// case study · iso 27001 internal audit

An independent ISO 27001 internal audit for a financial-services data platform

How an ISO 27001-certified fintech closed historical findings, strengthened surveillance-audit readiness and learned to run its own internal audits — over a twelve-month program.

ISO/IEC 27001  ·  Annex A controls  ·  surveillance audit readiness  ·  customer due diligence

// the business

A data-sharing platform that banks and lenders have to trust

An Australian fintech running a data-sharing platform for the financial-services sector. Their customers are banks, lenders and the businesses that need to move regulated financial data between them safely, which means every customer runs security due diligence before signing and repeats it at renewal. The company holds ISO/IEC 27001 certification, has a CISO, and runs a small engineering team that has to keep shipping while staying audit-ready.

Certification is not the finish line for a business like this: surveillance audits come every year, recertification every three, and customer questionnaires every month.

Sector: financial services (data-sharing platform)  ·  Certification: ISO/IEC 27001  ·  Team: CISO + small engineering team  ·  Engagement: 12 months

// the situation

Surveillance audits and customer due diligence were coming

The business needed an independent internal audit against ISO/IEC 27001 to prepare for surveillance audits and the due diligence its customers run. Internal audit has to be genuinely independent of the people who own the controls — certification auditors look for that first — and the findings had to be evidence-backed and reproducible, not opinions. Earlier reviews had left major findings open, and evidence was hard to trace back to the control it supported.

// what we did

A full Annex A program, sampled where it counts

We planned and executed an internal audit program across the Annex A control set, then went below the policy layer to check that the controls actually operate:

  • sampled the technical controls that fail most often in practice — access management, logging and monitoring, vulnerability management, backup and restore
  • reviewed database and application-layer evidence; verified hardening baselines and identity governance
  • issued nonconformity and opportunity-for-improvement reports, and facilitated root-cause analysis and risk treatment plans with the control owners
  • delivered a targeted remediation roadmap prioritised by risk and audit criticality — sized for a small engineering team to work through without service disruption
// outcome

Historical gaps closed, and the next audit is theirs to run

  • major findings carried over from earlier reviews closed
  • evidence traceability improved — each finding tied to something an external auditor can reproduce
  • stakeholder confidence lifted ahead of external audits and customer assessments
  • control owners coached to run future internal audits using our templates, cutting the cost and disruption of ongoing assurance

Independence preserved throughout, every finding evidence-backed, and no dependence on Securitribe tooling left behind.

// how we worked

Independent, evidence-led, and built to hand over

Internal audit only has value if it is independent, so we kept it that way: no involvement in operating the controls we audited, and every finding backed by evidence the client can show an external auditor. We wrote remediation as tasks an engineer can pick up, not as a report that sits on a shelf. Vendor-neutral by design, with cloud-native controls before any third-party tooling and the trade-offs written down rather than buried. Least-privilege access for our own staff, no secondary use of client data, and change approvals logged. Skills transfer through paired delivery and runbooks, so the client’s people run the result — the point is to reduce their future spend on us, not to create it.

// why it matters

Certification is the start of the obligation, not the end

Holding ISO 27001 means surveillance audits every year and recertification every three, on top of the questionnaires enterprise customers send. The internal audit is where most certified businesses are weakest: it gets done by the same people who run the controls, it samples the easy things, and findings are recorded without evidence. When an auditor raises that as a nonconformance, the fix is an independent program — which is exactly what this engagement delivered.

Related: all case studies

// next step

Not sure which obligations actually bind you?

Start with the free Obligations Check: one 30-minute conversation and a one-page read on what genuinely applies to your business. If a full assessment is the right next step, we’ll say so — and if it isn’t, we’ll say that too.