Services / Internal Audits

Internal Audits & Assessments

An independent view of whether controls work as intended

An internal audit should show whether defined requirements are being met — not produce a long checklist with no distinction between administrative corrections and material risk.

What an internal audit is meant to achieve

The scope, independence requirements, sampling approach, and expected outputs are established before fieldwork begins — so certification readiness, control maturity, and technical risk aren’t mixed into one unclear conclusion. Evidence is obtained from the people and systems responsible for the control, not from policy wording or management assertion alone.

The engagement terms state clearly whether Secalyx is evaluating conformity, assessing design, testing operation, or preparing you for another reviewer — each is a different objective with a different level of independence.

If Secalyx has designed or implemented controls under review, the potential self-review conflict is disclosed during scoping. The engagement is then re-scoped, independently reviewed, or assigned elsewhere, as appropriate. Certification, attestation, and statutory audit decisions remain with the authorized external body.

What the engagement covers

Defining the audit question

Conformity criteria, scope, sampling approach, and intended use of the report, agreed upfront.

Fieldwork

Document and record review, interviews, process walkthroughs, configuration examination, and sample-based control testing.

Findings that drive action

Requirement, condition observed, evidence, risk, likely cause, and recommended action with proposed ownership.

Reporting and stakeholder review

Draft findings discussed with responsible owners for factual accuracy before the report is finalized, without compromising the independence of the conclusion.

Closing the loop

Corrective-action tracking and follow-up validation, distinguishing closure from accepted residual risk.

The final scope, exclusions, responsibilities, timeline, and expected outputs are agreed before work begins.

The assurance lifecycle

Every audit runs through the same evidence-based cycle, regardless of the criteria being assessed against.

1. Plan

Objective, criteria, sampling

2. Examine

Documents & records

3. Validate

Interviews & walkthroughs

4. Conclude

Findings & report

5. Act

Corrective actions, owners, dates

6. Follow-up

Closure evidence

What you receive — and why it remains usable

Outputs

  • Audit or assessment plan
  • Scope, criteria, and sampling method
  • Findings register
  • Risk-prioritized audit report
  • Executive summary
  • Corrective-action tracker
  • Follow-up validation report

How Secalyx works

  • Findings classified consistently — nonconformities, control weaknesses, and observations aren’t blurred together.
  • Material issues discussed with stakeholders before the report is finalized.
  • Independence checked and safeguarded — where Secalyx has designed or implemented controls under review, that conflict is disclosed during scoping and the engagement is re-scoped, independently reviewed, or assigned elsewhere, as appropriate.
  • Report built for the purpose you actually need it for.

Need an independent view of whether your controls actually work?

Tell us the requirement, deadline, or pressure you are dealing with.

Related services: ISO 27001 Readiness · SOC 2 Readiness