Last reviewed 8 August 2026 by Daniyah Imran. This page is reviewed quarterly; the next review is due November 2026. Market facts are date-stamped “as of 07-08-2026”.
Short answer: anyone competent and demonstrably independent of the work audited can perform your ISO 27001 internal audit, your own staff, a peer arrangement, or an outsourced provider. Clause 9.2 does not require you to do it yourself: the standards framework explicitly contemplates an internal audit “conducted by the organisation itself, or by an external party on its behalf” (ISO Harmonized Structure, term 3.18, Note 2). What it forbids in practice is two things: your certification body auditing you (prohibited outright), and anyone auditing a system they built. For a 12–50 person software company where the same few people designed and operate the controls, an independent outsourced provider is usually the cleanest way to satisfy clause 9.2.2(b)’s objectivity and impartiality requirement (clause wording paraphrased from the ISO Harmonized Structure).
This list covers independent internal-audit providers serving software companies in the UK, Ireland and Europe, as of 07-08-2026. Still working out what clause 9.2 requires, scope, frequency, deliverables? Start with our sibling decision guide: ISO 27001 internal audit requirements.
How we selected the entries (read this before the list)
The criteria below are applied to every provider on this list, including us. Atoro wrote this list and is on it.
1. Independence from your implementation, the rule that includes us. A provider who built your ISMS cannot objectively audit it; clause 9.2.2(b) requires auditor selection that ensures objectivity and impartiality (paraphrased). So, plainly: if Atoro implemented your ISMS, we will not audit it; ask us for the build OR the audit, never both. The same test was applied to every entry below. If a consultancy both implements and audits, ask how it firewalls the two, the credible answer is separate teams and a written conflict-of-interest statement.
2. Not your certification body, with no cooling-off fix. Your certification body (CB) cannot provide your internal audit. ISO/IEC 27006-1 clause 5.2.2 states that the certification body “shall not provide internal information security reviews of the client’s ISMS subject to certification” and “shall be independent from the body or bodies (including any individuals) which provide the internal ISMS audit”. European Accreditation confirmed (FAQ Q49.4, March 2025) that for ISMS certification there is no two-year cooling-off mitigation, unlike the general ISO/IEC 17021-1 position. None of the entries below is a certification body.
3. Demonstrable competence, not certificates. No clause of ISO 27001 requires an internal auditor to hold a Lead Auditor certificate. The operative requirement is competence (clause 7.2, paraphrased), with ISO/IEC 27007:2020 providing the auditor-competence guidance. We favoured providers who state their auditors’ qualifications and method (ISO 19011 alignment) openly.
4. Software-company fit. Small software teams have a specific problem: the people who run the controls are the people who would audit them. We favoured providers with published experience auditing cloud-native, engineering-led organisations, including those working inside GRC platforms such as Drata or Vanta.
5. Deliverables that map to clause 9.2.2. A proper engagement should produce an audit programme and plan, defined criteria and scope, findings with nonconformities and improvement opportunities, a management-ready report, and documented evidence feeding your 9.3 management review and 10.2 corrective actions.
6. Transparent commercial shape. Pricing is rarely published in this market; where it is (as of 07-08-2026), we say so.
The providers
How this list is ordered. Our selection criteria are above. Atoro is first; the other providers follow alphabetically, described from their own published material.
Disclosure. This guide is published by Atoro, which is included in the comparison. We apply the stated criteria consistently, link to supporting evidence and identify claims we could not independently verify.
All entries follow the same structure. Provider descriptions are drawn from their own published pages (their own marketing claims, as of 07-08-2026); none has been independently audited by us.
Atoro
Atoro is an Irish AI governance and cyber compliance consultancy, ISO 27001 certified itself and the first consultancy in Europe certified against ISO 42001. Every auditor on the team is IRCA certified against ISO 27001. The third criterion on this list is demonstrable competence rather than certificates, and that is the test applied to us: we name the qualification and the body instead of asking you to assume them. Holding the certification ourselves also means the audit is run by people who have sat on the receiving end of one, so they know which evidence a certification auditor actually samples and where a control set goes thin under testing.
The audit runs either as a standalone cycle or continuously alongside a Drata or Vanta build, delivered by a team kept separate from Atoro’s implementation consultants. If Atoro built your ISMS, Atoro will not audit it, which is the same independence test applied to every entry here. A senior engineer in your time zone leads the work rather than an account manager. Pricing is fixed after scoping and published at atoro.io/pricing. Across security and compliance, Atoro has delivered more than 200 certifications. See how we run ISO 27001 internal audits.
- Best for: Scaling software and AI companies with enterprise customers, that want an independent, engineer-led internal audit, including where another firm built the ISMS.
Assent Risk Management
- Market: UK.
- Offer: Outsourced internal audits across Annex-SL standards including ISO 27001 (and a dedicated ISO 42001 page); risk-based programme aiming to cover every clause within the certification cycle, checked against ISO 19011.
- Delivery & pricing: Remote or onsite; an indicative ~£1,600 for a basic two-day remote audit is stated on its site (as of 07-08-2026).
- Good fit for: Buyers who want a published price anchor and a strong FAQ-led scoping process.
- assentriskmanagement.co.uk
CG Business Consulting (CGBC)
- Market: Ireland.
- Offer: An outsourced or “managed” internal-audit service covering ISO 27001 (and ISO 50001), positioned as an ongoing managed function rather than a one-off.
- Delivery & pricing: Not published in detail; page detail is sparse as of 07-08-2026.
- Good fit for: Irish SMEs wanting a local, managed audit programme across more than one management standard.
- cgbusinessconsulting.com
Evalian
- Market: UK.
- Offer: A dedicated ISO internal-audit service (27001, 9001, 22301) delivered one-off or ongoing: scoping, plan, schedule, onsite or remote audit, and a report with nonconformities and improvement opportunities.
- Delivery & pricing: Remote or onsite; pricing not published.
- Good fit for: Buyers who want a clearly staged process and an unusually thorough FAQ covering “who can perform it” and “can it be outsourced”.
- evalian.co.uk
Ledger Audits
- Market: UK, EU, Australia, UAE.
- Offer: A purpose-built brand for outsourced ISO 27001 internal audit (“Clause 9.2 requires an internal audit. It does not require you to do it yourself.”), targeting 30–250-person companies; multi-framework extensions (27017/27018/27701) and SOC 2 coordination for US-facing sellers.
- Delivery & pricing: Single audit cycle or an annual “Assurance Program”; pricing not published.
- Good fit for: Growth-stage software companies whose core problem is the small-team independence conflict.
- ledgeraudits.com
Romano Security Consulting
- Market: UK, onsite and remote; public-sector eligible via G-Cloud.
- Offer: Internal-audit resource with a detailed nonconformity report, delivered by consultants listed as CISM/CISA/CCP/Lead-Auditor qualified.
- Delivery & pricing: Published day rates of £750–£1,000 on the government’s Digital Marketplace (per G-Cloud listing as of 07-08-2026; pricing document not re-verified), the most transparent pricing found in this research.
- Good fit for: Buyers who want rate-card pricing and formal qualifications, including public-sector procurement.
- Digital Marketplace (G-Cloud) listing
Secrotec
- Market: Netherlands.
- Offer: Internal-audit and hired Lead Auditor services for ISO 27001, with a published “outsource or DIY?” guide advising outsourcing for most SMEs; cites ISO 19011 qualifications and warns against “certified in a few weeks” promises.
- Delivery & pricing: Pricing not published.
- Good fit for: Dutch and EU-headquartered software companies wanting a mainland-Europe auditor.
- secrotec.nl
URM Consulting
- Market: UK.
- Offer: A flexible range from planning and running a full three-year ISO 27001 audit programme to individual audits, alongside 22301/20000/9001; explicitly pitches the competence-plus-impartiality gap as the reason to outsource, and also offers a dedicated ISO 42001 internal-audit page.
- Delivery & pricing: Pricing not published.
- Good fit for: Organisations wanting a multi-year audit programme designed and run end-to-end by a long-established consultancy.
- urmconsulting.com
What buyers actually say
The following reflects how buyers and practitioners talk about this decision on Reddit (r/ISO27001, r/cybersecurity, collected 07-08-2026). It is practitioner sentiment, not verified fact:
- The small-team independence problem is the trigger. One startup founder put it: “since our small team designed and operates most of the controls, conducting the audit ourselves would not provide sufficient independence.”
- “You can review your work, not audit.” The most-quoted line in the threads, and the reason practitioners give for CBs rejecting internal audits signed off by the person who built the system (anecdote, unverified).
- Peer-swap arrangements exist. Practitioners describe consultancy teams auditing each other’s clients (“we audit each other’s work”) and even barter arrangements between founders (“I traded my capabilities as an internal auditor… and received the favour for internal audit”). These can satisfy independence in principle, but you carry the burden of evidencing competence and impartiality.
- A tough internal audit is valued, not feared. Buyers describe internal audits that surfaced “20 NCs and 40 OFIs” two months before the external audit as money well spent, the recurring vocabulary is “trial run” and “dry run”.
- The skip-and-scramble pattern is real. Consultants describe clients who “ghost us… then expect everything to be done in the couple months up to the surveillance audit”, and one thread describes a company that asked an AI assistant whether it needed a second-year internal audit, was told no, and hit a major nonconformity at surveillance (an account we could not verify; the grading position is in our sibling guide).
Frequently asked questions
1. Who can perform an ISO 27001 internal audit?
Anyone who is competent and independent of the work audited: a trained employee, a peer from another organisation, or an outsourced provider. The standards framework explicitly allows an internal audit to be “conducted by the organisation itself, or by an external party on its behalf” (ISO Harmonized Structure, term 3.18, Note 2). The auditor must not audit their own work (clause 9.2.2(b), paraphrased).
2. Can we do our own internal audit?
Yes, if you can evidence both competence (clause 7.2) and genuine independence. In a 12–50 person software company where the same people built and operate the controls, independence is usually the harder test, which is why small teams most often outsource.
3. Can our certification body do our internal audit?
No. ISO/IEC 27006-1 clause 5.2.2 prohibits the certification body from providing internal ISMS reviews or being connected to whoever performs your internal audit, and European Accreditation (FAQ Q49.4, March 2025) confirms there is no two-year cooling-off mitigation for ISMS, it can never happen.
4. Can the consultancy that built our ISMS audit it?
It should not. Clause 9.2.2(b) requires auditor selection that ensures objectivity and impartiality (paraphrased), and certification auditors treat builder-audits as a conflict of interest. Ask any combined build-and-audit provider how the teams are separated, and expect the answer in writing.
5. Does an ISO 27001 internal auditor need a certificate?
No. Neither ISO 27001 nor ISO 42001 requires the internal auditor to hold a Lead Auditor or Internal Auditor certificate. What must be demonstrable is competence, through education, training or experience, with documented evidence retained (clause 7.2, paraphrased). ISO/IEC 27007:2020 frames auditor requirements as competence guidance, not certification.
6. How much does an outsourced ISO 27001 internal audit cost?
Published anchors are rare. As of 07-08-2026: Romano Security Consulting lists £750–£1,000/day on the UK government’s G-Cloud marketplace (listing live as of 07-08-2026; pricing document not re-verified), and Assent states an indicative ~£1,600 for a basic two-day remote audit. Scope, sampling depth and onsite-vs-remote delivery move the price most.
7. How often do we need an internal audit?
The standard says only “at planned intervals”, there is no fixed annual mandate in clause 9.2.1. Certification practice has converged on at least one full internal-audit cycle per year, driven by annual surveillance audits and the management-review linkage (published practitioner guidance). Your own documented programme sets the bar your CB will hold you to.
8. Can we outsource the entire internal audit function?
Yes, the execution. The standard contemplates an external party conducting the audit on your behalf. But you cannot outsource ownership: the audit programme, the management review that receives its results, and the corrective actions remain your organisation’s responsibility under clauses 9.2, 9.3 and 10.2.