Internal Audit

Strengthen your organization's internal controls. We perform independent internal IT audits that objectively assess processes, systems and controls, delivering concrete improvement recommendations.

05

Internal Audit

Internal controls - Risk management - Independent assurance

Strengthen your organization's internal controls. We perform independent internal IT audits that objectively assess processes, systems and controls, delivering concrete improvement recommendations.

We assess the effectiveness of IT processes, internal controls and information security from an independent position. Our audits provide management and the board with objective insight into the quality of internal governance.

From general IT controls (ITGC) and application controls to access management and security management. We test what matters most. For each control we assess three things: design (is the control well designed), implementation (does it actually exist) and operating effectiveness (did it function consistently over the period). We do that through interviews, documentation review, inspection of system settings and sampling.

Many organizations are required or want to perform internal audits, but lack the independent position or the IT audit expertise in house. Whoever assesses their own work is not an internal auditor. We then fulfil the internal audit function as an external party: we draw up the audit programme, perform the audits and report directly to management or the board.

Every ISO management system standard requires internal audits at planned intervals: ISO 27001 for information security, ISO 42001 for AI management, ISO 9001 for quality, ISO 22301 for business continuity and NEN 7510 for Dutch healthcare. The certification body reviews not only whether the audits were performed, but also whether the audit programme covers the whole standard, whether the auditor is independent and competent, and whether findings led to corrective action.

We perform these internal audits as an independent party, with auditors who know the standards because they also work with them as external auditors. The guidance per requirement, with interview questions, expected documents and common nonconformities, is built into our platform. So you know in advance what the certification body will look at.

Further reading: internal audits for ISO certification and auditing your AI management system.

Stand-alone audits without a programme produce stand-alone findings. An audit programme records which topics are covered in which year, so that within a cycle of one to three years all relevant processes, systems and requirements have been tested. Frequency is risk-based: critical systems and topics with previous findings return more often than stable, low-risk processes.

We draw up the annual plan together with management and maintain it in our platform, including the schedule, the work programmes per audit and the follow-up of findings across the years. The programme moves with the organization: a new application, an incident or a change in legislation leads to adjustment, not to waiting for next year's plan.

Our internal audits are always risk-based. We focus on areas with the highest impact: critical systems, sensitive data and processes where the greatest risks reside. This ensures our findings deliver real value.

After completion, you receive a clear report with findings, risk classifications and concrete recommendations. Through our platform you can monitor the follow-up of improvement actions in real-time.

What is an internal IT audit?

An independent assessment of IT processes, controls and information security within your own organization, performed on behalf of management or the board. The audit establishes whether controls are designed, implemented and operating, and delivers findings with concrete improvement actions.

Can you outsource the internal audit function?

Yes. Many organizations are required or want to perform internal audits, but lack the independent position or the IT audit expertise in house. We then fulfil the internal audit function as an external party, including the audit programme, execution and reporting to management.

Is an internal audit mandatory for ISO certification?

Yes. ISO management system standards such as ISO 27001, ISO 42001, ISO 9001 and ISO 22301 require internal audits at planned intervals, performed by someone independent of the work being assessed. The certification body reviews the audit programme, the execution and the follow-up of findings.

What is the difference between an internal and an external audit?

An internal audit is performed on behalf of the organization itself, to learn and improve before someone else finds the issues. An external audit is performed on behalf of a third party, such as a certification body or a client's auditor, and results in a certificate or assurance report.

How often should you perform an internal IT audit?

That depends on the risk profile and on the requirements of standards or regulators. Common practice is an annual audit programme in which all relevant topics are covered within a cycle of one to three years, with higher frequency for the areas with the highest risk or previous findings.

Looking for an IT auditor?

Every organization is unique. Get in touch for a no-obligation conversation about IT audit, compliance or risk management.