within your organisational scope.

02 / SCOPE WE AGREE TOGETHER

Service scope

01

Define objectives and scope

Identify systems, processes, departments and criteria, distinguishing advisory work, readiness assessment and internal audit.

02

Review IT controls

Interview stakeholders and review selected areas such as accounts, changes, backups, incidents and outsourced services.

03

Inventory and review evidence

Map requirements to policies, procedures, records and actual practice, identifying document owners and missing items.

04

Assess gaps and risk

Summarise evidence-backed findings, prioritise by business impact and note where information is insufficient.

05

Plan improvements and follow-up

List tasks, owners, timeframes and progress evidence, with agreed review cycles.

03 / BEFORE WORK STARTS

Budget and timeline

Cost depends on systems, processes, evidence readiness, stakeholders and follow-up rounds. Document preparation and system changes are additional items where needed.

How we plan the schedule

Agree on scope and information first, then schedule interviews, evidence review and reporting. Timing depends on people and documents being available.

Information that helps us estimate accurately

  • Audit objectives and applicable standards or requirements
  • Systems, departments and responsible people in scope
  • Policies, procedures and previous reports available for review
  • Relevant deadlines and contacts for each area
04 / FAQs

Common questions about this service

Does this service issue ISO/IEC 27001 certification?

This is assessment and preparation within an agreed scope. Certification audits are performed by external certification bodies; issuing or guaranteeing certification is not included.

Does this cover an organisation-wide ISMS?

The initial scope focuses on relevant IT readiness and controls. Organisation-wide ISMS work requires reviewing people, processes and the expertise needed before proposing additional scope.

Can you act as an internal auditor?

We first assess competence, impartiality and conflicts from prior advice or work in scope. If an independent auditor is needed, we agree on an approach with the organisation.

Can we use this without seeking ISO certification?

Yes. Start with a control or readiness review for customer requirements, setting objectives and criteria to match the work.

Let’s discuss your project

An idea you’d like to start
Or a system you’d like to improve.

Tell us about your business, goals and concerns
Then we’ll work out a scope that fits

Discuss your project

Prepare a project brief

Start with your idea

Share what you know so far. We can work through the rest later.

Choose a service above to see questions tailored to your project.

Do not include passwords, login credentials or your customers’ personal data in the brief.

Choose a service and fill in the details. Loremworks will reply to the email you provide, or download a copy to keep for the conversation.