Assurance & Risk
Internal Audit
An internal audit is an independent test, not a self-assessment. Controls are sampled and tested rather than confirmed by asking whether they exist.
Methodology
- 01
Plan
Plan the audit and its programme.
- 02
Understand
Understand the processes in scope.
- 03
Assess
Assess the management system and its controls.
- 04
Test
Test controls by sampling rather than by enquiry alone.
- 05
Record Findings
Record what the testing found.
- 06
Report
Report the findings and nonconformities.
- 07
Follow Up
Follow up the corrective actions to closure.
Approach to testing
- Requirement — what does the applicable standard, regulation or framework require?
- Control — what control has the organisation established?
- Implementation — how is the control actually implemented?
- Evidence — what evidence demonstrates that the control operates?
- Risk — what happens if the control is ineffective or absent?
- Action — what needs to be changed?
- Validation — has the corrective action actually addressed the issue?
Types of assessment
Black-Box
Assessment begins with limited organisational information, to provide an independent perspective of the governance environment.
Grey-Box
Selected organisational documentation, process information and evidence are provided for structured assessment.
White-Box
Full documentation, evidence, stakeholder and process access is provided for detailed control validation.
Hybrid
Combines independent assessment techniques with detailed evidence and stakeholder validation.
Frameworks and standards
- The applicable standard or framework
- Provides the audit criteria.
- CyberSmithSECURE Internal Audit Toolkit
- The toolkit the audit is run from.
Tools used
Tooling is where testing starts, not where it ends. Every automated result is reproduced by hand before it reaches a report.
CyberSmithSECURE Internal Audit Toolkit
Audit planning, criteria, sampling, control testing and findings.
GRC Assessment Toolkit
Internal audit, evidence assessment and remediation tracking.
PlyoGRC
Where appropriate, the toolkits are supported through PlyoGRC for control, evidence, risk and compliance management.
Checklist approach
The checklist is the floor, not the ceiling. It guarantees coverage so nothing standard is missed; the findings that matter usually come from what a tester does after it is complete.
Planning
- Audit planning
- Scope definition
- Audit criteria
Fieldwork
- Process interviews
- Evidence review
- Sampling
- Control testing
Outcome
- Findings
- Nonconformity identification
- CAPA review
- Audit closure
How CSS tests
A unified swarm of agents, for blind spot detection
AI agents drive several testing tracks against the same target at once, then cross-check each other. A single tester works one hypothesis at a time; parallel agents cover the space a sequential pass leaves behind.
Framework Mapping Agent — maps requirements and controls across applicable frameworks.
Policy Analysis Agent — identifies potential missing, inconsistent or outdated requirements.
Evidence Analysis Agent — associates evidence with applicable controls and identifies evidence gaps.
Risk Analysis Agent — identifies recurring risk themes and potential control weaknesses.
Blind-Spot Detection Agent — looks for issues that may not be immediately visible through conventional checklist assessment.
Executive Reporting Agent — helps transform detailed assessment information into concise management reporting.
AI-assisted analysis supports the assessment team but does not replace professional judgement. Material findings, risk conclusions and recommendations are reviewed and validated by CyberSmithSECURE professionals.
Why this differs
What CSS does that most vendors do not
Every one of these is checkable. Ask any vendor for the same and compare the answers.
Beyond the checklist
Structured checklists and framework mappings establish coverage, but the assessment continues through implementation, evidence, risk, action and validation.
Tested, not confirmed
Controls are sampled and tested; an audit that only asks whether a control exists is not an audit.
Operating control, not documentation only
Evidence is validated across five stages: Designed — is it appropriately designed? Implemented — has it been implemented? Operating — is it actually performed? Evidenced — can operation be shown? Effective — is it achieving its goal?
Human-in-the-loop AI assistance
AI-assisted analysis supports the assessment team but does not replace professional judgement. Material findings, risk conclusions and recommendations are reviewed and validated by CyberSmithSECURE professionals.
What you receive
A working management system, not a folder of documents
The target state is that owners know what they must do, management knows what decisions are pending, and evidence exists to demonstrate that controls operate. Outputs are grouped by who uses them.
Executive layer
Scope, risk posture, roadmap, management decisions, KPI/KRI, readiness summary
GRC layer
Risk register, Statement of Applicability, policies, procedures, ownership, evidence map, action tracker
Assurance layer
Internal audit, findings, CAPA, management review, certification-readiness assessment
Operational layer
Control records, recurring reviews, awareness, supplier / access / incident / continuity evidence as applicable
Governance cadence established
- Monthly
- Risk / action review, evidence status, control exceptions, material incidents
- Quarterly
- Risk trend, supplier / control reviews, KPI/KRI, management action tracking
- Annual
- Internal audit programme, management review, ISMS objectives, risk refresh, improvement plan
For this engagement specifically
- Control owners
- IT teams
- Security teams
- Compliance teams
- Process owners
- Auditors
- Key risks
- Significant gaps
- Business impact
- Priority actions
- Ownership
- Target timelines
Case studies
What this finds in practice
Representative engagement patterns. Sector and scale only — no client is named, and no detail is included that could identify one.
A healthcare organisation in the EU with an established ISMS, preparing for an ISO 27001 certification or surveillance audit and seeking independent readiness testing.
- Finding
- Documentation existed but had not been tested against what was actually running. Evidence sat with different departments in different formats, and management had no consolidated view of it. Controls that operated in practice were not always recorded in a form an external auditor could verify.
- Recommendation
- Define the internal audit plan, scope and criteria against ISO 27001:2022; assess management system clauses 4-10 and the applicable Annex A controls against implementation rather than against the documentation; interview control owners and examine records to test whether controls operated as documented; and classify nonconformities and observations, tracking corrective actions toward closure.
- Outcome
- Audit planning, scope and criteria, evidence review, control testing, corrective actions and management reporting, delivered as an internal audit plan, working papers, a findings report, a corrective action tracker and a management summary. The organisation's trustee praised the thoroughness of the readiness audit.
An organisation preparing for an external ISO 27001 certification or surveillance audit, seeking an independent view of control readiness.
- Finding
- With a certification or surveillance audit approaching, the organisation needed an independent internal assessment of its ISMS before external auditors arrived. Documentation and control evidence had not been reviewed end to end, and management needed visibility into gaps and corrective actions ahead of the external audit itself.
- Recommendation
- Define audit scope, criteria and plan against ISO 27001:2022; review policies, control implementation and evidence across the ISMS; interview control owners to assess operating effectiveness; classify findings by risk and deliver a management report; and track remediation to closure ahead of the external audit.
- Outcome
- An independent view of control effectiveness, early identification of gaps and nonconformities, and structured tracking that improved readiness before the external auditors arrived.
Next
Scope this assessment
Most scopes are settled in one call. Tell us what the application does and who uses it, and we will tell you what testing it properly involves.