Case Study · HR Technology

A seamless ISO 27001 transition for Heartpace.

Heartpace, an HR-technology company operating across Europe, completed a full ISO 27001:2022 internal audit with Atoro in four weeks, reaching certification readiness with every identified gap remediated and zero disruption to operations.

ISO 27001 internal audit

HR technology

Remote-first

4 weeks

Results & impact

ISO
27001

4 weeksFull internal audit delivered.

ISO 27001:2022ISMS aligned to the standard.

100%Identified gaps remediated.

ZeroDisruption to operations.

At a glance

  • Industry: HR technology, operating across Europe.
  • Engagement: ISO 27001:2022 internal audit.
  • Delivery: fully remote, via G-Suite, Zoom and Slack.
  • Timeline: four weeks, end to end.

01 The challenge

Certification readiness, with clarity and speed

Heartpace, a fast-growing HR-tech company operating across Europe, needed to prepare for ISO 27001:2022 certification. They required a structured, remote-first internal audit to assess their ISMS, identify compliance gaps, and confirm they were ready for certification, with clarity and speed.

They needed a partner who could deliver a clear audit methodology aligned with ISO 27001:2022, working fully remotely using G-Suite, Zoom and Slack, with structured timelines and prioritised recommendations.

02 The Atoro approach

Review, remediate, deliver

Review

Reviewed Heartpace’s ISMS documentation, including key policies, procedures, and control mappings, to assess alignment with ISO 27001:2022 clauses and identify early gaps.

Remediate

Presented initial findings highlighting non-conformities and areas for improvement. Guided remediation with practical support, clarifying issues and reviewing updated controls.

Deliver

Delivered the final internal audit report, summarising all findings and verifying improvements, so Heartpace was fully prepared for their ISO 27001 certification audit.

Certification readiness in four weeks, with zero disruption to operations.

In the client’s words

“Atoro is a great and knowledgeable team to work with. Always on time, care about details but also about having a friendly co-working atmosphere.”

Henrik Dannert, CEO, Heartpace

FAQ

ISO 27001 internal audit FAQs

How long does an ISO 27001 internal audit take?

Heartpace’s ISO 27001 internal audit took four weeks. It can be done faster, but four weeks is the optimum: it gives the auditors time to develop a deeper understanding of the company’s specific circumstances and context, as ISO 27001 expects, dig properly into the controls, and provide real feedback. A three-day audit can only be superficial and work as a checkbox exercise; four weeks lets the audit genuinely improve your security posture.

Can an ISO 27001 internal audit be done remotely?

Yes. Heartpace’s audit was delivered fully remotely, using collaboration tools like G-Suite, Zoom and Slack, and modern GRC platforms such as Vanta and Drata make remote audits even more straightforward. Since 2020, certification bodies themselves have delivered audits remotely, so it only makes sense that internal auditors can too. Working remotely over a number of weeks also gives us the ability to understand the business properly and do a deeper review than a short on-site visit allows.

What does an ISO 27001 internal audit involve?

An ISO 27001 internal audit reviews your ISMS against the requirements of the standard. A lot of internal auditors stop there. What matters is going further: reviewing the ISMS against your actual business context and company, and making sure the controls you have selected are genuinely fit for purpose. That is where a really valuable internal audit comes into play, and it is what Atoro looks to deliver, along with expert guidance on remediation to ensure your certification audit succeeds.

Next step

Ready for an internal audit that finds the gaps early?

Book a call and we will tell you the timeline and the price for your ISO 27001 internal audit in 30 minutes.

The service behind this story

ISO 27001 internal audit: independent, remote-first, run as you implement

ISO 27001 implementation: the full certification path

TrustOps: stay certified after the audit