What We Deliver
Every ISO management system standard asks for the same thing in clause 9.2: internal audits at planned intervals, done by people who are independent of the work they audit. For a company of thirty or three hundred people that is hard to staff from the inside. The quality manager cannot audit their own process, the security officer cannot audit their own controls, and hardly anyone has a certified auditor for ISO/IEC 42001 yet.
We deliver internal audit as a service for ISO 9001, ISO 27001 and ISO/IEC 42001. You get an independent auditor, an audit programme that covers the whole standard over the certification cycle, audits run on site or remotely, and a report written the way a certification body writes it: major and minor non-conformities, observations and opportunities for improvement, each with the evidence behind it. Then we stay with you until the corrective actions are closed.
The three standards share the same high-level structure, so if you run an integrated system we audit it as one. A single audit cycle covers context, leadership, planning, support and performance evaluation. Separate depth goes where the standards differ: the Annex A controls of ISO 27001, the Annex A controls of ISO/IEC 42001 and the operational clauses of ISO 9001.
We are not a certification body and we have no stake in the verdict. Our team includes a certified ISO/IEC 42001 auditor and people who have built and audited ISO 27001 and ISO 9001 systems for years, so the report tells you what the external auditor will see, before they see it.
How We Work
We start from your certification calendar. Whether the next visit is a stage 2, a surveillance or a recertification audit, the internal audit has to land before it, with enough time to close what it finds. We agree the scope, the sites and processes, the standards covered and whether the audit runs remotely, on site or as a mix.
The audit itself follows ISO 19011 practice: document review first, then interviews and sampling of records, then a closing meeting where nothing in the report comes as a surprise. We audit against the standard and against your own documented system, because certification auditors do both.
The report reaches management shortly after the closing meeting. Each finding carries its grade, its evidence, the clause it relates to and a proposed deadline for the corrective action. When you tell us an action is done, we verify it and confirm the closure in writing, which is exactly what the certification auditor will ask to see.
For ISO/IEC 42001 in particular, if you are not yet at the audit stage, we start with the gap analysis and the inventory of AI systems, so the first internal audit has something real to audit.
Who It Is For
Certified companies that need an independent internal auditor without hiring one, in particular subsidiaries and mid-sized firms where the same few people run quality, security and now AI governance. Groups operating in several countries, including Romania, that want one auditor and one report format across all sites. Companies preparing for their first ISO/IEC 42001 certification, where experienced auditors are still scarce. And software or consulting firms whose customers ask, in due diligence, whether the management system is actually audited, not only certified.
We deliver in English and Romanian, remotely across the EU and on site where the audit needs it.
Expected Outcomes
An internal audit programme that satisfies clause 9.2 and stands up in the certification audit. A findings report your management can act on and your certification body can follow. Corrective actions verified and closed before the external auditor arrives. And, for ISO/IEC 42001, an early and honest picture of how far your AI management system is from certification.