ISO/IEC 27001 Internal Audit
A full internal audit of your ISMS against ISO/IEC 27001:2022, clauses 4 to 10 and the Annex A controls declared in your Statement of Applicability.
An audit is only worth having if the person running it is willing to tell you something you would rather not hear. We assess what you have built, evidence what we find, and hand you a report you can act on.
ZULTIV provides independent assurance, internal audit and readiness assessment. We are not an accredited certification body, we do not issue ISO certificates, and we do not act as a registrar.
That separation is the point. Because we are not the body that will certify you, we have no reason to soften a finding, and because we are not your implementer, we have no work of our own to defend. You get an honest read on where you stand before a certification body, a regulator or a customer forms their own.
Category 01
Clause 9.2 requires an internal audit programme. Running it with your own people is allowed, and often the wrong call, nobody audits the system they built with a straight face.
A full internal audit of your ISMS against ISO/IEC 27001:2022, clauses 4 to 10 and the Annex A controls declared in your Statement of Applicability.
Business continuity management audited against ISO 22301: BIA, recovery objectives, continuity strategy, and whether the exercises actually test anything.
Quality management system audit against ISO 9001: process interactions, risk-based thinking, and evidence of improvement rather than intention.
Category 02
Before the certification audit, the customer security review or the regulator's question, find out what the answer is going to be.
Administrative, physical and technical safeguards reviewed against the HIPAA Security and Privacy Rules, with a gap register you can work through.
Trust Services Criteria walked control by control, so your CPA firm's examination is not the moment you discover the evidence does not exist.
A structured look at your risk universe and control environment against the obligations that actually apply to you, including India's DPDP Act.
Your suppliers hold your data and your uptime. We assess them properly, on evidence, rather than on a returned questionnaire nobody read.
How we work
No two organisations look alike, but the discipline does not change. Every assessment we run follows ISO 19011 audit principles: evidence-based, impartial, and reported in language you can hand to a board.
We agree what is in scope, what is deliberately out, and what "good" looks like before anything is examined.
Documents, interviews, system evidence and sampling, enough to reach a conclusion that survives challenge.
Findings with the requirement, the evidence and the gap kept separate, each graded and each traceable.
A prioritised remediation path, and a follow-up review when you are ready to show the gaps are shut.
What you receive
Scope, method, sample, and every finding with its evidence trail, written so a third party can follow your reasoning without you in the room.
Each gap mapped to the clause or criterion it breaches, graded, and ranked by the risk it actually carries rather than how easy it is to fix.
A sequenced plan with owners and realistic effort, plus a management summary your leadership will read to the end.
Questions
Request an assessment
Describe the scope in your own words: a system, a standard, a customer's security questionnaire, or just a deadline you have been handed. We will tell you what it takes.