ISO 27001 Compliance Audit FAQs
Why does KirkpatrickPrice only offer ISO 27001 audits and not certification?
When you pursue an ISO 27001 certification, best practice is to hire one firm to perform the audit and a separate firm for the certification process. This process may seem tedious, but it instills independence so that conflict of interest is never a concern.
KirkpatrickPrice only offers ISO 27001 audits and consulting. Our firm is not a certifying body, so any quotes on our ISO 27001 services will never include certification. If you are considering working with a firm that offers both auditing and certification services or has a partnership with another organization in order to offer both, this is a red flag. It indicates a lack of integrity and a conflict of interest, which could have negative implications on your audit and certification.
Many organizations opt to undergo the ISO 27001 audit and not pursue certification. Certification is a possibility, not a requirement. In this scenario, you will have an ISO 27001 report to offer clients and stakeholders who need assurance of your ISMS’ effectiveness, and you only need to work with one firm for your ISO 27001 needs. Learn more here.
What do I receive when my ISO 27001 audit is complete?
An ISO 27001 audit culminates in a report, written by our in-house Professional Writing team. The report will provide stakeholders with independent third-party verification regarding the fairness and suitability of information security management, controls, and practices.
How much does an ISO 27001 audit cost?
Pricing for an ISO 27001 audit depends on scoping factors, including business applications, technology platforms, physical locations, third parties, and audit frequency. Pricing will also vary based on the inclusion of a gap analysis, or inclusion of additional remediation time.
How long does an ISO 27001 audit take to complete?
The average ISO 27001 audit, using KirkpatrickPrice’s process, is completed in 12 weeks. The engagement begins with scoping procedures, then moves into an onsite visit, evidence review, report writing, and concludes with the delivery of a report.
How long is an ISO 27001 report valid?
The opinion stated in an ISO 27001 report is valid for twelve months following the date the report was issued.
How frequently does an ISO 27001 audit need to be performed?
Industry-standard is to schedule an ISO 27001 audit to be performed annually or when significant changes are made that will impact the control environment. Any frequency less than every three years typically indicates that the organization has not been properly maintaining compliance.