ISO 27001 internal audits: how small businesses can prepare (and why a remote auditor makes it easier)
- Emily Schlaikier
- 2 days ago
- 3 min read
If you're certified to ISO 27001 or working towards it, an internal audit isn't optional. It's a mandatory part of the standard (clause 9.2), and it has to happen at least once a year. For a small business, that can feel like a lot of admin on top of an already-stretched to-do list. Here's what's actually required, how to prepare without losing a week to it, and why doing it remotely often works better than having someone on-site.

What the internal audit actually checks
The internal audit isn't a test you pass or fail. It's a check on two things: does your Information Security Management System (ISMS) meet the requirements of ISO 27001 and your own policies, and is it actually working day to day, not just written down somewhere.
An auditor will want to see evidence, not just documents. That means things like: access to systems is reviewed and revoked when people leave, backups are actually tested, incidents (even small ones) are logged and followed up, and supplier access is controlled. A policy that says this happens isn't enough - they'll want to see it happening.
Why small businesses find this trickier than they expect
Two things trip people up. First, evidence gaps - teams often do the right things but don't record them, so there's nothing to show an auditor. Second, independence. ISO 27001 requires that auditors don't audit their own work. In a five-person company, that's genuinely hard - if the same person manages IT and reviews IT controls, you've got a problem the standard flags directly.
How to prepare
A few things make the audit far less stressful:
Pull together your Statement of Applicability (SOA), your ISMS policies, and last year's audit findings before the audit date, not the morning of.
Check the high-impact areas first: access management, incident response, backups, supplier access, change control. These are where auditors tend to focus, and where gaps cause the most trouble.
Do a quick internal readiness check a few weeks out - walk through your own controls and ask "could I show evidence of this right now?" If the answer's no, fix it before the audit, not during.
Confirm who's auditing what, so you're not asking someone to review their own work.
Why a remote auditor is worth considering
For a small business, bringing an auditor on-site for a full day is often more disruptive and more expensive than it needs to be. A remote auditor can review documentation, run interviews over video, and check evidence electronically - all without anyone needing to clear a room or lose a day to hosting. It's also easier to schedule in shorter, focused sessions rather than one long block, which tends to suit smaller teams juggling audits alongside everything else.
It solves the independence problem too. If your business is small enough that nobody internal can audit impartially, an external (and often remote) auditor sidesteps that entirely - and you're not limited to whoever happens to be local. You get someone with real ISO 27001 audit experience, rather than whoever's within driving distance.
None of this changes what the audit covers. It just makes the process lighter to run.
If you'd like a hand with your internal audit - Maven offers this remotely, so no downtime and no one needing to clear their diary for a site visit. Get in touch and we'll talk through what it would look like for you.




Comments