Audit & Assurance
ISO 27001:2022 Gap Assessment and Internal Audit
Independent assessment of your information security management system against ISO/IEC 27001:2022 — the management system clauses and the Annex A control set — so you know exactly what stands between you and a clean certification audit.
An important distinction
Most firms marketing ISO 27001 services in this region sell implementation: they write your policies, build your ISMS, and then offer to audit it. A firm cannot independently audit a management system it built. That is a self-review threat, and a competent certification body or regulator will challenge it.
We do the assurance side only. We assess, we audit, we tell you what is missing. If you need implementation support we will happily point you to firms that do it well — but it will not be us, and that is the point.
What we assess
- Clauses 4 to 10 — context of the organisation, leadership and policy, planning and risk treatment, support and competence, operation, performance evaluation, and improvement. These are where most certification audits actually fail.
- The risk assessment and treatment methodology — whether it is defined, applied consistently, and produces treatment decisions that trace to controls.
- The Statement of Applicability — whether every Annex A control is justified as included or excluded, and whether the justification holds.
- Annex A controls across all four themes — organisational, people, physical and technological — tested for design and, where the ISMS has been running long enough, operating effectiveness.
- Mandatory documented information — the specific records a certification auditor will ask for on day one.
- Internal audit and management review — whether the cycle has actually run, with evidence.
What ISO/IEC 27001:2022 actually contains
Gap rating
Every requirement is rated on a consistent scale so you can plan remediation by effort and risk rather than working through an undifferentiated list. We report the gap, the evidence we saw or did not see, the specific clause or control reference, and what "closed" would look like.
Transitioning from the 2013 version
If your ISMS was built against ISO/IEC 27001:2013, the 2022 revision restructured Annex A substantially — the control set was reorganised into four themes, several controls were merged, and new controls were introduced covering areas such as threat intelligence, cloud services, and secure development. A transition gap assessment maps your existing control set onto the new structure, identifies genuinely new obligations, and rewrites the Statement of Applicability.
How the engagement runs
-
1
Scope confirmation
Agree the ISMS scope boundary, the sites, the systems and the exclusions, in writing.
-
2
Documentation review
Review the policy set, risk assessment, Statement of Applicability and mandatory records before we come on site.
-
3
Interviews and walkthroughs
Meet control owners across the scope to test whether the documented system is the one people actually follow.
-
4
Control testing
Sample-test Annex A controls for design and, where applicable, operating effectiveness.
-
5
Gap analysis
Rate every clause and control, with evidence and a defined closure condition for each gap.
-
6
Reporting and roadmap
Issue the gap report with a sequenced remediation plan and a realistic certification timeline.
What you receive
Frequently asked questions
Related services
Related regulatory frameworks
Start with the workbook
Our ISO 27001:2022 gap assessment workbook is free and scores itself. Use it first — you will scope the engagement better for having done so.
Request a proposal