Skip to content

Services, Wiki-Artikel und Blog-Beiträge durchsuchen

↑↓NavigierenEnterÖffnenESCSchließen

Internal Audit ISO 27001

Find weaknesses before the auditor does.

Our certified Lead Auditors review your ISMS with the same methodology as the external certification body - so you have no surprises in the real audit.

ISO/IEC 27001:2022 Certified Lead Auditors ISO 19011 compliant

Trusted by over 200 organisations

Internal audits conducted
100+
Pass the certification audit first time
93%
Years of audit experience
10+
To individual quote
24h

Why do organisations fail the certification audit?

The most common causes of Major nonconformities are avoidable - if you look carefully beforehand.

Organisational blind spots

Whoever built their own ISMS systematically overlooks gaps. The external perspective uncovers what is considered self-evident internally - but is not standard-compliant.

Documentation vs. reality

The ISMS is perfect on paper - but in day-to-day operations processes are bypassed, exceptions go undocumented, and controls are not practised. That is exactly what the external auditor checks.

Time pressure before the audit

Many organisations only start audit preparation shortly before the certification date. Major nonconformities discovered at that stage can cost months and thousands of euros.

Our audit process

The 5-phase audit process

From scoping through document review and on-site audit to the verified remediation of all nonconformities.

  1. Scoping & audit planning: Joint definition of the audit scope, the areas and controls to be examined. Creation of a detailed audit plan with timeline and points of contact.
  2. Document review: Advance analysis of your ISMS documentation: policy, risk assessment, SoA, guidelines, and procedures. Identification of gaps and inconsistencies.
  3. On-site audit: Interviews with process owners, sample checks, technical verification, and walkthroughs. We examine whether your ISMS is not only documented but genuinely practised.
  4. Audit report & action plan: Structured report with findings (Major/Minor/Observation/Strength), prioritised action plan, and concrete recommendations for remediation.
  5. Follow-up & verification: Support in implementing corrective actions. Verification of the remediation of nonconformities before the external certification audit.

Why AWARE7 for your internal audit

What sets us apart from other providers

Pure awareness platforms don't test systems. Pure consulting firms are too far removed. AWARE7 combines both: we hack your infrastructure and train your employees: tailored to mid-sized companies, personal, without enterprise overhead.

Research and teaching as our foundation

20 %

Around 20% of our revenue comes from research projects for the BSI and the BMBF. Our studies, published at ACM and Springer conferences, analyse millions of websites and tens of thousands of phishing emails. Three of our executives are professors at German universities at the same time.

Digital sovereignty: no compromises

100 %

All data is stored and processed exclusively in Germany, without US cloud providers. All staff are permanently employed, covered by social insurance and bound by uniform legal obligations.

Fixed price within 24h: predictable project timelines

24 h

Within 24 hours you receive a binding fixed-price quote without hourly rate risk. A well-practised team and standardised processes ensure a clear schedule with a defined start and end date.

Your dedicated contact

1:1

A personal project manager accompanies you from the first meeting to the retest. You book appointments directly with your contact person and keep the same contact throughout the project.

Peer-reviewed publications

First page of the paper: Different Seas, Different Phishes - Large-Scale Analysis of Phishing Simulations

Different Seas, Different Phishes - Large-Scale Analysis of Phishing Simulations

ACM AsiaCCS 2025

Oskar Braun, Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann

First page of the paper: A Platform for Physiological and Behavioral Security

A Platform for Physiological and Behavioral Security

NSPW 2025

Jan Hörnemann

First page of the paper: Privacy from 5 PM to 6 AM: Tracking and Transparency in the HbbTV Ecosystem

Privacy from 5 PM to 6 AM: Tracking and Transparency in the HbbTV Ecosystem

IEEE/IFIP DSN 2025

Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann

First page of the paper: Understanding Regional Filter Lists: Efficacy and Impact

Understanding Regional Filter Lists: Efficacy and Impact

PoPETS 2025

Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann

Who is AWARE7 the right partner for?

Mid-sized companies with 50-2,000 employees

Companies that need real security, without paying for a DAX-corporation provider. Fixed price, clear scope, one point of contact.

IT managers & CISOs

Who have to argue convincingly in-house and need a report in boardroom language for that, not just technical findings.

Regulated industries

Critical infrastructure, healthcare, financial services: NIS-2, ISO 27001, DORA. We know the requirements and deliver evidence that auditors accept.

Your Lead Auditors

IRCA-certified ISO 27001 Lead Auditors with 10+ years of audit experience - for internal audits that genuinely prepare you for certification.

Frequently asked questions about internal audits

Questions about the process, findings, costs, or technical testing? Find answers here.

ISO 27001 (Clause 9.2) requires regular internal audits as part of the continual improvement process (PDCA cycle - Plan-Do-Check-Act). Internal audits are the best preparation for the external certification audit - they uncover weaknesses before the external auditor finds them. Without evidence of internal audits, certification is not possible.
In principle yes, but ISO 27001 requires objectivity and impartiality from the auditor. Whoever implemented a process may not audit it themselves. In SMEs in particular, resources and the necessary distance are often lacking. An external internal auditor brings a fresh perspective, industry experience, and benchmarking knowledge - and saves you from having to build internal audit competence.
ISO 27001 requires at least annual internal audits covering the entire ISMS scope. In practice many organisations distribute audits across the year: different areas are reviewed at different times (rolling audit schedule). We recommend auditing critical controls more frequently.
A Major nonconformity is a serious failure: a key control element is missing, does not function, or was not implemented at all. A Minor nonconformity is a minor deficiency that does not endanger the overall effectiveness of the ISMS. Both must be remedied before certification, but Major nonconformities require immediate corrective action with root cause analysis.
An internal audit is conducted by or on behalf of the organisation itself and serves as self-assessment. The external certification audit is conducted by an accredited certification body (e.g. TUV, DEKRA) and leads to ISO 27001 certification on successful completion. Our internal audit simulates the external audit in methodology and depth - so that you have no surprises in the real audit.
Our audit report contains: executive summary for management, detailed findings with evidence and standard reference, classification of each finding (Major/Minor/Observation/Strength), a prioritised action plan with responsibilities and deadlines, and an overall assessment of your certification readiness. The report is structured so that it can serve directly as evidence for the external auditor.
Costs depend on scope size, number of sites, and the complexity of your ISMS. For an SME with 50-200 employees and a single site, the investment is typically EUR 3,000-8,000 for a complete internal audit including document review, on-site audit, and report. We provide an individual quote within 24 hours.
An internal audit for an SME typically takes 3-5 audit days on-site, plus 2-3 days for document review and report preparation. For larger organisations or multiple sites we plan correspondingly more time. From engagement to completed report: typically 2-4 weeks.
Yes. In addition to the organisational review (policies, processes, responsibilities), we also verify technical controls: access controls, network segmentation, patch management, backup procedures, logging, and monitoring. Where appropriate, we can combine the internal audit with a technical vulnerability scan.

Ready for your internal audit?

93% of organisations audited by AWARE7 pass their certification audit on the first attempt. Your individual quote is ready within 24 hours.

Kostenlos · 30 Minuten · Unverbindlich

Rufen Sie uns an

Mo-Fr, 8:00-17:00 Uhr - persönlich und unverbindlich.

0209 8830 6764
Jetzt anrufen