Services / Internal Audits
An independent view of whether controls work as intended
An internal audit should show whether defined requirements are being met — not produce a long checklist with no distinction between administrative corrections and material risk.
The scope, independence requirements, sampling approach, and expected outputs are established before fieldwork begins — so certification readiness, control maturity, and technical risk aren’t mixed into one unclear conclusion. Evidence is obtained from the people and systems responsible for the control, not from policy wording or management assertion alone.
The engagement terms state clearly whether Secalyx is evaluating conformity, assessing design, testing operation, or preparing you for another reviewer — each is a different objective with a different level of independence.
If Secalyx has designed or implemented controls under review, the potential self-review conflict is disclosed during scoping. The engagement is then re-scoped, independently reviewed, or assigned elsewhere, as appropriate. Certification, attestation, and statutory audit decisions remain with the authorized external body.
Conformity criteria, scope, sampling approach, and intended use of the report, agreed upfront.
Document and record review, interviews, process walkthroughs, configuration examination, and sample-based control testing.
Requirement, condition observed, evidence, risk, likely cause, and recommended action with proposed ownership.
Draft findings discussed with responsible owners for factual accuracy before the report is finalized, without compromising the independence of the conclusion.
Corrective-action tracking and follow-up validation, distinguishing closure from accepted residual risk.
The final scope, exclusions, responsibilities, timeline, and expected outputs are agreed before work begins.
Every audit runs through the same evidence-based cycle, regardless of the criteria being assessed against.
Objective, criteria, sampling
Documents & records
Interviews & walkthroughs
Findings & report
Corrective actions, owners, dates
Closure evidence
Tell us the requirement, deadline, or pressure you are dealing with.
Related services: ISO 27001 Readiness · SOC 2 Readiness