Audit planning
We draw up an individual, risk-based audit plan that fits your audit programme. Coordination starts early – at least four weeks before the start.
Your audit plan
A risk-based audit plan aligned with your audit programme.
Your situation
Your company has to carry out internal audits – but you lack the time, the experience or a neutral outside view? We support you with specific observations, realistic recommendations and a solid basis for certification.
Free of charge and without obligation.

Your situation
ISO/IEC 27001, BSI IT-Grundschutz, VDA ISA / TISAX®, BAIT, MaRisk, DORA or KRITIS (critical infrastructure) evidence under Section 8a BSIG require regular internal audits. Even without a formal obligation, BaFin, the KBA, internal audit departments or clients require them as part of their compliance rules.
Internal audits must be carried out by people who are both independent and competent. In-house, this is often difficult to achieve – anyone who helped shape the ISMS can hardly audit it independently. Other organisations want to replace their previous auditor or prepare for the external audit with audit training.
This is where we come in: our certified auditors audit in line with the standard and focus on your real processes rather than an ideal model. Our aim is not to find faults but to create transparency. If no audit is mandatory and you would like a well-founded position check, the Cyber Security Check (BSI/ISACA guideline) is an alternative.
Audit scope
Depending on the context, we audit against established standards, regulatory requirements or your own "best practice".
Services & results
You get transparency about your ISMS (information security management system) and a solid basis for certification: internal audits to ISO/IEC 27001, BSI IT-Grundschutz, VDA ISA / TISAX®, BAIT, MaRisk, DORA or for KRITIS evidence, carried out by certified auditors. The audit plan is risk-based, and your documents are reviewed in advance so that the audit goes straight to the key topics.
Our approach is based on ISO/IEC 27006, ISO/IEC 27007 and the BSI guideline for IS audits. Instead of a rigid questionnaire, we use a structured question framework that adapts specifically to your ISMS during the audit and that we regularly align with the state of the art.
We draw up an individual, risk-based audit plan that fits your audit programme. Coordination starts early – at least four weeks before the start.
Your audit plan
A risk-based audit plan aligned with your audit programme.
We review relevant documents for completeness, plausibility and practicability before the audit date. This way, we go straight to the key topics in the audit instead of reading policies together. This saves time and allows a deeper look at your actual ISMS.
Experienced, independent and certified auditors conduct interviews, visual inspections and sampling – clearly, critically and solution-oriented. You receive daily summaries.
At the end, there is a closing meeting with all relevant participants, with a wider group on request, such as senior management.
The audit report contains clear findings, traceable samples and identified potential for improvement. A competent person not involved in the audit reviews it for content, after which it is copy-edited. This ensures that findings are documented correctly, consistently and comprehensibly.
Your audit report
Findings you can use internally – for improvements, management decisions and the external audit.
You receive the report for review. If needed, we clarify open points in an additional closing meeting and adjust the report where necessary.
At secuvera, internal audits are carried out by trained and certified auditors, for example with the ISO 27001 Lead Auditor qualification. Our company also employs IS auditors and auditors for ISO 27001 on the basis of IT-Grundschutz; since December 2011, secuvera has been a BSI-certified IT security service provider for IS audit (IS-Revision).
Our audit methodology is based on ISO/IEC 27006, ISO/IEC 27007 and the BSI guideline for IS audits. We develop the question framework iteratively and regularly adapt it to the state of the art.
Every report goes through two-stage quality assurance: a technical review by a person not involved in the audit, followed by copy-editing.
Getting started
We discuss the standard, audit programme, organisational scope and date. Existing audit reports and ISMS documents help to set the focus.
On request, we also audit secure software development or compliance with internal technical requirements and policies. Depending on the context, we use OWASP SAMM, CIS Benchmarks or your company-specific requirements.

Audit criteria, roles and scope are agreed in advance. An internal audit does not replace certification or recognition by an authority.
Yes. secuvera carries out internal audits with trained and certified auditors, for example with the ISO 27001 Lead Auditor qualification. The audit assignment and independence are clarified in advance. The audit remains part of your internal audit programme.
Under the approach described, coordination starts at least four weeks before the start. Relevant documents are reviewed before the audit date. Which documents are needed depends on the audit criteria and the area under review.
Interviews, visual inspections and sampling examine the actual processes. The preparatory document review provides targeted questions for this. Feedback during the audit and a closing meeting put the findings into context with the participants.
This is one of the typical reasons why organisations come to us. A new perspective often reveals topics that no longer stand out in the usual routine. The requirements of your audit programme remain in place.
Yes. We offer audit training or an independent pre-audit for this. This way, your responsible staff know the procedure and the open points before the certification body audits.