Skip to content

Audit & Assurance

ISO 27001:2022 Gap Assessment and Internal Audit

Independent assessment of your information security management system against ISO/IEC 27001:2022 — the management system clauses and the Annex A control set — so you know exactly what stands between you and a clean certification audit.

An important distinction

Most firms marketing ISO 27001 services in this region sell implementation: they write your policies, build your ISMS, and then offer to audit it. A firm cannot independently audit a management system it built. That is a self-review threat, and a competent certification body or regulator will challenge it.

We do the assurance side only. We assess, we audit, we tell you what is missing. If you need implementation support we will happily point you to firms that do it well — but it will not be us, and that is the point.

What we assess

  • Clauses 4 to 10 — context of the organisation, leadership and policy, planning and risk treatment, support and competence, operation, performance evaluation, and improvement. These are where most certification audits actually fail.
  • The risk assessment and treatment methodology — whether it is defined, applied consistently, and produces treatment decisions that trace to controls.
  • The Statement of Applicability — whether every Annex A control is justified as included or excluded, and whether the justification holds.
  • Annex A controls across all four themes — organisational, people, physical and technological — tested for design and, where the ISMS has been running long enough, operating effectiveness.
  • Mandatory documented information — the specific records a certification auditor will ask for on day one.
  • Internal audit and management review — whether the cycle has actually run, with evidence.

What ISO/IEC 27001:2022 actually contains

MANAGEMENT SYSTEM Clauses 4–10 · context · leadership · planning · support ·operation · evaluation · improvement ANNEX A · 93 CONTROLS 37 Organisational 8 People 14 Physical 34 Technological Certification audits most often fail on the clauses, not the controls.
Clauses 4–10 plus 93 Annex A controls across four themes.

Gap rating

Every requirement is rated on a consistent scale so you can plan remediation by effort and risk rather than working through an undifferentiated list. We report the gap, the evidence we saw or did not see, the specific clause or control reference, and what "closed" would look like.

Transitioning from the 2013 version

If your ISMS was built against ISO/IEC 27001:2013, the 2022 revision restructured Annex A substantially — the control set was reorganised into four themes, several controls were merged, and new controls were introduced covering areas such as threat intelligence, cloud services, and secure development. A transition gap assessment maps your existing control set onto the new structure, identifies genuinely new obligations, and rewrites the Statement of Applicability.

How the engagement runs

  1. 1

    Scope confirmation

    Agree the ISMS scope boundary, the sites, the systems and the exclusions, in writing.

  2. 2

    Documentation review

    Review the policy set, risk assessment, Statement of Applicability and mandatory records before we come on site.

  3. 3

    Interviews and walkthroughs

    Meet control owners across the scope to test whether the documented system is the one people actually follow.

  4. 4

    Control testing

    Sample-test Annex A controls for design and, where applicable, operating effectiveness.

  5. 5

    Gap analysis

    Rate every clause and control, with evidence and a defined closure condition for each gap.

  6. 6

    Reporting and roadmap

    Issue the gap report with a sequenced remediation plan and a realistic certification timeline.

What you receive

Clause-by-clause assessment of ISO/IEC 27001:2022 clauses 4 to 10
Annex A control assessment across all four control themes
Reviewed and annotated Statement of Applicability
Gap register with rating, evidence, clause reference and closure criteria
Prioritised remediation roadmap with effort estimates
Realistic assessment of certification readiness and likely timeline

Frequently asked questions

No, and neither can any consultancy. Certification can only be issued by an accredited certification body. What we provide is the independent assessment that tells you whether you are ready to engage one, and the internal audit that ISO 27001 requires you to perform regardless of who certifies you.

Because ISO 27001 requires an internal audit that is objective and impartial, and your implementation consultant cannot provide it for the system they built. Separating the two also means the gaps get reported honestly rather than quietly closed.

It depends entirely on your starting point. An organisation with mature security practice but no formal ISMS might be six to nine months out. One starting from nothing should plan on twelve to eighteen. Anyone promising certification in eight weeks is either selling you a certificate from an unaccredited body or planning to fail the audit.

We can. Integrated assessments are efficient because the management system clauses are largely common across ISO management standards. Business continuity is covered on our dedicated ISO 22301 page.

Related services

Related regulatory frameworks

Start with the workbook

Our ISO 27001:2022 gap assessment workbook is free and scores itself. Use it first — you will scope the engagement better for having done so.

Request a proposal
Top