SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Internal audit

  Quote
Guest
Guest user Created:   Apr 21, 2021 Last commented:   Apr 21, 2021

Internal audit

I am advising a *** company at the moment, as well as a ‘daughter company’ in the *** on ISO 27001. Just some questions:

1 - In the ***, there is only one person actively working, but he is (of course) also shareholder. Would it be okay if he does the internal audit? In ***, we want to have the CTO as internal auditor. He doesn’t have shares, but he is part of Management. Would this be okay?

2 - What would be the cost of an online training for these internal auditors?

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Apr 21, 2021

1 - In the ***, there is only one person actively working, but he is (of course) also shareholder. Would it be okay if he does the internal audit? In ***, we want to have the CTO as internal auditor. He doesn’t have shares, but he is part of Management. Would this be okay?

ISO 27001 does not prescribe who must perform the internal audit, only requires this person to have the proper competencies for auditing, and that any situations that can lead to a conflict of interest are avoided (e.g., a person should not audit his/her own work).

Considering that:

  • for your first scenario, you should consider hire an external auditor or send a trained employee to perform the audit of the work performed by this single person
  • for your second scenario, you should consider hire an external auditor, or use a trained employee to perform the audit on the processes the CTO works on

This article will provide you a further explanation about internal audit:

This material will also help you regarding internal audit:

2 - What would be the cost of an online training for these internal auditors?

Advisera’s ISO 27001 Internal Auditor course is free to enroll (you only have to pay in case you want the course’s certificate). For more information about this course, please see:

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Apr 21, 2021

Apr 21, 2021

Suggested Topics